This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

avg says threat detected

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

im constantly getting this avg box every 5 mins… saying threat detected!
and the description says
file inaccesible…trojan downloader
here is the hijack this log..




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:14:06 AM, on 9/5/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Users\betson\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\betson\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (GoogleUpdateBeta) - Unknown owner - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ansys JobManager Service V11 (JobManagerService110) - Ansys, Inc - C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe
O23 - Service: Ansys ScriptHost Service V11 (ScriptHostService110) - Ansys, Inc. - C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 6374 bytes


hope this helps…..pls suggest me what to do?
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

Rootkit UnHooker (RkU)
Please download Rootkit Unhooker … Save it to your Desktop.
Note: The log can be very long, you may need to post it separately.
  • Double-click on RKUnhookerLE.exe to execute it.
    Vista - W7 users: Right click RKUnhookerLE.exe, choose "Run As Administrator" to execute it. If UAC prompts, please allow it.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth Code, Files and Code Hooks. Uncheck the rest. then Click OK. (See image below…)
    🖼Click to load external image (Posted Image)
    The scanning will toggle through the checked items "tabs" … it will take a while, so please be patient.
  • When the scanner is finished… click File, Save Report.
  • Save the file "Report.txt" to your Desktop… Press Close… then press Yes
  • Copy the entire contents of the Report.txt file in you're next reply.

Please Note:
You may get this warning, it is ok, just ignore it:
"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"




NEXT:



Please download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Enter 'Y' and hit ENTER for more options, or 'N' to exit:


Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.



NEXT:



  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %USERPROFILE%\Templates\*.*
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
here are the results as you had asked

1.rku
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows 7
Version 6.1.7600
Number of processors #2
==============================================
>Drivers
==============================================
0x9162C000 C:\Windows\system32\DRIVERS\igdkmd32.sys 5230592 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x82E4C000 C:\Windows\system32\ntkrnlpa.exe 4259840 bytes (Microsoft Corporation, NT Kernel & System)
0x82E4C000 PnpManager 4259840 bytes
0x82E4C000 RAW 4259840 bytes
0x82E4C000 WMIxWDM 4259840 bytes
0x98E50000 Win32k 2400256 bytes
0x98E50000 C:\Windows\System32\win32k.sys 2400256 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8B628000 C:\Windows\System32\drivers\tcpip.sys 1347584 bytes (Microsoft Corporation, TCP/IP Driver)
0x8B218000 C:\Windows\System32\Drivers\Ntfs.sys 1241088 bytes (Microsoft Corporation, NT File System Driver)
0x90A28000 C:\Windows\system32\DRIVERS\bcmwl6.sys 1146880 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver)
0x9203B000 C:\Windows\system32\DRIVERS\VSTDPV3.SYS 1056768 bytes (Conexant Systems, Inc., HSF_DP driver)
0x91B29000 C:\Windows\System32\drivers\dxgkrnl.sys 749568 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8B403000 C:\Windows\system32\drivers\ndis.sys 749568 bytes (Microsoft Corporation, NDIS 6.20 driver)
0x9213D000 C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 741376 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0x838FD000 C:\Windows\system32\CI.dll 700416 bytes (Microsoft Corporation, Code Integrity Module)
0x9C26E000 C:\Windows\system32\drivers\peauth.sys 618496 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x9A427000 C:\Windows\system32\drivers\HTTP.sys 544768 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8382A000 C:\Windows\system32\mcupdate_GenuineIntel.dll 491520 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x83A24000 C:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime)
0x99428000 C:\Windows\System32\Drivers\bthport.sys 409600 bytes (Microsoft Corporation, Bluetooth Bus Driver)
0x90C23000 C:\Windows\system32\drivers\csc.sys 409600 bytes (Microsoft Corporation, Windows Client Side Caching Driver)
0x8B385000 C:\Windows\System32\Drivers\cng.sys 380928 bytes (Microsoft Corporation, Kernel Cryptography, Next Generation)
0x8FECB000 C:\Windows\system32\drivers\afd.sys 368640 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x9C205000 C:\Windows\System32\DRIVERS\srv.sys 331776 bytes (Microsoft Corporation, Server driver)
0x90F2C000 C:\Windows\system32\drivers\HdAudio.sys 327680 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0x90D9E000 C:\Windows\system32\DRIVERS\yk62x86.sys 327680 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.)
0x9A592000 C:\Windows\System32\DRIVERS\srv2.sys 323584 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x99100000 C:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0x90D53000 C:\Windows\system32\DRIVERS\USBPORT.SYS 307200 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x83B65000 C:\Windows\System32\drivers\volmgrx.sys 307200 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x83AA3000 C:\Windows\system32\DRIVERS\ACPI.sys 294912 bytes (Microsoft Corporation, ACPI Driver for NT)
0x99576000 C:\Windows\system32\DRIVERS\nwifi.sys 286720 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x90E9A000 C:\Windows\system32\DRIVERS\usbhub.sys 278528 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x838BB000 C:\Windows\system32\CLFS.SYS 270336 bytes (Microsoft Corporation, Common Log File System Driver)
0x8FF8D000 C:\Windows\system32\DRIVERS\rdbss.sys 266240 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8B7AB000 C:\Windows\system32\DRIVERS\volsnap.sys 258048 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x8B4BA000 C:\Windows\system32\drivers\NETIO.SYS 253952 bytes (Microsoft Corporation, Network I/O Subsystem)
0x90EEF000 C:\Windows\system32\DRIVERS\VSTAZL3.SYS 249856 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0x9A53C000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 241664 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8FE5F000 C:\Windows\System32\Drivers\avgtdix.sys 237568 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)
0x90D1A000 C:\Windows\System32\drivers\dxgmms1.sys 233472 bytes (Microsoft Corporation, DirectX Graphics MMS)
0x82E15000 ACPI_HAL 225280 bytes
0x82E15000 C:\Windows\system32\halmacpi.dll 225280 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x90CB3000 C:\Windows\System32\Drivers\avgldx86.sys 212992 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)
0x839A8000 C:\Windows\system32\drivers\fltmgr.sys 212992 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x90E58000 C:\Windows\system32\DRIVERS\ks.sys 212992 bytes (Microsoft Corporation, Kernel CSA Library)
0x8B54A000 C:\Windows\System32\DRIVERS\fvevol.sys 204800 bytes (Microsoft Corporation, BitLocker Drive Encryption Driver)
0x8FE99000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x8B771000 C:\Windows\System32\drivers\fwpkclnt.sys 200704 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x92000000 C:\Windows\system32\drivers\portcls.sys 192512 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x8B51D000 C:\Windows\System32\drivers\rdyboost.sys 184320 bytes (Microsoft Corporation, ReadyBoost Driver)
0x90B4A000 C:\Windows\system32\DRIVERS\1394ohci.sys 180224 bytes (Microsoft Corporation, 1394 OpenHCI Driver)
0x8B347000 C:\Windows\System32\Drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x83AFC000 C:\Windows\system32\DRIVERS\pci.sys 172032 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x8B58D000 C:\Windows\system32\DRIVERS\CLASSPNP.SYS 151552 bytes (Microsoft Corporation, SCSI Class System Dll)
0x8B4F8000 C:\Windows\System32\Drivers\ksecpkg.sys 151552 bytes (Microsoft Corporation, Kernel Security Support Provider Interface Packages)
0x9948C000 C:\Windows\system32\DRIVERS\rfcomm.sys 147456 bytes (Microsoft Corporation, Bluetooth RFCOMM Driver)
0x90FAC000 C:\Windows\System32\Drivers\usbvideo.sys 147456 bytes (Microsoft Corporation, USB Video Class Driver)
0x83A00000 C:\Windows\system32\DRIVERS\ataport.SYS 143360 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9A519000 C:\Windows\system32\DRIVERS\mrxsmb.sys 143360 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x90C00000 C:\Windows\system32\DRIVERS\ndiswan.sys 139264 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x9A4F8000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x9A4AC000 C:\Windows\System32\DRIVERS\srvnet.sys 135168 bytes (Microsoft Corporation, Server Network driver)
0x90CE7000 C:\Windows\system32\DRIVERS\tunnel.sys 135168 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x83800000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0x8B5CD000 C:\Windows\system32\DRIVERS\cdrom.sys 126976 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0x91600000 C:\Windows\system32\DRIVERS\HDAudBus.sys 126976 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x8FF2C000 C:\Windows\system32\DRIVERS\pacer.sys 126976 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x990E0000 C:\Windows\System32\cdd.dll 122880 bytes (Microsoft Corporation, Canonical Display Driver)
0x994BD000 C:\Windows\system32\DRIVERS\bthpan.sys 110592 bytes (Microsoft Corporation, Bluetooth Personal Area Networking)
0x99531000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0x9A577000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 110592 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x9954C000 C:\Windows\system32\drivers\WudfPf.sys 106496 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0x9A4CD000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x90F7C000 C:\Windows\system32\drivers\drmk.sys 102400 bytes (Microsoft Corporation, Microsoft Trusted Audio Drivers)
0x90B76000 C:\Windows\system32\DRIVERS\sdbus.sys 102400 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0x90C87000 C:\Windows\System32\Drivers\dfsc.sys 98304 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x90B8F000 C:\Windows\system32\DRIVERS\i8042prt.sys 98304 bytes (Microsoft Corporation, i8042 Port Driver)
0x90A00000 C:\Windows\system32\DRIVERS\rasl2tp.sys 98304 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0x8FE00000 C:\Windows\system32\DRIVERS\raspppoe.sys 98304 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x90E1E000 C:\Windows\system32\DRIVERS\raspptp.sys 94208 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x90E35000 C:\Windows\system32\DRIVERS\rassstp.sys 94208 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8FE3D000 C:\Windows\system32\DRIVERS\tdx.sys 94208 bytes (Microsoft Corporation, TDI Translation Driver)
0x90F95000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0x83BC5000 C:\Windows\System32\drivers\mountmgr.sys 90112 bytes (Microsoft Corporation, Mount Point Manager)
0x994F5000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 77824 bytes (Microsoft Corporation, Hid Class Library)
0x8B372000 C:\Windows\System32\Drivers\ksecdd.sys 77824 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x995CC000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x8FF6A000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x90BDE000 C:\Windows\system32\DRIVERS\AgileVpn.sys 73728 bytes (Microsoft Corporation, RAS Agile Vpn Miniport Call Manager)
0x994D8000 C:\Windows\system32\DRIVERS\bthmodem.sys 73728 bytes (Microsoft Corporation, Bluetooth Communications Driver)
0x90E0A000 C:\Windows\System32\Drivers\BTHUSB.sys 73728 bytes (Microsoft Corporation, Bluetooth Miniport Driver)
0x90D08000 C:\Windows\system32\DRIVERS\intelppm.sys 73728 bytes (Microsoft Corporation, Processor Device Driver)
0x9A4E6000 C:\Windows\System32\drivers\mpsdrv.sys 73728 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8B57C000 C:\Windows\system32\DRIVERS\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x90FE8000 C:\Windows\System32\Drivers\dump_dumpfve.sys 69632 bytes
0x839DC000 C:\Windows\system32\drivers\fileinfo.sys 69632 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x90EDE000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x83B31000 C:\Windows\System32\drivers\partmgr.sys 69632 bytes (Microsoft Corporation, Partition Management Driver)
0x838A2000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x8FF4B000 C:\Windows\system32\DRIVERS\vwififlt.sys 69632 bytes (Microsoft Corporation, Virtual WiFi Filter Driver)
0x99566000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x8B600000 C:\Windows\System32\Drivers\mup.sys 65536 bytes (Microsoft Corporation, Multiple UNC Provider Driver)
0x995BC000 C:\Windows\system32\DRIVERS\ndisuio.sys 65536 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x8FF7D000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Remote Desktop Server Driver)
0x83B55000 C:\Windows\system32\DRIVERS\volmgr.sys 65536 bytes (Microsoft Corporation, Volume Manager Driver)
0x91BEB000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x90C9F000 C:\Windows\system32\DRIVERS\blbdrive.sys 57344 bytes (Microsoft Corporation, BLB Drive Driver)
0x8FF5C000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8FE2F000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x83BB7000 C:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8B3E2000 C:\Windows\System32\drivers\pcw.sys 57344 bytes (Microsoft Corporation, Performance Counters for Windows Driver)
0x90E8C000 C:\Windows\system32\DRIVERS\umbus.sys 57344 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x83A95000 C:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader)
0x994B0000 C:\Windows\system32\DRIVERS\BthEnum.sys 53248 bytes (Microsoft Corporation, Bluetooth Bus Extender)
0x90BD1000 C:\Windows\system32\DRIVERS\CompositeBus.sys 53248 bytes (Microsoft Corporation, Multi-Transport Composite Bus Enumerator)
0x90FD0000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x90BB4000 C:\Windows\system32\DRIVERS\kbdclass.sys 53248 bytes (Microsoft Corporation, Keyboard Class Driver)
0x921F2000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x90BA7000 C:\Windows\system32\DRIVERS\mouclass.sys 53248 bytes (Microsoft Corporation, Mouse Class Driver)
0x9C379000 C:\Windows\System32\drivers\tcpipreg.sys 53248 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x839ED000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver)
0x8FFE2000 C:\Windows\System32\drivers\discache.sys 49152 bytes (Microsoft Corporation, System Indexer/Cache Driver)
0x9950F000 C:\Windows\system32\DRIVERS\kbdhid.sys 49152 bytes (Microsoft Corporation, HID Keyboard Filter Driver)
0x8B200000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x83B4A000 C:\Windows\system32\DRIVERS\BATTC.SYS 45056 bytes (Microsoft Corporation, Battery Class Driver)
0x90FDD000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes
0x994EA000 C:\Windows\system32\DRIVERS\hidusb.sys 45056 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0x99526000 C:\Windows\system32\DRIVERS\monitor.sys 45056 bytes (Microsoft Corporation, Monitor Driver)
0x9951B000 C:\Windows\system32\DRIVERS\mouhid.sys 45056 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0x8FE24000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x90A18000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8FE54000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x91BE0000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x83B26000 C:\Windows\system32\DRIVERS\vdrvroot.sys 45056 bytes (Microsoft Corporation, Virtual Drive Root Enumerator)
0x92031000 C:\Windows\System32\Drivers\dump_msahci.sys 40960 bytes
0x90E00000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x83BE4000 C:\Windows\system32\DRIVERS\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8FFD8000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x8FFCE000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x90E4C000 C:\Windows\system32\DRIVERS\rdpbus.sys 40960 bytes (Microsoft Corporation, Microsoft RDP Bus Device driver)
0x9C305000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x90B40000 C:\Windows\system32\DRIVERS\vwifibus.sys 40960 bytes (Microsoft Corporation, Virtual WiFi Bus Driver)
0x83BEE000 C:\Windows\system32\DRIVERS\amdxata.sys 36864 bytes (Advanced Micro Devices, Storage Filter Driver)
0x83BDB000 C:\Windows\system32\DRIVERS\atapi.sys 36864 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x8B3F0000 C:\Windows\System32\Drivers\Fs_Rec.sys 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x9C386000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x990B0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8B7A2000 C:\Windows\system32\DRIVERS\vmstorfl.sys 36864 bytes (Microsoft Corporation, Virtual Storage Filter Driver)
0x90BC8000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x83AEB000 C:\Windows\system32\DRIVERS\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x838B3000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x83B42000 C:\Windows\system32\DRIVERS\compbatt.sys 32768 bytes (Microsoft Corporation, Composite Battery Driver)
0x8B610000 C:\Windows\System32\drivers\hwpolicy.sys 32768 bytes (Microsoft Corporation, Hardware Policy Driver)
0x80BB8000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Serial Kernel Debugger)
0x83AF4000 C:\Windows\system32\DRIVERS\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8B20C000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x83BF7000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Encoder Miniport)
0x83821000 C:\Windows\system32\drivers\rdprefmp.sys 32768 bytes (Microsoft Corporation, RDP Reflector Driver Miniport)
0x8B7EA000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8B5F3000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x99508000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x83BB0000 C:\Windows\system32\DRIVERS\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x8B5EC000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8FF25000 C:\Windows\system32\DRIVERS\wfplwf.sys 28672 bytes (Microsoft Corporation, WFP NDIS 6.20 Lightweight Filter Driver)
0x90CAD000 C:\Windows\System32\Drivers\avgmfx86.sys 24576 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver)
0x90BC4000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x90BC1000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 12288 bytes (GEAR Software Inc., CD DVD Filter)
0x90E56000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x9202F000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
!!!!!!!!!!!Hidden driver: 0x8649C8C3 ?_empty_? 1853 bytes
0x8649CCA1 unknown_irp_handler 863 bytes
!!!!!!!!!!!Hidden driver: 0x866C8DE0 ?_empty_? 0 bytes
==============================================
>Stealth
==============================================
0x83BDB000 WARNING: suspicious driver modification [atapi.sys::0x8649C8C3]
0x003A0000 Hidden Image–>ANSYS.JobManager.dll [ EPROCESS 0x87C03588 ] PID: 320, 126976 bytes
0x00510000 Hidden Image–>ANSYS.ScriptEngine.dll [ EPROCESS 0x87B08030 ] PID: 900, 126976 bytes
0x008F0000 Hidden Image–>ANSYS.JobManager.Common.dll [ EPROCESS 0x87C03588 ] PID: 320, 36864 bytes
0x9C339F2E Unknown thread object [ ETHREAD 0x87D56220 ] , 600 bytes
==============================================
>Files
==============================================
==============================================
>Hooks
==============================================
[1180]svchost.exe–>mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x74F32BBC–>00000000 [unknown_code_page]
[1180]svchost.exe–>mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x74F344B1–>00000000 [unknown_code_page]
[1180]svchost.exe–>mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x74F346B7–>00000000 [unknown_code_page]
[1180]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77486448–>00000000 [unknown_code_page]
[1180]svchost.exe–>ntdll.dll–>NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77485360–>00000000 [unknown_code_page]
[1180]svchost.exe–>ntdll.dll–>NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77485EE0–>00000000 [unknown_code_page]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x77C6178C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77C617F0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x77C61848–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77C617B8–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x77C61844–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>RegCreateKeyA, Type: IAT modification 0x00404014–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>RegSetValueExA, Type: IAT modification 0x00404010–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x77B61154–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77B611E0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x77B6118C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77B611B8–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x00404030–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>shell32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x738022B8–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>shell32.dll–>kernel32.dll–>MoveFileExW, Type: IAT modification 0x73802240–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>shell32.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x7380228C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77D11524–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77D114E0–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>RegCreateKeyExW, Type: IAT modification 0x77D114B4–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>RegOpenKeyExW, Type: IAT modification 0x77D11444–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>RegSetValueExW, Type: IAT modification 0x77D114AC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegCreateKeyExA, Type: IAT modification 0x71201284–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegCreateKeyExW, Type: IAT modification 0x712011D0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegDeleteValueA, Type: IAT modification 0x71201244–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegDeleteValueW, Type: IAT modification 0x712011D8–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegOpenKeyExA, Type: IAT modification 0x7120128C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegOpenKeyExW, Type: IAT modification 0x71201268–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegSetValueExA, Type: IAT modification 0x71201288–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegSetValueExW, Type: IAT modification 0x712011DC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>CopyFileA, Type: IAT modification 0x712012DC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>CreateFileA, Type: IAT modification 0x712014CC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x712014D0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>DeleteFileA, Type: IAT modification 0x712014F4–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x71201448–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7120144C–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileA, Type: IAT modification 0x71201318–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileExA, Type: IAT modification 0x71201444–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileExW, Type: IAT modification 0x71201310–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x71201314–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>SetFileAttributesA, Type: IAT modification 0x7120132C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>SetFileAttributesW, Type: IAT modification 0x71201400–>00000000 [AcGenral.dll]
[288]plugin-container.exe–>user32.dll–>TrackPopupMenu, Type: Inline - RelativeJump 0x75CF4B3B–>00000000 [xul.dll]
[2900]firefox.exe–>mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x74F32BBC–>00000000 [unknown_code_page]
[2900]firefox.exe–>mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x74F344B1–>00000000 [unknown_code_page]
[2900]firefox.exe–>mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x74F346B7–>00000000 [unknown_code_page]
[2900]firefox.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77486448–>00000000 [unknown_code_page]
[2900]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7749F585–>00000000 [firefox.exe]
[2900]firefox.exe–>ntdll.dll–>NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77485360–>00000000 [unknown_code_page]
[2900]firefox.exe–>ntdll.dll–>NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77485EE0–>00000000 [unknown_code_page]
[3124]explorer.exe–>mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x74F32BBC–>00000000 [unknown_code_page]
[3124]explorer.exe–>mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x74F344B1–>00000000 [unknown_code_page]
[3124]explorer.exe–>mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x74F346B7–>00000000 [unknown_code_page]
[3124]explorer.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77486448–>00000000 [unknown_code_page]
[3124]explorer.exe–>ntdll.dll–>NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77485360–>00000000 [unknown_code_page]
[3124]explorer.exe–>ntdll.dll–>NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77485EE0–>00000000 [unknown_code_page]



















——————————————————————————-
2.mbr

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron 1525
Logical Drives Mask: 0x000000bc

Kernel Drivers (total 170):
0x82E1D000 \SystemRoot\system32\ntkrnlpa.exe
0x8322D000 \SystemRoot\system32\halmacpi.dll
0x80BCE000 \SystemRoot\system32\kdcom.dll
0x83819000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x83891000 \SystemRoot\system32\PSHED.dll
0x838A2000 \SystemRoot\system32\BOOTVID.dll
0x838AA000 \SystemRoot\system32\CLFS.SYS
0x838EC000 \SystemRoot\system32\CI.dll
0x83A2C000 \SystemRoot\system32\drivers\Wdf01000.sys
0x83A9D000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x83AAB000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x83AF3000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x83AFC000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x83B04000 \SystemRoot\system32\DRIVERS\pci.sys
0x83B2E000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x83B39000 \SystemRoot\System32\drivers\partmgr.sys
0x83B4A000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x83B52000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x83B5D000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x83B6D000 \SystemRoot\System32\drivers\volmgrx.sys
0x83BB8000 \SystemRoot\system32\DRIVERS\intelide.sys
0x83BBF000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x83BCD000 \SystemRoot\System32\drivers\mountmgr.sys
0x83BE3000 \SystemRoot\system32\DRIVERS\atapi.sys
0x83A00000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x83BEC000 \SystemRoot\system32\DRIVERS\msahci.sys
0x83BF6000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x83997000 \SystemRoot\system32\drivers\fltmgr.sys
0x839CB000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B22E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B35D000 \SystemRoot\System32\Drivers\msrpc.sys
0x8B388000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B39B000 \SystemRoot\System32\Drivers\cng.sys
0x8B200000 \SystemRoot\System32\drivers\pcw.sys
0x8B20E000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8B428000 \SystemRoot\system32\drivers\ndis.sys
0x8B4DF000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B51D000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8B61D000 \SystemRoot\System32\drivers\tcpip.sys
0x8B766000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B797000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8B7A0000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8B7DF000 \SystemRoot\System32\Drivers\spldr.sys
0x8B542000 \SystemRoot\System32\drivers\rdyboost.sys
0x8B7E7000 \SystemRoot\System32\Drivers\mup.sys
0x8B7F7000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8B56F000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8B600000 \SystemRoot\system32\DRIVERS\disk.sys
0x8B5A1000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8B400000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8B41F000 \SystemRoot\System32\Drivers\Null.SYS
0x8B5EE000 \SystemRoot\System32\Drivers\Beep.SYS
0x8B217000 \SystemRoot\System32\drivers\vga.sys
0x839DC000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x83800000 \SystemRoot\System32\drivers\watchdog.sys
0x8B5F5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8B223000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8B3F8000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8380D000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90414000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90422000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90439000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x90444000 \SystemRoot\System32\Drivers\avgtdix.sys
0x9047E000 \SystemRoot\System32\DRIVERS\netbt.sys
0x904B0000 \SystemRoot\system32\drivers\afd.sys
0x9050A000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x90511000 \SystemRoot\system32\DRIVERS\pacer.sys
0x90530000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x90541000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9054F000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x90562000 \SystemRoot\system32\DRIVERS\termdd.sys
0x90572000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x905B3000 \SystemRoot\system32\drivers\nsiproxy.sys
0x905BD000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x905C7000 \SystemRoot\System32\drivers\discache.sys
0x90215000 \SystemRoot\system32\drivers\csc.sys
0x90279000 \SystemRoot\System32\Drivers\dfsc.sys
0x90291000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x9029F000 \SystemRoot\System32\Drivers\avgmfx86.sys
0x902A5000 \SystemRoot\System32\Drivers\avgldx86.sys
0x902D9000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x902FA000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x91625000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x91B22000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x9030C000 \SystemRoot\System32\drivers\dxgmms1.sys
0x91BD9000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x90345000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x91BE4000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x91600000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x90390000 \SystemRoot\system32\DRIVERS\yk62x86.sys
0x91200000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x91318000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x91322000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x9134E000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x91367000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x9137F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x9138C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x91399000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x9139C000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x913A0000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x913A9000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x913B6000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x913C8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x913E0000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x905D3000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x903E0000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x91E2C000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x91E43000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x91E5A000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x91E64000 \SystemRoot\system32\DRIVERS\swenum.sys
0x91E66000 \SystemRoot\system32\DRIVERS\ks.sys
0x91E9A000 \SystemRoot\system32\DRIVERS\umbus.sys
0x91EA8000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x91EEC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x91EFD000 \SystemRoot\system32\DRIVERS\VSTAZL3.SYS
0x91C3D000 \SystemRoot\system32\DRIVERS\VSTDPV3.SYS
0x91D3F000 \SystemRoot\system32\DRIVERS\VSTCNXT3.SYS
0x91C00000 \SystemRoot\system32\drivers\modem.sys
0x91F3A000 \SystemRoot\system32\drivers\HdAudio.sys
0x91C0D000 \SystemRoot\system32\drivers\portcls.sys
0x91F8A000 \SystemRoot\system32\drivers\drmk.sys
0x91FA3000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x91DF4000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x91FBA000 \SystemRoot\System32\Drivers\usbvideo.sys
0x91FDE000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x91E00000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x8C62E000 \SystemRoot\System32\Drivers\bthport.sys
0x8C692000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x8C6B6000 \SystemRoot\system32\DRIVERS\BthEnum.sys
0x8C6C3000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x8C6DE000 \SystemRoot\system32\DRIVERS\bthmodem.sys
0x8C6F0000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8C6FB000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8C70E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8C715000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8C721000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8C72C000 \SystemRoot\System32\Drivers\fastfat.SYS
0x8C756000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8C763000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8C76E000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x8C778000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x92A80000 \SystemRoot\System32\win32k.sys
0x8C789000 \SystemRoot\System32\drivers\Dxapi.sys
0x8C793000 \SystemRoot\system32\DRIVERS\monitor.sys
0x92CE0000 \SystemRoot\System32\TSDDD.dll
0x92D10000 \SystemRoot\System32\cdd.dll
0x8C79E000 \SystemRoot\system32\drivers\luafv.sys
0x8C7B9000 \SystemRoot\system32\drivers\WudfPf.sys
0x8C7D3000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x97E26000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x97E6C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x97E7C000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x97E8F000 \SystemRoot\system32\drivers\HTTP.sys
0x97F14000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x97F35000 \SystemRoot\system32\DRIVERS\bowser.sys
0x97F4E000 \SystemRoot\System32\drivers\mpsdrv.sys
0x97F60000 \SystemRoot\system32\drivers\mrxdav.sys
0x97F81000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x97FA4000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x97FDF000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xAB239000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAB288000 \SystemRoot\System32\DRIVERS\srv.sys
0xAB2F1000 \SystemRoot\system32\drivers\peauth.sys
0xAB388000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAB200000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAB22E000 \SystemRoot\System32\Drivers\Normandy.SYS
0x77890000 \Windows\System32\ntdll.dll
0x47C70000 \Windows\System32\smss.exe
0x77AD0000 \Windows\System32\apisetschema.dll
0x00F00000 \Windows\System32\autochk.exe

Processes (total 63):
0 System Idle Process
4 System
248 C:\Windows\System32\smss.exe
344 csrss.exe
380 C:\Windows\System32\wininit.exe
392 csrss.exe
404 C:\Program Files\AVG\AVG9\avgchsvx.exe
420 C:\Program Files\AVG\AVG9\avgrsx.exe
464 C:\Windows\System32\winlogon.exe
480 C:\Windows\System32\services.exe
496 C:\Windows\System32\lsass.exe
504 C:\Windows\System32\lsm.exe
688 C:\Program Files\AVG\AVG9\avgcsrvx.exe
696 C:\Windows\System32\svchost.exe
912 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1064 C:\Windows\System32\svchost.exe
1100 C:\Windows\System32\svchost.exe
1432 C:\Windows\System32\svchost.exe
1612 C:\Windows\System32\svchost.exe
1760 C:\Windows\System32\spoolsv.exe
1792 C:\Windows\System32\svchost.exe
1960 C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\intel\lmgrd.exe
1984 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
1992 C:\Windows\System32\conhost.exe
2028 C:\Program Files\AVG\AVG9\avgwdsvc.exe
112 C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\intel\lmgrd.exe
280 C:\Program Files\Bonjour\mDNSResponder.exe
304 C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\intel\ansyslmd.exe
272 C:\Windows\System32\svchost.exe
500 C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe
1008 C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe
1364 C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe
2052 C:\Program Files\AVG\AVG9\avgnsx.exe
2124 C:\Windows\System32\svchost.exe
2556 C:\Windows\System32\svchost.exe
2884 C:\Windows\System32\taskhost.exe
2948 C:\Windows\System32\dwm.exe
3020 C:\Windows\explorer.exe
3240 C:\Program Files\iTunes\iTunesHelper.exe
3252 C:\Program Files\AVG\AVG9\avgtray.exe
3264 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3336 C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
3356 C:\Users\betson\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
3368 C:\Program Files\LimeWire\LimeWire.exe
3388 C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
3708 C:\Program Files\iPod\bin\iPodService.exe
3780 C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
3920 C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
3960 C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
4008 C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
4076 C:\Windows\System32\SearchIndexer.exe
2900 C:\Program Files\Windows Media Player\wmpnetwk.exe
3344 C:\Program Files\Mozilla Firefox\firefox.exe
3540 C:\Windows\System32\svchost.exe
4328 C:\Program Files\Mozilla Firefox\plugin-container.exe
1244 C:\Windows\System32\audiodg.exe
6052 RKUnhookerLE.EXE
2372 C:\Windows\System32\SearchProtocolHost.exe
2680 C:\Windows\System32\SearchFilterHost.exe
5020 C:\Users\betson\Downloads\MBRCheck.exe
1140 C:\Windows\System32\conhost.exe
6036 C:\Windows\System32\dllhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000007`d0100000 (NTFS)
\\.\E: –> \\.\PhysicalDrive0 at offset 0x00000020`f5900000 (NTFS)

PhysicalDrive0 Model Number: WDCWD2500BEVS-75UST0, Rev: 01.01A01

Size Device Name MBR Status
——————————————–
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!


















———————————————————————————————————————————————————————-
3.otl

OTL logfile created on: 9/5/2010 10:09:43 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\betson\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 31.15 Gb Total Space | 1.12 Gb Free Space | 3.59% Space Free | Partition Type: NTFS
Drive D: | 100.59 Gb Total Space | 12.15 Gb Free Space | 12.08% Space Free | Partition Type: NTFS
Drive E: | 101.05 Gb Total Space | 1.19 Gb Free Space | 1.18% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 978.58 Mb Total Space | 309.96 Mb Free Space | 31.67% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: BETSON-PC
Current User Name: betson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\betson\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe (Google Inc)
PRC - C:\Users\betson\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)
PRC - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe (Ansys, Inc)
PRC - C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe (Ansys, Inc.)
PRC - C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\ansyslmd.exe ()
PRC - C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe (Macrovision Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\betson\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (GoogleUpdateBeta) – C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe (Google Inc)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (osppsvc) – C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (JobManagerService110) – C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe (Ansys, Inc)
SRV - (ScriptHostService110) – C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe (Ansys, Inc.)
SRV - (ANSYS FLEXlm license manager) – C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (upperdev) – C:\Windows\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (SrvHsfV92) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfWinac) – C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfHDA) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=937811"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.732

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/14 11:19:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/07/31 23:31:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/02 01:34:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox 3 Beta 5\components [2010/08/17 23:22:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3 Beta 5\plugins [2010/09/04 00:35:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/18 19:59:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/04 00:35:24 | 000,000,000 | —D | M]

[2010/05/14 20:47:42 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Extensions
[2010/05/14 20:47:42 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/05 01:27:24 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Firefox\Profiles\wgcprptx.default\extensions
[2010/08/18 20:01:09 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Firefox\Profiles\wgcprptx.default\extensions\[removed]
[2010/08/18 19:59:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/11 03:09:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - Startup: C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O4 - Startup: C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 03:12:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{f2c74a43-6ed0-11df-96ab-001fe2ddaedd}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/04 21:57:47 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\Buckyball-25th-anniversary-celebrated-by-interactive-Google-Doodle_files
[2010/09/04 21:57:41 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\Pac-Man-30th-anniversary-marked-by-Google-Doodle_files
[2010/09/04 21:44:04 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\hp.memristor_1_flash-memory-computer-memory-hp-labs_files
[2010/09/04 02:10:14 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/03 20:42:54 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\mcse
[2010/09/03 00:23:54 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2010/09/03 00:23:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/09/03 00:22:10 | 000,000,000 | —D | C] – C:\Program Files\Trojan Remover
[2010/09/03 00:22:10 | 000,000,000 | —D | C] – C:\ProgramData\Simply Super Software
[2010/09/02 01:34:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PCSuite
[2010/09/02 01:34:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010/09/02 01:33:38 | 000,000,000 | —D | C] – C:\Program Files\PC Connectivity Solution
[2010/09/01 01:04:32 | 000,000,000 | —D | C] – C:\Program Files\Wise Registry Cleaner 3
[2010/09/01 00:59:27 | 000,000,000 | —D | C] – C:\Program Files\Instant Player
[2010/08/29 15:20:50 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\quizlexia
[2010/08/25 00:35:47 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/08/25 00:35:37 | 000,000,000 | —D | C] – C:\Users\betson\AppData\Roaming\uTorrent
[2010/08/23 21:19:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/08/23 21:13:45 | 000,000,000 | —D | C] – C:\Program Files\SonicShack
[2010/08/20 18:45:09 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\proj
[2010/08/20 03:20:24 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\techtatva
[2010/08/19 23:17:49 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\TEE
[2010/08/18 19:59:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/08/15 21:54:18 | 000,000,000 | —D | C] – C:\Users\betson\.mnemosyne
[2010/08/15 21:53:54 | 000,000,000 | —D | C] – C:\Program Files\Mnemosyne
[2010/08/14 23:03:43 | 000,000,000 | —D | C] – C:\Users\betson\AppData\Local\Apps
[2010/08/14 23:03:41 | 000,000,000 | —D | C] – C:\Users\betson\AppData\Local\Deployment
[2010/08/14 10:15:01 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/08/13 22:14:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/13 22:13:57 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/08/13 22:13:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/08/13 22:13:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/08/09 21:34:22 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\New Folder

========== Files - Modified Within 30 Days ==========

[2010/09/05 10:11:22 | 003,145,728 | -HS- | M] () – C:\Users\betson\ntuser.dat
[2010/09/05 10:10:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001UA.job
[2010/09/05 09:38:58 | 064,319,035 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/09/05 09:38:09 | 000,010,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/05 09:38:09 | 000,010,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/05 09:33:06 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/05 09:32:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/05 09:32:35 | 2408,087,552 | -HS- | M] () – C:\hiberfil.sys
[2010/09/05 02:28:31 | 000,233,151 | —- | M] () – C:\Users\betson\Desktop\p275_chap1.pdf
[2010/09/05 00:48:57 | 000,693,124 | —- | M] () – C:\Windows\System32\perfh00C.dat
[2010/09/05 00:48:57 | 000,692,170 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2010/09/05 00:48:57 | 000,689,526 | —- | M] () – C:\Windows\System32\perfh013.dat
[2010/09/05 00:48:57 | 000,688,180 | —- | M] () – C:\Windows\System32\perfh010.dat
[2010/09/05 00:48:57 | 000,674,902 | —- | M] () – C:\Windows\System32\perfh019.dat
[2010/09/05 00:48:57 | 000,641,706 | —- | M] () – C:\Windows\System32\perfh007.dat
[2010/09/05 00:48:57 | 000,617,436 | —- | M] () – C:\Windows\System32\perfh01D.dat
[2010/09/05 00:48:57 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/05 00:48:57 | 000,461,294 | —- | M] () – C:\Windows\System32\perfh006.dat
[2010/09/05 00:48:57 | 000,448,222 | —- | M] () – C:\Windows\System32\perfh014.dat
[2010/09/05 00:48:57 | 000,433,070 | —- | M] () – C:\Windows\System32\perfh00B.dat
[2010/09/05 00:48:57 | 000,133,838 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2010/09/05 00:48:57 | 000,129,742 | —- | M] () – C:\Windows\System32\perfc013.dat
[2010/09/05 00:48:57 | 000,129,026 | —- | M] () – C:\Windows\System32\perfc019.dat
[2010/09/05 00:48:57 | 000,127,204 | —- | M] () – C:\Windows\System32\perfc00C.dat
[2010/09/05 00:48:57 | 000,126,062 | —- | M] () – C:\Windows\System32\perfc007.dat
[2010/09/05 00:48:57 | 000,124,140 | —- | M] () – C:\Windows\System32\perfc010.dat
[2010/09/05 00:48:57 | 000,120,782 | —- | M] () – C:\Windows\System32\perfc01D.dat
[2010/09/05 00:48:57 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/05 00:48:57 | 000,078,724 | —- | M] () – C:\Windows\System32\perfc00B.dat
[2010/09/05 00:48:57 | 000,076,754 | —- | M] () – C:\Windows\System32\perfc006.dat
[2010/09/05 00:48:57 | 000,074,136 | —- | M] () – C:\Windows\System32\perfc014.dat
[2010/09/05 00:48:56 | 007,770,798 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/04 23:10:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001Core.job
[2010/09/04 22:47:22 | 001,309,499 | —- | M] () – C:\Users\betson\Desktop\(PNG Image, 1280x546 pixels) - Scaled (98%).png
[2010/09/04 21:57:48 | 000,119,690 | —- | M] () – C:\Users\betson\Desktop\Buckyball-25th-anniversary-celebrated-by-interactive-Google-Doodle.html
[2010/09/04 21:57:43 | 000,113,676 | —- | M] () – C:\Users\betson\Desktop\Pac-Man-30th-anniversary-marked-by-Google-Doodle.html
[2010/09/04 21:44:06 | 000,058,061 | —- | M] () – C:\Users\betson\Desktop\hp.memristor_1_flash-memory-computer-memory-hp-labs.htm
[2010/09/04 15:19:59 | 002,049,323 | -H– | M] () – C:\Users\betson\AppData\Local\IconCache.db
[2010/09/04 02:10:14 | 000,002,969 | —- | M] () – C:\Users\betson\Desktop\HiJackThis.lnk
[2010/09/04 01:51:04 | 001,832,198 | —- | M] () – C:\Users\betson\Documents\nano_erasmus_mundus.pdf
[2010/09/04 01:50:57 | 000,236,960 | —- | M] () – C:\Users\betson\Documents\Electrical.pdf
[2010/09/04 01:50:18 | 001,874,524 | —- | M] () – C:\Users\betson\Documents\UNIVERSITYOFLEUVEN.pdf
[2010/09/04 01:50:05 | 001,278,016 | —- | M] () – C:\Users\betson\Documents\studying.pdf
[2010/09/04 01:48:11 | 004,424,200 | —- | M] () – C:\Users\betson\Documents\internationalprogrammes.pdf
[2010/09/03 12:34:17 | 002,027,366 | —- | M] () – C:\Users\betson\Documents\videoplayback.mp41.mp4
[2010/09/03 12:29:14 | 005,484,067 | —- | M] () – C:\Users\betson\Documents\Eye movement controled servo made by AGH MSIB student.mp4
[2010/09/03 12:25:43 | 001,738,251 | —- | M] () – C:\Users\betson\Documents\EOG - human computer interface.mp4
[2010/09/03 01:05:10 | 194,178,381 | —- | M] () – C:\Users\betson\Desktop\Lecture 5 Pixels Relationships II.mp4
[2010/09/02 21:51:30 | 000,392,677 | —- | M] () – C:\Users\betson\Documents\NSEWQuiz2007.pdf
[2010/09/02 10:01:51 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2010/08/31 20:28:44 | 000,294,248 | —- | M] () – C:\Users\betson\Documents\germany.docx
[2010/08/30 23:05:38 | 000,856,990 | —- | M] () – C:\Users\betson\Documents\sports_guide_2010-2011.pdf
[2010/08/30 22:38:17 | 000,888,057 | —- | M] () – C:\Users\betson\Documents\Masterstudyplan_SC_cours.pdf
[2010/08/30 22:32:04 | 000,965,160 | —- | M] () – C:\Users\betson\Documents\Masterstudyplan_EL.pdf
[2010/08/30 22:28:42 | 000,032,699 | —- | M] () – C:\Users\betson\Documents\en1_costofliving.pdf
[2010/08/29 02:38:44 | 212,997,495 | —- | M] () – C:\Users\betson\Desktop\Lecture 3 image digitization part-2.mp4
[2010/08/29 02:22:27 | 202,511,285 | —- | M] () – C:\Users\betson\Desktop\lecture 4_pixel relationships.mp4
[2010/08/28 18:58:51 | 000,037,809 | —- | M] () – C:\Users\betson\Documents\The PIC ,ads.docx
[2010/08/27 23:01:35 | 000,774,429 | —- | M] () – C:\Users\betson\Documents\Twenty19_smart_student_resume_guide.pdf
[2010/08/27 02:14:51 | 000,546,431 | —- | M] () – C:\Users\betson\Documents\firstonlinequizanswers-100823090543-phpapp02.pdf
[2010/08/27 02:11:25 | 001,652,343 | —- | M] () – C:\Users\betson\Documents\500wordsphrasesidiomsforthetoeflibtplustypingstrategies-100826015013-phpapp02.pdf
[2010/08/27 02:10:51 | 002,151,192 | —- | M] () – C:\Users\betson\Documents\quizzingunderthestarsaugust222010ccm2010prelaunchevent-100822011220-phpapp01.pdf
[2010/08/27 02:05:21 | 000,335,968 | —- | M] () – C:\Users\betson\Documents\bimtechprelims-quizzing-in-100319090235-phpapp02.pdf
[2010/08/27 02:02:18 | 001,071,014 | —- | M] () – C:\Users\betson\Documents\jack-kilby-science-and-technology-quiz-2009-prelims-091211230029-phpapp02.pdf
[2010/08/27 01:56:14 | 006,175,583 | —- | M] () – C:\Users\betson\Documents\generalquizwithoutanswers-100512050515-phpapp01.pdf
[2010/08/26 18:38:27 | 000,638,534 | —- | M] () – C:\Users\betson\Documents\Zulassungsbedingungen_e.pdf
[2010/08/25 07:25:20 | 000,026,432 | —- | M] () – C:\bootsqm.dat
[2010/08/25 02:05:58 | 212,664,463 | —- | M] () – C:\Users\betson\Desktop\Lecture 2 Image Digitization I.mp4
[2010/08/25 00:35:50 | 000,000,941 | —- | M] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/08/23 21:15:51 | 001,014,023 | —- | M] () – C:\Users\betson\Documents\casestudy.pdf
[2010/08/21 16:46:52 | 014,562,773 | —- | M] () – C:\Users\betson\Documents\videoplayback.mp4
[2010/08/19 22:49:05 | 000,262,025 | —- | M] () – C:\Users\betson\Desktop\TRI%20Grand%20Challenges.pdf
[2010/08/18 19:59:42 | 000,001,913 | —- | M] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/17 23:27:07 | 000,001,266 | —- | M] () – C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/14 23:26:27 | 105,074,293 | —- | M] () – C:\Users\betson\Documents\OK Go - This Too Shall Pass - Rube Goldberg Machine version - Official.mp4
[2010/08/14 22:45:10 | 029,473,902 | —- | M] () – C:\Users\betson\Documents\The Best Rube Goldberg EVER!!!!!!!!!!!!!!ever..mp4
[2010/08/14 22:35:47 | 002,844,236 | —- | M] () – C:\Users\betson\Documents\_Pythagoras Switch_ 2006_10_22.mp4
[2010/08/14 22:27:56 | 001,429,400 | —- | M] () – C:\Users\betson\Documents\Top 7 Japanese Rube Goldberg Machines #5.mp4
[2010/08/14 22:15:51 | 018,936,887 | —- | M] () – C:\Users\betson\Documents\4th Grade Science - Rube Goldberg using Simple Machines.mp4
[2010/08/14 10:15:02 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/08/14 10:15:01 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/08/14 10:15:01 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/08/14 10:14:26 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/08/13 23:48:00 | 000,696,545 | —- | M] () – C:\Users\betson\Documents\ece_news_fall08_FIMEngArt.pdf
[2010/08/13 22:47:36 | 011,920,193 | —- | M] () – C:\Users\betson\Documents\NJIT Undergraduate Research Project- Angioplasty.mp4
[2010/08/13 18:57:52 | 003,617,258 | —- | M] () – C:\Users\betson\Documents\Wireless Electricity & Wireless Communication ( dual purpose device ).mp4
[2010/08/13 18:37:04 | 000,142,495 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2010/08/13 17:58:20 | 005,669,694 | —- | M] () – C:\Users\betson\Documents\Renewable Energy projects.mp4
[2010/08/09 23:05:27 | 000,047,616 | —- | M] () – C:\Users\betson\Desktop\BETSON GEORGE-RESUME'.doc

========== Files Created - No Company Name ==========

[2010/09/05 02:28:31 | 000,233,151 | —- | C] () – C:\Users\betson\Desktop\p275_chap1.pdf
[2010/09/04 22:47:20 | 001,309,499 | —- | C] () – C:\Users\betson\Desktop\(PNG Image, 1280x546 pixels) - Scaled (98%).png
[2010/09/04 21:57:46 | 000,119,690 | —- | C] () – C:\Users\betson\Desktop\Buckyball-25th-anniversary-celebrated-by-interactive-Google-Doodle.html
[2010/09/04 21:57:40 | 000,113,676 | —- | C] () – C:\Users\betson\Desktop\Pac-Man-30th-anniversary-marked-by-Google-Doodle.html
[2010/09/04 21:44:04 | 000,058,061 | —- | C] () – C:\Users\betson\Desktop\hp.memristor_1_flash-memory-computer-memory-hp-labs.htm
[2010/09/04 02:10:14 | 000,002,969 | —- | C] () – C:\Users\betson\Desktop\HiJackThis.lnk
[2010/09/04 01:51:04 | 001,832,198 | —- | C] () – C:\Users\betson\Documents\nano_erasmus_mundus.pdf
[2010/09/04 01:50:57 | 000,236,960 | —- | C] () – C:\Users\betson\Documents\Electrical.pdf
[2010/09/04 01:50:18 | 001,874,524 | —- | C] () – C:\Users\betson\Documents\UNIVERSITYOFLEUVEN.pdf
[2010/09/04 01:50:05 | 001,278,016 | —- | C] () – C:\Users\betson\Documents\studying.pdf
[2010/09/04 01:48:11 | 004,424,200 | —- | C] () – C:\Users\betson\Documents\internationalprogrammes.pdf
[2010/09/03 12:34:17 | 002,027,366 | —- | C] () – C:\Users\betson\Documents\videoplayback.mp41.mp4
[2010/09/03 12:29:14 | 005,484,067 | —- | C] () – C:\Users\betson\Documents\Eye movement controled servo made by AGH MSIB student.mp4
[2010/09/03 12:25:42 | 001,738,251 | —- | C] () – C:\Users\betson\Documents\EOG - human computer interface.mp4
[2010/09/03 01:05:09 | 194,178,381 | —- | C] () – C:\Users\betson\Desktop\Lecture 5 Pixels Relationships II.mp4
[2010/09/02 21:51:30 | 000,392,677 | —- | C] () – C:\Users\betson\Documents\NSEWQuiz2007.pdf
[2010/09/02 10:01:51 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2010/08/31 20:28:43 | 000,294,248 | —- | C] () – C:\Users\betson\Documents\germany.docx
[2010/08/30 23:05:38 | 000,856,990 | —- | C] () – C:\Users\betson\Documents\sports_guide_2010-2011.pdf
[2010/08/30 22:38:17 | 000,888,057 | —- | C] () – C:\Users\betson\Documents\Masterstudyplan_SC_cours.pdf
[2010/08/30 22:32:04 | 000,965,160 | —- | C] () – C:\Users\betson\Documents\Masterstudyplan_EL.pdf
[2010/08/30 22:28:42 | 000,032,699 | —- | C] () – C:\Users\betson\Documents\en1_costofliving.pdf
[2010/08/29 02:38:44 | 212,997,495 | —- | C] () – C:\Users\betson\Desktop\Lecture 3 image digitization part-2.mp4
[2010/08/29 02:22:26 | 202,511,285 | —- | C] () – C:\Users\betson\Desktop\lecture 4_pixel relationships.mp4
[2010/08/28 18:58:50 | 000,037,809 | —- | C] () – C:\Users\betson\Documents\The PIC ,ads.docx
[2010/08/27 23:01:35 | 000,774,429 | —- | C] () – C:\Users\betson\Documents\Twenty19_smart_student_resume_guide.pdf
[2010/08/27 02:14:51 | 000,546,431 | —- | C] () – C:\Users\betson\Documents\firstonlinequizanswers-100823090543-phpapp02.pdf
[2010/08/27 02:11:25 | 001,652,343 | —- | C] () – C:\Users\betson\Documents\500wordsphrasesidiomsforthetoeflibtplustypingstrategies-100826015013-phpapp02.pdf
[2010/08/27 02:10:51 | 002,151,192 | —- | C] () – C:\Users\betson\Documents\quizzingunderthestarsaugust222010ccm2010prelaunchevent-100822011220-phpapp01.pdf
[2010/08/27 02:05:21 | 000,335,968 | —- | C] () – C:\Users\betson\Documents\bimtechprelims-quizzing-in-100319090235-phpapp02.pdf
[2010/08/27 02:02:18 | 001,071,014 | —- | C] () – C:\Users\betson\Documents\jack-kilby-science-and-technology-quiz-2009-prelims-091211230029-phpapp02.pdf
[2010/08/27 01:56:13 | 006,175,583 | —- | C] () – C:\Users\betson\Documents\generalquizwithoutanswers-100512050515-phpapp01.pdf
[2010/08/26 18:38:27 | 000,638,534 | —- | C] () – C:\Users\betson\Documents\Zulassungsbedingungen_e.pdf
[2010/08/25 07:25:20 | 000,026,432 | —- | C] () – C:\bootsqm.dat
[2010/08/25 02:05:57 | 212,664,463 | —- | C] () – C:\Users\betson\Desktop\Lecture 2 Image Digitization I.mp4
[2010/08/25 00:35:50 | 000,000,941 | —- | C] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/08/23 21:15:51 | 001,014,023 | —- | C] () – C:\Users\betson\Documents\casestudy.pdf
[2010/08/21 16:46:52 | 014,562,773 | —- | C] () – C:\Users\betson\Documents\videoplayback.mp4
[2010/08/19 22:49:05 | 000,262,025 | —- | C] () – C:\Users\betson\Desktop\TRI%20Grand%20Challenges.pdf
[2010/08/18 19:59:42 | 000,001,913 | —- | C] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/17 23:27:07 | 000,001,266 | —- | C] () – C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/14 23:26:25 | 105,074,293 | —- | C] () – C:\Users\betson\Documents\OK Go - This Too Shall Pass - Rube Goldberg Machine version - Official.mp4
[2010/08/14 23:05:09 | 000,000,912 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001UA.job
[2010/08/14 23:05:07 | 000,000,860 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001Core.job
[2010/08/14 22:45:09 | 029,473,902 | —- | C] () – C:\Users\betson\Documents\The Best Rube Goldberg EVER!!!!!!!!!!!!!!ever..mp4
[2010/08/14 22:35:47 | 002,844,236 | —- | C] () – C:\Users\betson\Documents\_Pythagoras Switch_ 2006_10_22.mp4
[2010/08/14 22:27:56 | 001,429,400 | —- | C] () – C:\Users\betson\Documents\Top 7 Japanese Rube Goldberg Machines #5.mp4
[2010/08/14 22:15:51 | 018,936,887 | —- | C] () – C:\Users\betson\Documents\4th Grade Science - Rube Goldberg using Simple Machines.mp4
[2010/08/13 23:48:00 | 000,696,545 | —- | C] () – C:\Users\betson\Documents\ece_news_fall08_FIMEngArt.pdf
[2010/08/13 22:47:36 | 011,920,193 | —- | C] () – C:\Users\betson\Documents\NJIT Undergraduate Research Project- Angioplasty.mp4
[2010/08/13 18:57:52 | 003,617,258 | —- | C] () – C:\Users\betson\Documents\Wireless Electricity & Wireless Communication ( dual purpose device ).mp4
[2010/08/13 17:58:20 | 005,669,694 | —- | C] () – C:\Users\betson\Documents\Renewable Energy projects.mp4
[2010/08/10 09:50:12 | 000,047,616 | —- | C] () – C:\Users\betson\Desktop\BETSON GEORGE-RESUME'.doc
[2009/12/07 10:16:00 | 000,007,358 | —- | C] () – C:\Program Files\logo_48x48.ico
[2009/07/14 05:21:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 05:12:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/05/04 21:08:53 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Ansys
[2010/09/05 09:36:01 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\LimeWire
[2010/07/26 23:30:11 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Nokia
[2010/06/19 12:38:45 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\PC Suite
[2010/08/25 07:18:31 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\uTorrent
[2010/09/02 10:00:47 | 000,032,548 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/11 03:12:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/08/25 07:25:20 | 000,026,432 | —- | M] () – C:\bootsqm.dat
[2009/06/11 03:12:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/05 09:32:35 | 2408,087,552 | -HS- | M] () – C:\hiberfil.sys
[2010/06/17 17:12:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/17 17:12:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/05 09:32:35 | 3210,784,768 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 10:22:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 10:22:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 10:22:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 10:22:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 03:01:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 06:45:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 06:46:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 10:11:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2009/12/07 10:16:00 | 000,007,358 | —- | M] () – C:\Program Files\logo_48x48.ico

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/25 17:10:11 | 000,000,221 | -HS- | M] () – C:\Users\betson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/11 02:50:04 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/04/25 16:06:56 | 000,000,402 | -HS- | M] () – C:\Users\betson\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< %USERPROFILE%\Templates\*.* >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >



























OTL Extras logfile created on: 9/5/2010 10:09:43 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\betson\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 31.15 Gb Total Space | 1.12 Gb Free Space | 3.59% Space Free | Partition Type: NTFS
Drive D: | 100.59 Gb Total Space | 12.15 Gb Free Space | 12.08% Space Free | Partition Type: NTFS
Drive E: | 101.05 Gb Total Space | 1.19 Gb Free Space | 1.18% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 978.58 Mb Total Space | 309.96 Mb Free Space | 31.67% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: BETSON-PC
Current User Name: betson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{127F1FD7-43BB-4428-8B2A-70539F4B6F1F}" = ANSYS Products 11.0 SP1
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.6
"{1B611B02-BCB6-4D2C-AD7C-F7370B272853}" = ANSYS Remote Solve Manager (RSM) 11.0
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{20140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 (Beta)
"{20140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 (Beta)
"{20140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 (Beta)
"{20140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 (Beta)
"{20140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 (Beta)
"{20140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 (Beta)
"{20140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 (Beta)
"{20140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 (Beta)
"{20140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 (Beta)
"{20140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 (Beta)
"{20140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 (Beta)
"{20140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 (Beta)
"{20140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 (Beta)
"{20140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 (Beta)
"{20140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 (Beta)
"{20140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 (Beta)
"{20140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 (Beta)
"{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}" = Nokia PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 21
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{C7C895CA-331B-4D7D-A0FB-D3BC637949F9}" = Apple Mobile Device Support
"{EA418519-2160-43A0-AABD-6608DDD8D87F}" = iTunes
"34EA302E7F4CBD17A19E33BBCB72363234956D7E" = Windows Driver Package - Nokia Modem (06/09/2010 4.5)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner (remove only)
"EEEE705096F837B7907659F100C9FE6DA001970F" = Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.7)
"LimeWire" = LimeWire PRO 5.3.6
"Mnemosyne_is1" = Mnemosyne 1.2.2
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nokia PC Suite" = Nokia PC Suite
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"SonicShack Design Studio_is1" = SonicShack Designer Adobe AIR version
"VLC media player" = VideoLAN VLC media player 0.8.6h

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/4/2010 4:27:57 AM | Computer Name = betson-PC | Source = VSS | ID = 8193
Description =

Error - 9/4/2010 5:00:40 AM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 11:41:43 AM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 12:13:29 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 1:14:25 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 2:14:32 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 3:03:33 PM | Computer Name = betson-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 1.9.2.3855, time
stamp: 0x4c48d5ce Faulting module name: js3250.dll, version: 0.0.0.0, time stamp:
0x4c48cd1a Exception code: 0xc0000005 Fault offset: 0x000518c9 Faulting process id:
0x1688 Faulting application start time: 0x01cb4c47f9acf4d6 Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\js3250.dll Report Id: 1c840753-b857-11df-8cbf-001fe2ddaedd

Error - 9/4/2010 3:12:32 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 4:04:04 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/4/2010 5:00:56 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ Media Center Events ]
Error - 7/21/2010 12:53:43 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 10:23:42 PM - Error connecting to the internet. 10:23:42 PM - Unable
to contact server..

Error - 7/23/2010 12:56:23 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 10:26:23 PM - Error connecting to the internet. 10:26:23 PM - Unable
to contact server..

Error - 7/26/2010 1:40:38 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 11:10:38 PM - Error connecting to the internet. 11:10:38 PM - Unable
to contact server..

Error - 7/28/2010 10:08:10 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 7:38:10 AM - Error connecting to the internet. 7:38:10 AM - Unable
to contact server..

Error - 7/30/2010 5:35:44 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 3:05:44 PM - Error connecting to the internet. 3:05:44 PM - Unable
to contact server..

Error - 8/1/2010 1:39:47 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 11:09:47 PM - Error connecting to the internet. 11:09:47 PM - Unable
to contact server..

Error - 8/3/2010 1:33:42 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 11:03:42 AM - Error connecting to the internet. 11:03:42 AM - Unable
to contact server..

Error - 8/7/2010 3:43:57 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 1:13:57 PM - Error connecting to the internet. 1:13:57 PM - Unable
to contact server..

Error - 8/9/2010 9:40:26 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 7:10:26 PM - Error connecting to the internet. 7:10:26 PM - Unable
to contact server..

Error - 8/11/2010 8:51:38 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 6:21:37 PM - Error connecting to the internet. 6:21:38 PM - Unable
to contact server..

[ System Events ]
Error - 9/4/2010 4:09:19 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 4:09:19 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 4:09:19 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 4:14:37 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 4:14:45 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 4:28:45 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 4:28:46 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 9/4/2010 11:36:36 AM | Computer Name = betson-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Audio service failed to start due to the following error:
%%776

Error - 9/4/2010 11:40:17 AM | Computer Name = betson-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 9/4/2010 3:15:52 PM | Computer Name = betson-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \…\DR2.


< End of report >
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
    IE - HKCU\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O33 - MountPoints2\{f2c74a43-6ed0-11df-96ab-001fe2ddaedd}\Shell - "" = AutoRun
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Running ComboFix
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
otl report……..

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c74a43-6ed0-11df-96ab-001fe2ddaedd}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f2c74a43-6ed0-11df-96ab-001fe2ddaedd}\ not found.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\betson\Downloads\cmd.bat deleted successfully.
C:\Users\betson\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully


[EMPTYTEMP]

User: All Users

User: betson
->Temp folder emptied: 53036904 bytes
->Temporary Internet Files folder emptied: 9889627 bytes
->Java cache emptied: 178796 bytes
->FireFox cache emptied: 91994669 bytes
->Google Chrome cache emptied: 594288 bytes
->Flash cache emptied: 102878 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56504 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 67272 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 149.00 mb


[EMPTYFLASH]

User: All Users

User: betson
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 09072010_191412

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

















here's the combo fix report!!!


ComboFix 10-09-06.04 - betson 09/07/2010 19:43:26.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3062.2339 [GMT 5.5:30]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\betson\AppData\Roaming\Microsoft\Windows\Recent\InstantPlayerENU.url
c:\windows\7Loader.TAG

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_GoogleUpdateBeta


((((((((((((((((((((((((( Files Created from 2010-08-07 to 2010-09-07 )))))))))))))))))))))))))))))))
.

2010-09-07 14:04 . 2010-09-07 14:05 ——– d—–w- C:\32788R22FWJFW
2010-09-07 13:44 . 2010-09-07 13:44 ——– d—–w- C:\_OTL
2010-09-07 13:14 . 2010-09-07 13:14 739328 —-a-w- c:\windows\system32\dloA968.dll
2010-09-05 04:44 . 2010-09-05 04:44 6656 —-a-w- c:\windows\system32\6E21D726.exe
2010-09-03 20:40 . 2010-09-03 20:40 ——– d—–w- c:\program files\Trend Micro
2010-09-02 18:53 . 2010-09-04 08:29 ——– d—–w- c:\program files\Yahoo!
2010-09-02 18:53 . 2010-09-02 18:54 ——– d—–w- c:\program files\CCleaner
2010-09-02 18:52 . 2010-09-04 08:34 ——– d—–w- c:\program files\Trojan Remover
2010-09-02 18:52 . 2010-09-02 18:52 ——– d—–w- c:\programdata\Simply Super Software
2010-09-01 20:04 . 2010-09-01 20:04 ——– d—–w- c:\program files\Common Files\PCSuite
2010-09-01 20:04 . 2010-09-01 20:04 ——– d—–w- c:\program files\Common Files\Nokia
2010-09-01 20:03 . 2010-09-01 20:03 ——– d—–w- c:\program files\PC Connectivity Solution
2010-08-31 19:34 . 2010-09-04 08:34 ——– d—–w- c:\program files\Wise Registry Cleaner 3
2010-08-31 19:29 . 2010-08-31 21:09 ——– d—–w- c:\program files\Instant Player
2010-08-25 01:55 . 2010-08-25 01:55 33040 ——w- C:\bootsqm.dat
2010-08-24 19:05 . 2010-08-24 19:05 ——– d—–w- c:\program files\uTorrent
2010-08-24 19:05 . 2010-08-25 01:48 ——– d—–w- c:\users\betson\AppData\Roaming\uTorrent
2010-08-23 15:49 . 2010-08-23 15:49 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-08-23 15:43 . 2010-08-23 15:49 ——– d—–w- c:\program files\SonicShack
2010-08-15 16:24 . 2010-08-29 10:58 ——– d—–w- c:\users\betson\.mnemosyne
2010-08-15 16:23 . 2010-08-15 16:23 ——– d—–w- c:\program files\Mnemosyne
2010-08-14 17:33 . 2010-08-14 17:33 ——– d—–w- c:\users\betson\AppData\Local\Apps
2010-08-14 17:33 . 2010-08-14 17:34 ——– d—–w- c:\users\betson\AppData\Local\Deployment
2010-08-14 04:45 . 2010-08-14 04:45 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-08-13 16:44 . 2010-08-13 16:44 ——– d—–w- c:\program files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-07 14:28 . 2010-05-14 15:17 ——– d—–w- c:\users\betson\AppData\Roaming\LimeWire
2010-09-03 20:40 . 2010-09-03 20:40 388096 —-a-r- c:\users\betson\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-03 18:56 . 2010-04-26 16:37 ——– d—–w- c:\program files\Common Files\Adobe
2010-09-02 04:31 . 2010-09-02 04:31 0 —ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
2010-09-01 20:04 . 2010-06-19 07:06 ——– d—–w- c:\program files\Nokia
2010-09-01 20:02 . 2010-09-01 20:02 95232 —-a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\pcswpcsi.exe
2010-09-01 20:02 . 2010-09-01 20:02 8192 —-a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\UninstCCD.exe
2010-09-01 20:02 . 2010-09-01 20:02 61440 —-a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-09-01 20:02 . 2010-09-01 20:02 10240 —-a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\UninstPCS.exe
2010-09-01 20:02 . 2010-06-19 07:05 ——– d—–w- c:\programdata\Installations
2010-09-01 20:01 . 2010-09-01 20:02 36365624 —-a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_eng.exe
2010-08-22 19:09 . 2010-06-19 07:07 ——– d—–w- c:\programdata\PC Suite
2010-08-18 14:27 . 2010-04-28 16:58 ——– d—–w- c:\program files\Mozilla Firefox 3 Beta 5
2010-08-14 04:45 . 2010-08-14 04:45 360584 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-08-14 04:45 . 2010-08-14 04:45 333192 —-a-w- c:\programdata\avg9\update\backup\avgldx86.sys
2010-08-14 04:45 . 2010-08-14 04:45 28424 —-a-w- c:\programdata\avg9\update\backup\avgmfx86.sys
2010-08-14 04:45 . 2010-07-31 18:01 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-14 04:45 . 2010-07-31 18:01 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-14 04:44 . 2010-07-31 18:01 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-13 19:10 . 2010-07-31 18:01 ——– d—–w- c:\programdata\avg9
2010-08-13 16:43 . 2010-05-14 15:13 ——– d—–w- c:\program files\Java
2010-08-13 12:21 . 2010-04-29 20:50 ——– d—–w- c:\program files\YouTube Downloader
2010-07-31 18:02 . 2010-07-31 18:01 ——– d—–w- c:\programdata\AVG Security Toolbar
2010-07-31 18:01 . 2010-07-31 18:01 ——– d—–w- c:\program files\AVG
2010-07-31 17:58 . 2010-04-26 18:24 ——– d—–w- c:\program files\Rising
2010-07-26 18:00 . 2010-06-19 07:07 ——– d—–w- c:\users\betson\AppData\Roaming\Nokia
2010-07-16 23:30 . 2010-05-20 21:22 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-06 18:14 . 2009-07-13 23:11 21584 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-06-19 07:06 . 2010-06-19 07:06 95232 —-a-w- c:\programdata\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
2010-06-19 07:06 . 2010-06-19 07:06 8192 —-a-w- c:\programdata\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
2010-06-19 07:06 . 2010-06-19 07:06 61440 —-a-w- c:\programdata\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-06-19 07:06 . 2010-06-19 07:06 10240 —-a-w- c:\programdata\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-07 04:46 . 2009-12-07 04:46 7358 —-a-w- c:\program files\logo_48x48.ico
2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AEE7EA3-02BF-4771-A11D-2F09783EFC35}]
2010-09-07 13:14 739328 —-a-w- c:\windows\System32\dloA968.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 06:42 1119488 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Enhanced Storage]
@="{4AEE7EA3-02BF-4771-A11D-2F09783EFC35}"
[HKEY_CLASSES_ROOT\CLSID\{4AEE7EA3-02BF-4771-A11D-2F09783EFC35}]
2010-09-07 13:14 739328 —-a-w- c:\windows\System32\dloA968.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\betson\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-08-14 136176]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-05-14 1479680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2009-09-27 83312]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-08-14 2065760]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-06-17 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

c:\users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2009-11-4 225680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

2;2 dquoihoi;RDP Winstation Support;c:\windows\System32\svchost.exe [x]
R3 6E21D726;6E21D726;c:\windows\system32\6E21D726.exe [2010-09-05 6656]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2009-10-29 30603640]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-09-26 4639136]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-08-14 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-08-14 243024]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ANSYS FLEXlm license manager;ANSYS FLEXlm license manager;c:\progra~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe [2006-11-03 1327104]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-08-14 308136]
S2 JobManagerService110;Ansys JobManager Service V11;c:\program files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe [2007-09-21 20480]
S2 ScriptHostService110;Ansys ScriptHost Service V11;c:\program files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe [2007-09-21 20480]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
dquoihoi
.
Contents of the 'Scheduled Tasks' folder

2010-09-07 c:\windows\Tasks\At1.job
- c:\windows\system32\dloA968.dll [2010-09-07 13:14]

2010-09-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001Core.job
- c:\users\betson\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-14 17:34]

2010-09-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001UA.job
- c:\users\betson\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-14 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\betson\AppData\Roaming\Mozilla\Firefox\Profiles\wgcprptx.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\progra~1\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\users\betson\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(1508)
c:\windows\system32\dloa968.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
———————— Other Running Processes ————————
.
c:\windows\system32\conhost.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\ansyslmd.exe
c:\windows\system32\taskhost.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conhost.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\iPod\bin\iPodService.exe
c:\users\betson\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
.
**************************************************************************
.
Completion time: 2010-09-07 20:04:19 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-07 14:34

Pre-Run: 4,111,540,224 bytes free
Post-Run: 3,854,807,040 bytes free

- - End Of File - - E1036852459B3E30E0DE291FFB3B9F08
Hello,

Show hidden files in Windows Vista
Please enable the Show Hidden Files and Folders option:
  • Close all programs so that you are at your desktop.
  • Press 🖼Click to load external image (Posted Image).
  • Click the Start Search box on the Start Menu
  • Copy and paste the following value, in the open text entry box:
    control folders
    • Depending on you view settings: choose one of these options:
    • Double-click on the Folder Options icon… then click on the View tab.
    • Click on the Appearance and Personalization link… then click on Show Hidden Files or Folders.
  • SELECT…button Show hidden files and folders.
    under the "Hidden files and folders" section.
  • Remove check mark from check box… Hide extensions for known file types.
  • Remove check mark from check box… Hide protected operating system files.
  • Press the Apply button…then the OK button.
Now Windows Vista is configured to show all hidden files.


NEXT:



VirusTotal File Scan
Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: c:\windows\System32\dloA968.dll
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI