This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

please help remove this trojan

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 30/10/2010 18:13:31 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Lisa\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148.89 Gb Total Space | 90.39 Gb Free Space | 60.71% Space Free | Partition Type: NTFS
Drive E: | 147.73 Gb Total Space | 142.46 Gb Free Space | 96.43% Space Free | Partition Type: NTFS

Computer Name: LISA-PC | User Name: Lisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Lisa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10k_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Mail\WinMail.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Windows\System32\brss01a.exe (brother Industries Ltd)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Lisa\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\vbscript.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wmiutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wbemsvc.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wbemprox.dll (Microsoft Corporation)
MOD - C:\Windows\System32\mssprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\fastprox.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\GdiPlus.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wbemdisp.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sxs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbemcomn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (GoogleDesktopManager-022208-143751) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (SmartFaceVWatchSrv) – C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
SRV - (TempoMonitoringService) – C:\Program Files\Toshiba TEMPRO\TempoSVC.exe (Toshiba Europe GmbH)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (jswpsapi) – C:\Program Files\Jumpstart\jswpsapi.exe (Atheros Communications, Inc.)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (Brother XP spl Service) – C:\Windows\System32\brsvc01a.exe (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (RapportCerberus_19917) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\Windows\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (RapportBuka) – C:\Windows\System32\drivers\RapportBuka.sys (Trusteer Ltd.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (jswpslwf) – C:\Windows\System32\drivers\jswpslwf.sys (Atheros Communications, Inc.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…A&bmod=TSEA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/10/30 11:21:36 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions
[2009/09/10 21:18:45 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/10/30 11:21:38 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/10/23 19:36:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/10/23 19:35:39 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/10/22 21:20:43 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [cfFncEnabler.exe] File not found
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Lisa\Pictures\Gabanna\DSC00146a.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lisa\Pictures\Gabanna\DSC00146a.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/10/30 16:21:26 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2010/10/29 19:05:49 | 000,017,744 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/10/29 19:05:48 | 000,165,584 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/10/29 19:05:48 | 000,046,672 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/10/29 19:05:48 | 000,023,376 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/10/29 19:05:47 | 000,050,768 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/10/29 19:05:32 | 000,038,848 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2010/10/29 19:05:31 | 000,167,592 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2010/10/29 19:05:17 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/10/29 19:05:17 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/10/27 10:20:23 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2010/10/27 10:20:20 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/27 10:20:19 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/23 19:36:04 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/23 19:36:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/23 19:36:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/10/23 19:35:30 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/10/23 12:36:08 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2010/10/23 10:39:21 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2010/10/23 10:38:01 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Local\Windows Live
[2010/10/22 22:15:09 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/10/22 22:01:26 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/22 22:01:24 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/10/22 22:01:24 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/22 21:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/10/22 21:24:18 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/10/22 21:24:18 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Local\temp
[2010/10/22 19:35:00 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/10/21 13:23:57 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010/10/21 11:41:36 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2010/10/20 18:51:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/10/20 18:51:45 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/10/18 16:26:06 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Local\Mozilla
[2010/10/18 16:25:54 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/10/17 23:59:02 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Roaming\AVG
[2010/10/17 23:56:19 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/10/15 11:04:52 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Roaming\PeerNetworking
[2010/10/15 10:59:17 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2010/10/15 10:59:05 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar(57)
[2010/10/15 10:41:12 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/10/13 11:08:33 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/13 11:07:28 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/13 11:06:28 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2010/10/13 11:06:20 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/13 11:06:15 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/13 11:06:15 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/13 11:06:15 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/13 11:06:13 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/13 11:06:13 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/13 11:06:13 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/13 11:06:12 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/13 11:06:12 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/13 11:06:12 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/13 11:06:12 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/13 11:06:12 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/13 11:06:12 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/13 11:06:12 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/13 11:06:12 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/13 11:06:12 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/13 11:06:12 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/13 11:06:11 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/13 11:06:07 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/13 11:06:06 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/13 11:06:03 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/13 11:05:58 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/03 23:43:44 | 000,059,240 | —- | C] (Trusteer Ltd.) – C:\Windows\System32\drivers\RapportKELL.sys

========== Files - Modified Within 30 Days ==========

[2010/10/30 17:27:01 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/30 17:17:27 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/30 17:17:27 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/30 16:21:30 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2010/10/30 11:22:07 | 000,604,520 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/10/30 11:22:07 | 000,107,796 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/10/30 11:20:15 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/30 11:17:06 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/30 11:17:02 | 3082,809,344 | -HS- | M] () – C:\hiberfil.sys
[2010/10/29 19:07:39 | 000,001,976 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/10/29 19:07:39 | 000,001,960 | —- | M] () – C:\Users\Lisa\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/29 19:05:49 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/10/29 19:05:47 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/10/28 23:38:30 | 000,013,259 | —- | M] () – C:\Users\Lisa\Documents\beef Greek Stifado.docx
[2010/10/28 23:35:33 | 000,433,487 | —- | M] () – C:\Users\Lisa\Documents\greek beef stifado.docx
[2010/10/24 19:32:19 | 000,406,520 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/23 19:35:37 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/10/23 19:35:37 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/23 19:35:37 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/23 19:35:37 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/10/22 22:01:28 | 000,000,823 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 21:20:43 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/10/19 11:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/10/18 16:26:11 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010/10/15 11:05:00 | 000,027,582 | —- | M] () – C:\Users\Lisa\AppData\Roaming\UserTile.png
[2010/10/03 23:43:44 | 000,059,240 | —- | M] (Trusteer Ltd.) – C:\Windows\System32\drivers\RapportKELL.sys
[2010/10/01 14:42:48 | 000,002,627 | —- | M] () – C:\Users\Lisa\Desktop\Microsoft Office Word 2007.lnk

========== Files Created - No Company Name ==========

[2010/10/29 19:07:39 | 000,001,976 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/10/29 19:07:39 | 000,001,960 | —- | C] () – C:\Users\Lisa\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/29 19:05:49 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/10/28 23:38:29 | 000,013,259 | —- | C] () – C:\Users\Lisa\Documents\beef Greek Stifado.docx
[2010/10/28 23:35:32 | 000,433,487 | —- | C] () – C:\Users\Lisa\Documents\greek beef stifado.docx
[2010/10/22 22:01:28 | 000,000,823 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/18 16:26:11 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/10/18 16:17:22 | 3082,809,344 | -HS- | C] () – C:\hiberfil.sys
[2010/10/15 11:05:00 | 000,027,582 | —- | C] () – C:\Users\Lisa\AppData\Roaming\UserTile.png
[2010/07/01 16:20:20 | 000,000,470 | —- | C] () – C:\Windows\{D084B1A9-153B-409D-AEBF-C40FCEF925EA}_WiseFW.ini
[2010/05/06 10:27:06 | 000,076,407 | —- | C] () – C:\Users\Lisa\AppData\Roaming\Smiley.ico
[2010/02/19 21:36:00 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/02/02 15:00:08 | 000,010,766 | -HS- | C] () – C:\Users\Lisa\AppData\Local\p30Wm5mg6k3hg
[2009/10/07 11:51:19 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2009/10/07 11:51:19 | 000,000,030 | —- | C] () – C:\Windows\System32\brss01a.ini
[2009/10/07 11:51:19 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2009/09/10 19:49:48 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/31 22:13:30 | 000,010,752 | —- | C] () – C:\Users\Lisa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/31 14:48:31 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2009/08/31 14:48:31 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2009/08/31 14:48:31 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2009/08/31 14:48:31 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2008/08/07 17:37:59 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/08/07 17:37:59 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/08/07 17:37:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/08/07 17:37:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/08/07 17:37:59 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/08/07 17:37:59 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2008/08/07 17:29:47 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2008/08/07 17:15:11 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1502.dll
[2008/08/07 16:31:36 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/04/24 18:43:50 | 000,057,344 | —- | C] () – C:\Windows\System32\SmartFaceVCapt.dll
[2008/04/24 18:42:44 | 000,479,232 | —- | C] () – C:\Windows\System32\SmartFaceVCP.dll
[2008/04/24 18:25:46 | 006,701,056 | —- | C] () – C:\Windows\System32\FaceHI.dll
[2008/04/24 18:25:46 | 000,995,328 | —- | C] () – C:\Windows\System32\FaceRec.dll
[2008/04/24 18:25:46 | 000,126,976 | —- | C] () – C:\Windows\System32\SmartFaceVCtrl.dll
[2008/04/24 18:23:58 | 000,094,208 | —- | C] () – C:\Windows\System32\IppLib.dll
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/10/18 00:29:24 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\AVG
[2010/08/28 21:14:40 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\LimeWire
[2009/08/31 23:14:11 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\myphotobook
[2010/10/15 11:04:52 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\PeerNetworking
[2010/03/06 18:10:03 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Toshiba
[2009/09/05 21:59:31 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Trusteer
[2010/10/30 09:51:38 | 000,032,552 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/08/07 15:16:30 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/10/30 11:17:02 | 3082,809,344 | -HS- | M] () – C:\hiberfil.sys
[2010/10/30 11:16:59 | 3396,603,904 | -HS- | M] () – C:\pagefile.sys
[2009/08/31 14:44:30 | 000,000,651 | —- | M] () – C:\RHDSetup.log
[2008/11/11 17:07:57 | 000,000,176 | -H– | M] () – C:\SWSTAMP.TXT

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/11 10:01:43 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/09 00:00:00 | 000,026,364 | —- | M] (Brother Industries ,Ltd ) – C:\Windows\System32\spool\prtprocs\w32x86\brmfpp1.dll
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/07 16:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/07/29 10:32:09 | 000,001,650 | -H– | M] () – C:\Users\Lisa\AppData\Roaming\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 04:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/08 20:49:12 | 000,000,286 | -HS- | M] () – C:\Users\Lisa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/10/30 16:21:30 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/08/31 15:08:47 | 000,000,402 | -HS- | M] () – C:\Users\Lisa\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-27 20:01:07

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >


OTL Extras logfile created on: 30/10/2010 18:13:31 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Lisa\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148.89 Gb Total Space | 90.39 Gb Free Space | 60.71% Space Free | Partition Type: NTFS
Drive E: | 147.73 Gb Total Space | 142.46 Gb Free Space | 96.43% Space Free | Partition Type: NTFS

Computer Name: LISA-PC | User Name: Lisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0FB6DFE2-08B5-4053-B5B8-46F26CE985FD}" = lport=138 | protocol=17 | dir=in | app=system |
"{30EA8FFC-409F-4871-9E32-D824F2FFE0FA}" = lport=445 | protocol=6 | dir=in | app=system |
"{333B292B-CCE3-4AEC-B86B-B6D30ABCD3A8}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{53E383B6-E801-422E-B6E2-BA13BB8ABC86}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{5B1795E9-BAC1-4AAA-9315-6325B8E42824}" = rport=138 | protocol=17 | dir=out | app=system |
"{61C01F09-22DC-4F24-A8B9-BBF3D8E3FACC}" = rport=137 | protocol=17 | dir=out | app=system |
"{74F2A7BC-D9F2-46B7-8486-139765FC5287}" = lport=137 | protocol=17 | dir=in | app=system |
"{7883D58C-CD0B-4821-8455-91D5E9684621}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{85E0D435-A5CC-4F68-9DDC-91BA7D3DDAF3}" = rport=139 | protocol=6 | dir=out | app=system |
"{A63EE363-CC9B-42AB-9CBF-900EF3B50DA1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AA538CAA-B40E-43EF-BB5D-3CF72CBD2A78}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BBA87489-BAB0-493F-B8EC-2F9E83662EC6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C1C82DA3-1AF1-456D-8323-22D950252759}" = lport=139 | protocol=6 | dir=in | app=system |
"{D1B293FB-51BA-4FDC-896A-5662D547FEEA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DC7EA973-63A9-444C-B430-833DDBE439EA}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{077CC331-5717-4625-95AA-4A49763A53E1}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{0C00132A-0092-4A21-8BFD-434C9C3C5336}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{0CA3E4BB-5276-4596-A4CF-1EDDDAA3AD6F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{1509F8F3-D4DD-43D4-A207-C5AC7485D849}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{388A03EB-5320-42E3-BE0F-19A24F677B13}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{398814D6-7D1A-4BA1-8DAB-23C7F43625D8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6E62CEDB-ED27-4599-9F35-911FF11C807E}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{7F616A6B-A0E6-441B-91A8-C2FCC28ADEC7}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{91E19D51-D90A-45E0-AE09-359EC16BCDEF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{934B743F-E17F-4B25-B99E-F2DB2956126F}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{961DD4A9-5C68-4ED2-A6FA-649BAECD273B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A2AEF280-40C7-4054-B5B1-D02EE46F2953}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A592D871-960F-4767-827B-3CBF34E123D8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B19693E5-D0F7-4B50-89C9-29BE8342E97A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{BA02AE11-27FB-4F4A-BEA3-2C090B0CCDC9}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"TCP Query User{35B13395-63E6-44AE-A642-4597B9910722}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{F5620DE2-4B23-4A74-A9E2-61C8EB03A412}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{1E0B311C-C7E7-42FE-A2CE-2563B56910A3}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{B238B849-8004-48A6-B039-036F853C6D4C}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03FAA727-E2B7-471C-AC41-2E1C7F29C7EA}" = Toshiba TEMPRO
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Atheros Wi-Fi Protected Setup Library
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{BB9AC6BF-71B6-42A4-9689-C17D9F44E79A}" = Brother MFL-Pro Suite
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"{E7271ABF-69D3-4E9D-AA0A-2DE34C10A93D}" = TOSHIBA Manuals
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"avast5" = avast! Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LimeWire" = LimeWire 5.5.14
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"myphotobook" = myphotobook 3.6
"Picasa 3" = Picasa 3
"RealPlayer 12.0" = RealPlayer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26/05/2010 14:35:15 | Computer Name = Lisa-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 26/05/2010 14:35:22 | Computer Name = Lisa-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 26/05/2010 14:35:22 | Computer Name = Lisa-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 26/05/2010 16:57:54 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/05/2010 04:30:46 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/05/2010 04:52:13 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/05/2010 05:49:50 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/05/2010 07:15:29 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/05/2010 11:33:58 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 28/05/2010 04:23:02 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 29/10/2010 07:56:21 | Computer Name = Lisa-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer Brother DCP-120C USB Printer
with shared resource name Brother DCP-120C USB Printer. Error 2114. The printer
cannot be used by others on the network.

Error - 29/10/2010 12:38:53 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7016
Description =

Error - 29/10/2010 13:49:58 | Computer Name = Lisa-PC | Source = DCOM | ID = 10010
Description =

Error - 29/10/2010 14:06:22 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 29/10/2010 14:06:23 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2010 15:42:46 | Computer Name = Lisa-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 29/10/2010 15:45:47 | Computer Name = Lisa-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 29/10/2010 17:31:51 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2010 17:34:14 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 30/10/2010 10:33:18 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7016
Description =


< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    [2010/10/23 12:36:08 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
    [2010/10/17 23:59:02 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Roaming\AVG
    [2010/10/15 10:59:05 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar(57)
    
    :Files
    c:\documentsandsettings\lisa\appdata\avg
    c:\documentsandsettings\lisa\appdata\roaming\pctuneup2011
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
just to let you know ie just siezed up again, so i switched off and on rebooting the system took itself to a chkdsk again, it looks like its still the volume that its trying to repair All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\ProgramData\AVG10\lsdb\prev folder moved successfully. C:\ProgramData\AVG10\lsdb folder moved successfully. C:\ProgramData\AVG10 folder moved successfully. C:\Users\Lisa\AppData\Roaming\AVG\Rescue\PC Tuneup 2011 folder moved successfully. C:\Users\Lisa\AppData\Roaming\AVG\Rescue folder moved successfully. C:\Users\Lisa\AppData\Roaming\AVG\PC Tuneup 2011\User Reports folder moved successfully. C:\Users\Lisa\AppData\Roaming\AVG\PC Tuneup 2011 folder moved successfully. C:\Users\Lisa\AppData\Roaming\AVG folder moved successfully. C:\ProgramData\AVG Security Toolbar(57)\Update folder moved successfully. C:\ProgramData\AVG Security Toolbar(57) folder moved successfully. ========== FILES ========== File\Folder c:\documentsandsettings\lisa\appdata\avg not found. File\Folder c:\documentsandsettings\lisa\appdata\roaming\pctuneup2011 not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Kate ->Temp folder emptied: 0 bytes User: Kate.Lisa-PC ->Temp folder emptied: 0 bytes User: Lisa ->Temp folder emptied: 15072529 bytes ->Temporary Internet Files folder emptied: 80227728 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 6196506 bytes ->Flash cache emptied: 10970 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 20649098 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 176930 bytes Total Files Cleaned = 117.00 mb OTL by OldTimer - Version 3.2.17.1 log created on 10302010_185450 Files\Folders moved on Reboot… File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot…
unbelievably it is still showing all 7 issues as well as some of the original registry errors. ok its now just showing me that the infected files are in c:\_otl\movedfiles|…… so should i assume if i now do the otl uninstall that my system will be fully clean?
Yes,the OTL clean up below will remove all traces of them,now you need to return to your other topic in the windows forum to try to resolve your other issues.

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
ive just changed my anti virus to avira as you recommended and its found two trojans on my system that it removed. how are these still on after all the tests weve done? the report is below Avira AntiVir Personal Report file date: 01 November 2010 16:22 Scanning for 2992847 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows Vista Windows version : (Service Pack 2) [6.0.6002] Boot mode : Normally booted Username : SYSTEM Computer name : LISA-PC Version information: BUILD.DAT : 10.0.0.567 32097 Bytes 19/04/2010 15:07:00 AVSCAN.EXE : 10.0.3.0 433832 Bytes 01/04/2010 13:37:38 AVSCAN.DLL : 10.0.3.0 46440 Bytes 01/04/2010 13:57:04 LUKE.DLL : 10.0.2.3 104296 Bytes 07/03/2010 19:33:04 LUKERES.DLL : 10.0.0.1 12648 Bytes 11/02/2010 00:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 10:05:36 VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 20:27:49 VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 18:37:42 VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 17:37:42 VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 12:29:03 VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 12:42:33 VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 12:42:36 VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 12:42:40 VBASE008.VDF : 7.10.11.133 3454464 Bytes 13/09/2010 12:42:44 VBASE009.VDF : 7.10.11.134 2048 Bytes 13/09/2010 12:42:44 VBASE010.VDF : 7.10.11.135 2048 Bytes 13/09/2010 12:42:45 VBASE011.VDF : 7.10.11.136 2048 Bytes 13/09/2010 12:42:45 VBASE012.VDF : 7.10.11.137 2048 Bytes 13/09/2010 12:42:45 VBASE013.VDF : 7.10.11.165 172032 Bytes 15/09/2010 12:42:45 VBASE014.VDF : 7.10.11.202 144384 Bytes 18/09/2010 12:42:46 VBASE015.VDF : 7.10.11.231 129024 Bytes 21/09/2010 12:42:46 VBASE016.VDF : 7.10.12.4 126464 Bytes 23/09/2010 12:42:46 VBASE017.VDF : 7.10.12.38 146944 Bytes 27/09/2010 12:42:47 VBASE018.VDF : 7.10.12.64 133120 Bytes 29/09/2010 12:42:47 VBASE019.VDF : 7.10.12.99 134144 Bytes 01/10/2010 12:42:47 VBASE020.VDF : 7.10.12.122 131584 Bytes 05/10/2010 12:42:48 VBASE021.VDF : 7.10.12.148 119296 Bytes 07/10/2010 12:42:48 VBASE022.VDF : 7.10.12.175 142848 Bytes 11/10/2010 12:42:48 VBASE023.VDF : 7.10.12.198 131584 Bytes 13/10/2010 12:42:49 VBASE024.VDF : 7.10.12.216 133120 Bytes 14/10/2010 12:42:49 VBASE025.VDF : 7.10.12.238 137728 Bytes 18/10/2010 12:42:49 VBASE026.VDF : 7.10.12.254 129536 Bytes 20/10/2010 12:42:50 VBASE027.VDF : 7.10.13.22 137728 Bytes 22/10/2010 12:42:50 VBASE028.VDF : 7.10.13.39 124416 Bytes 26/10/2010 12:42:50 VBASE029.VDF : 7.10.13.62 141312 Bytes 28/10/2010 12:42:51 VBASE030.VDF : 7.10.13.73 137216 Bytes 29/10/2010 12:42:51 VBASE031.VDF : 7.10.13.76 36864 Bytes 01/11/2010 12:42:51 Engineversion : 8.2.4.86 AEVDF.DLL : 8.1.2.1 106868 Bytes 01/11/2010 12:42:58 AESCRIPT.DLL : 8.1.3.45 1368443 Bytes 01/11/2010 12:42:58 AESCN.DLL : 8.1.6.1 127347 Bytes 01/11/2010 12:42:57 AESBX.DLL : 8.1.3.1 254324 Bytes 01/11/2010 12:42:58 AERDL.DLL : 8.1.9.2 635252 Bytes 01/11/2010 12:42:57 AEPACK.DLL : 8.2.3.11 471416 Bytes 01/11/2010 12:42:56 AEOFFICE.DLL : 8.1.1.8 201081 Bytes 01/11/2010 12:42:55 AEHEUR.DLL : 8.1.2.37 2974072 Bytes 01/11/2010 12:42:55 AEHELP.DLL : 8.1.14.0 246134 Bytes 01/11/2010 12:42:53 AEGEN.DLL : 8.1.3.23 401779 Bytes 01/11/2010 12:42:53 AEEMU.DLL : 8.1.2.0 393588 Bytes 01/11/2010 12:42:52 AECORE.DLL : 8.1.17.0 196982 Bytes 01/11/2010 12:42:52 AEBB.DLL : 8.1.1.0 53618 Bytes 01/11/2010 12:42:52 AVWINLL.DLL : 10.0.0.0 19304 Bytes 14/01/2010 13:03:38 AVPREF.DLL : 10.0.0.0 44904 Bytes 14/01/2010 13:03:35 AVREP.DLL : 10.0.0.8 62209 Bytes 18/02/2010 17:47:40 AVREG.DLL : 10.0.3.0 53096 Bytes 01/04/2010 13:35:46 AVSCPLR.DLL : 10.0.3.0 83816 Bytes 01/04/2010 13:39:51 AVARKT.DLL : 10.0.0.14 227176 Bytes 01/04/2010 13:22:13 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 26/01/2010 10:53:30 SQLITE3.DLL : 3.6.19.0 355688 Bytes 28/01/2010 13:57:58 AVSMTP.DLL : 10.0.0.17 63848 Bytes 16/03/2010 16:38:56 NETNT.DLL : 10.0.0.0 11624 Bytes 19/02/2010 15:41:00 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28/01/2010 14:10:20 RCTEXT.DLL : 10.0.53.0 97128 Bytes 09/04/2010 15:14:29 Configuration settings for the scan: Jobname………………………..: Complete system scan Configuration file………………: C:\program files\avira\antivir desktop\sysscan.avp Logging………………………..: low Primary action………………….: interactive Secondary action………………..: ignore Scan master boot sector………….: on Scan boot sector………………..: on Boot sectors……………………: C:, E:, Process scan……………………: on Extended process scan……………: on Scan registry…………………..: on Search for rootkits……………..: on Integrity checking of system files..: off Scan all files………………….: All files Scan archives…………………..: on Recursion depth…………………: 20 Smart extensions………………..: on Macro heuristic…………………: on File heuristic………………….: medium Deviating risk categories………..: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR, Start of the scan: 01 November 2010 16:22 Starting search for hidden objects. c:\program files\google\google toolbar\googletoolbaruser_32.exe c:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe [NOTE] The process is not visible. The scan of running processes will be started Scan process 'taskeng.exe' - '24' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'vssvc.exe' - '49' Module(s) have been scanned Scan process 'avscan.exe' - '81' Module(s) have been scanned Scan process 'FlashUtil10k_ActiveX.exe' - '34' Module(s) have been scanned Scan process 'GoogleToolbarUser_32.exe' - '65' Module(s) have been scanned Scan process 'iexplore.exe' - '137' Module(s) have been scanned Scan process 'iexplore.exe' - '101' Module(s) have been scanned Scan process 'svchost.exe' - '21' Module(s) have been scanned Scan process 'SynTPHelper.exe' - '19' Module(s) have been scanned Scan process 'wlcomm.exe' - '99' Module(s) have been scanned Scan process 'CFSwMgr.exe' - '74' Module(s) have been scanned Scan process 'wmpnetwk.exe' - '64' Module(s) have been scanned Scan process 'brccMCtl.exe' - '80' Module(s) have been scanned Scan process 'igfxext.exe' - '25' Module(s) have been scanned Scan process 'CEC_MAIN.exe' - '82' Module(s) have been scanned Scan process 'WinMail.exe' - '112' Module(s) have been scanned Scan process 'ehmsas.exe' - '25' Module(s) have been scanned Scan process 'ONENOTEM.EXE' - '21' Module(s) have been scanned Scan process 'wmpnscfg.exe' - '32' Module(s) have been scanned Scan process 'ehtray.exe' - '29' Module(s) have been scanned Scan process 'GoogleToolbarNotifier.exe' - '60' Module(s) have been scanned Scan process 'msnmsgr.exe' - '157' Module(s) have been scanned Scan process 'TOSCDSPD.exe' - '20' Module(s) have been scanned Scan process 'sidebar.exe' - '78' Module(s) have been scanned Scan process 'avgnt.exe' - '54' Module(s) have been scanned Scan process 'jusched.exe' - '22' Module(s) have been scanned Scan process 'igfxsrvc.exe' - '25' Module(s) have been scanned Scan process 'BrMfcWnd.exe' - '39' Module(s) have been scanned Scan process 'GrooveMonitor.exe' - '41' Module(s) have been scanned Scan process 'RtHDVCpl.exe' - '55' Module(s) have been scanned Scan process 'traybar.exe' - '27' Module(s) have been scanned Scan process 'TCrdMain.exe' - '66' Module(s) have been scanned Scan process 'SmoothView.exe' - '20' Module(s) have been scanned Scan process 'TPwrMain.exe' - '40' Module(s) have been scanned Scan process 'igfxpers.exe' - '26' Module(s) have been scanned Scan process 'hkcmd.exe' - '26' Module(s) have been scanned Scan process 'igfxtray.exe' - '27' Module(s) have been scanned Scan process 'Toshiba.Tempo.UI.TrayApplication.exe' - '76' Module(s) have been scanned Scan process 'NDSTray.exe' - '94' Module(s) have been scanned Scan process 'SynTPEnh.exe' - '36' Module(s) have been scanned Scan process 'Explorer.EXE' - '137' Module(s) have been scanned Scan process 'Dwm.exe' - '36' Module(s) have been scanned Scan process 'taskeng.exe' - '83' Module(s) have been scanned Scan process 'SmartFaceVWatchSrv.exe' - '33' Module(s) have been scanned Scan process 'taskeng.exe' - '49' Module(s) have been scanned Scan process 'WLIDSvcM.exe' - '16' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '60' Module(s) have been scanned Scan process 'WLIDSVC.EXE' - '69' Module(s) have been scanned Scan process 'svchost.exe' - '9' Module(s) have been scanned Scan process 'ULCDRSvr.exe' - '5' Module(s) have been scanned Scan process 'TosIPCSrv.exe' - '22' Module(s) have been scanned Scan process 'avshadow.exe' - '33' Module(s) have been scanned Scan process 'TosCoSrv.exe' - '20' Module(s) have been scanned Scan process 'TODDSrv.exe' - '23' Module(s) have been scanned Scan process 'TNaviSrv.exe' - '19' Module(s) have been scanned Scan process 'TempoSVC.exe' - '61' Module(s) have been scanned Scan process 'svchost.exe' - '46' Module(s) have been scanned Scan process 'svchost.exe' - '42' Module(s) have been scanned Scan process 'CFSvcs.exe' - '71' Module(s) have been scanned Scan process 'avguard.exe' - '64' Module(s) have been scanned Scan process 'agrsmsvc.exe' - '16' Module(s) have been scanned Scan process 'svchost.exe' - '59' Module(s) have been scanned Scan process 'sched.exe' - '56' Module(s) have been scanned Scan process 'spoolsv.exe' - '85' Module(s) have been scanned Scan process 'brss01a.exe' - '13' Module(s) have been scanned Scan process 'brsvc01a.exe' - '13' Module(s) have been scanned Scan process 'WLANExt.exe' - '45' Module(s) have been scanned Scan process 'svchost.exe' - '94' Module(s) have been scanned Scan process 'svchost.exe' - '81' Module(s) have been scanned Scan process 'SLsvc.exe' - '23' Module(s) have been scanned Scan process 'svchost.exe' - '37' Module(s) have been scanned Scan process 'svchost.exe' - '147' Module(s) have been scanned Scan process 'svchost.exe' - '114' Module(s) have been scanned Scan process 'svchost.exe' - '64' Module(s) have been scanned Scan process 'svchost.exe' - '33' Module(s) have been scanned Scan process 'PresentationFontCache.exe' - '30' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'winlogon.exe' - '30' Module(s) have been scanned Scan process 'lsm.exe' - '22' Module(s) have been scanned Scan process 'lsass.exe' - '62' Module(s) have been scanned Scan process 'services.exe' - '33' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'wininit.exe' - '26' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'E:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '378' files ). Starting the file scan: Begin scan in 'C:\' C:\ProgramData\MFAData\pack\bins\f10guix1136el.bin [0] Archive type: CAB (Microsoft) [DETECTION] Is the TR/Spy.ZBot.KR.1 Trojan –> data [1] Archive type: BZ2 –> 00000006-3B7D6F09 [2] Archive type: CAB (Microsoft) –> avgtray.exe [DETECTION] Is the TR/Spy.ZBot.KR.1 Trojan C:\ProgramData\MFAData\pack\bins\f10guix1144gk.bin [0] Archive type: CAB (Microsoft) [DETECTION] Is the TR/Spy.ZBot.KR.1 Trojan –> data [1] Archive type: BZ2 –> 00000006-3F5A8025 [2] Archive type: CAB (Microsoft) –> avgtray.exe [DETECTION] Is the TR/Spy.ZBot.KR.1 Trojan Begin scan in 'E:\' Beginning disinfection: C:\ProgramData\MFAData\pack\bins\f10guix1144gk.bin [DETECTION] Is the TR/Spy.ZBot.KR.1 Trojan [NOTE] The file was moved to the quarantine directory under the name '48645c42.qua'. C:\ProgramData\MFAData\pack\bins\f10guix1136el.bin [DETECTION] Is the TR/Spy.ZBot.KR.1 Trojan [NOTE] The file was moved to the quarantine directory under the name '50f373e6.qua'. End of the scan: 01 November 2010 17:28 Used time: 1:05:30 Hour(s) The scan has been done completely. 20891 Scanned directories 282757 Files were scanned 2 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 2 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 282755 Files not concerned 8699 Archives were scanned 0 Warnings 2 Notes 534714 Objects were scanned with rootkit scan 1 Hidden objects were found

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI