This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirects sometimes

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
Hi and thanks for you help
following is as requested
the extras foloow
OTL logfile created on: 09/10/2010 16:30:51 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = E:\Documents and Settings\Les\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): E:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
Drive E: | 149.04 Gb Total Space | 115.18 Gb Free Space | 77.28% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HAYHOULL
Current User Name: Les
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - E:\Documents and Settings\Les\Desktop\OTL.exe (OldTimer Tools)
PRC - E:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - E:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - E:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
PRC - E:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\WINDOWS\system32\rmctrl.exe ()
PRC - E:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - e:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - E:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - E:\Documents and Settings\Les\Desktop\OTL.exe (OldTimer Tools)
MOD - E:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - E:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (avg9emc) – E:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – E:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – E:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (ACDaemon) – E:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SNMP) – E:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
SRV - (p2pgasvc) – E:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Iprip) – E:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
SRV - (CCALib8) – E:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (LVPrcSrv) – e:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (SimpTcp) – E:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
SRV - (LPDSVC) – E:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (USBAAPL) – E:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (AvgTdiX) – E:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – E:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – E:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Tcpip6) – E:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – E:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – E:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (BANTExt) – E:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (nv) – E:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (lvmvdrv) – E:\WINDOWS\system32\drivers\LVMVdrv.sys ()
DRV - (LVPrcMon) – E:\WINDOWS\system32\drivers\LVPrcMon.sys ()
DRV - (Lvckap) – E:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (PID_08A0) QuickCam IM(PID_08A0) – E:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – E:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – E:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (STHDA) – E:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AR5211) – E:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: E:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/23 11:54:01 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/04 11:00:00 | 000,000,734 | —- | M]) - E:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - E:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - E:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - E:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - E:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] E:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] E:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RemoteControl] E:\WINDOWS\system32\rmctrl.exe ()
O4 - HKCU..\Run: [{2406EC9B-4C4D-C9DC-A879-8F5BCE7522E3}] E:\Documents and Settings\Les\Application Data\Atsuoq\iman.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - E:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O15 - HKCU\..Trusted Domains: live.com ([login] http in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {62415890-4985-0825-2508-23487C2A845F} http://85.211.235.108:8150/en/cab/ipcamera.cab (IPCamera Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/m3/photoup…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} http://update.hpphoto.com/download/HPSWUpdate.ocx (CUpdateCtl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 192.168.5.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.72,93.188.166.222
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - E:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - E:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - E:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: E:\Documents and Settings\Les\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: E:\Documents and Settings\Les\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (E:\WINDOWS\system32\ljJBtstR) - File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{ffdcb426-12d1-11de-bee8-0011f5ba649f}\Shell - "" = AutoRun
O33 - MountPoints2\{ffdcb426-12d1-11de-bee8-0011f5ba649f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ffdcb426-12d1-11de-bee8-0011f5ba649f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: Ias - File not found
NetSvcs: Iprip - E:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - E:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - E:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - E:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - E:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - E:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - E:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - E:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - E:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - E:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - E:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - E:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - E:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - E:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (5600070418300928)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/09 16:27:20 | 000,576,512 | —- | C] (OldTimer Tools) – E:\Documents and Settings\Les\Desktop\OTL.exe
[2010/10/05 15:49:08 | 000,000,000 | RH-D | C] – E:\Documents and Settings\Les\Recent
[2010/10/04 07:15:53 | 000,000,000 | —D | C] – E:\Program Files\BBC iPlayer Desktop
[2010/09/23 11:08:18 | 000,000,000 | —D | C] – E:\Documents and Settings\Les\Local Settings\Application Data\Mozilla
[7 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[6 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/09 16:33:00 | 000,000,878 | —- | M] () – E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/09 16:30:22 | 000,000,418 | -H– | M] () – E:\WINDOWS\tasks\User_Feed_Synchronization-{E6EC4259-0510-4250-8CF4-085C3D4A1E53}.job
[2010/10/09 16:30:00 | 000,000,418 | -H– | M] () – E:\WINDOWS\tasks\User_Feed_Synchronization-{EA788DCF-2E19-40DA-AF9C-799E555C33F7}.job
[2010/10/09 16:27:51 | 000,576,512 | —- | M] (OldTimer Tools) – E:\Documents and Settings\Les\Desktop\OTL.exe
[2010/10/09 12:19:27 | 000,000,874 | —- | M] () – E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/09 08:47:53 | 065,788,991 | —- | M] () – E:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/10/09 08:43:58 | 000,000,006 | -H– | M] () – E:\WINDOWS\tasks\SA.DAT
[2010/10/09 08:43:55 | 000,002,048 | –S- | M] () – E:\WINDOWS\bootstat.dat
[2010/10/09 05:58:22 | 004,980,736 | —- | M] () – E:\Documents and Settings\Les\ntuser.dat
[2010/10/08 19:13:44 | 000,000,585 | —- | M] () – E:\WINDOWS\win.ini
[2010/10/08 19:13:44 | 000,000,227 | —- | M] () – E:\WINDOWS\system.ini
[2010/10/04 07:15:54 | 000,000,750 | —- | M] () – E:\Documents and Settings\All Users\Desktop\BBC iPlayer Desktop.lnk
[2010/09/26 11:02:39 | 000,001,925 | —- | M] () – E:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/23 11:08:21 | 000,000,000 | —- | M] () – E:\WINDOWS\nsreg.dat
[2010/09/21 09:17:37 | 000,002,077 | —- | M] () – E:\Documents and Settings\Les\default.pls
[2010/09/21 09:17:05 | 000,000,069 | —- | M] () – E:\WINDOWS\NeroDigital.ini
[2010/09/21 08:55:00 | 000,084,480 | —- | M] () – E:\Documents and Settings\Les\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/15 11:25:53 | 000,000,692 | —- | M] () – E:\Documents and Settings\Les\Desktop\CCleaner.lnk
[7 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[6 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/04 07:15:23 | 000,000,750 | —- | C] () – E:\Documents and Settings\All Users\Desktop\BBC iPlayer Desktop.lnk
[2010/09/26 11:02:39 | 000,001,925 | —- | C] () – E:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/23 11:08:21 | 000,000,000 | —- | C] () – E:\WINDOWS\nsreg.dat
[2010/01/31 11:59:40 | 000,003,840 | —- | C] () – E:\WINDOWS\System32\drivers\BANTExt.sys
[2009/09/19 06:55:10 | 000,000,031 | -H– | C] () – E:\WINDOWS\UKCpInfo.sys
[2009/02/05 09:30:49 | 000,000,000 | —- | C] () – E:\WINDOWS\OpPrintServer.INI
[2008/10/17 07:40:44 | 000,000,000 | —- | C] () – E:\WINDOWS\regclear.INI
[2008/05/19 09:59:12 | 000,027,048 | —- | C] () – E:\WINDOWS\System32\drivers\mbamcatchme.sys
[2008/04/09 06:53:40 | 000,000,185 | —- | C] () – E:\WINDOWS\System32\MRT.INI
[2008/04/08 08:33:36 | 000,166,460 | -HS- | C] () – E:\WINDOWS\System32\RtstBJjl.ini
[2008/04/08 08:33:36 | 000,166,408 | -HS- | C] () – E:\WINDOWS\System32\RtstBJjl.ini2
[2008/04/06 18:19:19 | 000,145,833 | -HS- | C] () – E:\WINDOWS\System32\pqpqYJjl.ini2
[2008/04/06 18:19:19 | 000,145,833 | -HS- | C] () – E:\WINDOWS\System32\pqpqYJjl.ini
[2008/03/24 17:01:06 | 000,000,179 | —- | C] () – E:\WINDOWS\BTW.INI
[2008/03/07 11:03:21 | 000,000,376 | —- | C] () – E:\WINDOWS\ODBC.INI
[2008/03/02 08:19:01 | 000,036,864 | R— | C] () – E:\WINDOWS\System32\ctrldll.dll
[2007/12/05 15:51:08 | 000,000,000 | —- | C] () – E:\WINDOWS\hpqEmlSz.INI
[2007/12/01 09:31:40 | 000,110,080 | —- | C] () – E:\WINDOWS\System32\w32mkrc.dll
[2007/11/27 13:05:53 | 000,016,719 | —- | C] () – E:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/11/16 16:41:57 | 001,559,040 | —- | C] () – E:\WINDOWS\System32\xvidcore.dll
[2007/11/05 20:18:25 | 000,013,126 | R— | C] () – E:\WINDOWS\System32\lvcoinst.ini
[2007/11/05 20:15:45 | 000,000,719 | R— | C] () – E:\WINDOWS\System32\InstExec.ini
[2007/10/24 15:47:56 | 000,084,480 | —- | C] () – E:\Documents and Settings\Les\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/23 09:25:27 | 000,006,656 | —- | C] () – E:\WINDOWS\System32\CNMVSyf.DLL
[2007/10/20 18:01:34 | 000,000,069 | —- | C] () – E:\WINDOWS\NeroDigital.ini
[2007/09/17 01:07:00 | 001,703,936 | —- | C] () – E:\WINDOWS\System32\nvwdmcpl.dll
[2007/09/17 01:07:00 | 001,478,656 | —- | C] () – E:\WINDOWS\System32\nview.dll
[2007/09/17 01:07:00 | 001,019,904 | —- | C] () – E:\WINDOWS\System32\nvwimg.dll
[2007/09/17 01:07:00 | 000,466,944 | —- | C] () – E:\WINDOWS\System32\nvshell.dll
[2007/09/17 01:07:00 | 000,286,720 | —- | C] () – E:\WINDOWS\System32\nvnt4cpl.dll
[2005/12/09 16:37:42 | 002,400,256 | —- | C] () – E:\WINDOWS\System32\drivers\LVMVdrv.sys
[2005/12/09 16:37:42 | 000,016,768 | —- | C] () – E:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005/12/09 16:35:54 | 002,174,464 | —- | C] () – E:\WINDOWS\System32\drivers\Lvckap.sys
[2004/08/04 11:00:00 | 000,755,200 | —- | C] () – E:\WINDOWS\System32\ir50_32.dll
[2004/08/04 11:00:00 | 000,338,432 | —- | C] () – E:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 11:00:00 | 000,200,192 | —- | C] () – E:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 11:00:00 | 000,183,808 | —- | C] () – E:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 11:00:00 | 000,120,320 | —- | C] () – E:\WINDOWS\System32\ir41_qc.dll
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – E:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – E:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2010/06/16 06:49:05 | 000,000,000 | —D | M] – E:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/06/16 06:33:04 | 000,000,000 | —D | M] – E:\Documents and Settings\All Users\Application Data\avg9
[2007/10/17 11:07:40 | 000,000,000 | —D | M] – E:\Documents and Settings\All Users\Application Data\LightScribe
[2008/04/07 11:51:15 | 000,000,000 | —D | M] – E:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/14 17:23:07 | 000,000,000 | —D | M] – E:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/07/15 09:52:03 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\49E675F611B159799C77249896186261
[2008/08/05 13:00:07 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\Atsuoq
[2009/09/17 06:57:42 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2008/07/30 16:07:31 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\ntr
[2010/10/09 12:47:27 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\Ocaxa
[2009/01/03 22:45:00 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\OpenOffice.org
[2010/03/09 08:40:40 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\Opera
[2010/05/08 08:22:48 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\Skinux
[2008/10/17 07:50:57 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\TmpRecentIcons
[2007/12/17 18:27:35 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\Uniblue
[2010/05/01 06:29:19 | 000,000,000 | —D | M] – E:\Documents and Settings\Les\Application Data\Windows Live Writer
[2010/10/09 16:30:22 | 000,000,418 | -H– | M] () – E:\WINDOWS\Tasks\User_Feed_Synchronization-{E6EC4259-0510-4250-8CF4-085C3D4A1E53}.job
[2010/10/09 16:30:00 | 000,000,418 | -H– | M] () – E:\WINDOWS\Tasks\User_Feed_Synchronization-{EA788DCF-2E19-40DA-AF9C-799E555C33F7}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/12/07 11:16:08 | 059,249,664 | —- | M] () – E:\BKEVENT.DT6
[2008/01/09 09:24:42 | 027,479,936 | —- | M] () – E:\BKFIXFLE.SAV
[2007/12/05 18:34:29 | 006,777,856 | —- | M] () – E:\BKLOCATE.DT6
[2007/12/05 18:57:29 | 000,015,360 | —- | M] () – E:\BKMAIL.DT6
[2007/12/07 11:11:08 | 014,320,640 | —- | M] () – E:\BKMARR.DT6
[2007/12/02 13:06:09 | 001,445,888 | —- | M] () – E:\BKMESSG.DT6
[2007/12/07 11:12:32 | 001,389,568 | —- | M] () – E:\BKOTHER.DT6
[2008/01/09 09:19:47 | 085,784,576 | —- | M] () – E:\BKPERSON.DT6
[2005/06/12 22:51:29 | 001,218,560 | —- | M] () – E:\BKSOURCE.DT6
[2005/06/12 22:51:30 | 012,010,496 | —- | M] () – E:\BKSOURPT.DT6
[2007/10/17 11:15:00 | 000,000,210 | -HS- | M] () – E:\boot.ini
[2007/12/02 13:10:31 | 000,000,018 | —- | M] () – E:\CustomEvents.bk
[2007/12/02 13:39:33 | 000,000,009 | —- | M] () – E:\CustomEventsFamily.bk
[2007/12/01 09:32:24 | 000,001,320 | —- | M] () – E:\FlagName.BK
[2004/08/04 11:00:00 | 000,047,564 | RHS- | M] () – E:\NTDETECT.COM
[2008/10/25 05:24:49 | 000,250,048 | RHS- | M] () – E:\ntldr
[2010/10/09 08:43:52 | 2145,386,496 | -HS- | M] () – E:\pagefile.sys
[2007/08/21 12:18:50 | 012,662,176 | —- | M] (RealNetworks, Inc.) – E:\rp10-bbc-en-setup.exe
[2010/04/26 11:32:00 | 000,000,232 | -H– | M] () – E:\sqmdata00.sqm
[2010/04/26 11:49:01 | 000,000,232 | -H– | M] () – E:\sqmdata01.sqm
[2010/04/26 11:51:48 | 000,000,232 | -H– | M] () – E:\sqmdata02.sqm
[2010/04/26 21:02:53 | 000,000,232 | -H– | M] () – E:\sqmdata03.sqm
[2010/04/27 17:57:11 | 000,000,232 | -H– | M] () – E:\sqmdata04.sqm
[2010/04/28 07:23:35 | 000,000,232 | -H– | M] () – E:\sqmdata05.sqm
[2010/04/28 23:29:09 | 000,000,232 | -H– | M] () – E:\sqmdata06.sqm
[2010/04/29 21:14:25 | 000,000,232 | -H– | M] () – E:\sqmdata07.sqm
[2010/04/30 08:33:07 | 000,000,232 | -H– | M] () – E:\sqmdata08.sqm
[2010/04/19 07:19:55 | 000,000,232 | -H– | M] () – E:\sqmdata09.sqm
[2010/04/19 16:03:29 | 000,000,232 | -H– | M] () – E:\sqmdata10.sqm
[2010/04/19 18:43:56 | 000,000,232 | -H– | M] () – E:\sqmdata11.sqm
[2010/04/20 04:12:01 | 000,000,232 | -H– | M] () – E:\sqmdata12.sqm
[2010/04/20 09:42:57 | 000,000,232 | -H– | M] () – E:\sqmdata13.sqm
[2010/04/22 05:53:22 | 000,000,232 | -H– | M] () – E:\sqmdata14.sqm
[2010/04/23 09:22:40 | 000,000,232 | -H– | M] () – E:\sqmdata15.sqm
[2010/04/24 17:36:07 | 000,000,232 | -H– | M] () – E:\sqmdata16.sqm
[2010/04/25 05:42:09 | 000,000,232 | -H– | M] () – E:\sqmdata17.sqm
[2010/04/25 10:38:16 | 000,000,232 | -H– | M] () – E:\sqmdata18.sqm
[2010/04/26 06:47:50 | 000,000,232 | -H– | M] () – E:\sqmdata19.sqm
[2010/04/26 11:32:00 | 000,000,244 | -H– | M] () – E:\sqmnoopt00.sqm
[2010/04/26 11:49:01 | 000,000,244 | -H– | M] () – E:\sqmnoopt01.sqm
[2010/04/26 11:51:48 | 000,000,244 | -H– | M] () – E:\sqmnoopt02.sqm
[2010/04/26 21:02:53 | 000,000,244 | -H– | M] () – E:\sqmnoopt03.sqm
[2010/04/27 17:57:11 | 000,000,244 | -H– | M] () – E:\sqmnoopt04.sqm
[2010/04/28 07:23:35 | 000,000,244 | -H– | M] () – E:\sqmnoopt05.sqm
[2010/04/28 23:29:09 | 000,000,244 | -H– | M] () – E:\sqmnoopt06.sqm
[2010/04/29 21:14:25 | 000,000,244 | -H– | M] () – E:\sqmnoopt07.sqm
[2010/04/30 08:33:07 | 000,000,244 | -H– | M] () – E:\sqmnoopt08.sqm
[2010/04/19 07:19:55 | 000,000,244 | -H– | M] () – E:\sqmnoopt09.sqm
[2010/04/19 16:03:29 | 000,000,244 | -H– | M] () – E:\sqmnoopt10.sqm
[2010/04/19 18:43:56 | 000,000,244 | -H– | M] () – E:\sqmnoopt11.sqm
[2010/04/20 04:12:01 | 000,000,244 | -H– | M] () – E:\sqmnoopt12.sqm
[2010/04/20 09:42:57 | 000,000,244 | -H– | M] () – E:\sqmnoopt13.sqm
[2010/04/22 05:53:22 | 000,000,244 | -H– | M] () – E:\sqmnoopt14.sqm
[2010/04/23 09:22:40 | 000,000,244 | -H– | M] () – E:\sqmnoopt15.sqm
[2010/04/24 17:36:07 | 000,000,244 | -H– | M] () – E:\sqmnoopt16.sqm
[2010/04/25 05:42:09 | 000,000,244 | -H– | M] () – E:\sqmnoopt17.sqm
[2010/04/25 10:38:16 | 000,000,244 | -H– | M] () – E:\sqmnoopt18.sqm
[2010/04/26 06:47:50 | 000,000,244 | -H– | M] () – E:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – E:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – E:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – E:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – E:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/10/17 10:26:37 | 000,000,067 | -HS- | M] () – E:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/09/05 05:00:00 | 000,016,384 | —- | M] (CANON INC.) – E:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDyf.DLL
[2003/09/05 05:00:00 | 000,048,128 | —- | M] (CANON INC.) – E:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPyf.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – E:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/03/15 16:32:10 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – E:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2003/06/18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – E:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – E:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/06/02 18:55:09 | 000,001,682 | -H– | M] () – E:\Documents and Settings\Les\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/10/17 11:14:59 | 000,094,208 | —- | M] () – E:\WINDOWS\system32\config\default.sav
[2007/10/17 11:14:59 | 000,634,880 | —- | M] () – E:\WINDOWS\system32\config\software.sav
[2007/10/17 11:14:59 | 000,905,216 | —- | M] () – E:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/10/25 05:31:03 | 000,000,272 | -HS- | M] () – E:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/04/07 11:53:22 | 000,000,119 | -HS- | M] () – E:\Documents and Settings\Les\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/10/17 10:31:18 | 000,000,079 | —- | M] () – E:\Documents and Settings\Les\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/10/09 16:27:51 | 000,576,512 | —- | M] (OldTimer Tools) – E:\Documents and Settings\Les\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/04/07 11:53:22 | 000,000,122 | -HS- | M] () – E:\Documents and Settings\Les\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/10/07 09:29:11 | 000,000,067 | -HS- | M] () – E:\Documents and Settings\Les\Cookies\desktop.ini
[2010/10/09 16:30:03 | 000,196,608 | -HS- | M] () – E:\Documents and Settings\Les\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-14 07:01:11

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> E:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 09/10/2010 16:30:51 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = E:\Documents and Settings\Les\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): E:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
Drive E: | 149.04 Gb Total Space | 115.18 Gb Free Space | 77.28% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HAYHOULL
Current User Name: Les
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" %*
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"E:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = E:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = E:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = E:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = E:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = E:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"E:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = E:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe" = E:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\HP Software Update\HPWUCli.exe" = E:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"E:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = E:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"E:\Program Files\Grisoft\AVG7\avginet.exe" = E:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe – File not found
"E:\Program Files\Grisoft\AVG7\avgamsvr.exe" = E:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe – File not found
"E:\Program Files\Grisoft\AVG7\avgcc.exe" = E:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe – File not found
"E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"E:\Program Files\Kontiki\KService.exe" = E:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service – File not found
"E:\Program Files\Java\jre6\bin\java.exe" = E:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"E:\Program Files\K-Lite Codec Pack\Filters\ac3config.exe" = E:\Program Files\K-Lite Codec Pack\Filters\ac3config.exe:*:Enabled:AC3Filter – ()
"E:\Program Files\Spotify\spotify.exe" = E:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – File not found
"E:\Program Files\Opera\opera.exe" = E:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – File not found
"E:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = E:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime Essentials – (Nero AG)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – File not found
"E:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = E:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"E:\Program Files\AVG\AVG9\avgemc.exe" = E:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"E:\Program Files\AVG\AVG9\avgupd.exe" = E:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"E:\Program Files\AVG\AVG9\avgnsx.exe" = E:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"E:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = E:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = E:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = E:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = E:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = E:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"E:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = E:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe" = E:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe – (Hewlett-Packard Development Co. L.P.)
"E:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = E:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"E:\Program Files\HP\HP Software Update\HPWUCli.exe" = E:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"E:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = E:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"E:\Program Files\Google\Google Earth\plugin\geplugin.exe" = E:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Disabled:Google Earth – (Google)
"E:\WINDOWS\explorer.exe" = E:\WINDOWS\explorer.exe:*:Enabled:Windows Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}" = Canon PhotoRecord
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = PhotoStitch
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = RemoteCapture Task 1.1
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3C349576-B3B4-6708-F73C-DC2932065357}" = BBC iPlayer Desktop
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = RAW Image Task 1.2
"{4C96958A-6562-4143-B820-FF4890D3B734}" = Camera Window DVC
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Camera Window DS
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Camera Support Core Library
"{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B28B351F-1232-46EA-85EF-B8EA91641033}" = Nero 7 Essentials
"{B34E4B72-37C6-4f79-A5B3-008EEFC6EA8B}" = PS_AIO_02_Software_min
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B46AC30C-22D2-4610-B041-1DA7BB29EB57}" = HP Photosmart All-In-One Software 9.0
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B7E5D642-E74E-40a4-B5C7-6AB6EE916814}" = PS_AIO_02_ProductContext
"{BAFFEF7F-08B3-45b3-B215-418175C4E9DD}" = c5200_Help
"{BC10649A-983B-494e-AD1F-DE0BF717D701}" = PS_AIO_02_Software
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C191BE7C-8542-4A61-973A-714EF76C5995}" = Logitech QuickCam Software
"{C708333C-B1B9-43be-B797-49FEC7A8D15B}" = C5200
"{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Camera Window MC
"{C7DD90E2-61F6-47F7-ADB3-8A61088F1F12}" = Sibelius Scorch (ActiveX Only)
"{C994D98C-293D-4825-958E-EB684B4D413F}" = MSN Toolbar
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D1E03284-66FD-4292-8239-504CEC5B0CC3}" = C5200_doccd
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E6CFBFB5-9232-410C-B353-AF6E614B2681}" = LightScribe System Software 1.10.16.1
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG9Uninstall" = AVG Free 9.0
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Belarc Advisor" = Belarc Advisor 8.1
"Brother's Keeper 6.2" = Brother's Keeper 6.2
"CAL" = Canon Camera Access Library
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CCleaner" = CCleaner
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{4C96958A-6562-4143-B820-FF4890D3B734}" = Canon Camera Window DVC for ZoomBrowser EX
"InstallShield_{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Canon Camera Support Core Library
"InstallShield_{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Canon Camera Window for ZoomBrowser EX
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.5.3 Basic
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Connections Drivers
"QcDrv" = Logitech® Camera Driver
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Visual Home" = Visual Home Deluxe version 1,1EUR
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 29/09/2010 04:17:56 | Computer Name = HAYHOULL | Source = MsiInstaller | ID = 11706
Description = Product: HPPhotosmartEssential – Error 1706. An installation package
for the product HPPhotosmartEssential cannot be found. Try the installation again
using a valid copy of the installation package 'HPPhotosmartEssential.msi'.

Error - 29/09/2010 04:23:16 | Computer Name = HAYHOULL | Source = MsiInstaller | ID = 11706
Description = Product: HPPhotosmartEssential – Error 1706. An installation package
for the product HPPhotosmartEssential cannot be found. Try the installation again
using a valid copy of the installation package 'HPPhotosmartEssential.msi'.

Error - 29/09/2010 04:25:04 | Computer Name = HAYHOULL | Source = MsiInstaller | ID = 11706
Description = Product: HPPhotosmartEssential – Error 1706. An installation package
for the product HPPhotosmartEssential cannot be found. Try the installation again
using a valid copy of the installation package 'HPPhotosmartEssential.msi'.

Error - 29/09/2010 04:45:26 | Computer Name = HAYHOULL | Source = MsiInstaller | ID = 11706
Description = Product: HPPhotosmartEssential – Error 1706. An installation package
for the product HPPhotosmartEssential cannot be found. Try the installation again
using a valid copy of the installation package 'HPPhotosmartEssential.msi'.

Error - 07/10/2010 04:36:41 | Computer Name = HAYHOULL | Source = Application Error | ID = 1000
Description = Faulting application extexport.exe, version 8.0.6001.18702, faulting
module sqlite3.dll, version 3.6.22.0, fault address 0x0001072b.

Error - 07/10/2010 04:36:54 | Computer Name = HAYHOULL | Source = Application Error | ID = 1001
Description = Fault bucket 1817646763.

Error - 08/10/2010 04:52:12 | Computer Name = HAYHOULL | Source = Application Error | ID = 1000
Description = Faulting application 0.832386874907151.exe, version 8.0.0.11, faulting
module unknown, version 0.0.0.0, fault address 0x32b1c623.

Error - 08/10/2010 04:52:12 | Computer Name = HAYHOULL | Source = Application Error | ID = 1000
Description = Faulting application 0.8921148239071034.exe, version 8.0.0.11, faulting
module unknown, version 0.0.0.0, fault address 0x32b1c623.

Error - 08/10/2010 05:22:29 | Computer Name = HAYHOULL | Source = MsiInstaller | ID = 11321
Description = Product: Adobe Reader 8.2.5 – Error 1321.The Installer has insufficient
privileges to modify the file E:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe.

Error - 08/10/2010 05:22:31 | Computer Name = HAYHOULL | Source = MsiInstaller | ID = 1024
Description = Product: Adobe Reader 8.2.5 - Update 'Adobe Reader 8.2.5 - CPSID_83708'
could not be installed. Error code 1603. Windows Installer can create logs to help
troubleshoot issues with installing software packages. Use the following link for
instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

[ System Events ]
Error - 08/10/2010 23:55:13 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:13 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 08/10/2010 23:55:14 | Computer Name = HAYHOULL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 09/10/2010 07:01:03 | Computer Name = HAYHOULL | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
Sorry, I couldn't complete last night as machine crashed and I had to go up to the hall as there was a function on up there. I have been up since 4 this morning trying to get this report but each time the machine crashes, this is the 3rd time . It is now 7.23 am and I am going back to bed but will try again in a couple of hours unless you can sugest that I try running something else??. Regards Les
Leave GMER and run this instead.

Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers and Stealth Code,
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning, it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

sorry tried to run it again but it crashed then had to go to inlaws for breakfast and crashed again but have downloaded Rootkit Unhooker and reports follow. Sorry but have to go to sister in law for lunch now, but thanks a lot for your help. be back later on. Regards Les ps. sorry I realised after I left that there was no Hijack This log RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xB9719000 E:\WINDOWS\system32\DRIVERS\nv4_mini.sys 6856704 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 163.71 ) 0xBF012000 E:\WINDOWS\System32\nv4_disp.dll 5783552 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 163.71 ) 0xB6754000 E:\WINDOWS\system32\drivers\Lvckap.sys 2174976 bytes (-, -) 0x804D7000 E:\WINDOWS\system32\ntkrnlpa.exe 2150400 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2150400 bytes 0x804D7000 RAW 2150400 bytes 0x804D7000 WMIxWDM 2150400 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 E:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xB6EA1000 E:\WINDOWS\system32\drivers\sthda.sys 1015808 bytes (SigmaTel, Inc., NDRC) 0xB6967000 E:\WINDOWS\system32\DRIVERS\LV302AV.SYS 917504 bytes (Logitech Inc., Logitech QuickCam Driver) 0xB9E43000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB9647000 E:\WINDOWS\system32\DRIVERS\ar5211.sys 466944 bytes (Atheros Communications, Inc., Driver for Atheros AR5001 Wireless Network Adapter) 0xB6647000 E:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB959E000 E:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xB6DF1000 E:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xB5C88000 E:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 E:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xB53E4000 E:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB6D31000 E:\WINDOWS\System32\Drivers\avgtdix.sys 237568 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0xB6D91000 E:\WINDOWS\system32\DRIVERS\tcpip6.sys 229376 bytes (Microsoft Corporation, IPv6 driver) 0xB6613000 E:\WINDOWS\System32\Drivers\avgldx86.sys 212992 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xB5F87000 E:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB9E16000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB47FD000 E:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xB66DF000 E:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xB96DD000 E:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xB672C000 E:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xB6D6B000 E:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xB6E7D000 E:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB96B9000 E:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB9624000 E:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xB670A000 E:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806E4000 ACPI_HAL 134400 bytes 0x806E4000 E:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB9EF9000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB9DFC000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB9F31000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xB65AD000 E:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB9F19000 E:\WINDOWS\System32\Drivers\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xB9ED0000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB960D000 E:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xB56FB000 E:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB9705000 E:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xB6E4A000 E:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF000000 E:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB9EE7000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB95FC000 E:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xBA108000 E:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xBA308000 E:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xBA1D8000 E:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBA318000 E:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xB57B8000 E:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xBA258000 E:\WINDOWS\system32\drivers\usbaudio.sys 61440 bytes (Microsoft Corporation, USB Audio Class Driver) 0xBA1E8000 E:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xBA238000 E:\WINDOWS\system32\drivers\lvusbsta.sys 57344 bytes (Logitech Inc., USB Statistic Driver) 0xBA0E8000 E:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xB5D27000 E:\WINDOWS\system32\DRIVERS\HPZid412.sys 53248 bytes (HP, IEEE-1284.4-1999 Driver (Windows 2000)) 0xBA158000 E:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xBA248000 E:\WINDOWS\system32\DRIVERS\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0) 0xBA0C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA178000 E:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xBA278000 E:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xBA2F8000 E:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA168000 E:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xBA1B8000 E:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xBA198000 E:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xBA0D8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xBA228000 E:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xBA2E8000 E:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xBA208000 E:\WINDOWS\system32\drivers\ip6fw.sys 36864 bytes (Microsoft Corporation, IPv6 Windows Firewall Driver) 0xBA188000 E:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xBA268000 E:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xB5738000 E:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xBA218000 E:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xBA338000 cercsr6.sys 32768 bytes (Adaptec, Inc., DELL CERC SATA1.5/6ch Miniport Driver) 0xBA478000 E:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xBA480000 E:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xBA410000 E:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA460000 E:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xBA328000 E:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBA448000 E:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver) 0xBA390000 E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xBA488000 E:\WINDOWS\System32\Drivers\avgmfx86.sys 24576 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0xBA4A0000 E:\WINDOWS\system32\DRIVERS\HPZius12.sys 24576 bytes (HP, 1284.4<->Usb Datalink Driver (Windows 2000)) 0xBA430000 E:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBA438000 E:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xBA408000 E:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xBA468000 E:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBA498000 E:\WINDOWS\system32\drivers\LVPrcMon.sys 20480 bytes (-, -) 0xBA470000 E:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xBA420000 E:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xBA428000 E:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xBA418000 E:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xBA4B0000 E:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xB6268000 E:\WINDOWS\system32\DRIVERS\HPZipr12.sys 16384 bytes (HP, IEEE-1284.4-1999 Print Class Driver) 0xBA554000 E:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xBA580000 E:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xB622C000 E:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB6258000 E:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver) 0xBA4B8000 E:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xB6DD1000 E:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xBA544000 E:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xBA548000 E:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xBA574000 E:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB9DBB000 E:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xBA56C000 E:\WINDOWS\system32\DRIVERS\tunmp.sys 12288 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0xBA558000 E:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0xBA5EE000 E:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xBA62C000 E:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xBA5EC000 E:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xBA5A8000 E:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xBA5F4000 E:\WINDOWS\system32\DRIVERS\lv302af.sys 8192 bytes (Logitech Inc., Audio filter for Express Plus) 0xBA5F0000 E:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xBA5F2000 E:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xBA5DC000 E:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xBA5EA000 E:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xBA5AA000 E:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA736000 E:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA7EB000 E:\WINDOWS\System32\Drivers\BANTExt.sys 4096 bytes 0xBA74C000 E:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xBA74A000 E:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ==============================================
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.72,93.188.166.222
    O30 - LSA: Authentication Packages - (E:\WINDOWS\system32\ljJBtstR) - File not found
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )







Next

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi Mowman,
have run OTL and attached report following.
eventually downloaded ComboFix to dektop
tried disabling AVG antivirus software but machine was hanging for a 15 or 20 minutes after I tried to use See this Link so used ComboFix anyway and have attached the log after OTL log. Hopefully it worked OK as I seem to be able to get into the network a lot quicker ie almost instantanious.
Regards
Les

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:E:\WINDOWS\system32\ljJBtstR deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
E:\Documents and Settings\Les\Desktop\cmd.bat deleted successfully.
E:\Documents and Settings\Les\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41661 bytes

User: Les
->Temp folder emptied: 1541534 bytes
->Temporary Internet Files folder emptied: 18805005 bytes
->Java cache emptied: 106605 bytes
->Google Chrome cache emptied: 593984 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 45331 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 54184 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 96255 bytes

User: test
->Temp folder emptied: 1968 bytes
->Temporary Internet Files folder emptied: 16679716 bytes
->Java cache emptied: 13690471 bytes
->Flash cache emptied: 41 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2195181 bytes
%systemroot%\System32 .tmp files removed: 3135488 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 458752 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 51222580 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34269 bytes
RecycleBin emptied: 405882 bytes

Total Files Cleaned = 104.00 mb


OTL by OldTimer - Version 3.2.14.1 log created on 10102010_190612

Files\Folders moved on Reboot…
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\PK356XHV\default[1].htm moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\O81TDCTE\ie8[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\O81TDCTE\layout[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\FMUWA7LS\button[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\FMUWA7LS\like[1].htm moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\FD68J5ZL\index[1].htm moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\FD68J5ZL\modules[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\DTW8RW83\fullie[1].js moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\DTW8RW83\print[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\C8DRDOY0\content[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\C8DRDOY0\ibank[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\C8DRDOY0\theme[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\12ZVOFC1\button[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\12ZVOFC1\content[1].css moved successfully.
E:\Documents and Settings\Les\Local Settings\Temporary Internet Files\Content.IE5\12ZVOFC1\iframe[5].htm moved successfully.

Registry entries deleted on Reboot…

ComboFix 10-10-09.06 - Les 10/10/2010 20:24:56.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2046.1570 [GMT 1:00]
Running from: e:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

e:\documents and settings\Les\Application Data\Atsuoq
e:\documents and settings\Les\Application Data\Atsuoq\iman.exe
e:\documents and settings\Les\Local Settings\Application Data\{23964BDD-1C60-4B33-BB5F-090CF4464097}
e:\documents and settings\Les\Local Settings\Application Data\{23964BDD-1C60-4B33-BB5F-090CF4464097}\chrome\content\_cfg.js
e:\documents and settings\Les\Local Settings\Application Data\{23964BDD-1C60-4B33-BB5F-090CF4464097}\chrome\content\overlay.xul
e:\documents and settings\Les\Local Settings\Application Data\{23964BDD-1C60-4B33-BB5F-090CF4464097}\install.rdf
e:\windows\system32\AutoRun.inf
e:\windows\system32\lowsec
e:\windows\system32\net.net
e:\windows\system32\pqpqYJjl.ini
e:\windows\system32\pqpqYJjl.ini2
e:\windows\system32\RtstBJjl.ini
e:\windows\system32\RtstBJjl.ini2

.
((((((((((((((((((((((((( Files Created from 2010-09-10 to 2010-10-10 )))))))))))))))))))))))))))))))
.

2010-10-10 18:06 . 2010-10-10 18:06 ——– d—–w- E:\_OTL
2010-10-04 06:15 . 2010-10-04 06:15 ——– d—–w- e:\program files\BBC iPlayer Desktop
2010-09-23 10:08 . 2010-09-23 10:08 ——– d—–w- e:\documents and settings\Les\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 09:25 2117704 —-a-w- e:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2007-09-17 8491008]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-17 08:11 12536 —-a-w- e:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=e:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=e:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=e:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]

[HKLM\~\startupfolder\E:^Documents and Settings^Les^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk]
path=e:\documents and settings\Les\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
backup=e:\windows\pss\BBC iPlayer Desktop.lnkStartup

[HKLM\~\startupfolder\E:^Documents and Settings^Les^Start Menu^Programs^Startup^OpenOffice.org 2.2.lnk]
path=e:\documents and settings\Les\Start Menu\Programs\Startup\OpenOffice.org 2.2.lnk
backup=e:\windows\pss\OpenOffice.org 2.2.lnkStartup

[HKLM\~\startupfolder\E:^Documents and Settings^Les^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=e:\documents and settings\Les\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=e:\windows\pss\OpenOffice.org 3.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
e:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2009-08-13 15:51 177440 —-a-w- e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 10:19 207360 —-a-w- e:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-10-05 08:54 2067808 —-a-w- e:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 17:05 143360 —-a-w- e:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- e:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 —-a-w- e:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-08-20 09:54 150016 —-a-w- e:\program files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-11-12 15:19 67128 —-a-w- e:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-09-19 20:48 455968 —-a-w- e:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
2005-12-07 10:26 489472 —-a-w- e:\program files\Logitech\Video\CameraAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraService(E)]
2004-11-01 17:22 262144 —-a-w- e:\windows\system32\ElkCtrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
2005-12-07 10:33 73728 —-a-w- e:\program files\Logitech\Video\InstallHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2005-12-09 15:32 225280 —-a-w- e:\windows\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 14:40 155648 —-a-w- e:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2007-09-17 00:07 8491008 —-a-w- e:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2007-09-17 00:07 81920 —-a-w- e:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-09-17 00:07 1626112 —-a-w- e:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2008-02-27 16:36 32768 ——r- e:\windows\system32\rmctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2005-03-22 16:20 339968 —-a-w- e:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 04:17 149280 —-a-w- e:\program files\Java\jre6\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"e:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"e:\\Program Files\\K-Lite Codec Pack\\Filters\\ac3config.exe"=
"e:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"e:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"e:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"e:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"e:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG Free AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [04/07/2008 08:09 216400]
R1 AvgTdiX;AVG Free Network Redirector;e:\windows\system32\drivers\avgtdix.sys [04/07/2008 08:09 243024]
R2 avg9emc;AVG Free E-mail Scanner;e:\program files\AVG\AVG9\avgemc.exe [17/07/2010 09:11 921952]
R2 avg9wd;AVG Free WatchDog;e:\program files\AVG\AVG9\avgwdsvc.exe [17/07/2010 09:11 308136]
R2 Iprip;RIP Listener;e:\windows\System32\svchost.exe -k netsvcs [04/08/2004 11:00 14336]
S2 gupdate;Google Update Service (gupdate);e:\program files\Google\Update\GoogleUpdate.exe [08/07/2009 05:06 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;e:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [16/06/2010 06:36 430152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-09-19 20:46 451872 —-a-w- e:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-10-10 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 04:06]

2010-10-10 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 04:06]

2010-10-10 e:\windows\Tasks\User_Feed_Synchronization-{E6EC4259-0510-4250-8CF4-085C3D4A1E53}.job
- e:\windows\system32\msfeedssync.exe [2006-10-17 03:31]

2010-10-10 e:\windows\Tasks\User_Feed_Synchronization-{EA788DCF-2E19-40DA-AF9C-799E555C33F7}.job
- e:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
Trusted Zone: live.com\login
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - e:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - e:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {62415890-4985-0825-2508-23487C2A845F} - hxxp://85.211.235.108:8150/en/cab/ipcamera.cab
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Adobe ARM - e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MSConfigStartUp-Adobe Reader Speed Launcher - e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-Google Update - e:\documents and settings\Les\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-MsnMsgr - e:\program files\Windows Live\Messenger\msnmsgr.exe
MSConfigStartUp-QuickTime Task - e:\program files\QuickTime\qttask.exe
MSConfigStartUp-TkBellExe - e:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-{2406EC9B-4C4D-C9DC-A879-8F5BCE7522E3} - e:\documents and settings\Les\Application Data\Atsuoq\iman.exe


.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-10-10 20:31:40
ComboFix-quarantined-files.txt 2010-10-10 19:31

Pre-Run: 123,667,574,784 bytes free
Post-Run: 123,628,298,240 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 32A533565D4C2251AE321662AB3493A4
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.






Next

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
first run of MalwareBytes AntiMalware was fine following updatades but there was nothing to check and there was no option to REMOVE SELECTED so there was no second run but log is attached followed by report from Eset Online Scanner, hope this is of some use to you. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4794 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11/10/2010 16:38:11 mbam-log-2010-10-11 (16-38-11).txt Scan type: Quick scan Objects scanned: 140946 Time elapsed: 5 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Report of Eset Online Scanner follows ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=f6ef3df9a8c7b74690bbda82764b031b # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-10-11 04:29:52 # local_time=2010-10-11 05:29:52 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777175 100 0 10146109 10146109 0 0 # compatibility_mode=8192 67108863 100 0 335 335 0 0 # scanned=72776 # found=10 # cleaned=0 # scan_time=1901 E:\Qoobox\Quarantine\E\Documents and Settings\Les\Application Data\Atsuoq\iman.exe.vir a variant of Win32/Kryptik.HGM trojan 00000000000000000000000000000000 I E:\Qoobox\Quarantine\E\Documents and Settings\Les\Local Settings\Application Data\{23964BDD-1C60-4B33-BB5F-090CF4464097}\chrome\content\overlay.xul.vir probably a variant of Win32/Agent.NVQFFQI trojan 00000000000000000000000000000000 I E:\Qoobox\Quarantine\E\WINDOWS\system32\net.net.vir Win32/TrojanClicker.Punad.AA trojan 00000000000000000000000000000000 I E:\Qoobox\Quarantine\E\WINDOWS\system32\pqpqYJjl.ini.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I E:\Qoobox\Quarantine\E\WINDOWS\system32\pqpqYJjl.ini2.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I E:\Qoobox\Quarantine\E\WINDOWS\system32\RtstBJjl.ini.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I E:\Qoobox\Quarantine\E\WINDOWS\system32\RtstBJjl.ini2.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I E:\System Volume Information\_restore{3A5A593C-0C3F-47BA-AC10-2A1133F2EFDC}\RP947\A0142183.exe a variant of Win32/Kryptik.HGM trojan 00000000000000000000000000000000 I E:\System Volume Information\_restore{3A5A593C-0C3F-47BA-AC10-2A1133F2EFDC}\RP947\A0142185.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I E:\System Volume Information\_restore{3A5A593C-0C3F-47BA-AC10-2A1133F2EFDC}\RP947\A0142186.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I
Hi, report follows, Computer is running fine now, no holdups whatsoever.

OTL logfile created on: 11/10/2010 23:30:44 - Run 4
OTL by OldTimer - Version 3.2.14.1 Folder = E:\Documents and Settings\Les\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): E:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
Drive E: | 149.04 Gb Total Space | 115.09 Gb Free Space | 77.22% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HAYHOULL
Current User Name: Les
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - E:\Documents and Settings\Les\Desktop\OTL.exe (OldTimer Tools)
PRC - E:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - E:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - E:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
PRC - E:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - e:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - E:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - E:\Documents and Settings\Les\Desktop\OTL.exe (OldTimer Tools)
MOD - E:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - E:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll File not found
SRV - (AppMgmt) – E:\WINDOWS\System32\appmgmts.dll File not found
SRV - (avg9emc) – E:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – E:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – E:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (ACDaemon) – E:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SNMP) – E:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
SRV - (p2pgasvc) – E:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Iprip) – E:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
SRV - (CCALib8) – E:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (LVPrcSrv) – e:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (SimpTcp) – E:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
SRV - (LPDSVC) – E:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (USBAAPL) – E:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (catchme) – E:\DOCUME~1\Les\LOCALS~1\Temp\catchme.sys File not found
DRV - (AvgTdiX) – E:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – E:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – E:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Tcpip6) – E:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – E:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – E:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (BANTExt) – E:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (nv) – E:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (lvmvdrv) – E:\WINDOWS\system32\drivers\LVMVdrv.sys ()
DRV - (LVPrcMon) – E:\WINDOWS\system32\drivers\LVPrcMon.sys ()
DRV - (Lvckap) – E:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (PID_08A0) QuickCam IM(PID_08A0) – E:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – E:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – E:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (STHDA) – E:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AR5211) – E:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: E:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/23 11:54:01 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/10/10 20:30:01 | 000,000,027 | —- | M]) - E:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - E:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - E:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - E:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - E:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] E:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] E:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - E:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O15 - HKCU\..Trusted Domains: live.com ([login] http in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {62415890-4985-0825-2508-23487C2A845F} http://85.211.235.108:8150/en/cab/ipcamera.cab (IPCamera Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/m3/photoup…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} http://update.hpphoto.com/download/HPSWUpdate.ocx (CUpdateCtl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 192.168.5.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - E:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - E:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - E:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: E:\Documents and Settings\Les\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: E:\Documents and Settings\Les\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/11 16:52:59 | 000,000,000 | —D | C] – E:\WINDOWS\LastGood
[2010/10/11 16:52:57 | 000,000,000 | —D | C] – E:\Program Files\ESET
[2010/10/10 20:51:36 | 000,000,000 | -HSD | C] – E:\RECYCLER
[2010/10/10 20:18:48 | 000,000,000 | RHSD | C] – E:\cmdcons
[2010/10/10 20:15:31 | 000,212,480 | —- | C] (SteelWerX) – E:\WINDOWS\SWXCACLS.exe
[2010/10/10 20:15:31 | 000,161,792 | —- | C] (SteelWerX) – E:\WINDOWS\SWREG.exe
[2010/10/10 20:15:31 | 000,136,704 | —- | C] (SteelWerX) – E:\WINDOWS\SWSC.exe
[2010/10/10 20:15:31 | 000,031,232 | —- | C] (NirSoft) – E:\WINDOWS\NIRCMD.exe
[2010/10/10 20:10:12 | 000,000,000 | —D | C] – E:\WINDOWS\ERDNT
[2010/10/10 20:05:24 | 000,000,000 | —D | C] – E:\Qoobox
[2010/10/10 19:06:12 | 000,000,000 | —D | C] – E:\_OTL
[2010/10/10 09:08:11 | 000,576,512 | —- | C] (OldTimer Tools) – E:\Documents and Settings\Les\Desktop\OTL.exe
[2010/10/05 15:49:08 | 000,000,000 | RH-D | C] – E:\Documents and Settings\Les\Recent
[2010/10/04 07:15:53 | 000,000,000 | —D | C] – E:\Program Files\BBC iPlayer Desktop
[2010/09/23 11:08:18 | 000,000,000 | —D | C] – E:\Documents and Settings\Les\Local Settings\Application Data\Mozilla

========== Files - Modified Within 30 Days ==========

[2010/10/11 23:30:00 | 000,000,418 | -H– | M] () – E:\WINDOWS\tasks\User_Feed_Synchronization-{EA788DCF-2E19-40DA-AF9C-799E555C33F7}.job
[2010/10/11 22:33:00 | 000,000,878 | —- | M] () – E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/11 16:12:42 | 000,000,418 | -H– | M] () – E:\WINDOWS\tasks\User_Feed_Synchronization-{E6EC4259-0510-4250-8CF4-085C3D4A1E53}.job
[2010/10/11 08:56:28 | 065,897,506 | —- | M] () – E:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/10/11 08:53:17 | 000,000,874 | —- | M] () – E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/11 08:52:12 | 000,000,006 | -H– | M] () – E:\WINDOWS\tasks\SA.DAT
[2010/10/11 08:52:10 | 000,002,048 | –S- | M] () – E:\WINDOWS\bootstat.dat
[2010/10/11 07:57:55 | 004,980,736 | —- | M] () – E:\Documents and Settings\Les\ntuser.dat
[2010/10/10 20:34:00 | 000,000,178 | -HS- | M] () – E:\Documents and Settings\Les\ntuser.ini
[2010/10/10 20:33:51 | 000,000,585 | —- | M] () – E:\WINDOWS\win.ini
[2010/10/10 20:33:51 | 000,000,227 | —- | M] () – E:\WINDOWS\system.ini
[2010/10/10 20:30:01 | 000,000,027 | —- | M] () – E:\WINDOWS\System32\drivers\etc\hosts
[2010/10/10 20:18:55 | 000,000,327 | RHS- | M] () – E:\boot.ini
[2010/10/10 19:16:39 | 003,876,688 | R— | M] () – E:\Documents and Settings\Les\Desktop\ComboFix.exe
[2010/10/10 13:55:28 | 000,133,632 | —- | M] () – E:\Documents and Settings\Les\Desktop\RKUnhookerLE.EXE
[2010/10/10 09:08:11 | 000,576,512 | —- | M] (OldTimer Tools) – E:\Documents and Settings\Les\Desktop\OTL.exe
[2010/10/04 07:15:54 | 000,000,750 | —- | M] () – E:\Documents and Settings\All Users\Desktop\BBC iPlayer Desktop.lnk
[2010/09/26 11:02:39 | 000,001,925 | —- | M] () – E:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/23 11:08:21 | 000,000,000 | —- | M] () – E:\WINDOWS\nsreg.dat
[2010/09/21 09:17:37 | 000,002,077 | —- | M] () – E:\Documents and Settings\Les\default.pls
[2010/09/21 09:17:05 | 000,000,069 | —- | M] () – E:\WINDOWS\NeroDigital.ini
[2010/09/21 08:55:00 | 000,084,480 | —- | M] () – E:\Documents and Settings\Les\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2010/10/10 20:30:08 | 000,000,734 | —- | C] () – E:\Documents and Settings\Les\Desktop\Brother's Keeper 6.lnk
[2010/10/10 20:18:55 | 000,000,210 | —- | C] () – E:\Boot.bak
[2010/10/10 20:18:51 | 000,260,272 | RHS- | C] () – E:\cmldr
[2010/10/10 20:15:31 | 000,256,512 | —- | C] () – E:\WINDOWS\PEV.exe
[2010/10/10 20:15:31 | 000,098,816 | —- | C] () – E:\WINDOWS\sed.exe
[2010/10/10 20:15:31 | 000,080,412 | —- | C] () – E:\WINDOWS\grep.exe
[2010/10/10 20:15:31 | 000,077,312 | —- | C] () – E:\WINDOWS\MBR.exe
[2010/10/10 20:15:31 | 000,068,096 | —- | C] () – E:\WINDOWS\zip.exe
[2010/10/10 19:16:39 | 003,876,688 | R— | C] () – E:\Documents and Settings\Les\Desktop\ComboFix.exe
[2010/10/10 13:55:28 | 000,133,632 | —- | C] () – E:\Documents and Settings\Les\Desktop\RKUnhookerLE.EXE
[2010/10/04 07:15:23 | 000,000,750 | —- | C] () – E:\Documents and Settings\All Users\Desktop\BBC iPlayer Desktop.lnk
[2010/09/26 11:02:39 | 000,001,925 | —- | C] () – E:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/23 11:08:21 | 000,000,000 | —- | C] () – E:\WINDOWS\nsreg.dat
[2010/01/31 11:59:40 | 000,003,840 | —- | C] () – E:\WINDOWS\System32\drivers\BANTExt.sys
[2009/09/19 06:55:10 | 000,000,031 | -H– | C] () – E:\WINDOWS\UKCpInfo.sys
[2009/02/05 09:30:49 | 000,000,000 | —- | C] () – E:\WINDOWS\OpPrintServer.INI
[2008/10/17 07:40:44 | 000,000,000 | —- | C] () – E:\WINDOWS\regclear.INI
[2008/05/19 09:59:12 | 000,027,048 | —- | C] () – E:\WINDOWS\System32\drivers\mbamcatchme.sys
[2008/04/09 06:53:40 | 000,000,185 | —- | C] () – E:\WINDOWS\System32\MRT.INI
[2008/03/24 17:01:06 | 000,000,179 | —- | C] () – E:\WINDOWS\BTW.INI
[2008/03/07 11:03:21 | 000,000,376 | —- | C] () – E:\WINDOWS\ODBC.INI
[2008/03/02 08:19:01 | 000,036,864 | R— | C] () – E:\WINDOWS\System32\ctrldll.dll
[2007/12/05 15:51:08 | 000,000,000 | —- | C] () – E:\WINDOWS\hpqEmlSz.INI
[2007/12/01 09:31:40 | 000,110,080 | —- | C] () – E:\WINDOWS\System32\w32mkrc.dll
[2007/11/27 13:05:53 | 000,016,719 | —- | C] () – E:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/11/16 16:41:57 | 001,559,040 | —- | C] () – E:\WINDOWS\System32\xvidcore.dll
[2007/11/05 20:18:25 | 000,013,126 | R— | C] () – E:\WINDOWS\System32\lvcoinst.ini
[2007/11/05 20:15:45 | 000,000,719 | R— | C] () – E:\WINDOWS\System32\InstExec.ini
[2007/10/24 15:47:56 | 000,084,480 | —- | C] () – E:\Documents and Settings\Les\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/23 09:25:27 | 000,006,656 | —- | C] () – E:\WINDOWS\System32\CNMVSyf.DLL
[2007/10/20 18:01:34 | 000,000,069 | —- | C] () – E:\WINDOWS\NeroDigital.ini
[2007/09/17 01:07:00 | 001,703,936 | —- | C] () – E:\WINDOWS\System32\nvwdmcpl.dll
[2007/09/17 01:07:00 | 001,478,656 | —- | C] () – E:\WINDOWS\System32\nview.dll
[2007/09/17 01:07:00 | 001,019,904 | —- | C] () – E:\WINDOWS\System32\nvwimg.dll
[2007/09/17 01:07:00 | 000,466,944 | —- | C] () – E:\WINDOWS\System32\nvshell.dll
[2007/09/17 01:07:00 | 000,286,720 | —- | C] () – E:\WINDOWS\System32\nvnt4cpl.dll
[2005/12/09 16:37:42 | 002,400,256 | —- | C] () – E:\WINDOWS\System32\drivers\LVMVdrv.sys
[2005/12/09 16:37:42 | 000,016,768 | —- | C] () – E:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005/12/09 16:35:54 | 002,174,464 | —- | C] () – E:\WINDOWS\System32\drivers\Lvckap.sys
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – E:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – E:\WINDOWS\System32\Iyvu9_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> E:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)












Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.








Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.









[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 21 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 21 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u21 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.








Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI