This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware problem

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can post any logs if needed. I have Avast Pro installed and it has been working, but I believe some things have gotten through. When I am in firefox, every minute or so, the address bar flashes blue (like the address is being highlighted and maybe copied), and takes away from whatever I'm typing, if I am typing. Every couple minutes or so, a new window will open automatically, behind my current window, and the page that loads up tries to post stuff on my facebook page. I ended up disabling a certain facebook application, so the posts stopped and I deleted them, but the window still pops up and tries to post. The address of the page is: alloutblackhat (dot) com/i/redirect.php?m= and the website itself looks to be some malicious front-end. Every 6 seconds, my cursor flashes from the standard pointer, to the pointer/loading cursor, and does this quickly. But it happens every 6 seconds. It gets rather irritating, but I think there's something behind it. I ran Avast, Malwarebytes, and windows defender before coming here, but I am still having issues. I removed the Bing toolbar that had been installed in IE and Firefox, and got rid of whatever the previously mentioned programs found, but there is still something going on. I am computer-literate and would like some help! Thanks, Mike
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post




Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
I will post the logs shortly. But when I try to run GMER.exe, it says: "C:\Windows\system32\config\system: The system cannot find the file specified." I am running Windows 7 64-bit. Should I still try and run GMER? Thanks.
Leave GMER,run this instead.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
OTL.txt

OTL logfile created on: 9/28/2010 3:32:27 PM - Run 1
OTL by OldTimer - Version 3.2.14.1     Folder = C:\Users\Mike Mulholland\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 187.32 Gb Free Space | 62.84% Space Free | Partition Type: NTFS
Drive D: | 159.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 298.09 Gb Total Space | 275.76 Gb Free Space | 92.51% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 365.09 Gb Free Space | 39.19% Space Free | Partition Type: NTFS
Drive G: | 1863.01 Gb Total Space | 597.18 Gb Free Space | 32.05% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 61.77 Gb Free Space | 3.32% Space Free | Partition Type: NTFS
Drive I: | 931.51 Gb Total Space | 427.71 Gb Free Space | 45.92% Space Free | Partition Type: NTFS
Drive J: | 465.76 Gb Total Space | 34.64 Gb Free Space | 7.44% Space Free | Partition Type: NTFS
Drive X: | 298.09 Gb Total Space | 51.44 Gb Free Space | 17.26% Space Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 33.89 Gb Free Space | 11.37% Space Free | Partition Type: NTFS
Drive Z: | 465.76 Gb Total Space | 287.53 Gb Free Space | 61.73% Space Free | Partition Type: NTFS
 
Computer Name: WORKSTATION
Current User Name: Mike Mulholland
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Mike Mulholland\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Mike Mulholland\AppData\Roaming\fbx.exe (noOrg)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe (Teleca)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe (TODO: )
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe (Teleca AB)
PRC - C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
PRC - C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe ()
PRC - C:\Program Files\PreSonus\1394AudioDriver_FireBox\FireBox.exe (PreSonus Audio Electronics)
PRC - C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe (Realtime Soft Ltd)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe (Popwire AB)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\CapabilityManager.exe (Teleca Sweden AB)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Mike Mulholland\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\UltraMon\RTSUltraMonHookX32.dll (Realtime Soft Ltd)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (ZuneWlanCfgSvc) – C:\Windows\SysNative\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:64bit: - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Adobe Version Cue CS4) – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (AnyDVD) – C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (pae_1394) – C:\Windows\SysNative\drivers\pae_1394_x64.sys (Archwave AG)
DRV:64bit: - (pae_avs) – C:\Windows\SysNative\drivers\pae_avs_x64.sys (Archwave AG)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (HTCAND64) – C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (netr28x) – C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (Si3114r5) – C:\Windows\SysNative\drivers\Si3114r5.sys (Silicon Image, Inc)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (SiRemFil) – C:\Windows\SysNative\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV:64bit: - (JGOGO) – C:\Windows\SysNative\drivers\JGOGO.sys (JMicron )
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (SiFilter) – C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (AnyDVD) – C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (UltraMonUtility) – C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys (Realtime Soft Ltd)
DRV - (adfs) – C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server 2003 DDK provider)
DRV - (WINIO) – C:\Program Files (x86)\Centrafuse\Centrafuse Auto\WinIo.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = about:blank
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {EA7EB1AF-308C-4A4A-A175-6C17028D665F}:1.9.1
FF - prefs.js..extensions.enabledItems: {5B40C443-0044-401C-86EA-7C7FCC6D8D16}:1.9.1
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/03/17 12:11:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}: C:\Windows\system32\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\ [2010/06/18 18:02:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{5B40C443-0044-401C-86EA-7C7FCC6D8D16}: C:\Users\Mike Mulholland\AppData\Local\{5B40C443-0044-401C-86EA-7C7FCC6D8D16} [2010/07/26 11:05:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/09/27 08:04:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/27 07:55:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010/09/17 06:21:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2010/03/22 02:13:53 | 000,000,000 | —D | M]
 
[2010/09/27 08:04:45 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Mozilla\Extensions
[2010/03/15 20:21:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike Mulholland\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/09/27 08:04:45 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Mozilla\Firefox\Profiles\se2gvgyu.default\extensions
[2010/09/28 08:26:19 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/07/12 23:54:28 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/07/12 23:54:12 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/15 19:02:03 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/06/15 16:17:52 | 000,002,076 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml
 
O1 HOSTS File: ([2010/03/29 05:01:10 | 000,001,389 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O1 - Hosts: 127.0.0.1       activate.adobe.com
O1 - Hosts: 127.0.0.1       practivate.adobe.com
O1 - Hosts: 127.0.0.1       ereg.adobe.com
O1 - Hosts: 127.0.0.1       activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1       wip3.adobe.com
O1 - Hosts: 127.0.0.1       3dns-3.adobe.com
O1 - Hosts: 127.0.0.1       3dns-2.adobe.com
O1 - Hosts: 127.0.0.1       adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1       adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1       adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1       ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1       activate-sea.adobe.com
O1 - Hosts: 127.0.0.1       pagead2.googlesyndication.com
O1 - Hosts: 127.0.0.1       wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1       activate-sjc0.adobe.com
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe ()
O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKCU..\Run: [{33D1385C-146C-C636-AB1D-CD011C87803E}] C:\Users\Mike Mulholland\AppData\Roaming\Begifu\ehzy.exe File not found
O4 - HKCU..\Run: [Allway Sync] C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe ()
O4 - HKCU..\Run: [InstallMon] C:\Users\Mike Mulholland\AppData\Roaming\fbx.exe (noOrg)
O4 - Startup: C:\Users\Mike Mulholland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{91d38fa3-3714-11df-b16e-0018f34f2c86}\Shell - "" = AutoRun
O33 - MountPoints2\{91d38fa3-3714-11df-b16e-0018f34f2c86}\Shell\AutoRun\command - "" = K:\LaunchU3.exe – File not found
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\setup.exe – File not found
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\SETUP.EXE – File not found
O33 - MountPoints2\J\Shell\configure\command - "" = J:\SETUP.EXE – File not found
O33 - MountPoints2\J\Shell\install\command - "" = J:\SETUP.EXE – File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
Drivers32:64bit: msacm.ac3filter - ac3filter.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.ffds - ff_vfw.dll ()
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.avis - C:\Windows\SysWow64\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010/09/28 15:30:24 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Mike Mulholland\Desktop\OTL.exe
[2010/09/28 04:27:51 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Desktop\New folder
[2010/09/27 22:08:58 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Documents\VisualDesigner
[2010/09/27 22:08:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Zoran Horvat
[2010/09/27 07:45:08 | 008,534,336 | —- | C] (Mozilla) – C:\Users\Mike Mulholland\Desktop\Firefox Setup 3.6.10.exe
[2010/09/27 06:25:12 | 003,629,944 | —- | C] (Microsoft Corporation) – C:\Users\Mike Mulholland\Desktop\SyncToySetupPackage_v21_x64.exe
[2010/09/27 00:41:19 | 000,424,016 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2010/09/27 00:41:19 | 000,121,936 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/09/27 00:41:19 | 000,022,096 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/09/27 00:41:18 | 000,051,280 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/09/27 00:41:18 | 000,028,752 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/09/27 00:41:17 | 000,063,568 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/09/27 00:40:57 | 000,165,032 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/09/27 00:40:57 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/09/26 23:35:40 | 000,000,000 | -H-D | C] – C:\ProgramData\{E6BD42D3-E8A6-4469-B72F-B5256066F41F}
[2010/09/26 23:35:39 | 000,000,000 | —D | C] – C:\Program Files\Lexicon
[2010/09/26 23:34:41 | 015,010,248 | —- | C] (Lexicon                                                                                                                                                                                                                                                                                                     ) – C:\Users\Mike Mulholland\Desktop\AlphaDriverInstaller.exe
[2010/09/26 23:29:38 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Desktop\AD1988AB_Audio_V6585_XpVistaWin7
[2010/09/25 01:39:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\FLAC
[2010/09/24 20:24:46 | 000,081,920 | —- | C] (noOrg) – C:\Users\Mike Mulholland\AppData\Roaming\fbx.exe
[2010/09/23 01:17:29 | 004,859,796 | —- | C] (www.Centrafuse-Forum.de) – C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31(2).exe
[2010/09/22 22:32:09 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Desktop\GarminMobilePC_50060
[2010/09/22 16:38:52 | 175,504,056 | —- | C] (Igor Pavlov) – C:\Users\Mike Mulholland\Desktop\GarminMobilePC_50070.exe
[2010/09/22 16:19:16 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Desktop\FileSync
[2010/09/22 07:20:57 | 004,859,796 | —- | C] (www.Centrafuse-Forum.de) – C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31.exe
[2010/09/22 06:29:33 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Desktop\jojo mayer - nerve - ep1
[2010/09/22 06:27:12 | 000,000,000 | —D | C] – C:\Users\Mike Mulholland\Desktop\jojo mayer - nerve - ep2
[2010/09/15 03:00:59 | 002,441,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/09/08 15:03:50 | 000,000,000 | —D | C] – C:\Program Files\SyncToy 2.1
[2010/09/08 15:03:13 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010/09/28 15:33:46 | 003,932,160 | -HS- | M] () – C:\Users\Mike Mulholland\ntuser.dat
[2010/09/28 15:30:26 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Mike Mulholland\Desktop\OTL.exe
[2010/09/28 02:40:21 | 007,722,336 | —- | M] () – C:\Users\Mike Mulholland\Desktop\Centrafuse design.psd
[2010/09/27 23:27:40 | 000,148,596 | —- | M] () – C:\Users\Mike Mulholland\Desktop\IMG_4183.jpg
[2010/09/27 23:27:38 | 000,204,401 | —- | M] () – C:\Users\Mike Mulholland\Desktop\IMG_4179.jpg
[2010/09/27 23:27:31 | 000,196,085 | —- | M] () – C:\Users\Mike Mulholland\Desktop\IMG_4178.jpg
[2010/09/27 22:09:03 | 000,003,185 | —- | M] () – C:\Users\Mike Mulholland\Desktop\VisualDesigner2.lnk
[2010/09/27 21:58:44 | 000,027,463 | —- | M] () – C:\Users\Mike Mulholland\Desktop\body-bg.jpg
[2010/09/27 18:00:00 | 000,000,380 | —- | M] () – C:\Windows\tasks\At1.job
[2010/09/27 16:42:04 | 000,017,360 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/27 16:42:04 | 000,017,360 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/27 16:35:02 | 000,000,344 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2010/09/27 16:34:49 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/27 16:34:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/27 16:34:35 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2010/09/27 16:26:43 | 001,873,870 | -H– | M] () – C:\Users\Mike Mulholland\AppData\Local\IconCache.db
[2010/09/27 15:10:18 | 000,001,015 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/27 07:55:56 | 000,001,969 | —- | M] () – C:\Users\Mike Mulholland\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/27 07:45:08 | 008,534,336 | —- | M] (Mozilla) – C:\Users\Mike Mulholland\Desktop\Firefox Setup 3.6.10.exe
[2010/09/27 07:39:04 | 000,040,114 | —- | M] () – C:\Users\Mike Mulholland\Documents\cc_20100927_073844.reg
[2010/09/27 07:37:22 | 000,044,323 | —- | M] () – C:\Users\Mike Mulholland\Desktop\rear_off.png
[2010/09/27 07:05:13 | 000,103,343 | —- | M] () – C:\Users\Mike Mulholland\Desktop\bookmarks-2010-09-27.json
[2010/09/27 07:04:26 | 000,415,759 | —- | M] () – C:\Users\Mike Mulholland\Desktop\ASIO4ALL_2_10_English.exe
[2010/09/27 06:25:18 | 003,629,944 | —- | M] (Microsoft Corporation) – C:\Users\Mike Mulholland\Desktop\SyncToySetupPackage_v21_x64.exe
[2010/09/27 05:42:36 | 000,013,744 | —- | M] () – C:\Users\Mike Mulholland\Desktop\btn_pageleft_off.png
[2010/09/27 05:28:43 | 000,444,971 | —- | M] () – C:\Users\Mike Mulholland\Desktop\background_F150.png
[2010/09/27 05:28:22 | 000,310,988 | —- | M] () – C:\Users\Mike Mulholland\Desktop\background_F150_Blur.png
[2010/09/27 05:14:25 | 000,407,725 | —- | M] () – C:\Users\Mike Mulholland\Desktop\backgroundf150.png
[2010/09/27 04:40:40 | 000,048,640 | —- | M] () – C:\Users\Mike Mulholland\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/27 04:36:14 | 000,001,902 | —- | M] () – C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2010/09/27 00:41:17 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/09/27 00:21:11 | 000,040,344 | —- | M] () – C:\Users\Mike Mulholland\AppData\Roaming\FbxU.exe
[2010/09/26 23:44:04 | 000,111,960 | —- | M] () – C:\Users\Mike Mulholland\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/26 23:38:53 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2010/09/26 23:38:19 | 003,029,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/09/26 23:35:11 | 015,010,248 | —- | M] (Lexicon                                                                                                                                                                                                                                                                                                     ) – C:\Users\Mike Mulholland\Desktop\AlphaDriverInstaller.exe
[2010/09/26 23:30:04 | 000,001,769 | —- | M] () – C:\Windows\Language_trs.ini
[2010/09/25 19:01:46 | 000,129,401 | —- | M] () – C:\Windows\SysWow64\crack.exe
[2010/09/24 20:24:46 | 000,081,920 | —- | M] (noOrg) – C:\Users\Mike Mulholland\AppData\Roaming\fbx.exe
[2010/09/23 01:22:09 | 000,048,589 | —- | M] () – C:\Users\Mike Mulholland\Desktop\FORDLogo.jpg
[2010/09/23 01:22:02 | 000,050,003 | —- | M] () – C:\Users\Mike Mulholland\Desktop\Ford_Logo_Large.jpg
[2010/09/22 16:17:01 | 000,893,193 | —- | M] () – C:\Users\Mike Mulholland\Desktop\FileSync3.zip
[2010/09/22 07:21:36 | 004,859,796 | —- | M] (www.Centrafuse-Forum.de) – C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31.exe
[2010/09/22 06:29:07 | 115,229,057 | —- | M] () – C:\Users\Mike Mulholland\Desktop\jojo mayer - nerve - ep1.zip
[2010/09/22 06:24:24 | 119,028,164 | —- | M] () – C:\Users\Mike Mulholland\Desktop\jojo mayer - nerve - ep2.zip
[2010/09/22 01:53:51 | 079,896,398 | —- | M] () – C:\Users\Mike Mulholland\Desktop\Realtek_13i.zip
[2010/09/22 01:51:53 | 041,553,402 | —- | M] () – C:\Users\Mike Mulholland\Desktop\WinVista7_64_Intel_Graphics_Driver_ PV.zip
[2010/09/22 01:49:45 | 005,874,604 | —- | M] () – C:\Users\Mike Mulholland\Desktop\121am_Win7.zip
[2010/09/22 01:48:58 | 005,554,746 | —- | M] () – C:\Users\Mike Mulholland\Desktop\MEI_SOL_13i.zip
[2010/09/22 01:48:43 | 002,436,490 | —- | M] () – C:\Users\Mike Mulholland\Desktop\11ia_INF.zip
[2010/09/22 01:40:51 | 000,778,150 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/22 01:40:51 | 000,661,172 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/09/22 01:40:51 | 000,121,090 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/09/16 06:58:11 | 000,039,424 | —- | M] () – C:\Users\Mike Mulholland\Desktop\F150.xls
[2010/09/14 23:28:32 | 000,080,191 | —- | M] () – C:\Users\Mike Mulholland\Desktop\SUB ENCLOSURE.jpg
[2010/09/14 23:28:21 | 000,733,355 | —- | M] () – C:\Users\Mike Mulholland\Desktop\SUB ENCLOSURE.psd
[2010/09/14 09:35:25 | 001,877,679 | —- | M] () – C:\Users\Mike Mulholland\Desktop\IMAG0069.jpg
[2010/09/10 17:39:20 | 071,430,448 | —- | M] () – C:\Users\Mike Mulholland\Desktop\chriscolemanmeinl2010.mp4
[2010/09/10 17:39:08 | 017,719,797 | —- | M] () – C:\Users\Mike Mulholland\Desktop\chriscolemansolohudson.mov
[2010/09/10 17:39:05 | 014,397,449 | —- | M] () – C:\Users\Mike Mulholland\Desktop\chriscolemanbassdrum.mov
[2010/09/10 17:38:54 | 014,367,335 | —- | M] () – C:\Users\Mike Mulholland\Desktop\chriscolemanbop.mov
[2010/09/10 17:38:35 | 014,435,079 | —- | M] () – C:\Users\Mike Mulholland\Desktop\chriscolemannamm2.mov
[2010/09/10 17:38:31 | 013,283,817 | —- | M] () – C:\Users\Mike Mulholland\Desktop\chriscolemannamm1.mov
[2010/09/02 16:03:34 | 000,027,648 | —- | M] () – C:\Users\Mike Mulholland\Desktop\AUDIO.xls
[2010/09/02 05:47:15 | 000,034,816 | —- | M] () – C:\Users\Mike Mulholland\Desktop\carpc.xls
[2010/08/31 01:19:12 | 002,441,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/08/29 22:15:52 | 000,002,655 | —- | M] () – C:\Users\Mike Mulholland\Desktop\Microsoft Office Excel 2007.lnk
[2010/08/29 21:53:24 | 000,092,051 | —- | M] () – C:\Users\Mike Mulholland\Desktop\deck.skp
[2010/08/29 18:40:51 | 000,012,537 | —- | M] () – C:\Users\Mike Mulholland\Desktop\UhOh.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010/09/28 15:32:34 | 000,293,376 | —- | C] () – C:\Users\Mike Mulholland\Desktop\gmer.exe
[2010/09/28 00:09:17 | 007,722,336 | —- | C] () – C:\Users\Mike Mulholland\Desktop\Centrafuse design.psd
[2010/09/27 23:27:40 | 000,148,596 | —- | C] () – C:\Users\Mike Mulholland\Desktop\IMG_4183.jpg
[2010/09/27 23:27:38 | 000,204,401 | —- | C] () – C:\Users\Mike Mulholland\Desktop\IMG_4179.jpg
[2010/09/27 23:27:31 | 000,196,085 | —- | C] () – C:\Users\Mike Mulholland\Desktop\IMG_4178.jpg
[2010/09/27 22:09:03 | 000,003,185 | —- | C] () – C:\Users\Mike Mulholland\Desktop\VisualDesigner2.lnk
[2010/09/27 21:58:43 | 000,027,463 | —- | C] () – C:\Users\Mike Mulholland\Desktop\body-bg.jpg
[2010/09/27 15:10:18 | 000,001,015 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/27 07:55:56 | 000,001,969 | —- | C] () – C:\Users\Mike Mulholland\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/27 07:38:59 | 000,040,114 | —- | C] () – C:\Users\Mike Mulholland\Documents\cc_20100927_073844.reg
[2010/09/27 07:37:17 | 000,044,323 | —- | C] () – C:\Users\Mike Mulholland\Desktop\rear_off.png
[2010/09/27 07:05:13 | 000,103,343 | —- | C] () – C:\Users\Mike Mulholland\Desktop\bookmarks-2010-09-27.json
[2010/09/27 07:04:25 | 000,415,759 | —- | C] () – C:\Users\Mike Mulholland\Desktop\ASIO4ALL_2_10_English.exe
[2010/09/27 05:42:34 | 000,013,744 | —- | C] () – C:\Users\Mike Mulholland\Desktop\btn_pageleft_off.png
[2010/09/27 05:28:41 | 000,444,971 | —- | C] () – C:\Users\Mike Mulholland\Desktop\background_F150.png
[2010/09/27 05:28:19 | 000,310,988 | —- | C] () – C:\Users\Mike Mulholland\Desktop\background_F150_Blur.png
[2010/09/27 04:58:25 | 000,407,725 | —- | C] () – C:\Users\Mike Mulholland\Desktop\backgroundf150.png
[2010/09/27 00:41:19 | 000,001,902 | —- | C] () – C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2010/09/27 00:21:11 | 000,040,344 | —- | C] () – C:\Users\Mike Mulholland\AppData\Roaming\FbxU.exe
[2010/09/26 23:38:53 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2010/09/26 23:30:04 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/25 19:01:46 | 000,129,401 | —- | C] () – C:\Windows\SysWow64\crack.exe
[2010/09/23 01:22:09 | 000,048,589 | —- | C] () – C:\Users\Mike Mulholland\Desktop\FORDLogo.jpg
[2010/09/23 01:22:02 | 000,050,003 | —- | C] () – C:\Users\Mike Mulholland\Desktop\Ford_Logo_Large.jpg
[2010/09/22 22:04:06 | 152,494,080 | —- | C] () – C:\Users\Mike Mulholland\Desktop\GarminMobilePC_50060.exe
[2010/09/22 16:16:57 | 000,893,193 | —- | C] () – C:\Users\Mike Mulholland\Desktop\FileSync3.zip
[2010/09/22 06:22:45 | 115,229,057 | —- | C] () – C:\Users\Mike Mulholland\Desktop\jojo mayer - nerve - ep1.zip
[2010/09/22 06:20:20 | 119,028,164 | —- | C] () – C:\Users\Mike Mulholland\Desktop\jojo mayer - nerve - ep2.zip
[2010/09/22 01:49:56 | 041,553,402 | —- | C] () – C:\Users\Mike Mulholland\Desktop\WinVista7_64_Intel_Graphics_Driver_ PV.zip
[2010/09/22 01:49:23 | 079,896,398 | —- | C] () – C:\Users\Mike Mulholland\Desktop\Realtek_13i.zip
[2010/09/22 01:49:12 | 005,874,604 | —- | C] () – C:\Users\Mike Mulholland\Desktop\121am_Win7.zip
[2010/09/22 01:48:46 | 005,554,746 | —- | C] () – C:\Users\Mike Mulholland\Desktop\MEI_SOL_13i.zip
[2010/09/22 01:48:32 | 002,436,490 | —- | C] () – C:\Users\Mike Mulholland\Desktop\11ia_INF.zip
[2010/09/14 23:28:30 | 000,080,191 | —- | C] () – C:\Users\Mike Mulholland\Desktop\SUB ENCLOSURE.jpg
[2010/09/14 23:28:20 | 000,733,355 | —- | C] () – C:\Users\Mike Mulholland\Desktop\SUB ENCLOSURE.psd
[2010/09/14 09:35:24 | 001,877,679 | —- | C] () – C:\Users\Mike Mulholland\Desktop\IMAG0069.jpg
[2010/09/10 17:38:41 | 014,397,449 | —- | C] () – C:\Users\Mike Mulholland\Desktop\chriscolemanbassdrum.mov
[2010/09/10 17:38:34 | 014,367,335 | —- | C] () – C:\Users\Mike Mulholland\Desktop\chriscolemanbop.mov
[2010/09/10 17:38:30 | 017,719,797 | —- | C] () – C:\Users\Mike Mulholland\Desktop\chriscolemansolohudson.mov
[2010/09/10 17:38:12 | 014,435,079 | —- | C] () – C:\Users\Mike Mulholland\Desktop\chriscolemannamm2.mov
[2010/09/10 17:38:05 | 013,283,817 | —- | C] () – C:\Users\Mike Mulholland\Desktop\chriscolemannamm1.mov
[2010/09/10 17:37:29 | 071,430,448 | —- | C] () – C:\Users\Mike Mulholland\Desktop\chriscolemanmeinl2010.mp4
[2010/09/03 05:40:06 | 000,039,424 | —- | C] () – C:\Users\Mike Mulholland\Desktop\F150.xls
[2010/09/02 05:47:15 | 000,034,816 | —- | C] () – C:\Users\Mike Mulholland\Desktop\carpc.xls
[2010/08/29 22:15:52 | 000,002,655 | —- | C] () – C:\Users\Mike Mulholland\Desktop\Microsoft Office Excel 2007.lnk
[2010/08/29 21:53:24 | 000,092,051 | —- | C] () – C:\Users\Mike Mulholland\Desktop\deck.skp
[2010/08/29 18:40:50 | 000,012,537 | —- | C] () – C:\Users\Mike Mulholland\Desktop\UhOh.mp3
[2010/07/12 00:47:59 | 000,774,176 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/06/18 21:58:14 | 000,000,000 | —- | C] () – C:\Users\Mike Mulholland\AppData\Local\Unolow.bin
[2010/06/18 21:58:14 | 000,000,000 | —- | C] () – C:\Users\Mike Mulholland\AppData\Local\Kwajagonamanew.dat
[2010/06/18 04:13:02 | 000,000,745 | —- | C] () – C:\Users\Mike Mulholland\AppData\Roaming\AtomicAlarmClock.ini
[2010/04/14 12:44:05 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2010/04/13 19:22:46 | 000,001,107 | —- | C] () – C:\Program Files\explorer(shortcut).exe.lnk
[2010/04/13 19:22:46 | 000,000,041 | —- | C] () – C:\Program Files\explorer.bat
[2010/03/29 00:47:42 | 000,000,005 | —- | C] () – C:\Windows\hmphlgge.ini
[2010/03/19 05:38:57 | 000,327,168 | —- | C] () – C:\Windows\SysWow64\cutil32.dll
[2010/03/15 20:41:16 | 000,048,640 | —- | C] () – C:\Users\Mike Mulholland\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/21 04:48:22 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009/08/16 10:08:36 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/29 15:52:26 | 000,204,800 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 15:47:06 | 000,881,664 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2007/02/05 19:05:26 | 000,000,038 | —- | C] () – C:\Windows\AviSplitter.INI
[2006/11/13 14:40:22 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\io.dll
[2006/05/22 14:45:38 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\InFillCOM.dll
[2002/10/03 13:52:34 | 000,147,456 | —- | C] () – C:\Windows\SysWow64\STTubeDevice203.dll
 
========== LOP Check ==========
 
[2010/06/13 18:06:05 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Ableton
[2010/03/15 18:04:34 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\acccore
[2010/09/27 05:08:11 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Begifu
[2010/04/26 01:35:36 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Cakewalk
[2010/04/05 15:47:50 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\dBpoweramp
[2010/05/17 03:29:31 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Edison
[2010/03/28 22:43:29 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\FireBox Mixer
[2010/03/17 12:12:07 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Foxit
[2010/07/12 23:55:43 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Gmote
[2010/03/21 20:58:23 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Hardcore
[2010/03/16 22:56:29 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\ImgBurn
[2010/03/24 22:45:03 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Miranda
[2010/06/23 01:22:19 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\mkvtoolnix
[2010/09/27 16:13:41 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Nyra
[2010/03/26 15:46:10 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Rainmeter
[2010/04/16 19:20:04 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Shark007
[2010/03/21 20:58:35 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Slicex
[2010/03/18 22:26:35 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Sync App Settings
[2010/07/10 16:03:12 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Teleca
[2010/03/15 20:21:21 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Thunderbird
[2010/03/22 17:38:23 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Waves Audio
[2010/04/16 19:19:03 | 000,000,000 | —D | M] – C:\Users\Mike Mulholland\AppData\Roaming\Win7codecs
[2010/07/12 00:49:16 | 000,000,000 | -HSD | M] – C:\Users\Mike Mulholland\AppData\Roaming\wyUpdate AU
[2010/09/27 18:00:00 | 000,000,380 | —- | M] () – C:\Windows\Tasks\At1.job
[2010/09/27 16:35:02 | 000,000,344 | —- | M] () – C:\Windows\Tasks\GlaryInitialize.job
[2009/07/14 01:08:49 | 000,016,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*.* >
[2010/03/17 04:20:57 | 000,001,024 | —- | M] () – C:\.rnd
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/03/15 03:48:28 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/09/27 16:34:35 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2010/03/17 12:30:42 | 000,000,696 | -H– | M] () – C:\IPH.PH
[2010/09/27 16:34:37 | 4294,098,944 | -HS- | M] () – C:\pagefile.sys
 
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.jpg >
 
< %systemroot%\*.png >
 
< %systemroot%\*.scr >
[2010/02/14 03:07:34 | 000,303,616 | —- | M] (Realtime Soft Ltd) – C:\Windows\UltraMon.scr
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\System32\config\*.sav >
 
< %PROGRAMFILES%\bak. /s >
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/15 02:07:03 | 000,000,221 | -HS- | M] () – C:\Users\Mike Mulholland\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
 
< %USERPROFILE%\Desktop\*.exe >
[2010/09/26 23:35:11 | 015,010,248 | —- | M] (Lexicon                                                                                                                                                                                                                                                                                                     ) – C:\Users\Mike Mulholland\Desktop\AlphaDriverInstaller.exe
[2010/09/27 07:04:26 | 000,415,759 | —- | M] () – C:\Users\Mike Mulholland\Desktop\ASIO4ALL_2_10_English.exe
[2010/09/27 07:45:08 | 008,534,336 | —- | M] (Mozilla) – C:\Users\Mike Mulholland\Desktop\Firefox Setup 3.6.10.exe
[2010/09/22 22:24:07 | 152,494,080 | —- | M] () – C:\Users\Mike Mulholland\Desktop\GarminMobilePC_50060.exe
[2009/12/15 11:24:48 | 000,293,376 | —- | M] () – C:\Users\Mike Mulholland\Desktop\gmer.exe
[2010/06/23 01:13:44 | 005,798,942 | —- | M] (Moritz Bunkus) – C:\Users\Mike Mulholland\Desktop\mkvtoolnix-unicode-4.0.0-setup.exe
[2010/09/23 01:18:08 | 004,859,796 | —- | M] (www.Centrafuse-Forum.de) – C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31(2).exe
[2010/09/22 07:21:36 | 004,859,796 | —- | M] (www.Centrafuse-Forum.de) – C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31.exe
[2010/09/28 15:30:26 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Mike Mulholland\Desktop\OTL.exe
[2010/09/27 06:25:18 | 003,629,944 | —- | M] (Microsoft Corporation) – C:\Users\Mike Mulholland\Desktop\SyncToySetupPackage_v21_x64.exe
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.* >
 
< %systemroot%\AppPatch\Custom\*.* >
 
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
 
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
 
< %PROGRAMFILES%\Internet Explorer\*.tmp >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %USERPROFILE%\My Documents\*.exe >
 
< %USERPROFILE%\*.exe >
 
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf
 
< %systemroot%\assembly\*.bak2 >
 
< %systemroot%\Config\*.* >
 
< %systemroot%\REPAIR\*.bak2 >
 
< %systemroot%\SECURITY\Database\*.sdb /x >
 
< %systemroot%\SYSTEM\*.bak2 >
 
< %systemroot%\Web\*.bak2 >
 
< %systemroot%\Driver Cache\*.* >
 
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
 
< %ProgramFiles%\Microsoft Common\*.* >
 
< %ProgramFiles%\TinyProxy. >
 
< %USERPROFILE%\Favorites\*.url /x >
[2010/08/03 07:19:45 | 000,000,402 | -HS- | M] () – C:\Users\Mike Mulholland\Favorites\desktop.ini
 
< %systemroot%\system32\*.bk >
 
< %systemroot%\*.te >
 
< %systemroot%\system32\system32\*.* >
 
< %ALLUSERSPROFILE%\*.dat /x >
[2010/04/14 12:44:05 | 000,000,040 | -HS- | M] () – C:\ProgramData\.zreglib
 
< %systemroot%\system32\drivers\*.rmv >
 
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
 
< dir /b "%systemroot%\*.exe" | find /i " " /c >
 
< %PROGRAMFILES%\Microsoft\*.* >
 
< %systemroot%\System32\Wbem\proquota.exe >
 
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
 
< %USERPROFILE%\Cookies\*.txt /x >
 
< %SystemRoot%\system32\fonts\*.* >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:7717F034
< End of report >



Extras.txt

OTL Extras logfile created on: 9/28/2010 3:32:27 PM - Run 1
OTL by OldTimer - Version 3.2.14.1     Folder = C:\Users\Mike Mulholland\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 187.32 Gb Free Space | 62.84% Space Free | Partition Type: NTFS
Drive D: | 159.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 298.09 Gb Total Space | 275.76 Gb Free Space | 92.51% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 365.09 Gb Free Space | 39.19% Space Free | Partition Type: NTFS
Drive G: | 1863.01 Gb Total Space | 597.18 Gb Free Space | 32.05% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 61.77 Gb Free Space | 3.32% Space Free | Partition Type: NTFS
Drive I: | 931.51 Gb Total Space | 427.71 Gb Free Space | 45.92% Space Free | Partition Type: NTFS
Drive J: | 465.76 Gb Total Space | 34.64 Gb Free Space | 7.44% Space Free | Partition Type: NTFS
Drive X: | 298.09 Gb Total Space | 51.44 Gb Free Space | 17.26% Space Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 33.89 Gb Free Space | 11.37% Space Free | Partition Type: NTFS
Drive Z: | 465.76 Gb Total Space | 287.53 Gb Free Space | 61.73% Space Free | Partition Type: NTFS
 
Computer Name: WORKSTATION
Current User Name: Mike Mulholland
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile [edit] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [edit] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{03AC245F-4C64-425C-89CF-7783C1D3AB2C}" = Microsoft Sync Framework 2.0 Provider Services (x64) ENU 
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{33691AFF-9ABF-4278-BDB6-902EE07D9237}" = Native Instruments Guitar Rig 3
"{370BCBBA-67D7-4535-ADCD-58CD1C8DEC99}" = Zune Language Pack (DE)
"{371B17C3-9624-4583-A497-DF980313D851}" = Native Instruments Absynth 5
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{40EC6323-497B-44DA-8A88-74578622D9B3}" = Zune Language Pack (IT)
"{43E7798A-248E-4A3D-9969-FEA63543A462}" = Native Instruments Kontakt 4
"{491DF203-7B61-4F0E-BDCB-A1218C4DAFE9}" = Native Instruments Massive
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6BED4DFE-C527-463E-B93A-6F6848B74DD0}" = Native Instruments Battery 3
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{888FFC82-688D-46AB-A776-B417885432B6}" = Zune
"{88DAAF05-5A72-46D2-A7C5-C3759697E943}" = SyncToy 2.1 (x64)
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}" = Microsoft Sync Framework 2.0 Core Components (x64) ENU 
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{AAFA253A-08A9-46A8-AB30-B4C26E578424}" = Lexicon Alpha Driver
"{B2552FA6-86E3-410D-84AD-265C2242D410}" = Native Instruments FM8
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C7FAFC98-5ECC-40FC-B440-A5D5FE3A6A6E}" = Native Instruments Guitar Rig 4
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{D799CC16-F3B5-468D-AC67-6F77AAA98173}" = Native Instruments Komplete 6
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E9EA5F38-6299-45A1-9D23-F21729A19357}" = Native Instruments Reaktor 5
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.15
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MyDefrag v4.2.9_is1" = MyDefrag v4.2.9
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR archiver
"x64 Components_is1" = x64 Components v2.5.3
"Zune" = Zune
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{7F8726E6-89A5-4707-ADB3-21F616BEB843}" = VisualDesigner
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F1B6AE0B-E56F-4515-B540-3BD854FE5D64}" = Centrafuse
"{FCAFEEB3-3520-4539-89AF-4B743D2DFAEC}" = HTC Sync
"Aqua Skin" = Aqua Skin
"avast5" = avast! Pro Antivirus
"BrightShopping" = BrightShopping
"CF3OnyxNightSkin" = CF3OnyxNightSkin
"Lexicon Alpha Driver" = Lexicon Alpha Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MKVtoolnix" = MKVtoolnix 4.0.0
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >


MBRCheck_09.28.10_18.32.43.txt

MBRCheck, version 1.2.3
© 2010, AD

Command-line:			
Windows Version:		Windows 7 Ultimate Edition
Windows Information:		 (build 7600), 64-bit
Base Board Manufacturer:	ASUSTeK Computer INC.
BIOS Manufacturer:		American Megatrends Inc.
System Manufacturer:		System manufacturer
System Product Name:		System Product Name
Logical Drives Mask:		0x038007fc

Kernel Drivers (total 184):
  0x02C5B000 \SystemRoot\system32\ntoskrnl.exe
  0x02C12000 \SystemRoot\system32\hal.dll
  0x00B9B000 \SystemRoot\system32\kdcom.dll
  0x00CAA000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
  0x00CEE000 \SystemRoot\system32\PSHED.dll
  0x00D02000 \SystemRoot\system32\CLFS.SYS
  0x00E01000 \SystemRoot\system32\CI.dll
  0x00EC1000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x00F65000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x00F74000 \SystemRoot\system32\DRIVERS\ACPI.sys
  0x00FCB000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
  0x00FD4000 \SystemRoot\system32\DRIVERS\msisadrv.sys
  0x00D60000 \SystemRoot\system32\DRIVERS\pci.sys
  0x00FDE000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
  0x00FEB000 \SystemRoot\System32\drivers\partmgr.sys
  0x00D93000 \SystemRoot\system32\DRIVERS\volmgr.sys
  0x00C00000 \SystemRoot\System32\drivers\volmgrx.sys
  0x00C5C000 \SystemRoot\system32\DRIVERS\intelide.sys
  0x00C64000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
  0x00C74000 \SystemRoot\system32\DRIVERS\pciide.sys
  0x00C7B000 \SystemRoot\System32\drivers\mountmgr.sys
  0x00C95000 \SystemRoot\system32\DRIVERS\atapi.sys
  0x00DA8000 \SystemRoot\system32\DRIVERS\ataport.SYS
  0x00DD2000 \SystemRoot\system32\DRIVERS\msahci.sys
  0x00DDD000 \SystemRoot\system32\DRIVERS\jraid.sys
  0x010F7000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
  0x01126000 \SystemRoot\system32\DRIVERS\Si3114r5.sys
  0x01178000 \SystemRoot\system32\DRIVERS\amdxata.sys
  0x01183000 \SystemRoot\system32\drivers\fltmgr.sys
  0x011CF000 \SystemRoot\system32\drivers\fileinfo.sys
  0x011E3000 \SystemRoot\system32\DRIVERS\SiWinAcc.sys
  0x011ED000 \SystemRoot\System32\Drivers\PxHlpa64.sys
  0x01213000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x01000000 \SystemRoot\System32\Drivers\msrpc.sys
  0x013B6000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x0105E000 \SystemRoot\System32\Drivers\cng.sys
  0x013D0000 \SystemRoot\System32\drivers\pcw.sys
  0x013E1000 \SystemRoot\System32\Drivers\Fs_Rec.sys
  0x014A7000 \SystemRoot\system32\drivers\ndis.sys
  0x01599000 \SystemRoot\system32\drivers\NETIO.SYS
  0x01400000 \SystemRoot\System32\Drivers\ksecpkg.sys
  0x01600000 \SystemRoot\System32\drivers\tcpip.sys
  0x0142B000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x01475000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
  0x018FD000 \SystemRoot\system32\DRIVERS\volsnap.sys
  0x01949000 \SystemRoot\System32\Drivers\spldr.sys
  0x01951000 \SystemRoot\SysWOW64\speedfan.sys
  0x01958000 \SystemRoot\system32\DRIVERS\SiRemFil.sys
  0x01960000 \SystemRoot\system32\DRIVERS\sbp2port.sys
  0x0197D000 \SystemRoot\System32\drivers\rdyboost.sys
  0x019B7000 \SystemRoot\System32\Drivers\mup.sys
  0x019C9000 \SystemRoot\system32\DRIVERS\JGOGO.sys
  0x019D0000 \SystemRoot\System32\drivers\hwpolicy.sys
  0x01800000 \SystemRoot\System32\DRIVERS\fvevol.sys
  0x0183A000 \SystemRoot\system32\DRIVERS\disk.sys
  0x01850000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
  0x018B6000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x02C38000 \SystemRoot\System32\Drivers\aswSnx.SYS
  0x02CA5000 \SystemRoot\System32\Drivers\Null.SYS
  0x02CAE000 \SystemRoot\System32\Drivers\Beep.SYS
  0x02CB5000 \SystemRoot\System32\drivers\vga.sys
  0x02CC3000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x02CE8000 \SystemRoot\System32\drivers\watchdog.sys
  0x02CF8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x02D01000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x02D0A000 \SystemRoot\system32\drivers\rdprefmp.sys
  0x02D13000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x02D1E000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x02D2F000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x02D4D000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x02D5A000 \SystemRoot\System32\Drivers\aswTdi.SYS
  0x02D6A000 \SystemRoot\System32\Drivers\avgtdia.sys
  0x03A4A000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x03A8F000 \SystemRoot\system32\drivers\afd.sys
  0x03B19000 \SystemRoot\System32\Drivers\aswRdr.SYS
  0x03B23000 \SystemRoot\system32\DRIVERS\wfplwf.sys
  0x03B2C000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x03B52000 \SystemRoot\system32\DRIVERS\vwififlt.sys
  0x03B68000 \SystemRoot\system32\DRIVERS\vpcnfltr.sys
  0x03B7C000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x03B8B000 \SystemRoot\system32\DRIVERS\serial.sys
  0x03BA8000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x040E6000 \SystemRoot\system32\drivers\vpcvmm.sys
  0x0413D000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x04151000 \SystemRoot\System32\Drivers\SCDEmu.SYS
  0x0416B000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x041BC000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x041C8000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x041D3000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
  0x041DE000 \SystemRoot\System32\drivers\discache.sys
  0x04000000 \SystemRoot\system32\drivers\csc.sys
  0x04083000 \SystemRoot\System32\Drivers\dfsc.sys
  0x040A1000 \SystemRoot\system32\DRIVERS\blbdrive.sys
  0x040B2000 \SystemRoot\System32\Drivers\avgmfx64.sys
  0x042AC000 \SystemRoot\System32\Drivers\avgldx64.sys
  0x04319000 \SystemRoot\System32\Drivers\aswSP.SYS
  0x0433C000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x04362000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0x0FECE000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
  0x10BF5000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
  0x04815000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x04909000 \SystemRoot\System32\drivers\dxgmms1.sys
  0x0494F000 \SystemRoot\system32\DRIVERS\usbuhci.sys
  0x0495C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x049B2000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x049C3000 \SystemRoot\System32\Drivers\AnyDVD.sys
  0x0FE00000 \SystemRoot\system32\DRIVERS\yk62x64.sys
  0x04200000 \SystemRoot\system32\DRIVERS\netr28x.sys
  0x049E5000 \SystemRoot\system32\DRIVERS\vwifibus.sys
  0x0FE65000 \SystemRoot\system32\DRIVERS\1394ohci.sys
  0x049F2000 \SystemRoot\system32\DRIVERS\serenum.sys
  0x04800000 \SystemRoot\system32\DRIVERS\ASACPI.sys
  0x0FEA3000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
  0x04808000 \SystemRoot\system32\DRIVERS\lmimirr.sys
  0x0FEB3000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
  0x04378000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x0439C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x043A8000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x043D7000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x040B9000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x03BC3000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x043F2000 \SystemRoot\system32\DRIVERS\rdpbus.sys
  0x041ED000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x03BDD000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x0480F000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x03A00000 \SystemRoot\system32\DRIVERS\ks.sys
  0x03BEC000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x02DDF000 \SystemRoot\system32\DRIVERS\vpcusb.sys
  0x02C00000 \SystemRoot\system32\DRIVERS\usbrpm.sys
  0x04811000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x04C50000 \SystemRoot\system32\DRIVERS\vpchbus.sys
  0x04C8C000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x04CE6000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x04CFB000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x04D09000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x04D22000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x04D2B000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x04D38000 \SystemRoot\system32\DRIVERS\usbccgp.sys
  0x04D55000 \SystemRoot\system32\drivers\usbaudio.sys
  0x04D70000 \SystemRoot\system32\drivers\ksthunk.sys
  0x04D76000 \SystemRoot\system32\DRIVERS\WinUsb.sys
  0x04D87000 \SystemRoot\system32\DRIVERS\kbdhid.sys
  0x00060000 \SystemRoot\System32\win32k.sys
  0x04D95000 \SystemRoot\System32\drivers\Dxapi.sys
  0x04DA1000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x00550000 \SystemRoot\System32\TSDDD.dll
  0x00680000 \SystemRoot\System32\cdd.dll
  0x04DAF000 \SystemRoot\system32\DRIVERS\cdfs.sys
  0x00870000 \SystemRoot\System32\ATMFD.DLL
  0x04DCC000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x04DDA000 \SystemRoot\System32\Drivers\dump_dumpata.sys
  0x04DE6000 \SystemRoot\System32\Drivers\dump_atapi.sys
  0x04C00000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
  0x04C13000 \SystemRoot\system32\drivers\luafv.sys
  0x02C0F000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
  0x04C36000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
  0x019D9000 \SystemRoot\system32\drivers\WudfPf.sys
  0x01880000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x06028000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x0607B000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0x0608E000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x060A6000 \SystemRoot\system32\drivers\HTTP.sys
  0x0616E000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0x0619B000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x061B9000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x061D1000 \SystemRoot\system32\drivers\mrxdav.sys
  0x0666E000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x0669B000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x066E9000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0x0670C000 \SystemRoot\System32\DRIVERS\srv2.sys
  0x068A4000 \SystemRoot\System32\DRIVERS\srv.sys
  0x0693A000 \SystemRoot\System32\Drivers\adfs.SYS
  0x06952000 \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
  0x06959000 \??\C:\Windows\system32\drivers\LMIRfsDriver.sys
  0x06C9F000 \SystemRoot\system32\drivers\peauth.sys
  0x06D45000 \SystemRoot\System32\Drivers\secdrv.SYS
  0x06D50000 \SystemRoot\System32\drivers\tcpipreg.sys
  0x06D62000 \??\C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys
  0x00A60000 \SystemRoot\System32\lmimirr.dll
  0x00CF0000 \SystemRoot\System32\lmimirr2.dll
  0x77490000 \Windows\System32\ntdll.dll
  0x47D80000 \Windows\System32\smss.exe
  0xFF7B0000 \Windows\System32\apisetschema.dll
  0xFFDF0000 \Windows\System32\autochk.exe

Processes (total 70):
       0 System Idle Process
       4 System
     408 C:\Windows\System32\smss.exe
     548 csrss.exe
     616 C:\Windows\System32\wininit.exe
     632 csrss.exe
     672 C:\Windows\System32\services.exe
     704 C:\Windows\System32\lsass.exe
     712 C:\Windows\System32\lsm.exe
     764 C:\Windows\System32\winlogon.exe
     868 C:\Windows\System32\svchost.exe
     980 C:\Windows\System32\nvvsvc.exe
    1020 C:\Windows\System32\svchost.exe
     504 C:\Windows\System32\svchost.exe
     660 C:\Windows\System32\svchost.exe
    1004 C:\Windows\System32\svchost.exe
    1172 C:\Windows\System32\svchost.exe
    1252 C:\Windows\System32\nvvsvc.exe
    1372 C:\Windows\System32\svchost.exe
    1468 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    1876 C:\Windows\System32\spoolsv.exe
    1924 C:\Windows\System32\svchost.exe
    1932 C:\Windows\System32\taskhost.exe
    1992 C:\Windows\System32\dwm.exe
    2036 C:\Windows\explorer.exe
    2084 C:\Program Files (x86)\LogMeIn\x64\ramaint.exe
    2120 C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
    2156 C:\Program Files (x86)\LogMeIn\x64\LMIGuardian.exe
    2208 C:\Windows\System32\svchost.exe
    2632 C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
    2884 C:\Windows\System32\svchost.exe
    2956 C:\Program Files (x86)\LogMeIn\x64\LMIGuardian.exe
    1744 C:\Program Files\Zune\ZuneLauncher.exe
    2568 C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe
    2628 C:\Users\Mike Mulholland\AppData\Roaming\fbx.exe
    2584 C:\Program Files\PreSonus\1394AudioDriver_FireBox\FireBox.exe
    2688 C:\Program Files\UltraMon\UltraMon.exe
    1708 C:\Program Files\Rainmeter\Rainmeter.exe
    1504 C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe
    1060 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    2572 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    3128 C:\Program Files\UltraMon\UltraMonTaskbar.exe
    3172 C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
    3236 C:\Program Files (x86)\Common Files\Teleca Shared\CapabilityManager.exe
    3260 C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe
    3388 C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
    3520 C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
    3604 C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
    3700 C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
    3724 C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
    3768 C:\Windows\System32\SearchIndexer.exe
    3960 C:\Program Files\Windows Media Player\wmpnetwk.exe
    4072 C:\Windows\System32\svchost.exe
    3464 C:\Windows\System32\svchost.exe
    4556 C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
    4752 C:\Program Files (x86)\AIM\aim.exe
    4964 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    4992 C:\Windows\System32\svchost.exe
    4608 C:\Windows\System32\taskhost.exe
    4352 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
     128 C:\Windows\System32\notepad.exe
    4692 C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
    3300 C:\Program Files (x86)\LogMeIn\x64\LMIGuardian.exe
    3852 C:\Windows\System32\notepad.exe
    3304 C:\Windows\System32\SearchProtocolHost.exe
    3628 C:\Windows\System32\SearchFilterHost.exe
    2184 C:\Windows\SysWOW64\ctfmon.exe
    4020 C:\Users\Mike Mulholland\Desktop\MBRCheck.exe
    2180 C:\Windows\System32\conhost.exe
    4400 C:\Windows\System32\dllhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00  (NTFS)
\\.\E: –> \\.\PhysicalDrive2 at offset 0x00000000`00007e00  (NTFS)
\\.\F: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00  (NTFS)
\\.\G: –> \\.\PhysicalDrive5 at offset 0x00000000`00100000  (NTFS)
\\.\H: –> \\.\PhysicalDrive4 at offset 0x00000000`00100000  (NTFS)
\\.\I: –> \\.\PhysicalDrive3 at offset 0x00000000`00100000  (NTFS)
\\.\J: –> \\.\PhysicalDrive8 at offset 0x00000000`00007e00  (NTFS)
\\.\X: –> \\.\PhysicalDrive9 at offset 0x00000000`00007e00  (NTFS)
\\.\Y: –> \\.\PhysicalDrive7 at offset 0x00000000`00007e00  (NTFS)
\\.\Z: –> \\.\PhysicalDrive6 at offset 0x00000000`00007e00  (NTFS)

PhysicalDrive0 Model Number: ST3320620AS, Rev: 3.AAK   
PhysicalDrive2 Model Number: ST3320620NS, Rev: 3.AEG   
PhysicalDrive1 Model Number: WDCWD10EADS-00L5B1, Rev: 01.01A01
PhysicalDrive5 Model Number: HitachiHDS722020ALA330, Rev: JKAOA20N
PhysicalDrive4 Model Number: HitachiHDS722020ALA330, Rev: JKAOA20N
PhysicalDrive3 Model Number: WDCWD10EADS-00M2B0, Rev: 01.00A01
PhysicalDrive8 Model Number: ST3320620NS, Rev: 3.AEG   
PhysicalDrive9 Model Number: ST3320620NS, Rev: 3.AEG   
PhysicalDrive7 Model Number: SATAST332062, Rev: 
PhysicalDrive6 Model Number: SATAST350063, Rev: 

      Size  Device Name          MBR Status
  ——————————————–
    298 GB  \\.\PhysicalDrive0   Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    298 GB  \\.\PhysicalDrive2   Windows XP MBR code detected
            SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    931 GB  \\.\PhysicalDrive1   Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
   1863 GB  \\.\PhysicalDrive5   Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
   1863 GB  \\.\PhysicalDrive4   Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    931 GB  \\.\PhysicalDrive3   Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    465 GB  \\.\PhysicalDrive8   RE: Windows XP MBR code detected
            SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    298 GB  \\.\PhysicalDrive9   RE: Windows XP MBR code detected
            SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    298 GB  \\.\PhysicalDrive7   Windows XP MBR code detected
            SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    465 GB  \\.\PhysicalDrive6   Windows XP MBR code detected
            SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!

Thanks again for the help.
Please do the following


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [{33D1385C-146C-C636-AB1D-CD011C87803E}] C:\Users\Mike Mulholland\AppData\Roaming\Begifu\ehzy.exe File not found
    O33 - MountPoints2\{91d38fa3-3714-11df-b16e-0018f34f2c86}\Shell - "" = AutoRun
    O33 - MountPoints2\{91d38fa3-3714-11df-b16e-0018f34f2c86}\Shell\AutoRun\command - "" = K:\LaunchU3.exe – File not found
    O33 - MountPoints2\I\Shell - "" = AutoRun
    O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\setup.exe – File not found
    O33 - MountPoints2\J\Shell - "" = AutoRun
    O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\SETUP.EXE – File not found
    O33 - MountPoints2\J\Shell\configure\command - "" = J:\SETUP.EXE – File not found
    O33 - MountPoints2\J\Shell\install\command - "" = J:\SETUP.EXE – File not found
    [2010/09/25 19:01:46 | 000,129,401 | —- | M] () – C:\Windows\SysWow64\crack.exe
    [2010/09/27 00:21:11 | 000,040,344 | —- | C] () – C:\Users\Mike Mulholland\AppData\Roaming\FbxU.exe
    [2010/06/18 21:58:14 | 000,000,000 | —- | C] () – C:\Users\Mike Mulholland\AppData\Local\Unolow.bin
    [2010/06/18 21:58:14 | 000,000,000 | —- | C] () – C:\Users\Mike Mulholland\AppData\Local\Kwajagonamanew.dat
    [2010/03/29 00:47:42 | 000,000,005 | —- | C] () – C:\Windows\hmphlgge.ini
    [2010/09/27 18:00:00 | 000,000,380 | —- | M] () – C:\Windows\Tasks\At1.job
    
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )







  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.






I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
OLT log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0C8413C1-FAD1-446C-8584-BE50576F863E} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0C8413C1-FAD1-446C-8584-BE50576F863E}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{33D1385C-146C-C636-AB1D-CD011C87803E} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33D1385C-146C-C636-AB1D-CD011C87803E}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{91d38fa3-3714-11df-b16e-0018f34f2c86}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91d38fa3-3714-11df-b16e-0018f34f2c86}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{91d38fa3-3714-11df-b16e-0018f34f2c86}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91d38fa3-3714-11df-b16e-0018f34f2c86}\ not found. File K:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\ not found. File I:\setup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ not found. File J:\SETUP.EXE not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ not found. File J:\SETUP.EXE not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ not found. File J:\SETUP.EXE not found. File C:\Windows\SysWow64\crack.exe not found. File C:\Users\Mike Mulholland\AppData\Roaming\FbxU.exe not found. File C:\Users\Mike Mulholland\AppData\Local\Unolow.bin not found. File C:\Users\Mike Mulholland\AppData\Local\Kwajagonamanew.dat not found. File C:\Windows\hmphlgge.ini not found. File C:\Windows\Tasks\At1.job not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33103 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Mike Mulholland ->Temp folder emptied: 62608760 bytes ->Temporary Internet Files folder emptied: 10476559 bytes ->Java cache emptied: 58820 bytes ->FireFox cache emptied: 44140984 bytes ->Flash cache emptied: 2152846 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 35024 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50400 bytes RecycleBin emptied: 15108108457 bytes Total Files Cleaned = 14,522.00 mb OTL by OldTimer - Version 3.2.14.1 log created on 09292010_091224 Files\Folders moved on Reboot… C:\Users\Mike Mulholland\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Mike Mulholland\AppData\Local\Temp\~DFAFB10C2A177FCF8E.TMP not found! Registry entries deleted on Reboot…
Malwarebytes' log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4715 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 9/29/2010 9:24:37 AM mbam-log-2010-09-29 (09-24-37).txt Scan type: Quick scan Objects scanned: 149462 Time elapsed: 3 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{fe4c2c37-edc8-4c00-b864-3c38cf3ba834} (Adware.Adshot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\ProgramData\Update\seupd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
ESET: C:\Windows\System32\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\chrome\content\overlay.xul probably a variant of Win32/Agent.NVQFFQI trojan C:\Windows\System32\config\systemprofile\AppData\LocalLow\BrightShopping\mcsap.dll Win32/Adware.EasyPrediction application C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\chrome\content\overlay.xul probably a variant of Win32/Agent.NVQFFQI trojan C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\BrightShopping\mcsap.dll Win32/Adware.EasyPrediction application Operating memory a variant of Win32/Packed.VMProtect.AAA trojan
Please copy/paste the logs directly into the reply box.


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Windows\System32\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\chrome\content\overlay.xul 
    C:\Windows\System32\config\systemprofile\AppData\LocalLow\BrightShopping\mcsap.dll 
    C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\chrome\content\overlay.xul
    C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\BrightShopping\mcsap.dll 
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Windows\System32\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\chrome\content\overlay.xul moved successfully. C:\Windows\System32\config\systemprofile\AppData\LocalLow\BrightShopping\mcsap.dll moved successfully. File\Folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\chrome\content\overlay.xul not found. File\Folder C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\BrightShopping\mcsap.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Mike Mulholland ->Temp folder emptied: 879 bytes ->Temporary Internet Files folder emptied: 38774 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 17064080 bytes ->Flash cache emptied: 434 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 608 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 16.00 mb OTL by OldTimer - Version 3.2.14.1 log created on 09292010_184527 Files\Folders moved on Reboot… C:\Users\Mike Mulholland\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Mike Mulholland\AppData\Local\Temp\~DF7776F94FF339E804.TMP not found! File\Folder C:\Windows\temp\_asw_aisI.tm~a00424\setup.lok not found! Registry entries deleted on Reboot…
Please open OTL

Change the Extra registry to use safe list

  • Click the Run Scan button.The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.



Also please tell me how the computer is running now.
OTL Extras logfile created on: 9/29/2010 7:35:07 PM - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\Mike
Mulholland\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format:
M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory |
68.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging
File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% =
C:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 188.17 Gb Free Space | 63.12% Space
Free | Partition Type: NTFS
Drive D: | 159.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free
| Partition Type: CDFS
Drive E: | 298.09 Gb Total Space | 275.76 Gb Free Space | 92.51% Space
Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 378.49 Gb Free Space | 40.63% Space
Free | Partition Type: NTFS
Drive G: | 1863.01 Gb Total Space | 597.18 Gb Free Space | 32.05% Space
Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 61.77 Gb Free Space | 3.32% Space
Free | Partition Type: NTFS
Drive I: | 931.51 Gb Total Space | 427.71 Gb Free Space | 45.92% Space
Free | Partition Type: NTFS
Drive J: | 465.76 Gb Total Space | 34.64 Gb Free Space | 7.44% Space
Free | Partition Type: NTFS
Drive X: | 298.09 Gb Total Space | 51.44 Gb Free Space | 17.26% Space
Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 33.89 Gb Free Space | 11.37% Space
Free | Partition Type: NTFS
Drive Z: | 465.76 Gb Total Space | 287.53 Gb Free Space | 61.73% Space
Free | Partition Type: NTFS

Computer Name: WORKSTATION
Current User Name: Mike Mulholland
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft
Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla
Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft
Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft
Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1"
(Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe"
"C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
(Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe
%SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files
(x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe"
–started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%*
(Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft
Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft
Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1"
(Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe"
"C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
(Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe
%SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files
(x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe"
–started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List
==========


64bit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{03AC245F-4C64-425C-89CF-7783C1D3AB2C}" = Microsoft Sync Framework 2.0
Provider Services (x64) ENU
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005
Redistributable (x64)
"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics
Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{33691AFF-9ABF-4278-BDB6-902EE07D9237}" = Native Instruments Guitar Rig 3
"{370BCBBA-67D7-4535-ADCD-58CD1C8DEC99}" = Zune Language Pack (DE)
"{371B17C3-9624-4583-A497-DF980313D851}" = Native Instruments Absynth 5
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{40EC6323-497B-44DA-8A88-74578622D9B3}" = Zune Language Pack (IT)
"{43E7798A-248E-4A3D-9969-FEA63543A462}" = Native Instruments Kontakt 4
"{491DF203-7B61-4F0E-BDCB-A1218C4DAFE9}" = Native Instruments Massive
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008
Redistributable - x64 9.0.30729.4148
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008
Redistributable - x64 9.0.30729
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6BED4DFE-C527-463E-B93A-6F6848B74DD0}" = Native Instruments Battery 3
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008
Redistributable - x64 9.0.30729.17
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{888FFC82-688D-46AB-A776-B417885432B6}" = Zune
"{88DAAF05-5A72-46D2-A7C5-C3759697E943}" = SyncToy 2.1 (x64)
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}" = Microsoft Sync Framework 2.0
Core Components (x64) ENU
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4
Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office
64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared
64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared
64-bit Setup Metadata MUI (English) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error
Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{AAFA253A-08A9-46A8-AB30-B4C26E578424}" = Lexicon Alpha Driver
"{B2552FA6-86E3-410D-84AD-265C2242D410}" = Native Instruments FM8
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon
Handler x64
"{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL
Update kb973923 - x64 8.0.50727.4053
"{C7FAFC98-5ECC-40FC-B440-A5D5FE3A6A6E}" = Native Instruments Guitar Rig 4
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{D799CC16-F3B5-468D-AC67-6F77AAA98173}" = Native Instruments Komplete 6
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E9EA5F38-6299-45A1-9D23-F21729A19357}" = Native Instruments Reaktor 5
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4
Client Profile
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.15
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4
Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MyDefrag v4.2.9_is1" = MyDefrag v4.2.9
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR archiver
"x64 Components_is1" = x64 Components v2.5.3
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008
Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{7F8726E6-89A5-4707-ADB3-21F616BEB843}" = VisualDesigner
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional
Plus 2007
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005
Compact Edition [ENU]
"{F1B6AE0B-E56F-4515-B540-3BD854FE5D64}" = Centrafuse
"{FCAFEEB3-3520-4539-89AF-4B743D2DFAEC}" = HTC Sync
"Aqua Skin" = Aqua Skin
"avast5" = avast! Pro Antivirus
"BrightShopping" = BrightShopping
"CF3OnyxNightSkin" = CF3OnyxNightSkin
"ESET Online Scanner" = ESET Online Scanner v3
"Lexicon Alpha Driver" = Lexicon Alpha Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MKVtoolnix" = MKVtoolnix 4.0.0
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or
the Event Logs are corrupt!

< End of report >
There should have been two logs produced when you ran OTL,please post OTL.txt


Also please tell me how the computer is running now.

Please answer this question.
Apologies. I am remote desktop'ing to my computer from work.

As far as I can tell, the computer seems to be running better. In Firefox, the address bar doesn't get highlighted and my cursor doesn't direct to there anymore.

"BrightShopping" is still in my Remove Programs list. Before coming here I tried to uninstall it from there but it wouldn't. I'm not sure what this file is.





OTL logfile created on: 9/29/2010 7:35:07 PM - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\Mike
Mulholland\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format:
M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory |
68.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging
File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% =
C:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 188.17 Gb Free Space | 63.12% Space
Free | Partition Type: NTFS
Drive D: | 159.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free
| Partition Type: CDFS
Drive E: | 298.09 Gb Total Space | 275.76 Gb Free Space | 92.51% Space
Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 378.49 Gb Free Space | 40.63% Space
Free | Partition Type: NTFS
Drive G: | 1863.01 Gb Total Space | 597.18 Gb Free Space | 32.05% Space
Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 61.77 Gb Free Space | 3.32% Space
Free | Partition Type: NTFS
Drive I: | 931.51 Gb Total Space | 427.71 Gb Free Space | 45.92% Space
Free | Partition Type: NTFS
Drive J: | 465.76 Gb Total Space | 34.64 Gb Free Space | 7.44% Space
Free | Partition Type: NTFS
Drive X: | 298.09 Gb Total Space | 51.44 Gb Free Space | 17.26% Space
Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 33.89 Gb Free Space | 11.37% Space
Free | Partition Type: NTFS
Drive Z: | 465.76 Gb Total Space | 287.53 Gb Free Space | 61.73% Space
Free | Partition Type: NTFS

Computer Name: WORKSTATION
Current User Name: Mike Mulholland
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Mike Mulholland\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Mike Mulholland\AppData\Roaming\fbx.exe (noOrg)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Messaging)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files (x86)\HTC\HTC
Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe (Teleca)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone
Monitor\epmworker.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone
Monitor\FsynSrvStarter.exe (TODO: )
PRC - C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone
Monitor\HTCVBTServer.exe (Teleca AB)
PRC - C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe ()
PRC - C:\Program Files\PreSonus\1394AudioDriver_FireBox\FireBox.exe
(PreSonus Audio Electronics)
PRC - C:\Program Files (x86)\Common Files\Realtime
Soft\RTSHookInterop\x32\RTSHookInterop.exe (Realtime Soft Ltd)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
(Teleca AB)
PRC - C:\Program Files (x86)\HTC\HTC Sync\Application
Launcher\Application Launcher.exe (Teleca Sweden AB)
PRC - C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe
(Popwire AB)
PRC - C:\Program Files (x86)\Common Files\Teleca
Shared\CapabilityManager.exe (Teleca Sweden AB)


========== Modules (SafeList) ==========

MOD - C:\Users\Mike Mulholland\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\UltraMon\RTSUltraMonHookX32.dll (Realtime Soft Ltd)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD -
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll

(Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil
Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil
Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil
Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program
Files\Common Files\Macrovision Shared\FLEXnet
Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (ZuneWlanCfgSvc) –
C:\Windows\SysNative\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:64bit: - (ZuneNetworkSvc) – C:\Program
Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll
(Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) –
C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows
Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll
(Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll
(Microsoft Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
(LogMeIn, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common
Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(Acresso Software Inc.)
SRV - (aspnet_state) –
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) –
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft
Corporation)
SRV - (clr_optimization_v4.0.30319_32) –
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft
Corporation)
SRV - (Adobe Version Cue CS4) – C:\Program Files (x86)\Common
Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe
Systems Incorporated)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
(LogMeIn, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) –
C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (aswMonFlt) –
C:\Windows\SysNative\drivers\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (AnyDVD) – C:\Windows\SysNative\drivers\AnyDVD.sys
(SlySoft, Inc.)
DRV:64bit: - (AvgTdiA) –
C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) –
C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) –
C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (pae_1394) –
C:\Windows\SysNative\drivers\pae_1394_x64.sys (Archwave AG)
DRV:64bit: - (pae_avs) –
C:\Windows\SysNative\drivers\pae_avs_x64.sys (Archwave AG)
DRV:64bit: - (ElbyCDIO) –
C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (HTCAND64) –
C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (vpcnfltr) –
C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys
(Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys
(Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys
(Microsoft Corporation)
DRV:64bit: - (amdsata) –
C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) –
C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys
(AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) –
C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys
(Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys
(Microsoft Corporation)
DRV:64bit: - (storflt) –
C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) –
C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) –
C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys
(Microsoft Corporation)
DRV:64bit: - (VMBusHID) –
C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys
(Microsoft Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (netr28x) –
C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys
(Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys
(Broadcom Corporation)
DRV:64bit: - (b57nd60a) –
C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) –
C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (LMIRfsDriver) –
C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) –
C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (Si3114r5) –
C:\Windows\SysNative\drivers\Si3114r5.sys (Silicon Image, Inc)
DRV:64bit: - (PxHlpa64) –
C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys
(JMicron Technology Corp.)
DRV:64bit: - (SiRemFil) –
C:\Windows\SysNative\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV:64bit: - (JGOGO) – C:\Windows\SysNative\drivers\JGOGO.sys
(JMicron )
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (SiFilter) –
C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (AnyDVD) – C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (UltraMonUtility) – C:\Program Files (x86)\Common Files\Realtime
Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys (Realtime Soft Ltd)
DRV - (adfs) – C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys
(LogMeIn, Inc.)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server
2003 DDK provider)
DRV - (WINIO) – C:\Program Files (x86)\Centrafuse\Centrafuse
Auto\WinIo.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
about:blank
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - Reg
Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:
"ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems:
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems:
{EA7EB1AF-308C-4A4A-A175-6C17028D665F}:1.9.1
FF - prefs.js..extensions.enabledItems:
{5B40C443-0044-401C-86EA-7C7FCC6D8D16}:1.9.1


FF -
HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}:
C:\Program Files (x86)\AVG\AVG9\Firefox [2010/03/17 12:11:45 |
000,000,000 | —D | M]
FF -
HKLM\software\mozilla\Firefox\Extensions\\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}:
C:\Windows\system32\config\systemprofile\AppData\Local\{EA7EB1AF-308C-4A4A-A175-6C17028D665F}\

[2010/06/18 18:02:53 | 000,000,000 | —D | M]
FF -
HKLM\software\mozilla\Firefox\Extensions\\{5B40C443-0044-401C-86EA-7C7FCC6D8D16}:
C:\Users\Mike
Mulholland\AppData\Local\{5B40C443-0044-401C-86EA-7C7FCC6D8D16}
[2010/07/26 11:05:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox
3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla
Firefox\components [2010/09/27 08:04:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins:
C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/27 07:55:53 |
000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird
3.1.4\extensions\\Components: C:\Program Files (x86)\Mozilla
Thunderbird\components [2010/09/17 06:21:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird
3.1.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla
Thunderbird\plugins [2010/03/22 02:13:53 | 000,000,000 | —D | M]

[2010/09/27 08:04:45 | 000,000,000 | —D | M] – C:\Users\Mike
Mulholland\AppData\Roaming\Mozilla\Extensions
[2010/03/15 20:21:21 | 000,000,000 | —D | M] (No name found) –
C:\Users\Mike
Mulholland\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/09/27 08:04:45 | 000,000,000 | —D | M] – C:\Users\Mike
Mulholland\AppData\Roaming\Mozilla\Firefox\Profiles\se2gvgyu.default\extensions
[2010/09/29 07:50:46 | 000,000,000 | —D | M] – C:\Program Files
(x86)\Mozilla Firefox\extensions
[2010/07/12 23:54:28 | 000,000,000 | —D | M] (Java Console) –
C:\Program Files (x86)\Mozilla
Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/07/12 23:54:12 | 000,411,368 | —- | M] (Sun Microsystems, Inc.)
– C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/15 19:02:03 | 000,075,208 | —- | M] (Foxit Software Company)
– C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/06/15 16:17:52 | 000,002,076 | —- | M] () – C:\Program Files
(x86)\Mozilla Firefox\searchplugins\google_search.xml

O1 HOSTS File: ([2010/03/29 05:01:10 | 000,001,389 | —- | M]) -
C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 pagead2.googlesyndication.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216}
- C:\Program Files (x86)\Adobe\/Adobe Contribute
CS4/contributeieplugin.dll ()
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) -
{AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} -
C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) -
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) -
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files
(x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) -
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files
(x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program
Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil
Software\Avast5\avastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe ()
O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files
(x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca
Sweden AB)
O4 - HKCU..\Run: [Allway Sync] C:\Program Files (x86)\Allway
Sync\Bin\syncappw.exe ()
O4 - HKCU..\Run: [InstallMon] C:\Users\Mike
Mulholland\AppData\Roaming\fbx.exe (noOrg)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe
(BitTorrent, Inc.)
O4 - Startup: C:\Users\Mike
Mulholland\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\Rainmeter.lnk = C:\Program
Files\Rainmeter\Rainmeter.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoStartMenuMorePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Append Link Target to
Existing PDF - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF -
C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe
PDF - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF -
C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF -
C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files
(x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe
Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF -
C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files
(x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe
Systems Incorporated)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
(Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab
(Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
(Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
(Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
192.168.1.1 74.128.17.114 74.128.19.102
O18:64bit: - Protocol\Handler\ms-help
{314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not
found
O20:64bit: - AppInit_DLLs: (avgrssta.dll) -
C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) -
C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet -
(SystemPropertiesPerformance.exe) -
C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -
C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -
C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck -
{E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID
or File not found.
O27:64bit: - HKLM IFEO\ehshell.exe: Debugger - C:\Program Files
(x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O27 - HKLM IFEO\ehshell.exe: Debugger - "C:\Program Files
(x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect (LogMeIn, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days
==========


[2010/09/29 09:27:10 | 000,000,000 | —D | C] – C:\Program Files
(x86)\ESET
[2010/09/29 09:04:17 | 000,000,000 | —D | C] – C:\_OTL
[2010/09/29 03:00:27 | 000,243,712 | —- | C] (Microsoft Corporation)
– C:\Windows\SysNative\drivers\ks.sys
[2010/09/28 15:30:24 | 000,575,488 | —- | C] (OldTimer Tools) –
C:\Users\Mike Mulholland\Desktop\OTL.exe
[2010/09/27 22:08:58 | 000,000,000 | —D | C] – C:\Users\Mike
Mulholland\Documents\VisualDesigner
[2010/09/27 22:08:56 | 000,000,000 | —D | C] – C:\Program Files
(x86)\Zoran Horvat
[2010/09/27 07:45:08 | 008,534,336 | —- | C] (Mozilla) –
C:\Users\Mike Mulholland\Desktop\Firefox Setup 3.6.10.exe
[2010/09/27 06:25:12 | 003,629,944 | —- | C] (Microsoft Corporation)
– C:\Users\Mike Mulholland\Desktop\SyncToySetupPackage_v21_x64.exe
[2010/09/27 00:41:19 | 000,424,016 | —- | C] (ALWIL Software) –
C:\Windows\SysNative\drivers\aswSnx.sys
[2010/09/27 00:41:19 | 000,121,936 | —- | C] (ALWIL Software) –
C:\Windows\SysNative\drivers\aswSP.sys
[2010/09/27 00:41:19 | 000,022,096 | —- | C] (ALWIL Software) –
C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/09/27 00:41:18 | 000,051,280 | —- | C] (ALWIL Software) –
C:\Windows\SysNative\drivers\aswTdi.sys
[2010/09/27 00:41:18 | 000,028,752 | —- | C] (ALWIL Software) –
C:\Windows\SysNative\drivers\aswRdr.sys
[2010/09/27 00:41:17 | 000,063,568 | —- | C] (ALWIL Software) –
C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/09/27 00:40:57 | 000,165,032 | —- | C] (ALWIL Software) –
C:\Windows\SysWow64\aswBoot.exe
[2010/09/27 00:40:57 | 000,038,848 | —- | C] (ALWIL Software) –
C:\Windows\SysWow64\avastSS.scr
[2010/09/26 23:35:40 | 000,000,000 | -H-D | C] –
C:\ProgramData\{E6BD42D3-E8A6-4469-B72F-B5256066F41F}
[2010/09/26 23:35:39 | 000,000,000 | —D | C] – C:\Program Files\Lexicon
[2010/09/26 23:34:41 | 015,010,248 | —- | C]
(Lexicon



) – C:\Users\Mike Mulholland\Desktop\AlphaDriverInstaller.exe
[2010/09/26 23:29:38 | 000,000,000 | —D | C] – C:\Users\Mike
Mulholland\Desktop\AD1988AB_Audio_V6585_XpVistaWin7
[2010/09/25 01:39:50 | 000,000,000 | —D | C] – C:\Program Files
(x86)\FLAC
[2010/09/24 20:24:46 | 000,081,920 | —- | C] (noOrg) – C:\Users\Mike
Mulholland\AppData\Roaming\fbx.exe
[2010/09/22 16:19:16 | 000,000,000 | —D | C] – C:\Users\Mike
Mulholland\Desktop\FileSync
[2010/09/22 07:20:57 | 004,859,796 | —- | C] (www.Centrafuse-Forum.de)
– C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31.exe
[2010/09/22 06:29:33 | 000,000,000 | —D | C] – C:\Users\Mike
Mulholland\Desktop\jojo mayer - nerve - ep1
[2010/09/22 06:27:12 | 000,000,000 | —D | C] – C:\Users\Mike
Mulholland\Desktop\jojo mayer - nerve - ep2
[2010/09/15 03:00:59 | 002,441,216 | —- | C] (Microsoft Corporation)
– C:\Windows\SysNative\iertutil.dll
[2010/09/08 15:03:50 | 000,000,000 | —D | C] – C:\Program
Files\SyncToy 2.1
[2010/09/08 15:03:13 | 000,000,000 | —D | C] – C:\Program
Files\Microsoft Sync Framework

========== Files - Modified Within 30 Days ==========

[2010/09/29 19:35:12 | 003,932,160 | -HS- | M] () – C:\Users\Mike
Mulholland\ntuser.dat
[2010/09/29 18:57:14 | 000,000,344 | —- | M] () –
C:\Windows\tasks\GlaryInitialize.job
[2010/09/29 18:55:28 | 000,017,360 | -H– | M] () –
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/29 18:55:28 | 000,017,360 | -H– | M] () –
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/29 18:48:15 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/29 18:48:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/29 18:48:01 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2010/09/29 18:46:06 | 001,885,103 | -H– | M] () – C:\Users\Mike
Mulholland\AppData\Local\IconCache.db
[2010/09/29 09:27:02 | 002,672,312 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\esetsmartinstaller_enu.exe
[2010/09/29 02:35:01 | 001,289,269 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\f150forum signature.psd
[2010/09/28 18:30:10 | 000,080,384 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\MBRCheck.exe
[2010/09/28 15:30:26 | 000,575,488 | —- | M] (OldTimer Tools) –
C:\Users\Mike Mulholland\Desktop\OTL.exe
[2010/09/28 02:40:21 | 007,722,336 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\Centrafuse design.psd
[2010/09/27 23:27:40 | 000,148,596 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\IMG_4183.jpg
[2010/09/27 23:27:38 | 000,204,401 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\IMG_4179.jpg
[2010/09/27 23:27:35 | 004,444,121 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\7Loader.zip
[2010/09/27 23:27:31 | 000,196,085 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\IMG_4178.jpg
[2010/09/27 22:09:03 | 000,003,185 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\VisualDesigner2.lnk
[2010/09/27 21:58:44 | 000,027,463 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\body-bg.jpg
[2010/09/27 15:10:18 | 000,001,015 | —- | M] () –
C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/27 07:55:56 | 000,001,969 | —- | M] () – C:\Users\Mike
Mulholland\Application Data\Microsoft\Internet Explorer\Quick
Launch\Mozilla Firefox.lnk
[2010/09/27 07:45:08 | 008,534,336 | —- | M] (Mozilla) –
C:\Users\Mike Mulholland\Desktop\Firefox Setup 3.6.10.exe
[2010/09/27 07:39:04 | 000,040,114 | —- | M] () – C:\Users\Mike
Mulholland\Documents\cc_20100927_073844.reg
[2010/09/27 07:37:22 | 000,044,323 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\rear_off.png
[2010/09/27 07:05:13 | 000,103,343 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\bookmarks-2010-09-27.json
[2010/09/27 07:04:26 | 000,415,759 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\ASIO4ALL_2_10_English.exe
[2010/09/27 06:25:18 | 003,629,944 | —- | M] (Microsoft Corporation)
– C:\Users\Mike Mulholland\Desktop\SyncToySetupPackage_v21_x64.exe
[2010/09/27 05:42:36 | 000,013,744 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\btn_pageleft_off.png
[2010/09/27 05:28:43 | 000,444,971 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\background_F150.png
[2010/09/27 05:28:22 | 000,310,988 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\background_F150_Blur.png
[2010/09/27 05:14:25 | 000,407,725 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\backgroundf150.png
[2010/09/27 04:40:40 | 000,048,640 | —- | M] () – C:\Users\Mike
Mulholland\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/27 04:36:14 | 000,001,902 | —- | M] () –
C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2010/09/27 00:41:17 | 000,000,000 | —- | M] () –
C:\Windows\SysWow64\config.nt
[2010/09/26 23:44:04 | 000,111,960 | —- | M] () – C:\Users\Mike
Mulholland\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/26 23:38:53 | 000,000,000 | -H– | M] () –
C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2010/09/26 23:38:19 | 003,029,168 | —- | M] () –
C:\Windows\SysNative\FNTCACHE.DAT
[2010/09/26 23:35:11 | 015,010,248 | —- | M]
(Lexicon



) – C:\Users\Mike Mulholland\Desktop\AlphaDriverInstaller.exe
[2010/09/26 23:30:04 | 000,001,769 | —- | M] () –
C:\Windows\Language_trs.ini
[2010/09/24 20:24:46 | 000,081,920 | —- | M] (noOrg) – C:\Users\Mike
Mulholland\AppData\Roaming\fbx.exe
[2010/09/23 01:22:09 | 000,048,589 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\FORDLogo.jpg
[2010/09/23 01:22:02 | 000,050,003 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\Ford_Logo_Large.jpg
[2010/09/22 16:17:01 | 000,893,193 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\FileSync3.zip
[2010/09/22 07:21:36 | 004,859,796 | —- | M] (www.Centrafuse-Forum.de)
– C:\Users\Mike Mulholland\Desktop\OnyxNightSkinCF31.exe
[2010/09/22 06:29:07 | 115,229,057 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\jojo mayer - nerve - ep1.zip
[2010/09/22 06:24:24 | 119,028,164 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\jojo mayer - nerve - ep2.zip
[2010/09/22 01:40:51 | 000,778,150 | —- | M] () –
C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/22 01:40:51 | 000,661,172 | —- | M] () –
C:\Windows\SysNative\perfh009.dat
[2010/09/22 01:40:51 | 000,121,090 | —- | M] () –
C:\Windows\SysNative\perfc009.dat
[2010/09/16 06:58:11 | 000,039,424 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\F150.xls
[2010/09/14 23:28:32 | 000,080,191 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\SUB ENCLOSURE.jpg
[2010/09/14 23:28:21 | 000,733,355 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\SUB ENCLOSURE.psd
[2010/09/14 09:35:25 | 001,877,679 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\IMAG0069.jpg
[2010/09/07 16:01:30 | 000,000,003 | RHS- | M] () – C:\win7ldr
[2010/09/07 16:01:30 | 000,000,003 | —- | M] () – C:\Windows\7Loader.TAG
[2010/09/07 16:01:16 | 000,203,316 | RHS- | M] () – C:\grldr
[2010/09/02 16:03:34 | 000,027,648 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\AUDIO.xls
[2010/09/02 05:47:15 | 000,034,816 | —- | M] () – C:\Users\Mike
Mulholland\Desktop\carpc.xls
[2010/08/31 01:19:12 | 002,441,216 | —- | M] (Microsoft Corporation)
– C:\Windows\SysNative\iertutil.dll

========== Files Created - No Company Name ==========

[2010/09/29 09:26:42 | 002,672,312 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\esetsmartinstaller_enu.exe
[2010/09/29 02:34:59 | 001,289,269 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\f150forum signature.psd
[2010/09/28 18:30:09 | 000,080,384 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\MBRCheck.exe
[2010/09/28 15:32:34 | 000,293,376 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\gmer.exe
[2010/09/28 00:09:17 | 007,722,336 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\Centrafuse design.psd
[2010/09/27 23:27:40 | 000,148,596 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\IMG_4183.jpg
[2010/09/27 23:27:38 | 000,204,401 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\IMG_4179.jpg
[2010/09/27 23:27:31 | 000,196,085 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\IMG_4178.jpg
[2010/09/27 22:09:03 | 000,003,185 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\VisualDesigner2.lnk
[2010/09/27 21:58:43 | 000,027,463 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\body-bg.jpg
[2010/09/27 15:10:18 | 000,001,015 | —- | C] () –
C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/27 07:55:56 | 000,001,969 | —- | C] () – C:\Users\Mike
Mulholland\Application Data\Microsoft\Internet Explorer\Quick
Launch\Mozilla Firefox.lnk
[2010/09/27 07:38:59 | 000,040,114 | —- | C] () – C:\Users\Mike
Mulholland\Documents\cc_20100927_073844.reg
[2010/09/27 07:37:17 | 000,044,323 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\rear_off.png
[2010/09/27 07:05:13 | 000,103,343 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\bookmarks-2010-09-27.json
[2010/09/27 07:04:25 | 000,415,759 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\ASIO4ALL_2_10_English.exe
[2010/09/27 05:42:34 | 000,013,744 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\btn_pageleft_off.png
[2010/09/27 05:28:41 | 000,444,971 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\background_F150.png
[2010/09/27 05:28:19 | 000,310,988 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\background_F150_Blur.png
[2010/09/27 04:58:25 | 000,407,725 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\backgroundf150.png
[2010/09/27 00:41:19 | 000,001,902 | —- | C] () –
C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2010/09/26 23:38:53 | 000,000,000 | -H– | C] () –
C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2010/09/26 23:30:04 | 000,001,769 | —- | C] () –
C:\Windows\Language_trs.ini
[2010/09/23 01:22:09 | 000,048,589 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\FORDLogo.jpg
[2010/09/23 01:22:02 | 000,050,003 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\Ford_Logo_Large.jpg
[2010/09/22 16:16:57 | 000,893,193 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\FileSync3.zip
[2010/09/22 06:22:45 | 115,229,057 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\jojo mayer - nerve - ep1.zip
[2010/09/22 06:20:20 | 119,028,164 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\jojo mayer - nerve - ep2.zip
[2010/09/14 23:28:30 | 000,080,191 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\SUB ENCLOSURE.jpg
[2010/09/14 23:28:20 | 000,733,355 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\SUB ENCLOSURE.psd
[2010/09/14 09:35:24 | 001,877,679 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\IMAG0069.jpg
[2010/09/07 16:01:30 | 000,203,316 | RHS- | C] () – C:\grldr
[2010/09/07 16:01:30 | 000,000,003 | RHS- | C] () – C:\win7ldr
[2010/09/07 16:01:30 | 000,000,003 | —- | C] () – C:\Windows\7Loader.TAG
[2010/09/07 15:59:12 | 003,541,702 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\Loader.exe
[2010/09/07 15:51:19 | 004,444,121 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\7Loader.zip
[2010/09/03 05:40:06 | 000,039,424 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\F150.xls
[2010/09/02 05:47:15 | 000,034,816 | —- | C] () – C:\Users\Mike
Mulholland\Desktop\carpc.xls
[2010/07/12 00:47:59 | 000,774,176 | —- | C] () –
C:\Windows\SysWow64\PerfStringBackup.INI
[2010/06/18 04:13:02 | 000,000,745 | —- | C] () – C:\Users\Mike
Mulholland\AppData\Roaming\AtomicAlarmClock.ini
[2010/04/14 12:44:05 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2010/04/13 19:22:46 | 000,001,107 | —- | C] () – C:\Program
Files\explorer(shortcut).exe.lnk
[2010/04/13 19:22:46 | 000,000,041 | —- | C] () – C:\Program
Files\explorer.bat
[2010/03/19 05:38:57 | 000,327,168 | —- | C] () –
C:\Windows\SysWow64\cutil32.dll
[2010/03/15 20:41:16 | 000,048,640 | —- | C] () – C:\Users\Mike
Mulholland\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/21 04:48:22 | 000,085,504 | —- | C] () –
C:\Windows\SysWow64\ff_vfw.dll
[2009/08/16 10:08:36 | 000,178,176 | —- | C] () –
C:\Windows\SysWow64\unrar.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () –
C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () –
C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/29 15:52:26 | 000,204,800 | —- | C] () –
C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 15:47:06 | 000,881,664 | —- | C] () –
C:\Windows\SysWow64\xvidcore.dll
[2007/02/05 19:05:26 | 000,000,038 | —- | C] () –
C:\Windows\AviSplitter.INI
[2006/11/13 14:40:22 | 000,045,056 | —- | C] () –
C:\Windows\SysWow64\io.dll
[2006/05/22 14:45:38 | 000,036,864 | —- | C] () –
C:\Windows\SysWow64\InFillCOM.dll
[2002/10/03 13:52:34 | 000,147,456 | —- | C] () –
C:\Windows\SysWow64\STTubeDevice203.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:7717F034
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI