Thanks for cleaning up my accidental double post. …Whoops
And yes, Its still happening. It's happened twice within the last 20 minutes…
OTL fix log:
All processes killed
========== REGISTRY ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoFolderOptions deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
File F:\Support\AutoRun\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File G:\Autorun.exe not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Vincent Pinto\Desktop\cmd.bat deleted successfully.
C:\Users\Vincent Pinto\Desktop\cmd.txt deleted successfully.
File\Folder C:\Users\VINCEN~1\AppData\Local\Temp\rnmxesocaw.exe not found.
File\Folder C:\Users\VINCEN~1\AppData\Local\Temp\sraonecxmw.exe not found.
File\Folder C:\Users\Vincent Pinto\AppData\Local\Temp\Ox7.exe not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56504 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: Vincent Pinto
->Temp folder emptied: 3634509 bytes
->Temporary Internet Files folder emptied: 45748270 bytes
->Java cache emptied: 51144598 bytes
->FireFox cache emptied: 118769731 bytes
->Flash cache emptied: 294850 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8182188 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 217.00 mb
Error creating restore point.
OTL by OldTimer - Version 3.2.11.0 log created on 09092010_223901
Files\Folders moved on Reboot…
C:\Users\Vincent Pinto\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
————————————————————————————
OTL:
OTL logfile created on: 11/09/2010 8:29:29 PM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Vincent Pinto\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
12.00 Gb Total Physical Memory | 8.00 Gb Available Physical Memory | 68.00% Memory free
24.00 Gb Paging File | 20.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.08 Gb Total Space | 328.17 Gb Free Space | 55.06% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 671.64 Gb Free Space | 72.10% Space Free | Partition Type: NTFS
Drive E: | 1397.14 Gb Total Space | 299.05 Gb Free Space | 21.40% Space Free | Partition Type: NTFS
Unable to calculate disk information.
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHAOS_MKII
Current User Name: Vincent Pinto
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Vincent Pinto\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Users\Vincent Pinto\My Documents\G15\SirReal\LCDSirReal.exe ()
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\Vincent Pinto\AppData\Local\FLVService\lib\FLVSrvLib.dll (Applian Technologies, Inc.)
MOD - C:\Users\Vincent Pinto\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Logitech\SetPoint\x86\GameHook.dll (Logitech, Inc.)
MOD - C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll (Logitech, Inc.)
MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:
64bit: - (TabletServiceWacom) – C:\Windows\SysNative\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:
64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:
64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:
64bit: - (StorSvc) – C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation)
SRV:
64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (ServiceLayer) – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WLSetupSvc) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (vmm) – C:\Windows\SysNative\drivers\VMM.sys (Microsoft Corporation)
DRV:
64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:
64bit: - (LGVirHid) – C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:
64bit: - (LGBusEnum) – C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:
64bit: - (UsbserFilt) – C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys (Nokia)
DRV:
64bit: - (nmwcdcx64) – C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:
64bit: - (upperdev) – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:
64bit: - (nmwcdx64) – C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:
64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:
64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:
64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:
64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:
64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:
64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (usbser) – C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:
64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:
64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:
64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:
64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:
64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:
64bit: - (pccsmcfd) – C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:
64bit: - (VPCNetS2) – C:\Windows\SysNative\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV:
64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server 2003 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 23 4F 75 52 B9 50 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.enabled: false
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/29 04:10:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/09 22:36:47 | 000,000,000 | —D | M]
[2009/12/30 21:45:28 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Extensions
[2009/12/30 21:45:28 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/11 20:07:53 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (Freecorder Toolbar) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/29 20:54:29 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/15 17:28:51 | 000,002,746 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\searchplugins\ebaycomau.xml
[2010/04/08 05:43:32 | 000,002,057 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\searchplugins\youtube-video-search.xml
[2010/09/11 20:07:53 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/09/09 22:36:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/16 19:36:46 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/07/16 19:36:46 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/07/16 19:36:46 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/07/16 19:36:46 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/05/15 03:40:20 | 000,000,875 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:
64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:
64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/09/09 22:39:01 | 000,000,000 | —D | C] – C:\_OTL
[2010/09/09 22:37:08 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/09/09 22:37:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/09/09 22:36:47 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/09/09 22:36:47 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/09/09 22:36:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/09/09 22:36:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/09/09 19:46:48 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
[2010/09/09 19:40:17 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\Desktop\backups
[2010/09/08 22:17:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Vincent Pinto\Desktop\HiJackThis.exe
[2010/09/08 00:22:33 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\AppData\Local\Windows Server
[2010/09/08 00:22:26 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\AppData\Roaming\D52C82E4F8474F02F12730D6FFE8B107
[2010/08/31 00:21:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lame for Audacity
[2010/08/25 22:16:24 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
========== Files - Modified Within 30 Days ==========
[2010/09/11 20:29:44 | 003,932,160 | -HS- | M] () – C:\Users\Vincent Pinto\NTUSER.DAT
[2010/09/11 19:54:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/11 13:49:52 | 000,020,512 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/11 13:49:52 | 000,020,512 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/11 13:40:14 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/11 13:40:05 | 1071,738,878 | -HS- | M] () – C:\hiberfil.sys
[2010/09/10 17:41:56 | 002,084,535 | -H– | M] () – C:\Users\Vincent Pinto\AppData\Local\IconCache.db
[2010/09/10 04:54:31 | 000,634,130 | —- | M] () – C:\Users\Public\Documents\Thorns of the Roses.png
[2010/09/09 19:46:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
[2010/09/09 19:44:12 | 000,080,384 | —- | M] () – C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
[2010/09/08 22:16:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Vincent Pinto\Desktop\HiJackThis.exe
[2010/09/08 21:36:51 | 000,782,154 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/08 21:36:51 | 000,668,918 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/09/08 21:36:51 | 000,126,634 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/09/08 05:42:02 | 000,010,921 | —- | M] () – C:\Users\Vincent Pinto\Documents\New Microsoft Office Word Document.docx
[2010/09/04 04:41:55 | 006,363,136 | —- | M] () – C:\Users\Vincent Pinto\Documents\23 - Emiya -Kenji Kawai ver.-.mp3
[2010/09/04 04:32:10 | 004,434,836 | —- | M] () – C:\Users\Vincent Pinto\Documents\Fate_Stay Night OST - Emiya.mp3
[2010/09/03 21:12:02 | 000,078,522 | —- | M] () – C:\Windows\SysWow64\cid_store.dat
[2010/09/03 19:10:49 | 000,000,026 | —- | M] () – C:\Windows\SysWow64\xlhcc.dat
[2010/09/02 02:58:35 | 000,029,580 | —- | M] () – C:\Users\Vincent Pinto\Documents\Peace being epic or something.docx
[2010/09/02 01:44:57 | 000,141,994 | —- | M] () – C:\Users\Public\Documents\T.T.T C2.jpg
[2010/09/01 15:24:46 | 000,149,911 | —- | M] () – C:\Users\Public\Documents\T.T.T C1.jpg
[2010/08/29 02:31:17 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/17 19:33:28 | 000,000,224 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\default.rss
[2010/08/17 19:33:27 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
========== Files Created - No Company Name ==========
[2010/09/10 04:54:29 | 000,634,130 | —- | C] () – C:\Users\Public\Documents\Thorns of the Roses.png
[2010/09/09 19:44:10 | 000,080,384 | —- | C] () – C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
[2010/09/08 05:41:50 | 000,010,921 | —- | C] () – C:\Users\Vincent Pinto\Documents\New Microsoft Office Word Document.docx
[2010/09/04 04:41:19 | 006,363,136 | —- | C] () – C:\Users\Vincent Pinto\Documents\23 - Emiya -Kenji Kawai ver.-.mp3
[2010/09/04 04:30:04 | 004,434,836 | —- | C] () – C:\Users\Vincent Pinto\Documents\Fate_Stay Night OST - Emiya.mp3
[2010/09/02 02:58:34 | 000,029,580 | —- | C] () – C:\Users\Vincent Pinto\Documents\Peace being epic or something.docx
[2010/09/02 01:44:57 | 000,141,994 | —- | C] () – C:\Users\Public\Documents\T.T.T C2.jpg
[2010/09/01 14:41:21 | 000,149,911 | —- | C] () – C:\Users\Public\Documents\T.T.T C1.jpg
[2010/06/11 21:28:23 | 000,001,456 | —- | C] () – C:\Users\Vincent Pinto\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/05/25 22:48:53 | 000,000,224 | —- | C] () – C:\Users\Vincent Pinto\AppData\Roaming\default.rss
[2010/05/25 22:48:40 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/05/15 04:21:30 | 000,000,132 | —- | C] () – C:\Users\Vincent Pinto\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/04/05 07:46:19 | 000,003,584 | —- | C] () – C:\Users\Vincent Pinto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/14 23:00:44 | 000,769,110 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/01/29 22:57:12 | 000,003,088 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/01/29 22:57:12 | 000,000,008 | RHS- | C] () – C:\ProgramData\8AFF345C7D.sys
[2009/12/24 14:33:06 | 000,146,432 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/12/24 14:33:06 | 000,072,704 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
========== Custom Scans ==========
< MD5 for: EXPLORER.EXE >
[2009/07/14 11:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\SysWOW64\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\SysWOW64\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2009/10/31 16:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=41B469C2933A478A9A2F9D10EE160033 – C:\Windows\explorer.exe
[2009/08/03 16:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009/10/31 16:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 15:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/31 16:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 15:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 11:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 16:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/08/03 16:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:9D1B94FD
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:2B19EBF3
< End of report >
———————————————
Original MBAM Log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4555
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
8/09/2010 1:49:00 AM
mbam-log-2010-09-08 (01-49-00).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 799824
Time elapsed: 1 hour(s), 18 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 59
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 68
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b1ba40a2-75f2-51bd-f413-04b13a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b1ba40a2-75f2-51bd-f413-04b13a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ewrgetuj (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlhb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlhb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkic (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkic (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlmoc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlmoc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlna (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlna (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejloc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejloc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlotc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlotc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlppf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlppf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlprc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlprc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqvc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqvc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlrxc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlrxc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlswc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlswc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlyr (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlyr (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mediafix70700en02.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqqyc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqqyc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqrtc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqrtc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqsz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqsz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqtw+ (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqtw+ (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqurb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqurb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvpc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvpc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Vincent Pinto\AppData\Local\Temp\e55z4uf.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\Local Settings\Application Data\Windows Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\winamp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\avp32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\crhnici.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\mdm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\login.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\b26ayz45.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\hexdump.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\cmd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\hwblyxbm.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\le4f7z.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\knam.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Windows\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\nwcemxasro.exe (Trojan.Bamital.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\install.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox4.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\services.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\nvsvc32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\scraxomwen.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\spoolsv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\wininst.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\uo43hs4q88ntx8.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\wininst.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\tmvxmfu.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Windows\System32\o67e8k4fzw.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\win.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\csrss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\av4wkpm.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Windows\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\debug.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\tujserrew.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Roaming\D52C82E4F8474F02F12730D6FFE8B107\mediafix70700en02.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\hexdump.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\geurge.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\o67e8k4fzw.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\maeswornxc.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\winlogon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN03YMSO\mqupjickr[1].htm (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RSMDAJ11\nezgb[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\user.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDZFHJAN\mqupjickr[1].htm (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox5.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\bl8v3uxpa.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\d3qxn7rt.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\sxcfgslr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\iexplorer.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\ikjuc0.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Windows\Oqocaa.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\av4wkpm.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\mx8abzcoxfg.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\rph4gsb2.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\orhck4ecq8ydss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox3.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\rph4gsb2.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\uk19rr.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox6.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\skaioejiesfjoee.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\thuurs.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN03YMSO\cgbvd[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\uk19rr.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUDNHL4E\mediafix70700en02[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.