This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Suspicious Mystic Via Antimalware Doctor

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was just surfing the internet yesterday and antimalware doctor pops up, I follow some guides on the internet and i'm pretty sure i've got rid of it using rkill and malwarebytes. I installed norton yesterday just to check all the problems were gone and it picks up on Suspicious Mystic and deletes explorer.exe and temp.tmp files. Following some more internet guides including http://forums.whatthetech.com/index.php?sh…548#entry682477, i think i've managed to recover explorer.exe but my spybot search and destroy is still picking up on changes to do with winlogon and other changes with dll.s when i boot up the system.
In the guide included it advises to use combofix which i did and it helped to repair my explorer.exe, the combofix log is included at the end. And i've just read on the thread guide i shouldn't have used the program but it seems that everything is running fine.

Thanks in advance

OTL
=======
OTL.txt

OTL logfile created on: 9/16/2010 5:39:03 PM - Run 1
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Users\Andy\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.44 Gb Total Space | 18.86 Gb Free Space | 16.92% Space Free | Partition Type: NTFS
Drive D: | 107.90 Gb Total Space | 107.45 Gb Free Space | 99.59% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDY-PC
Current User Name: Andy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Andy\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Andy\AppData\Local\temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton 360\Engine\4.2.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files\Acer Bio Protection\BASVC.exe (Egis Technology Inc.)
PRC - C:\Program Files\Acer Bio Protection\CompPtcVUI.exe (Egis Technology Inc.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Common Files\SPBA\upeksvr.exe (UPEK Inc.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Andy\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (N360) – C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (VMCService) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (IGBASVC) – C:\Program Files\Acer Bio Protection\BASVC.exe (Egis Technology Inc.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\Andy\AppData\Local\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100916.002\navex15.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100916.002\naveng.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100901.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100914.003\IDSvix86.sys (Symantec Corporation)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0402000.00C\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0402000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0402000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0402000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0402000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\system32\drivers\N360\0402000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0402000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\System32\drivers\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (nuvotoncir) – C:\Windows\System32\drivers\nuvotoncir.sys (Nuvoton Technology Corporation)
DRV - (RTHDMIAzAudService) – C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (TcUsb) – C:\Windows\System32\drivers\tcusb.sys (UPEK Inc.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (usbfilter) – C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices)
DRV - (DKbFltr) – C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys ()
DRV - (winbondcir) – C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 C8 97 73 49 82 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: avg@igeared:4.504.019.002
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:4.51
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5

FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/08/17 09:28:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/09/15 20:55:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/09/16 03:21:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/08 20:00:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/08 20:00:18 | 000,000,000 | —D | M]

[2009/12/21 15:52:24 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Extensions
[2010/09/15 19:29:07 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions
[2010/05/30 15:57:55 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/05/10 23:32:20 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\cfxe@Triton
[2010/05/10 23:32:20 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\cfxHelper@Triton
[2010/06/06 18:05:08 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\[removed]
[2010/09/11 10:17:04 | 000,001,238 | —- | M] () – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\searchplugins\facebook.xml
[2009/12/22 16:44:48 | 000,001,512 | —- | M] () – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\searchplugins\imdb.xml
[2009/12/21 16:00:04 | 000,001,720 | —- | M] () – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\searchplugins\youtube-video-search.xml
[2010/09/15 19:29:07 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/16 01:55:13 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/16 01:55:13 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/16 01:55:13 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/16 01:55:13 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/09/16 16:53:05 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VitaKeyPdtWzd] C:\Program Files\Acer Bio Protection\PdtWzd.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.)
O9 - Extra 'Tools' menuitem : Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\spba: DllName - C:\Program Files\Common Files\SPBA\homefus2.dll - C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/16 17:15:56 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/09/16 17:01:47 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/09/16 16:53:17 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/09/16 16:50:41 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Local\temp
[2010/09/16 16:43:56 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/09/16 16:43:56 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/09/16 16:43:56 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/09/16 16:43:44 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/09/16 16:43:30 | 000,000,000 | —D | C] – C:\Qoobox
[2010/09/16 16:43:15 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/09/16 16:43:13 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/09/16 12:20:56 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010/09/15 23:59:50 | 000,064,288 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2010/09/15 23:59:47 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/09/15 23:55:06 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Local\Sunbelt Software
[2010/09/15 23:54:17 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/09/15 23:54:17 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/09/15 23:44:59 | 000,000,000 | -H-D | C] – C:\ProgramData\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/09/15 18:24:04 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Roaming\Tific
[2010/09/15 18:24:03 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Local\Symantec
[2010/09/15 17:52:39 | 000,339,504 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\symtdiv.sys
[2010/09/15 17:52:39 | 000,328,752 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\symds.sys
[2010/09/15 17:52:39 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\symefa.sys
[2010/09/15 17:52:39 | 000,043,696 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\srtspx.sys
[2010/09/15 17:52:38 | 000,501,888 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\cchpx86.sys
[2010/09/15 17:52:38 | 000,325,680 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\srtsp.sys
[2010/09/15 17:52:38 | 000,116,784 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\ironx86.sys
[2010/09/15 17:52:00 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360\0402000.00C
[2010/09/15 16:23:54 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2010/09/15 16:22:47 | 000,000,000 | —D | C] – C:\Users\Andy\Documents\Symantec
[2010/09/15 16:22:04 | 000,107,368 | R— | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/09/15 16:22:01 | 000,124,976 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/09/15 16:22:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/09/15 16:22:01 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/09/15 16:21:21 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360
[2010/09/15 16:21:18 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/09/15 16:21:17 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2010/09/15 16:19:27 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2010/09/15 16:19:27 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/09/13 22:05:35 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Roaming\Malwarebytes
[2010/09/13 22:05:26 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/09/13 22:05:25 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/09/13 22:05:23 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/09/13 22:05:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/13 21:52:32 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Server
[2010/09/13 15:28:45 | 000,000,000 | —D | C] – C:\HanWJ
[2010/08/30 13:48:28 | 000,000,000 | —D | C] – C:\Users\Andy\Desktop\Movies
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/16 17:40:44 | 008,388,608 | -HS- | M] () – C:\Users\Andy\ntuser.dat
[2010/09/16 17:32:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/16 17:31:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/16 17:24:32 | 000,014,832 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/16 17:24:32 | 000,014,832 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/16 17:21:43 | 000,623,784 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/16 17:21:43 | 000,109,736 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/16 17:21:42 | 000,720,082 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/16 17:16:07 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/16 17:15:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/16 17:15:45 | 2590,789,632 | -HS- | M] () – C:\hiberfil.sys
[2010/09/16 17:10:58 | 001,375,048 | -H– | M] () – C:\Users\Andy\AppData\Local\IconCache.db
[2010/09/16 16:58:54 | 064,691,171 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/09/16 16:53:43 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/09/16 16:53:05 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/09/16 00:00:30 | 000,989,364 | —- | M] () – C:\Windows\System32\drivers\N360\0402000.00C\Cat.DB
[2010/09/15 23:59:46 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/09/15 23:54:35 | 000,001,128 | —- | M] () – C:\Users\Andy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/15 23:54:35 | 000,001,104 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/09/15 18:22:59 | 000,002,326 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2010/09/15 16:22:01 | 000,124,976 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/09/15 16:22:01 | 000,007,443 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/09/15 16:22:01 | 000,000,805 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010/09/13 15:31:36 | 000,001,167 | —- | M] () – C:\Windows\HWJ.INI
[2010/09/13 15:29:50 | 000,000,768 | —- | M] () – C:\Windows\SCtrlSet1.bin
[2010/09/09 15:34:59 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/09/02 14:59:09 | 000,417,891 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.msn
[2010/09/02 14:59:09 | 000,417,891 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100914-192628.backup
[2010/09/02 14:58:59 | 000,417,891 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100902-215909.backup
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/16 16:43:56 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/09/16 16:43:56 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/09/16 16:43:56 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/09/16 16:43:56 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/09/16 16:43:56 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/09/16 01:55:21 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/09/15 23:54:35 | 000,001,128 | —- | C] () – C:\Users\Andy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/15 23:54:35 | 000,001,104 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/09/15 18:22:09 | 000,989,364 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\Cat.DB
[2010/09/15 17:52:39 | 000,007,873 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symefa.cat
[2010/09/15 17:52:39 | 000,007,787 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnetv.cat
[2010/09/15 17:52:39 | 000,007,442 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtspx.cat
[2010/09/15 17:52:39 | 000,007,425 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symds.cat
[2010/09/15 17:52:39 | 000,007,368 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnet.cat
[2010/09/15 17:52:39 | 000,003,373 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symefa.inf
[2010/09/15 17:52:39 | 000,002,793 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symds.inf
[2010/09/15 17:52:39 | 000,001,473 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnetv.inf
[2010/09/15 17:52:39 | 000,001,445 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnet.inf
[2010/09/15 17:52:39 | 000,001,388 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtspx.inf
[2010/09/15 17:52:38 | 000,007,438 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtsp.cat
[2010/09/15 17:52:38 | 000,007,438 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\iron.cat
[2010/09/15 17:52:38 | 000,007,396 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\cchpx86.cat
[2010/09/15 17:52:38 | 000,001,754 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\cchpx86.inf
[2010/09/15 17:52:38 | 000,001,382 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtsp.inf
[2010/09/15 17:52:38 | 000,000,741 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\iron.inf
[2010/09/15 17:52:00 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\isolate.ini
[2010/09/15 16:22:01 | 000,007,443 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/09/15 16:22:01 | 000,000,805 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010/09/15 16:21:54 | 000,002,326 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2010/09/13 15:29:50 | 000,000,768 | —- | C] () – C:\Windows\SCtrlSet1.bin
[2010/09/13 15:29:49 | 000,001,167 | —- | C] () – C:\Windows\HWJ.INI
[2010/04/15 23:37:14 | 000,002,330 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/02/15 22:03:53 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2009/08/28 14:16:16 | 000,130,238 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2009/07/14 00:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2008/09/11 13:01:00 | 000,081,920 | —- | C] () – C:\Windows\System32\INT15.dll
[2008/09/09 10:38:48 | 000,097,792 | —- | C] () – C:\Windows\System32\INT15_64.dll
[2008/09/09 10:38:48 | 000,015,656 | —- | C] () – C:\Windows\System32\drivers\int15_64.sys
[2008/03/12 12:52:34 | 000,069,632 | —- | C] () – C:\Windows\System32\drivers\int15.sys

========== LOP Check ==========

[2010/01/10 00:02:29 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Octoshape
[2010/09/02 14:32:34 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Spotify
[2010/09/15 18:24:04 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Tific
[2010/09/16 08:07:14 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\uTorrent
[2010/03/30 13:04:24 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Vodafone
[2010/08/29 14:30:09 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/16 17:15:36 | 000,001,340 | —- | M] () – C:\aaw7boot.log
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/12/21 22:58:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/09/16 17:01:45 | 000,020,971 | —- | M] () – C:\ComboFix.txt
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/16 17:15:45 | 2590,789,632 | -HS- | M] () – C:\hiberfil.sys
[2008/10/12 04:38:20 | 000,000,020 | —- | M] () – C:\Medion.ini
[2009/12/21 16:09:14 | 000,001,684 | —- | M] () – C:\netfxlog.txt
[2010/09/16 17:15:37 | 3454,386,176 | -HS- | M] () – C:\pagefile.sys
[2008/10/12 04:31:55 | 000,000,060 | —- | M] () – C:\Partition.txt
[2009/12/21 16:25:17 | 000,003,216 | —- | M] () – C:\RHDSetup.log
[2010/09/15 22:01:49 | 000,000,458 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/08/17 21:27:36 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4x6.dll
[2009/07/14 02:15:26 | 000,280,064 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzppw71.dll
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/21 15:25:26 | 000,000,221 | -HS- | M] () – C:\Users\Andy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-15 19:58:52

< End of report >
================================================================================
=====================================================
Extras.txt

OTL Extras logfile created on: 9/16/2010 5:39:03 PM - Run 1
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Users\Andy\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.44 Gb Total Space | 18.86 Gb Free Space | 16.92% Space Free | Partition Type: NTFS
Drive D: | 107.90 Gb Total Space | 107.45 Gb Free Space | 99.59% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDY-PC
Current User Name: Andy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075315E8-E9E1-4DB3-8CBD-0BEBA9E2BAC3}" = ProductContext
"{0DCF3CFB-0FB6-01DF-AA2B-3DBC40A5839F}" = Catalyst Control Center Graphics Full Existing
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{10035C61-374F-4E19-3DE6-FFAD64F20152}" = CCC Help Portuguese
"{1107B37C-A748-A839-7B95-C22668E84446}" = CCC Help Chinese Standard
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14DB02D4-3B2E-42CE-93F8-AA01C352839F}" = Origin8 Viewer
"{172BE173-7514-13D8-26A0-21BE6D02849A}" = CCC Help Finnish
"{1742DE47-1693-4E7C-8121-8E1D6AED5B25}" = J5700
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BB4C660-E5E0-8C76-52CA-861A3F1C122C}" = CCC Help Dutch
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1FA94A28-5D32-CDC3-4FC7-F8AB6842AB55}" = CCC Help Japanese
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{26E5F8B6-CB96-D266-6631-C2E998138A48}" = CCC Help Thai
"{2C997A7A-B527-6250-B6FE-696E72290CCF}" = CCC Help German
"{2D3858B1-226A-420D-9C9D-B51864E85429}" = Nuvoton CIR Device Driver
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3143EA78-CF29-631E-DD1D-E567A0939D73}" = Catalyst Control Center Graphics Light
"{36A98148-A6B5-EBA5-6353-9833C7F5C06E}" = Catalyst Control Center Graphics Full New
"{3DBA8005-4659-C0C2-32FC-CCAEBA155AC6}" = CCC Help Russian
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{453DC0A2-6F09-FCEC-57A0-2B3540B363B4}" = CCC Help Korean
"{46E6CCE4-99DA-F751-555A-A83D08727108}" = CCC Help Polish
"{48FD7162-300B-FBD6-BBF1-E787DCA61C02}" = CCC Help Swedish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{5239B19E-21EE-327A-7F8A-47ABC68BA306}" = CCC Help English
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6560081A-2245-41B9-CF3C-7EA6C9BEAE51}" = Catalyst Control Center Localization All
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C810E30-FC8A-7059-5752-8800FCA6203C}" = CCC Help Chinese Traditional
"{6E699A98-4FDF-AC94-8F2B-8ECCAC09794A}" = ccc-utility
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{70CAF6DA-C2F4-40C4-A0A4-10FB04701669}" = bpd_scan
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75EF9F92-76D4-F910-6A98-AE8F2EBF99BB}" = ccc-core-static
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7BC46298-4325-EDF3-D3EA-C39390B315AF}" = CCC Help Turkish
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82809116-D1EE-443C-AE31-F19E709DDF7A}" = AMD USB Filter Driver
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B0B72BC-3007-45E9-BBA3-7B7EF8819FA3}" = 5700_Help
"{8B999A44-8314-493B-877E-A1DA5B54D9B8}" = Catalyst Control Center - Branding
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96B51C0B-D3BE-4DF3-959C-28B22C10CFBB}" = Vodafone Mobile Connect Lite
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8B4A92C-BAB9-4CBC-A095-BEE5F44686F5}" = J5700_Basic
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB39BF09-4A6D-4D5A-C18C-5FA93ACA7AEF}" = Catalyst Control Center InstallProxy
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2717DE0-E633-F8A5-727A-30EE10F85932}" = CCC Help Norwegian
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B68D9CA9-23EF-D5C9-035F-61B5B2DE228B}" = Catalyst Control Center Core Implementation
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C0AF9DFE-8B2A-4AC4-22B8-F0EF518C8443}" = CCC Help Greek
"{C12F5BC8-AA4A-6046-2C5C-5822317733CD}" = CCC Help French
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C6A037B6-C14B-D618-01F2-75F7C6DFF69E}" = CCC Help Danish
"{C7C7ABDD-3787-A13B-1F47-27CA9C39DB96}" = CCC Help Spanish
"{C9FD8F40-C7BB-A23E-4C87-57485D7501EF}" = CCC Help Czech
"{D3A65B0A-403B-4C20-A488-BFED2BC5D2EF}" = HP OfficeJet J5700
"{D43B1A55-6957-4E93-A674-338F78B4A202}" = BPDSoftware
"{DA703982C580418795BF4001AA9D7061}" = DivX Plus Media Foundation Components
"{DB44C345-3CD6-0076-D710-47936E6B4BA6}" = CCC Help Hungarian
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09664BB-BB08-45FA-87D1-33EAB0E017F5}" = Fingerprint Solution
"{E0A1335B-3D84-413B-B92C-DF2D4BAACA0C}" = BPDSoftware_Ini
"{E2DFCB25-A7CE-AEF9-99C2-2421F076C840}" = CCC Help Italian
"{ECCD28B2-8798-4D16-8126-625D728294A1}" = SPBA 5.8
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EFBB78E7-56FF-9793-E36D-E2F4FEEFB6C7}" = ATI Catalyst Install Manager
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Google Chrome" = Google Chrome
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"InstallShield_{E09664BB-BB08-45FA-87D1-33EAB0E017F5}" = Acer Bio Protection
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"N360" = Norton 360
"Shop for HP Supplies" = Shop for HP Supplies
"Spotify" = Spotify
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ULTIMATER" = Microsoft Office Ultimate 2007
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape Streaming Services" = Octoshape Streaming Services

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/16/2010 11:43:59 AM | Computer Name = Andy-PC | Source = VSS | ID = 18
Description =

Error - 9/16/2010 11:43:59 AM | Computer Name = Andy-PC | Source = VSS | ID = 8193
Description =

Error - 9/16/2010 11:43:59 AM | Computer Name = Andy-PC | Source = System Restore | ID = 8193
Description =

Error - 9/16/2010 11:52:33 AM | Computer Name = Andy-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 9/16/2010 11:56:34 AM | Computer Name = Andy-PC | Source = .NET Runtime Optimization Service | ID = 1111
Description =

Error - 9/16/2010 11:56:34 AM | Computer Name = Andy-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/16/2010 12:02:54 PM | Computer Name = Andy-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/16/2010 12:13:22 PM | Computer Name = Andy-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 9/16/2010 12:16:25 PM | Computer Name = Andy-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 9/16/2010 12:19:29 PM | Computer Name = Andy-PC | Source = .NET Runtime Optimization Service | ID = 1111
Description =

[ System Events ]
Error - 5/24/2010 4:31:36 AM | Computer Name = Andy-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 5/24/2010 6:56:49 AM | Computer Name = Andy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 5/24/2010 6:56:49 AM | Computer Name = Andy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 5/24/2010 6:56:50 AM | Computer Name = Andy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 5/24/2010 6:56:50 AM | Computer Name = Andy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 5/24/2010 11:46:36 AM | Computer Name = Andy-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/24/2010 11:46:36 AM | Computer Name = Andy-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 5/24/2010 1:50:20 PM | Computer Name = Andy-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 5/25/2010 3:52:11 AM | Computer Name = Andy-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/25/2010 3:52:11 AM | Computer Name = Andy-PC | Source = atikmdag | ID = 43029
Description = Display is not active


< End of report >
================================================================================
==================
Hijackthis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:47:39, on 16/09/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Users\Andy\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Andy\Downloads\OTL.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\notepad.exe
C:\Windows\notepad.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Andy\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [VitaKeyPdtWzd] "C:\Program Files\Acer Bio Protection\PdtWzd.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1ca8266b0f331a7) (gupdate1ca8266b0f331a7) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - C:\Program Files\Acer Bio Protection\BASVC.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

–
End of file - 7970 bytes
================================================================================
=====================================================
Combofix

ComboFix 10-09-15.02 - Andy 16/09/2010 16:44:41.1.2 - x86 NETWORK
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3294.2512 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Andy\AppData\Roaming\900E0F3EEBC00BD9348F8FC019BEF464
c:\users\Andy\AppData\Roaming\900E0F3EEBC00BD9348F8FC019BEF464\enemies-names.txt
c:\users\Andy\AppData\Roaming\900E0F3EEBC00BD9348F8FC019BEF464\local.ini

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

Infected copy of c:\windows\System32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
.
((((((((((((((((((((((((( Files Created from 2010-08-16 to 2010-09-16 )))))))))))))))))))))))))))))))
.

2010-09-16 15:43 . 2010-09-16 15:43 ——– d—–w- C:\32788R22FWJFW
2010-09-16 11:20 . 2009-10-31 06:00 2614272 —-a-w- c:\windows\explorer.exe
2010-09-16 00:55 . 2010-08-12 12:15 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-09-15 22:59 . 2010-08-12 12:15 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-09-15 22:59 . 2010-09-15 22:59 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-15 22:55 . 2010-09-15 22:55 ——– d—–w- c:\users\Andy\AppData\Local\Sunbelt Software
2010-09-15 22:54 . 2010-09-15 22:59 ——– d—–w- c:\programdata\Lavasoft
2010-09-15 22:54 . 2010-09-15 22:54 ——– d—–w- c:\program files\Lavasoft
2010-09-15 22:44 . 2010-09-15 22:54 ——– dc-h–w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-15 17:28 . 2010-08-21 05:32 316928 —-a-w- c:\windows\system32\spoolsv.exe
2010-09-15 17:24 . 2010-09-15 17:24 ——– d—–w- c:\users\Andy\AppData\Roaming\Tific
2010-09-15 17:24 . 2010-09-15 17:24 ——– d—–w- c:\users\Andy\AppData\Local\Symantec
2010-09-15 15:23 . 2010-09-15 15:23 ——– d—–w- C:\N360_BACKUP
2010-09-15 15:22 . 2009-05-18 22:17 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-09-15 15:22 . 2008-04-17 21:12 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-09-15 15:22 . 2010-09-15 15:28 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-09-15 15:22 . 2010-09-15 15:22 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-09-15 15:22 . 2010-09-15 15:22 ——– d—–w- c:\program files\Symantec
2010-09-15 15:21 . 2010-09-15 17:23 ——– d—–w- c:\windows\system32\drivers\N360
2010-09-15 15:21 . 2010-09-15 15:21 ——– d—–w- c:\program files\Norton 360
2010-09-15 15:21 . 2010-09-16 02:21 ——– d—–w- c:\programdata\Norton
2010-09-15 15:19 . 2010-09-15 15:20 ——– d—–w- c:\programdata\NortonInstaller
2010-09-15 15:19 . 2010-09-15 15:19 ——– d—–w- c:\program files\NortonInstaller
2010-09-13 21:05 . 2010-09-13 21:05 ——– d—–w- c:\users\Andy\AppData\Roaming\Malwarebytes
2010-09-13 21:05 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-13 21:05 . 2010-09-13 21:05 ——– d—–w- c:\programdata\Malwarebytes
2010-09-13 21:05 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-13 21:05 . 2010-09-15 21:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-13 14:29 . 2010-09-13 14:29 768 —-a-w- c:\windows\SCtrlSet1.bin
2010-09-13 14:28 . 2010-09-13 14:31 ——– d—–w- C:\HanWJ
2010-08-25 08:10 . 2010-04-07 07:10 571904 —-a-w- c:\windows\system32\oleaut32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-16 07:07 . 2010-01-03 01:47 ——– d—–w- c:\users\Andy\AppData\Roaming\uTorrent
2010-09-16 02:21 . 2009-07-14 04:52 ——– d—–w- c:\program files\Windows Portable Devices
2010-09-15 19:58 . 2010-01-09 20:19 ——– d—–w- c:\programdata\Microsoft Help
2010-09-15 15:22 . 2010-09-15 15:22 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-09-15 15:22 . 2010-09-15 15:22 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-09-14 20:28 . 2009-12-21 18:03 ——– d—–w- c:\users\Andy\AppData\Roaming\vlc
2010-09-13 14:33 . 2010-08-15 13:43 ——– d—–w- c:\programdata\Skype
2010-09-09 17:00 . 2010-01-02 13:24 ——– d—–w- c:\programdata\NOS
2010-09-02 13:32 . 2010-06-17 20:30 ——– d—–w- c:\users\Andy\AppData\Roaming\Spotify
2010-08-29 06:31 . 2010-06-05 12:00 ——– d—–w- c:\program files\uTorrent
2010-08-17 15:04 . 2010-08-17 08:28 ——– d—–w- c:\programdata\AVG Security Toolbar
2010-08-15 13:43 . 2010-08-15 13:43 ——– d—–w- c:\program files\Skype
2010-08-12 12:16 . 2010-09-15 22:54 2979848 -c–a-w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
2010-07-29 06:30 . 2010-08-11 04:38 197632 —-a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-11 04:38 82944 —-a-w- c:\windows\system32\iccvid.dll
2010-07-19 12:28 . 2010-01-09 20:21 ——– d—–w- c:\program files\Microsoft.NET
2010-07-19 09:03 . 2009-12-21 14:48 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-19 09:03 . 2010-07-19 09:03 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-07-19 09:03 . 2009-12-21 14:48 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-16 09:38 . 2010-08-28 06:04 836096 —-a-w- c:\users\Andy\AppData\Roaming\Octoshape\Octoshape Streaming Services\pmv307a-1007160-0-libOctoshapeClient.dll
2010-06-30 06:25 . 2010-08-11 04:38 978432 —-a-w- c:\windows\system32\wininet.dll
2010-06-22 02:47 . 2010-08-11 04:38 310784 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-08-11 04:38 307200 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-08-11 04:38 113664 —-a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 06:33 . 2010-08-11 04:38 3955080 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33 . 2010-08-11 04:38 3899784 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23 . 2010-08-11 04:38 37376 —-a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-08-11 04:38 2326016 —-a-w- c:\windows\system32\win32k.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 02:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-19 2065760]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"VitaKeyPdtWzd"="c:\program files\Acer Bio Protection\PdtWzd.exe" [2009-09-05 3575808]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-29 98304]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2009-07-07 817672]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk.disabled [2010-4-16 2073]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2009-06-26 10:05 568072 —-a-w- c:\program files\Common Files\SPBA\homefus2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"MobileConnect"=%programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

R2 gupdate1ca8266b0f331a7;Google Update Service (gupdate1ca8266b0f331a7);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 133104]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-04-19 430152]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-01 1343400]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-08-12 64288]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0402000.00C\SYMDS.SYS [2009-10-15 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0402000.00C\SYMEFA.SYS [2010-04-22 173104]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-19 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-19 243024]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100901.003\BHDrvx86.sys [2010-09-01 692272]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0402000.00C\ccHPx86.sys [2010-02-26 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100910.001\IDSvix86.sys [2010-08-26 344112]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0402000.00C\Ironx86.SYS [2010-04-29 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360\0402000.00C\SYMTDIV.SYS [2010-05-06 339504]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-29 176128]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-19 308136]
S2 IGBASVC;EgisTec Service;c:\program files\Acer Bio Protection\BASVC.exe [2009-09-05 3453440]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-09-15 1355928]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe [2010-02-26 126392]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2009-09-18 9216]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-09-15 102448]
S3 nuvotoncir;Nuvoton IR Transceiver;c:\windows\system32\DRIVERS\nuvotoncir.sys [2009-06-24 44544]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-08-10 171520]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 27320]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-09-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 17:54]

2010-09-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 17:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\cfxHelper@Triton\components\dwmxpcom.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Andy\AppData\Roaming\Mozilla\plugins\npoctoshape.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-LSI Soft Modem - c:\windows\agrsmdel



[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.2.0.12\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4252)
c:\windows\System32\ieframe.dll
c:\progra~1\SPYBOT~1\SDHelper.dll
c:\program files\Norton 360\Engine\4.2.0.12\BuEng.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\SPBA\upeksvr.exe
c:\program files\Acer Bio Protection\CompPtcVUI.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\users\Andy\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\sppsvc.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-09-16 17:01:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-16 16:01

Pre-Run: 20,347,101,184 bytes free
Post-Run: 20,188,811,264 bytes free

- - End Of File - - 74B8F23572FA6FE030469A850C61AA30
Hi Woony

:welcome:

Sorry for the delay in replying, we are very busy at the moment. My name is Blottedisk, I'll be happy to assist you with all your malware problems you have on your computer. Solving any malware-related problem may or may not solve other issues you have with your machine. Before we start fixing your computer, there are a few points you need to know:

  • The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.. Please don't start a new topic, but reply on this one.
  • Malware Logs can sometimes take a lot of time to research and interpret. Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • If you don't understand something, please ask! If you find any new problems and/or details, please post them!
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process. Please do not delete anything unless instructed to. Do not use the comptuer exept for downloading tools and checking this topic
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay in response time, but I will do my best to keep it as short as possible.

Remember: absence of symptoms does not mean your computer is clean.

Reply to this topic until I say your computer is clean. Please bear with me, I will post back to you as soon as I can.

Thanks :thumbup:
Hi again Woony,


You should not be following fixes in another threads as those fixes are specifically for those computers. Following someone elses fix may harm your computer.


P2P Software


You are using peer-to-peer programs, specifically uTorrent.
These are what we call an optional removal. However, anytime you are running any type of peer-to-peer application, you are more prone to infection by malware, and this is probably how you became infected in the first place. The choice to remove them is entirely up to you, but I would strongly recommend that you do.
If you do not want to, please at least refrain from using any peer-to-peer programs for the remainder of my fix.


Two Antivirus Running

You are also operating your computer with multiple Anti Virus programs running in memory at once:

  • Norton 360
  • AVG9
Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having more than one program running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

Please go to Start –> Run and type appwiz and press enter. Uninstall either Norton360 or AVG9


Post Spybot S&D Logs

Please navigate to the following location:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs

Copy the contents of your latest fixes, checks and resident logfiles and paste them in your next reply. You will recognize the latest ones because they are dated, in this format:

Checks.yymmdd-hhmm and Fixes.yymmdd-hhmm and Resident.yymmdd-hhmm


Post Malwarebyte's Logs


Please open Malwarebyte´s Antimalware and go to the Logs tab.
Have a look through the different dated logs, and double-click the newest one. A .txt file will be opened.
Again, have a look through the different dated logs, and double-click the previous to the newest one. A .txt file will be opened.
Please copy the contents of both txt files and paste them in your next reply.
Hi thanks for replying. All i could find in the logs of spybot search and destory are the resident logs.

Spybot Resident Logs
==================
9/15/2010 4:20:39 PM Allowed (based on user decision) value "N360" (new data: ""C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\2454B0AB\4.0.0.127\InstStub.exe" /RELAUNCH /RUNONCE /PRODID N360") added in System Startup global entry!
9/15/2010 4:21:28 PM Allowed (based on user decision) value "N360" (new data: ""C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\2454B0AB\4.0.0.127\InstStub.exe" /RELAUNCH /RUNONCE /NOPROMPT /PRODID N360") changed in System Startup global entry!
9/15/2010 4:22:03 PM Allowed (based on user decision) value "N360" (new data: "") deleted in System Startup global entry!
9/15/2010 4:22:16 PM Allowed (based on authenticode whitelist) value "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" (new data: "Norton Toolbar") added in Global browser toolbar!
9/15/2010 4:22:24 PM Allowed (based on authenticode whitelist) value "{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}" (new data: "") added in Browser Helper Object!
9/15/2010 4:22:34 PM Allowed (based on authenticode whitelist) value "{6D53EC84-6AAE-4787-AEEE-F4628F01010C}" (new data: "") added in Browser Helper Object!
9/15/2010 4:31:00 PM Allowed (based on user decision) value "Shell" (new data: "Explorer.exe") changed in Winlogon!
9/15/2010 10:05:37 PM Allowed (based on authenticode whitelist) value "Malwarebytes' Anti-Malware" (new data: "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent") added in System Startup global entry!
9/15/2010 11:58:38 PM Allowed (based on user decision) value "Malwarebytes' Anti-Malware" (new data: "") deleted in System Startup global entry!
9/16/2010 8:06:18 AM Allowed (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") changed in Session manager!
9/16/2010 4:55:01 PM Denied (based on user decision) value "System" (new data: "") added in Winlogon!
16/09/2010 17:13:47 Denied (based on user decision) value "System" (new data: "") added in Winlogon!
9/16/2010 5:18:12 PM Denied (based on user decision) value "NCInstallQueue" (new data: "rundll32 netman.dll,ProcessQueue") added in System Startup global entry!
9/16/2010 5:18:19 PM Denied (based on user decision) value "System" (new data: "") added in Winlogon!
9/17/2010 11:57:38 PM Allowed (based on user decision) value "{D4027C7F-154A-4066-A1AD-4243D8127440}" (new data: "") deleted in Global browser toolbar!
9/20/2010 1:41:12 PM Allowed (based on user decision) value "{A3BC75A2-1F87-4686-AA43-5347D756017C}" (new data: "") deleted in Browser Helper Object!
9/20/2010 1:41:13 PM Allowed (based on user decision) value "{A3BC75A2-1F87-4686-AA43-5347D756017C}" (new data: "") deleted in Internet Explorer searches!
9/20/2010 1:41:17 PM Allowed (based on user decision) value "AVG9_TRAY" (new data: "") deleted in System Startup global entry!
9/20/2010 1:42:00 PM Allowed (based on user decision) value "AvgUninstallURL" (new data: "cmd.exe /c start http://www.avg.com/ww.special-uninstallati…=9.0.839") added in System Startup global entry!


Malwarebytes' Log
===================
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4610

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

14/09/2010 07:18:39
mbam-log-2010-09-14 (07-18-39).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 210963
Time elapsed: 56 minute(s), 44 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
C:\Users\Andy\AppData\Roaming\900E0F3EEBC00BD9348F8FC019BEF464\handlerfix70700en00.exe (Rogue.Installer) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\handlerfix70700en00.exe (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xaswrenocm.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Andy\AppData\Roaming\900E0F3EEBC00BD9348F8FC019BEF464\handlerfix70700en00.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Andy\AppData\Local\Temp\xaswrenocm.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Andy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3M8TV89G\handlerfix70700en00[2].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp (Rootkit.Agent.Gen) -> Quarantined and deleted successfully.
C:\Users\Andy\Downloads\setup.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Users\Andy\Templates\memory.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

Thanks again
Hi Woony,


Have you received any more Spybot alerts regarding to winlogon and those dlls in the last 2 days?
Please do the following:


Step 1 | As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.

The log can also be found here:

  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when the application is started.

Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.
Failure to reboot will prevent MBAM from removing all the malware.


Step 2 | Please go to Kaspersky website and perform an online antivirus scan. Note: Internet Explorer should be used.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.

[external image: Posted Image]



Step 3 | Lets take another OTL log. Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

  • Click the Quick Scan button without changing any settings. The scan wont take long.
    • When the scan completes, it will open a notepad window: OTL.Txt. It is saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of OTL.Txt, and post it in your next reply.
  • Note: there will only be an OTL.txt this time



Please post back with:

Malwarebyte's Antimalware Log
Kaspersky log
OTL.txt
I've had no more updates from spybot about winlogon and the dlls since the day i used combofix and it all seems to be running smoothly now. My norton deleted explorer.exe.vir due to suspicious mystic, i've not rebooted yet so i don't know if this has caused a problem. Thanks again

Malwarebytes

=====================
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4667

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

21/09/2010 23:43:51
mbam-log-2010-09-21 (23-43-51).txt

Scan type: Quick scan
Objects scanned: 143659
Time elapsed: 9 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Kaspersky Online Scanner
===========================
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, September 22, 2010
Operating system: Microsoft Home Edition (build 7600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, September 21, 2010 19:39:17
Records in database: 4235783
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 86494
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 03:00:41

No threats found. Scanned area is clean.

Selected area has been scanned.

OTL.txt
===============
OTL logfile created on: 9/22/2010 12:59:50 PM - Run 2
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Users\Andy\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.44 Gb Total Space | 8.21 Gb Free Space | 7.37% Space Free | Partition Type: NTFS
Drive D: | 107.90 Gb Total Space | 107.45 Gb Free Space | 99.59% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDY-PC
Current User Name: Andy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Andy\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Andy\AppData\Local\temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Norton 360\Engine\4.2.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files\Acer Bio Protection\PdtWzd.exe (Egis Technology Inc.)
PRC - C:\Program Files\Acer Bio Protection\BASVC.exe (Egis Technology Inc.)
PRC - C:\Program Files\Acer Bio Protection\CompPtcVUI.exe (Egis Technology Inc.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Common Files\SPBA\upeksvr.exe (UPEK Inc.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Andy\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (VMCService) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (IGBASVC) – C:\Program Files\Acer Bio Protection\BASVC.exe (Egis Technology Inc.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\Andy\AppData\Local\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100921.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100921.003\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100901.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100920.001\IDSvix86.sys (Symantec Corporation)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0402000.00C\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0402000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0402000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0402000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0402000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\system32\drivers\N360\0402000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0402000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\System32\drivers\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (nuvotoncir) – C:\Windows\System32\drivers\nuvotoncir.sys (Nuvoton Technology Corporation)
DRV - (RTHDMIAzAudService) – C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (TcUsb) – C:\Windows\System32\drivers\tcusb.sys (UPEK Inc.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (usbfilter) – C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices)
DRV - (DKbFltr) – C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys ()
DRV - (winbondcir) – C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 C8 97 73 49 82 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:4.51
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/09/15 20:55:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/09/16 03:21:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/17 12:47:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/17 12:47:16 | 000,000,000 | —D | M]

[2009/12/21 15:52:24 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Extensions
[2010/09/21 14:07:06 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions
[2010/05/30 15:57:55 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/05/10 23:32:20 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\cfxe@Triton
[2010/05/10 23:32:20 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\extensions\cfxHelper@Triton
[2010/09/18 10:56:48 | 000,001,238 | —- | M] () – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\searchplugins\facebook.xml
[2009/12/22 16:44:48 | 000,001,512 | —- | M] () – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\searchplugins\imdb.xml
[2009/12/21 16:00:04 | 000,001,720 | —- | M] () – C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\el0ka41n.default\searchplugins\youtube-video-search.xml
[2010/09/21 14:07:06 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/16 01:55:13 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/16 01:55:13 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/16 01:55:13 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/16 01:55:13 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/09/16 16:53:05 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VitaKeyPdtWzd] C:\Program Files\Acer Bio Protection\PdtWzd.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.)
O9 - Extra 'Tools' menuitem : Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer Bio Protection\PwdBank.exe (Egis Technology Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\spba: DllName - C:\Program Files\Common Files\SPBA\homefus2.dll - C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/09/21 01:15:53 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Roaming\DivX
[2010/09/21 01:11:15 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/09/16 17:15:56 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/09/16 17:01:47 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/09/16 16:53:17 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/09/16 16:50:41 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Local\temp
[2010/09/16 16:43:56 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/09/16 16:43:56 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/09/16 16:43:56 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/09/16 16:43:44 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/09/16 16:43:30 | 000,000,000 | —D | C] – C:\Qoobox
[2010/09/16 16:43:15 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/09/16 16:43:13 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/09/15 23:59:50 | 000,064,288 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2010/09/15 23:59:47 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/09/15 23:55:06 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Local\Sunbelt Software
[2010/09/15 23:54:17 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/09/15 23:54:17 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/09/15 23:44:59 | 000,000,000 | -H-D | C] – C:\ProgramData\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/09/15 18:24:04 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Roaming\Tific
[2010/09/15 18:24:03 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Local\Symantec
[2010/09/15 17:52:39 | 000,339,504 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\symtdiv.sys
[2010/09/15 17:52:39 | 000,328,752 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\symds.sys
[2010/09/15 17:52:39 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\symefa.sys
[2010/09/15 17:52:39 | 000,043,696 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\srtspx.sys
[2010/09/15 17:52:38 | 000,501,888 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\cchpx86.sys
[2010/09/15 17:52:38 | 000,325,680 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\srtsp.sys
[2010/09/15 17:52:38 | 000,116,784 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0402000.00C\ironx86.sys
[2010/09/15 17:52:00 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360\0402000.00C
[2010/09/15 16:23:54 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2010/09/15 16:22:47 | 000,000,000 | —D | C] – C:\Users\Andy\Documents\Symantec
[2010/09/15 16:22:01 | 000,124,976 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/09/15 16:22:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/09/15 16:22:01 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/09/15 16:21:21 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360
[2010/09/15 16:21:18 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/09/15 16:21:17 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2010/09/15 16:19:27 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2010/09/15 16:19:27 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/09/13 22:05:35 | 000,000,000 | —D | C] – C:\Users\Andy\AppData\Roaming\Malwarebytes
[2010/09/13 22:05:26 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/09/13 22:05:25 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/09/13 22:05:23 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/09/13 22:05:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/13 21:52:32 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Server
[2010/09/13 15:28:45 | 000,000,000 | —D | C] – C:\HanWJ
[2010/08/30 13:48:28 | 000,000,000 | —D | C] – C:\Users\Andy\Desktop\Movies
[2010/08/15 14:43:05 | 000,000,000 | —D | C] – C:\Program Files\Skype
[2010/08/15 14:43:02 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2010/08/11 12:36:53 | 000,000,000 | —D | C] – C:\Users\Andy\Desktop\SaM146
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/09/22 13:01:55 | 008,388,608 | -HS- | M] () – C:\Users\Andy\ntuser.dat
[2010/09/22 12:32:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/22 03:15:33 | 000,989,364 | —- | M] () – C:\Windows\System32\drivers\N360\0402000.00C\Cat.DB
[2010/09/21 17:31:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/21 12:45:36 | 000,014,832 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/21 12:45:36 | 000,014,832 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/21 12:38:51 | 000,000,370 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/09/21 12:37:21 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/21 12:37:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/21 12:36:58 | 2590,789,632 | -HS- | M] () – C:\hiberfil.sys
[2010/09/21 06:15:21 | 001,727,483 | -H– | M] () – C:\Users\Andy\AppData\Local\IconCache.db
[2010/09/19 04:45:37 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/09/19 04:07:11 | 000,720,082 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/19 04:07:11 | 000,623,784 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/19 04:07:11 | 000,109,736 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/16 16:53:43 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/09/16 16:53:05 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/09/15 23:59:46 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/09/15 23:54:35 | 000,001,128 | —- | M] () – C:\Users\Andy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/15 18:22:59 | 000,002,326 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2010/09/15 16:22:01 | 000,124,976 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/09/15 16:22:01 | 000,007,443 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/09/15 16:22:01 | 000,000,805 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010/09/13 15:31:36 | 000,001,167 | —- | M] () – C:\Windows\HWJ.INI
[2010/09/13 15:29:50 | 000,000,768 | —- | M] () – C:\Windows\SCtrlSet1.bin
[2010/09/02 14:59:09 | 000,417,891 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.msn
[2010/09/02 14:59:09 | 000,417,891 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100914-192628.backup
[2010/09/02 14:58:59 | 000,417,891 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100902-215909.backup
[2010/08/12 13:15:20 | 000,064,288 | —- | M] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2010/08/12 13:15:20 | 000,015,880 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2010/08/11 11:23:46 | 000,011,188 | —- | M] () – C:\Users\Andy\Desktop\326 Kam Tsin TsuenSheng ShuiNT.docx
[2010/08/11 10:51:39 | 000,409,784 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/07/22 20:44:25 | 000,414,782 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100902-215859.backup
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/19 12:24:31 | 000,000,370 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/09/16 16:43:56 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/09/16 16:43:56 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/09/16 16:43:56 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/09/16 16:43:56 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/09/16 16:43:56 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/09/16 01:55:21 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/09/15 23:54:35 | 000,001,128 | —- | C] () – C:\Users\Andy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/15 18:22:09 | 000,989,364 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\Cat.DB
[2010/09/15 17:52:39 | 000,007,873 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symefa.cat
[2010/09/15 17:52:39 | 000,007,787 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnetv.cat
[2010/09/15 17:52:39 | 000,007,442 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtspx.cat
[2010/09/15 17:52:39 | 000,007,425 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symds.cat
[2010/09/15 17:52:39 | 000,007,368 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnet.cat
[2010/09/15 17:52:39 | 000,003,373 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symefa.inf
[2010/09/15 17:52:39 | 000,002,793 | R— | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symds.inf
[2010/09/15 17:52:39 | 000,001,473 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnetv.inf
[2010/09/15 17:52:39 | 000,001,445 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\symnet.inf
[2010/09/15 17:52:39 | 000,001,388 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtspx.inf
[2010/09/15 17:52:38 | 000,007,438 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtsp.cat
[2010/09/15 17:52:38 | 000,007,438 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\iron.cat
[2010/09/15 17:52:38 | 000,007,396 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\cchpx86.cat
[2010/09/15 17:52:38 | 000,001,754 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\cchpx86.inf
[2010/09/15 17:52:38 | 000,001,382 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\srtsp.inf
[2010/09/15 17:52:38 | 000,000,741 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\iron.inf
[2010/09/15 17:52:00 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\N360\0402000.00C\isolate.ini
[2010/09/15 16:22:01 | 000,007,443 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/09/15 16:22:01 | 000,000,805 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010/09/15 16:21:54 | 000,002,326 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2010/09/13 15:29:50 | 000,000,768 | —- | C] () – C:\Windows\SCtrlSet1.bin
[2010/09/13 15:29:49 | 000,001,167 | —- | C] () – C:\Windows\HWJ.INI
[2010/08/11 11:19:02 | 000,011,188 | —- | C] () – C:\Users\Andy\Desktop\326 Kam Tsin TsuenSheng ShuiNT.docx
[2010/04/15 23:37:14 | 000,002,330 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/02/15 22:03:53 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2009/08/28 14:16:16 | 000,130,238 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2009/07/14 00:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2008/09/11 13:01:00 | 000,081,920 | —- | C] () – C:\Windows\System32\INT15.dll
[2008/09/09 10:38:48 | 000,097,792 | —- | C] () – C:\Windows\System32\INT15_64.dll
[2008/09/09 10:38:48 | 000,015,656 | —- | C] () – C:\Windows\System32\drivers\int15_64.sys
[2008/03/12 12:52:34 | 000,069,632 | —- | C] () – C:\Windows\System32\drivers\int15.sys

========== LOP Check ==========

[2010/01/10 00:02:29 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Octoshape
[2010/09/02 14:32:34 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Spotify
[2010/09/15 18:24:04 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Tific
[2010/09/22 12:37:12 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\uTorrent
[2010/03/30 13:04:24 | 000,000,000 | —D | M] – C:\Users\Andy\AppData\Roaming\Vodafone
[2010/09/21 12:38:51 | 000,000,370 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/08/29 14:30:09 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
Hi Woony,


The Winlogon thing is fixed, and Norton is just dealing with an old infected file. It seems there's no more malware in your machine.
We're done, good job :)


Please follow these last steps.



Step 1 | Delete ComboFix and Clean Up

The following will implement some cleanup procedures as well as reset System Restore points. Click Start > Run and copy/paste the following underlined text into the Run box and click OK:

ComboFix /Uninstall

Please advise if this step is missed for any reason as it performs some important actions.


Step 2 | Clean up with OTL

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Now, from the desktop, delete any logs that you have left over. including these ones:

    C:\rkill.log
    Rkill itself

Step 3 | Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

  • Click on the following link to visit java website: Java Runtime Environment (JRE) 6
  • Scroll down to where it says "JDK 6 Update 21 (JDK or JRE)".
  • Click the "Download" button to the right column (JRE).
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue. The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the recently downloaded java installer icon to install the newest version.
  • After the install is complete, go into the Control Panel
    (using Classic View) and double-click the Java Icon. (looks like a
    coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

Step 4 | Please download TFC by OldTimer to your desktop.

  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • Click the Start button in the bottom left of TFC
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.


Last Step | Now, in order to avoid future infections, please take time to read the following articles:


Read those articles and your potential for being infected again will reduce dramatically. Avoid underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.


Thank you for your patience, and performing all of the procedures requested. I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can then be closed. Posted Image

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI