This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help in clearing the virus

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here is the OTL

OTL logfile created on: 9/22/2010 5:46:58 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Wati\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.32 Gb Total Space | 162.41 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 270.44 Gb Total Space | 267.10 Gb Free Space | 98.76% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 239.53 Mb Total Space | 25.98 Mb Free Space | 10.85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: UBS
Current User Name: Wati
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Wati\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Wati\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - D:\OpenDrive\shah\OpenDrive_Tray.exe ()
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\ParetoLogic\FileCure\FileCure.exe (ParetoLogic)
PRC - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAV.exe (PC Tools Research Pty Ltd)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - D:\UBSACC90\NETWORK\Serialkey\UBSLicenseService.exe (home)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Wati\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (USBLAN_Ldr) – E:\Ubs\Network\V92\Service\USBLAN_Ldr.EXE File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PCTAVSvc) – C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (UBSLicense) – D:\UBSACC90\NETWORK\Serialkey\UBSLicenseService.exe (home)


========== Driver Services (SafeList) ==========

DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AVRec) – C:\WINDOWS\system32\drivers\AVRec.sys (PC Tools Research Pty Ltd )
DRV - (AVHook) – C:\WINDOWS\system32\drivers\AVHook.sys (PC Tools Research Pty Ltd.)
DRV - (AVFilter) – C:\WINDOWS\system32\drivers\AVFilter.sys (PC Tools Research Pty Ltd)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "data:text/plain,browser.startup.homepage=http://malaysia.search.yahoo.com/firefox/?fr=yff35k-sfp"
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://my.search.yahoo.com/search?ei=UTF-8&fr=yff35kawe&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "ToggleEN Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://malaysia.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://malaysia.search.yahoo.com/firefox/?fr=yff35k-sfp"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {210779b6-fbf4-42ea-97f2-570782d136a3}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {038cb5c7-48ea-4af9-94e0-a1646542e62b}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:[removed]
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/30 12:14:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/14 03:49:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/06 13:54:34 | 000,000,000 | —D | M]

[2010/07/14 03:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Extensions
[2010/08/28 12:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions
[2010/08/03 13:10:18 | 000,000,000 | —D | M] (ToggleEN Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
[2010/08/03 13:05:35 | 000,000,000 | —D | M] (Overget Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{210779b6-fbf4-42ea-97f2-570782d136a3}
[2010/08/24 16:48:21 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/03 13:25:11 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/08/18 13:44:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/08/03 13:16:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\[removed]
[2010/06/30 19:22:32 | 000,000,919 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\searchplugins\conduit.xml
[2010/08/23 14:13:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/14 03:49:10 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

O1 HOSTS File: ([2010/06/22 03:43:01 | 000,012,407 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: '>http://www.w3.org/TR/html4/strict.dtd">
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Yahoo! GeoCities: Get a web site with easy-to-use site building tools.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:

O1 - Hosts:

O1 - Hosts: 90 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ToggleEN Toolbar) - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OpenDrive Tray] D:\OpenDrive\shah\OpenDrive_Tray.exe ()
O4 - HKLM..\Run: [PCTAVApp] C:\Program Files\PC Tools AntiVirus\PCTAV.exe (PC Tools Research Pty Ltd)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Wati\Start Menu\Programs\Startup\1E0D1C.lnk = C:\WINDOWS\System32\414227\1E0D1C.EXE File not found
O4 - Startup: C:\Documents and Settings\Wati\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Wati\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/18 09:00:05 | 000,000,007 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{722cd71c-a681-11df-8db0-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{722cd71c-a681-11df-8db0-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{788fe03b-9def-11df-8d9f-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{788fe03b-9def-11df-8d9f-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\1\Command - "" = G:\Recycle.exe – File not found
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\2\Command - "" = G:\Recycle.exe – File not found
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\AutoRun\command - "" = qevfra.exe
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\explore\Command - "" = qevfra.exe
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\open\Command - "" = qevfra.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: hoffwr - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: lyixs - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: smkckp - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: yobykmkdf - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: vkxohf - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: ycppmaor - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: dzgooky - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: yjerilywj - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: zlxylksc - C:\WINDOWS\System32\crwrw.dll File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/22 17:38:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/09/22 17:38:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/09/18 13:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2010/09/15 08:50:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Wati\Recent
[2010/09/09 11:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\New Folder
[2010/09/08 09:34:08 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\IECompatCache
[2010/09/04 10:35:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\OpenDrive
[2010/09/04 10:13:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\Gygan Downloads
[2010/09/04 10:13:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Application Data\Gygan
[2010/09/04 10:13:43 | 000,000,000 | —D | C] – C:\Program Files\Xenocode
[2010/09/04 10:13:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Xenocode
[2010/09/04 10:13:41 | 000,000,000 | —D | C] – C:\Program Files\Gygan BETA
[2010/09/01 12:00:59 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\PrivacIE
[2010/09/01 11:53:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\IETldCache
[2010/09/01 11:45:20 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2010/09/01 11:44:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/09/01 11:44:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/08/30 14:57:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Deployment
[2010/08/27 15:16:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Conduit
[2010/08/27 15:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ParetoLogic
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/08/26 13:36:06 | 000,000,000 | —D | C] – C:\Program Files\ParetoLogic
[2010/08/26 11:13:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\shah
[2010/08/26 10:39:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\audex
[2010/08/26 09:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\acc
[2010/08/24 17:03:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Yahoo
[2010/08/24 16:48:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2010/08/24 16:48:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Application Data\Yahoo!
[2010/08/24 16:47:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2010/08/24 15:43:47 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/22 17:50:40 | 000,000,374 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/22 17:40:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/09/22 17:40:01 | 000,000,378 | —- | M] () – C:\WINDOWS\tasks\FileCure Startup.job
[2010/09/22 17:40:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/22 17:39:59 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/22 17:39:26 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Wati\NTUSER.DAT
[2010/09/22 17:39:04 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Wati\ntuser.ini
[2010/09/22 17:38:44 | 000,000,826 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/22 17:38:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/22 17:36:10 | 000,157,074 | —- | M] () – C:\WINDOWS\System32\x
[2010/09/22 17:08:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/09/22 17:02:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003UA.job
[2010/09/22 17:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/09/22 15:02:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003Core.job
[2010/09/21 15:41:29 | 000,059,904 | —- | M] () – C:\Documents and Settings\Wati\My Documents\BANK RECON AUG 2010.xls
[2010/09/21 15:28:39 | 001,712,720 | —- | M] () – C:\Documents and Settings\Wati\My Documents\How%20To%20Register%20a%20Business%20Online%20Using%20SSM%20ebook.pdf
[2010/09/18 14:02:20 | 000,002,283 | —- | M] () – C:\Documents and Settings\Wati\Desktop\Google Chrome.lnk
[2010/09/18 14:02:20 | 000,002,261 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/09/17 16:31:59 | 000,016,896 | —- | M] () – C:\Documents and Settings\Wati\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 16:31:59 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/09/17 13:50:15 | 000,202,240 | —- | M] () – C:\Documents and Settings\Wati\Desktop\PPE2010.xls
[2010/09/13 18:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2010/09/13 02:04:00 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\FileCure Default.job
[2010/09/11 05:42:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2010/09/09 16:57:04 | 000,067,584 | —- | M] () – C:\Documents and Settings\Wati\My Documents\draft FS - aug 2010.xls
[2010/09/09 11:32:01 | 000,000,123 | —- | M] () – C:\Documents and Settings\Wati\Application Data\default.rss
[2010/09/08 15:57:24 | 000,025,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JVJUL.xls
[2010/09/08 15:57:12 | 000,027,136 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JVAUG.xls
[2010/09/08 15:56:50 | 000,025,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JV.xls
[2010/09/07 18:22:05 | 004,813,446 | -H– | M] () – C:\Documents and Settings\Wati\Local Settings\Application Data\IconCache.db
[2010/09/07 12:44:02 | 000,156,250 | —- | M] () – C:\Documents and Settings\Wati\Desktop\newcf.xlsx
[2010/09/06 16:46:29 | 000,013,513 | —- | M] () – C:\Documents and Settings\Wati\Desktop\Purchase Order Form.docx
[2010/09/05 15:39:01 | 000,000,810 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/09/04 12:10:11 | 000,001,448 | —- | M] () – C:\Documents and Settings\All Users\Desktop\UBS Accounting System 9.2 (SR2).lnk
[2010/09/04 10:13:41 | 000,000,627 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Gygan.lnk
[2010/09/03 15:04:13 | 000,192,000 | —- | M] () – C:\Documents and Settings\Wati\My Documents\Presentation1.ppt
[2010/09/03 14:42:23 | 000,437,346 | —- | M] () – C:\Documents and Settings\Wati\My Documents\The%20letters%20of%20the%20Prophet%20Muhammad%20to%20the%20Kings%20beyond%20Arabia.pdf
[2010/09/02 14:02:08 | 000,000,160 | —- | M] () – C:\Documents and Settings\Wati\default.pls
[2010/09/02 10:10:39 | 000,009,485 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MCELEMAILDIRECTORY.xlsx
[2010/09/01 11:53:58 | 000,000,821 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/01 11:45:33 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/30 14:56:59 | 000,021,163 | —- | M] () – C:\Documents and Settings\Wati\My Documents\Contoh%20Kertas%20Kerja.pdf
[2010/08/30 09:42:49 | 000,173,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MULTI PHONE DIRECTORY.TIF
[2010/08/28 15:40:48 | 001,683,456 | —- | M] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls
[2010/08/28 15:40:39 | 000,192,000 | —- | M] () – C:\Documents and Settings\Wati\Desktop\7Excel Format- Tables(latest).xls
[2010/08/28 15:25:20 | 001,738,752 | —- | M] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls1.xls
[2010/08/27 14:33:22 | 001,680,896 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MCELOG_Budget_201112 (3).xls
[2010/08/27 14:32:02 | 000,187,392 | —- | M] () – C:\Documents and Settings\Wati\My Documents\7Excel Format- Tables(latest).xls
[2010/08/26 13:36:07 | 000,000,918 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,900 | —- | M] () – C:\Documents and Settings\Wati\My Documents\ParetoLogic FileCure.lnk
[2010/08/24 16:48:24 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/08/24 16:47:55 | 000,000,826 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/22 17:47:23 | 000,000,374 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/22 17:38:44 | 000,000,826 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/22 17:36:10 | 000,157,074 | —- | C] () – C:\WINDOWS\System32\x
[2010/09/21 15:41:29 | 000,059,904 | —- | C] () – C:\Documents and Settings\Wati\My Documents\BANK RECON AUG 2010.xls
[2010/09/21 15:28:39 | 001,712,720 | —- | C] () – C:\Documents and Settings\Wati\My Documents\How%20To%20Register%20a%20Business%20Online%20Using%20SSM%20ebook.pdf
[2010/09/17 10:41:13 | 000,202,240 | —- | C] () – C:\Documents and Settings\Wati\Desktop\PPE2010.xls
[2010/09/09 16:57:04 | 000,067,584 | —- | C] () – C:\Documents and Settings\Wati\My Documents\draft FS - aug 2010.xls
[2010/09/08 15:57:12 | 000,027,136 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JVAUG.xls
[2010/09/08 15:56:49 | 000,025,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JV.xls
[2010/09/08 15:56:25 | 000,025,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JVJUL.xls
[2010/09/04 10:13:41 | 000,000,627 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Gygan.lnk
[2010/09/03 15:04:11 | 000,192,000 | —- | C] () – C:\Documents and Settings\Wati\My Documents\Presentation1.ppt
[2010/09/03 14:42:23 | 000,437,346 | —- | C] () – C:\Documents and Settings\Wati\My Documents\The%20letters%20of%20the%20Prophet%20Muhammad%20to%20the%20Kings%20beyond%20Arabia.pdf
[2010/09/02 10:10:39 | 000,009,485 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MCELEMAILDIRECTORY.xlsx
[2010/08/30 15:04:25 | 000,002,283 | —- | C] () – C:\Documents and Settings\Wati\Desktop\Google Chrome.lnk
[2010/08/30 15:04:25 | 000,002,261 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/30 14:57:56 | 000,000,974 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003UA.job
[2010/08/30 14:57:56 | 000,000,922 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003Core.job
[2010/08/30 14:56:59 | 000,021,163 | —- | C] () – C:\Documents and Settings\Wati\My Documents\Contoh%20Kertas%20Kerja.pdf
[2010/08/30 09:42:48 | 000,173,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MULTI PHONE DIRECTORY.TIF
[2010/08/28 14:05:05 | 001,738,752 | —- | C] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls1.xls
[2010/08/28 09:08:26 | 001,683,456 | —- | C] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls
[2010/08/28 09:08:26 | 000,192,000 | —- | C] () – C:\Documents and Settings\Wati\Desktop\7Excel Format- Tables(latest).xls
[2010/08/27 14:33:21 | 001,680,896 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MCELOG_Budget_201112 (3).xls
[2010/08/27 14:32:02 | 000,187,392 | —- | C] () – C:\Documents and Settings\Wati\My Documents\7Excel Format- Tables(latest).xls
[2010/08/26 13:36:12 | 000,000,442 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2010/08/26 13:36:09 | 000,000,378 | —- | C] () – C:\WINDOWS\tasks\FileCure Startup.job
[2010/08/26 13:36:09 | 000,000,362 | —- | C] () – C:\WINDOWS\tasks\FileCure Default.job
[2010/08/26 13:36:07 | 000,000,918 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,900 | —- | C] () – C:\Documents and Settings\Wati\My Documents\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2010/08/24 16:48:24 | 000,262,144 | —- | C] () – C:\ntuser.dat
[2010/08/24 16:47:55 | 000,000,826 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/08/18 09:27:20 | 000,012,407 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\Bron.tok.A12.em.bin
[2010/08/16 17:28:07 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.12.Bron.Tok.bin
[2010/08/16 17:22:03 | 000,000,349 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\BronFoldNetDomList.txt
[2010/08/16 17:18:18 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A12.em.bin
[2010/08/11 11:29:38 | 000,000,123 | —- | C] () – C:\Documents and Settings\Wati\Application Data\default.rss
[2010/08/11 11:03:41 | 000,169,608 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/03 13:12:03 | 000,000,085 | —- | C] () – C:\Documents and Settings\Wati\Application Data\toolbar_log.txt
[2010/07/30 11:31:30 | 000,014,022 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/07/23 08:14:06 | 000,000,051 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
[2010/07/23 08:08:31 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ListHost12.txt
[2010/07/23 03:11:01 | 000,016,896 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/15 03:57:34 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/07/10 06:42:35 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/07/10 06:36:49 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2010/06/22 05:03:58 | 000,000,552 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\NetMailTmp.bin
[2010/06/22 03:43:01 | 000,012,407 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\ListHost12.txt
[2007/11/20 06:42:56 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\XYNetComClient.dll
[2007/07/27 20:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/01/11 21:02:03 | 000,026,190 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\NetMailTmp.bin

========== LOP Check ==========

[2010/08/03 13:40:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/09/05 15:38:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/08/26 13:36:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/09/22 17:40:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/03 14:47:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\AskToolbar
[2010/09/21 17:55:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\BitTorrent
[2010/08/03 13:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\DVDVideoSoftIEHelpers
[2010/08/13 09:12:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\FreeFileViewer
[2010/09/04 10:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Gygan
[2010/09/22 12:21:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\PriceGong
[2010/07/29 16:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\RadioBar
[2010/09/22 17:08:00 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010/09/13 02:04:00 | 000,000,362 | —- | M] () – C:\WINDOWS\Tasks\FileCure Default.job
[2010/09/22 17:40:01 | 000,000,378 | —- | M] () – C:\WINDOWS\Tasks\FileCure Startup.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/22 17:50:40 | 000,000,374 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2010/09/13 18:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2010/09/11 05:42:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2010/09/22 17:40:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job
[2010/09/22 17:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/18 09:00:05 | 000,000,007 | -HS- | M] () – C:\AUTOEXEC.BAT
[2010/07/10 06:23:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/07/10 06:28:16 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/10 06:28:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/10 06:28:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/27 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2007/07/27 20:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/08/24 16:48:24 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/08/24 16:48:24 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2010/09/22 17:39:57 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/19 20:21:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/07/02 22:37:10 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/19 20:21:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/07/02 22:37:12 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/07/10 06:28:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/14 16:43:18 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2006/10/27 10:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2006/10/14 16:44:44 | 000,671,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/07/09 23:17:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/07/09 23:17:02 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/07/09 23:17:02 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/10 06:28:20 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/10 06:31:32 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/10 06:31:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >




OTL Extras logfile created on: 9/22/2010 5:46:58 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Wati\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.32 Gb Total Space | 162.41 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 270.44 Gb Total Space | 267.10 Gb Free Space | 98.76% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 239.53 Mb Total Space | 25.98 Mb Free Space | 10.85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: UBS
Current User Name: Wati
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\Wati\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\ParetoLogic\FileCure\FileCure_noapp.exe %1 (ParetoLogic)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"2033:TCP" = 2033:TCP:LocalSubNet:Enabled:UBS Licensing Daemon

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"2033:TCP" = 2033:TCP:LocalSubNet:Enabled:UBS Licensing Daemon
"3145:TCP" = 3145:TCP:*:Enabled:hhrtfdev
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – File not found
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"E:\Ubs\Network\V92\Service\UsbServer2k.exe" = E:\Ubs\Network\V92\Service\UsbServer2k.exe:*:Enabled:UsbLanServer – File not found
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE – (Software 2000 Limited)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – File not found
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{12345678-1234-1234-1234-12345678911C}" = UBS Accounting System 9.2 (SR2)
"{12345678-1234-1234-1234-12345678921A}" = UBS Inventory & Billing 9.2 (SR2)
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1AA4E6C7-6ED7-4A0B-BBA0-D7D579CF6793}" = OpenDrive
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision Help
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{714DAA5E-803F-44A2-8512-64F26E681030}_is1" = Gygan
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{A20A58C4-6784-4B4B-86CC-94E2E3671033}" = Nero 7 Ultra Edition
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{b86754dd-2ddb-4ac0-9015-cb487277254e}" = InCD Help
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C1C441C4-57FA-4950-BDBA-BABFBAA2AA39}" = ParetoLogic FileCure
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}" = HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{eb2ffb1e-d1d1-4f6a-8e8a-cda5bff40283}" = Nero 9 Essentials
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitTorrent" = BitTorrent
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"PC Tools AntiVirus_is1" = PC Tools AntiVirus 6.0
"SelfAccounts" = SelfAccounts 2.0
"ToggleEN Toolbar" = ToggleEN Toolbar
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/17/2010 4:51:23 AM | Computer Name = UBS | Source = Microsoft Office 12 | ID = 5000
Description = EventType officelifeboathang, P1 outlook.exe, P2 12.0.4518.1014, P3
ntdll.dll, P4 5.1.2600.2180, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 9/22/2010 5:40:21 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 9/22/2010 5:40:41 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 9/22/2010 5:40:42 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 9/22/2010 5:40:45 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 9/22/2010 5:40:56 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 9/22/2010 5:41:00 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 9/22/2010 5:41:01 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 9/22/2010 5:41:03 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 9/22/2010 5:51:31 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =

[ OSession Events ]
Error - 7/30/2010 12:06:11 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10052
seconds with 1080 seconds of active time. This session ended with a crash.

Error - 7/31/2010 2:02:25 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7404
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/11/2010 11:31:52 PM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6006
seconds with 1800 seconds of active time. This session ended with a crash.

Error - 8/30/2010 2:54:12 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 848
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Support Center service terminated with the following error: %%126

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Shell Security service terminated with the following error: %%126

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7000
Description = The USBLAN_Ldr service failed to start due to the following error:
%%21

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Helper Universal service terminated with the following error:
%%126

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Driver Shell service terminated with the following error: %%126

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Helper Boot service terminated with the following error: %%126

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Monitor Network service terminated with the following error: %%126

Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Monitor Config service terminated with the following error: %%126

Error - 9/22/2010 5:51:29 AM | Computer Name = UBS | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147618124

User:
UBS\Wati Name: Worm:Win32/Conficker.B ID: 2147618124 Severity: Severe Category: Worm

Path:
Action: %%808 Error Code: 0x80070032 Error description: The request is not supported.
Status: Signature Version: AV: 1.91.343.0, AS: 1.91.343.0 Engine Version: 1.1.6201.0

Error - 9/22/2010 5:51:29 AM | Computer Name = UBS | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147618124

User:
UBS\Wati Name: Worm:Win32/Conficker.B ID: 2147618124 Severity: Severe Category: Worm

Path:
Action: %%809 Error Code: 0x80070032 Error description: The request is not supported.
Status: Signature Version: AV: 1.91.343.0, AS: 1.91.343.0 Engine Version: 1.1.6201.0


< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI