This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Freezes when I want to Shutdown.

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my XP PC freezes for some unknown reason when I want to shut down my PC. I downloaded the virus removal tools and these are the scan results.


OTL logfile created on: 10/31/2010 8:07:25 PM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\TriT\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 30.01 Gb Total Space | 3.95 Gb Free Space | 13.16% Space Free | Partition Type: NTFS
Drive E: | 60.00 Gb Total Space | 2.32 Gb Free Space | 3.87% Space Free | Partition Type: NTFS
Drive F: | 60.00 Gb Total Space | 2.47 Gb Free Space | 4.12% Space Free | Partition Type: NTFS
Drive G: | 60.00 Gb Total Space | 3.31 Gb Free Space | 5.52% Space Free | Partition Type: NTFS
Drive H: | 88.07 Gb Total Space | 1.05 Gb Free Space | 1.19% Space Free | Partition Type: NTFS

Computer Name: GOBESHON-5EFF6D | User Name: TriT | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe (Speedbit Ltd.)
PRC - C:\Documents and Settings\TriT\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe ()
PRC - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe ()
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe ()
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe ()
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe ()
PRC - C:\Program Files\Gigabyte\ET6\GUI.exe ()
PRC - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\TriT\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Internet Download Manager\idmmkb.dll (Tonec Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (VideoAcceleratorService) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe ()
SRV - (ioloFileInfoList) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe ()
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE ()
SRV - (BlueSoleilCS) – C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe ()
SRV - (BsHelpCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe ()
SRV - (BsMobileCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe ()


========== Driver Services (SafeList) ==========

DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\System32\DRIVERS\RTL8139.SYS File not found
DRV - (ADASPROT) – C:\Program Files\Advanced System Optimizer 3\adasprot32.sys File not found
DRV - (GVTDrv) – C:\WINDOWS\system32\drivers\GVTDrv.sys ()
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (etdrv) – C:\WINDOWS\etdrv.sys (Windows ® 2000 DDK provider)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (eamon) – C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (epfwtdir) – C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) – C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (AODDriver) – C:\Program Files\Gigabyte\ET6\i386\AODDriver.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (BtHidBus) – C:\WINDOWS\System32\Drivers\BtHidBus.sys (IVT Corporation.)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (btnetBUs) – C:\WINDOWS\system32\drivers\btnetBus.sys ()
DRV - (BT) – C:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (IvtBtBUs) – C:\WINDOWS\system32\drivers\IvtBtBus.sys (IVT Corporation.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (BTNetFilter) – C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys (IVT Corporation.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:0.04
FF - prefs.js..extensions.enabledItems: [removed]:6.9.7
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.608
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/29 02:53:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/11 02:14:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/10/11 02:10:17 | 000,000,000 | —D | M]

[2010/07/31 02:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Mozilla\Extensions
[2010/09/23 00:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions
[2010/09/04 01:49:23 | 000,000,000 | —D | M] (Screengrab) – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/08/12 23:07:09 | 000,000,000 | —D | M] (FlashGot) – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010/08/12 23:03:52 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/07/31 02:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\[removed]
[2010/08/22 23:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\[removed]
[2010/07/31 20:26:40 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\[removed]
[2010/09/23 00:05:37 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Mozilla\Firefox\Profiles\rpsdtyyz.default\extensions\[removed]
[2010/09/23 00:05:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/15 15:20:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/15 15:20:45 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2001/08/23 23:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BtTray] C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe ()
O4 - HKLM..\Run: [EasyTuneVI] C:\Program Files\Gigabyte\ET6\ETcall.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Send by Bluetooth - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm ()
O8 - Extra context menu item: Send via &Message… - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (I:\MINUS\ona.exe) - I:\MINUS\ona.exe File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\TriT\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\TriT\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/30 11:58:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/09/16 22:41:13 | 000,000,090 | —- | M] () - H:\AUTORUN.INF – [ NTFS ]
O33 - MountPoints2\{3dee9fe6-e491-11df-a5b3-101111111111}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\cmd.exe – [2004/08/04 10:56:50 | 000,388,608 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{3dee9fe6-e491-11df-a5b3-101111111111}\Shell\open\command - "" = C:\WINDOWS\System32\cmd.exe – [2004/08/04 10:56:50 | 000,388,608 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{6a8369c9-9d3c-11df-a455-002127c7c03f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a8369c9-9d3c-11df-a455-002127c7c03f}\Shell\AutoRun\command - "" = I:\PRZHI\\hladi.exe – File not found
O33 - MountPoints2\{6a8369c9-9d3c-11df-a455-002127c7c03f}\Shell\explore\command - "" = I:\PRZHI\\\hladi.exe – File not found
O33 - MountPoints2\{6a8369c9-9d3c-11df-a455-002127c7c03f}\Shell\open\command - "" = I:\PRZHI\\\hladi.exe – File not found
O33 - MountPoints2\{6a8369cf-9d3c-11df-a455-002127c7c03f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a8369cf-9d3c-11df-a455-002127c7c03f}\Shell\AutoRun\command - "" = I:\PRZHI\\hladi.exe – File not found
O33 - MountPoints2\{6a8369cf-9d3c-11df-a455-002127c7c03f}\Shell\explore\command - "" = I:\PRZHI\\\hladi.exe – File not found
O33 - MountPoints2\{6a8369cf-9d3c-11df-a455-002127c7c03f}\Shell\open\command - "" = I:\PRZHI\\\hladi.exe – File not found
O33 - MountPoints2\{939897e1-b00d-11df-a4b8-002127c7c03f}\Shell\AutoRun\command - "" = J:\USBNB.exe – File not found
O33 - MountPoints2\{a36e3dd8-a510-11df-a47a-002127c7c03f}\Shell\AutoRun\command - "" = I:\usecure\usecure32.exe – File not found
O33 - MountPoints2\{a36e3dd8-a510-11df-a47a-002127c7c03f}\Shell\explore\command - "" = I:\usecure\usecure32.exe – File not found
O33 - MountPoints2\{a36e3dd8-a510-11df-a47a-002127c7c03f}\Shell\open\command - "" = I:\usecure\usecure32.exe – File not found
O33 - MountPoints2\{c3e2ffea-9bce-11df-aff1-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{c3e2ffea-9bce-11df-aff1-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cc50cfbe-a235-11df-a46e-002127c7c03f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cc50cfbe-a235-11df-a46e-002127c7c03f}\Shell\AutoRun\command - "" = I:\MINUS\ona.exe – File not found
O33 - MountPoints2\{cc50cfbe-a235-11df-a46e-002127c7c03f}\Shell\explore\command - "" = I:\MINUS\\ona.exe – File not found
O33 - MountPoints2\{cc50cfbe-a235-11df-a46e-002127c7c03f}\Shell\open\command - "" = I:\MINUS\\ona.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (sasnative32) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/12 21:06:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Speedbit
[2012/09/12 21:06:21 | 000,172,032 | —- | C] (Jin Hui E-mail: [removed] Web: http://www.jcomsoft.com) – C:\WINDOWS\System32\AniGIF.ocx
[2012/09/12 21:06:21 | 000,000,000 | —D | C] – C:\Program Files\SpeedBit Video Accelerator
[2010/10/31 20:02:29 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\TriT\Desktop\HiJackThis.exe
[2010/10/31 20:01:19 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\TriT\Desktop\OTL.exe
[2010/10/31 03:16:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\TriT\Recent
[2010/10/12 09:14:20 | 000,093,096 | —- | C] (iolo technologies, LLC) – C:\WINDOWS\System32\IncContxMenu.dll
[2010/10/11 21:50:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nokia
[2010/10/11 21:49:03 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/10/11 21:49:02 | 000,018,816 | —- | C] (Nokia) – C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010/10/11 21:48:56 | 000,000,000 | —D | C] – C:\Program Files\PC Connectivity Solution
[2010/10/11 21:48:42 | 000,092,672 | —- | C] (Nokia) – C:\WINDOWS\System32\nmwcdcls.dll
[2010/10/11 21:46:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Installations
[2010/10/11 02:50:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/10/11 02:23:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2010/10/11 02:10:16 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/10/11 02:10:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/10/11 01:13:51 | 000,000,000 | —D | C] – C:\Program Files\eMule
[2010/10/10 19:06:28 | 000,000,000 | —D | C] – C:\Documents and Settings\TriT\Application Data\skypePM
[2010/10/08 01:33:42 | 000,000,000 | —D | C] – C:\Program Files\GNU
[2010/10/03 17:13:26 | 000,000,000 | —D | C] – C:\Documents and Settings\TriT\My Documents\Peyote
[2010/10/03 17:07:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2010/10/03 12:17:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SRSLabs
[2010/10/02 23:13:50 | 000,000,000 | —D | C] – C:\Program Files\SRSLabs
[2010/10/02 23:13:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SRS
[2010/10/02 19:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\TriT\Desktop\Sha
[2010/07/30 12:31:22 | 000,004,096 | —- | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/12 21:06:21 | 000,172,032 | —- | M] (Jin Hui E-mail: [removed] Web: http://www.jcomsoft.com) – C:\WINDOWS\System32\AniGIF.ocx
[2012/09/11 19:13:56 | 000,000,780 | —- | M] () – C:\Documents and Settings\TriT\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2012/09/11 19:13:56 | 000,000,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\GOM Player.lnk
[2012/09/11 10:07:40 | 000,000,406 | —- | M] () – C:\WINDOWS\System32\ioloBootDefrag.cfg
[2010/10/31 20:03:19 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\TriT\Desktop\HiJackThis.exe
[2010/10/31 20:02:30 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\TriT\Desktop\OTL.exe
[2010/10/31 19:58:19 | 000,024,944 | —- | M] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2010/10/31 19:58:19 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\GVTunner.ref
[2010/10/31 19:58:04 | 000,006,278 | —- | M] () – C:\WINDOWS\System32\LOCALSERVICE.INI
[2010/10/31 19:58:01 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2010/10/31 19:57:57 | 000,001,047 | —- | M] () – C:\WINDOWS\System32\bscs.ini
[2010/10/31 19:57:54 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/31 17:37:46 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\etdrv.sys
[2010/10/31 17:36:26 | 000,171,520 | —- | M] () – C:\Documents and Settings\TriT\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/31 17:26:15 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/10/31 07:49:12 | 000,000,107 | —- | M] () – C:\WINDOWS\System32\LOCALDEVICE.INI
[2010/10/31 00:03:10 | 000,107,185 | —- | M] () – C:\Documents and Settings\TriT\Desktop\utyuyu.jpg
[2010/10/30 22:16:32 | 000,000,611 | —- | M] () – C:\WINDOWS\System32\REMOTEDEVICE.INI
[2010/10/30 22:06:27 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/10/30 12:20:02 | 000,035,488 | —- | M] () – C:\Documents and Settings\TriT\Desktop\01-10-10_0001.jpg
[2010/10/28 23:45:10 | 000,002,228 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/12 09:14:24 | 000,001,689 | —- | M] () – C:\Documents and Settings\TriT\Desktop\System Mechanic.lnk
[2010/10/10 19:06:29 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/31 19:58:19 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\GVTunner.ref
[2010/10/31 00:03:09 | 000,107,185 | —- | C] () – C:\Documents and Settings\TriT\Desktop\utyuyu.jpg
[2010/10/30 12:20:02 | 000,035,488 | —- | C] () – C:\Documents and Settings\TriT\Desktop\01-10-10_0001.jpg
[2010/10/12 09:14:24 | 000,001,689 | —- | C] () – C:\Documents and Settings\TriT\Desktop\System Mechanic.lnk
[2010/10/12 09:14:19 | 002,315,688 | —- | C] () – C:\WINDOWS\System32\Incinerator.dll
[2010/10/12 09:13:33 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\smrgdf.exe
[2010/10/12 09:13:32 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\iolobtdfg.exe
[2010/10/10 19:06:29 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/09/22 23:54:43 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2010/09/22 23:54:33 | 000,471,552 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2010/08/28 17:33:20 | 000,003,325 | —- | C] () – C:\WINDOWS\System32\SHORTCUT.INI
[2010/08/28 17:33:05 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\REMOTEDEVICE.INI
[2010/08/28 17:29:50 | 000,006,278 | —- | C] () – C:\WINDOWS\System32\LOCALSERVICE.INI
[2010/08/28 17:29:48 | 000,000,107 | —- | C] () – C:\WINDOWS\System32\LOCALDEVICE.INI
[2010/08/28 17:24:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\BSPRINT.INI
[2010/08/13 19:13:38 | 000,000,076 | —- | C] () – C:\WINDOWS\zip_crck.ini
[2010/08/13 14:43:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/08/12 21:28:24 | 000,270,336 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/31 15:45:05 | 000,000,084 | —- | C] () – C:\WINDOWS\ringtonemaker.INI
[2010/07/31 15:34:29 | 000,000,999 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2010/07/31 14:19:52 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2010/07/31 13:06:21 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/07/31 13:06:21 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2010/07/31 13:06:18 | 000,881,664 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/07/31 13:06:18 | 000,205,824 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/07/31 13:06:17 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/07/31 02:06:17 | 000,024,944 | —- | C] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2010/07/30 17:45:50 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/07/30 12:16:02 | 000,171,520 | —- | C] () – C:\Documents and Settings\TriT\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/27 17:04:46 | 000,001,047 | —- | C] () – C:\WINDOWS\System32\bscs.ini
[2009/02/27 16:45:16 | 000,405,589 | —- | C] () – C:\WINDOWS\System32\BsUI.dll
[2009/02/27 16:44:50 | 000,278,647 | —- | C] () – C:\WINDOWS\System32\outlookAddin.dll
[2009/02/27 16:44:28 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\HtmPrintHelper.dll
[2009/02/27 16:44:10 | 000,622,693 | —- | C] () – C:\WINDOWS\System32\BSShell.dll
[2009/02/27 16:41:38 | 000,098,403 | —- | C] () – C:\WINDOWS\System32\Bs2Res.dll
[2009/02/27 16:41:02 | 000,122,976 | —- | C] () – C:\WINDOWS\System32\BsMobileSDK.dll
[2009/02/27 16:40:50 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\BsMobileCSps.dll
[2008/12/07 12:44:54 | 000,030,088 | —- | C] () – C:\WINDOWS\System32\drivers\btnetBus.sys
[2008/10/22 15:30:30 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\BsVistaCommon.dll
[2008/03/07 13:54:22 | 017,907,824 | —- | C] () – C:\WINDOWS\System32\BsLangInDepRes.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2004/08/04 10:56:44 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2004/07/17 21:36:38 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2002/03/20 22:01:06 | 000,006,688 | R— | C] () – C:\WINDOWS\System32\Digita.sys
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportUSB.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportSerial.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportIrDA.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportIrCOMM.dll

========== LOP Check ==========

[2010/09/18 19:47:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2010/08/05 03:07:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/10/11 02:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/10/11 21:46:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2012/09/11 13:03:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2010/08/15 15:24:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JCreator
[2010/09/22 23:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2010/10/11 21:50:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nokia
[2012/09/12 21:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Speedbit
[2010/10/03 12:17:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SRSLabs
[2010/10/11 02:31:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Systweak
[2010/09/22 23:21:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/18 19:50:09 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\ACD Systems
[2010/08/12 21:30:02 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\adma
[2010/10/31 17:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\BitTorrent
[2010/10/31 19:58:01 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\DMCache
[2010/07/30 12:21:29 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\ESET
[2010/09/20 23:45:29 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\IDM
[2012/09/11 10:06:10 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\iolo
[2010/08/15 15:24:39 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\JCreator
[2010/08/08 12:12:26 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Pavtube
[2010/10/11 02:31:11 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Systweak
[2010/07/30 12:09:35 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Windows Desktop Search
[2010/07/30 12:09:39 | 000,000,000 | —D | M] – C:\Documents and Settings\TriT\Application Data\Windows Search
[2010/09/16 12:17:26 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\shutdown.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/22 23:49:29 | 000,001,024 | —- | M] () – C:\.rnd
[2010/07/30 11:58:26 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/09/22 22:55:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/07/30 11:58:26 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/30 12:43:39 | 000,000,195 | —- | M] () – C:\csb.log
[2010/07/30 12:42:39 | 000,000,197 | —- | M] () – C:\Install.log
[2010/07/30 11:58:26 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/30 11:58:26 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 08:59:34 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/31 19:57:53 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/07/30 12:40:13 | 000,001,519 | —- | M] () – C:\RHDSetup.log
[2010/10/31 19:58:11 | 000,000,145 | —- | M] () – C:\service.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/09/22 22:57:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 18:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/09/27 14:49:26 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2008/07/06 16:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/09/16 23:01:04 | 000,001,610 | -H– | M] () – C:\Documents and Settings\TriT\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/09/23 04:48:26 | 000,270,336 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/09/22 22:42:17 | 000,049,152 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2010/09/23 04:48:26 | 025,427,968 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/09/23 04:48:27 | 005,242,880 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/22 22:58:23 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/30 12:05:18 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\TriT\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/30 12:05:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\TriT\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/10/31 20:03:19 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\TriT\Desktop\HiJackThis.exe
[2010/10/31 20:02:30 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\TriT\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9D1B94FD
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54D4173A

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:23:47 PM, on 10/31/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\GIGABYTE\ET6\GUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\TriT\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [EasyTuneVI] C:\Program Files\GIGABYTE\ET6\ETcall.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [BtTray] "C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send by Bluetooth - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
O8 - Extra context menu item: Send via &Message… - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9263AAE-71F7-4531-9513-21833D073542}: NameServer = 114.31.0.66 210.4.77.180
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: BlueSoleilCS - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
O23 - Service: BsHelpCS - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
O23 - Service: BsMobileCS - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

–
End of file - 8113 bytes









DDS (Ver_10-10-21.02) - NTFSx86
Run by [removed] at 20:26:27.28 on Sun 10/31/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2012.1287 [GMT 6:00]

AV: ESET NOD32 Antivirus 4.2 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\GIGABYTE\ET6\GUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\TriT\Desktop\HiJackThis.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\TriT\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll
mWinlogon: Taskman=i:\minus\ona.exe
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
uRun: [SpeedBitVideoAccelerator] c:\program files\speedbit video accelerator\VideoAccelerator.exe
mRun: [EasyTuneVI] c:\program files\gigabyte\et6\ETcall.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [BtTray] "c:\program files\ivt corporation\bluesoleil\BtTray.exe"
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send by Bluetooth - c:\program files\ivt corporation\bluesoleil\transsend\ie\tsinfo.htm
IE: Send via &Message… - c:\program files\ivt corporation\bluesoleil\transsend\ie\tssms.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\progra~1\speedb~1\sblsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {F9263AAE-71F7-4531-9513-21833D073542} = 114.31.0.66 210.4.77.180
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\trit\applic~1\mozilla\firefox\profiles\rpsdtyyz.default\
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\trit\application data\idm\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\documents and settings\trit\application data\mozilla\firefox\profiles\rpsdtyyz.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);

============= SERVICES / DRIVERS ===============

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2009-1-7 20744]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-7-29 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-8-3 95896]
R2 BsMobileCS;BsMobileCS;c:\program files\ivt corporation\bluesoleil\BsMobileCS.exe [2009-2-27 143467]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2010-8-12 810144]
R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2010-7-30 68136]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-7-31 704432]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-7-31 704432]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-9-27 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-5-31 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-9-22 47640]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm –> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
R3 AODDriver;AODDriver;c:\program files\gigabyte\et6\i386\AODDriver.sys [2009-2-23 7168]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2008-12-7 30088]
R3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2010-7-31 24944]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2008-7-2 26248]
S3 ADASPROT;SYSTWEAKASO;\??\c:\program files\advanced system optimizer 3\adasprot32.sys –> c:\program files\advanced system optimizer 3\adasprot32.sys [?]
S3 etdrv;etdrv;c:\windows\etdrv.sys [2010-7-31 17488]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

=============== Created Last 30 ================

2012-09-12 15:06:22 ——– d—–w- c:\docume~1\alluse~1\applic~1\Speedbit
2012-09-12 15:06:21 172032 —-a-w- c:\windows\system32\AniGIF.ocx
2012-09-12 15:06:21 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2010-10-12 03:14:20 93096 —-a-w- c:\windows\system32\IncContxMenu.dll
2010-10-12 03:14:19 2315688 —-a-w- c:\windows\system32\Incinerator.dll
2010-10-12 03:13:33 12288 —-a-w- c:\windows\system32\smrgdf.exe
2010-10-12 03:13:32 30208 —-a-w- c:\windows\system32\iolobtdfg.exe
2010-10-11 15:50:18 ——– d—–w- c:\docume~1\alluse~1\applic~1\Nokia
2010-10-11 15:49:02 18816 —-a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-10-11 15:48:56 ——– d—–w- c:\program files\PC Connectivity Solution
2010-10-11 15:48:42 92672 —-a-w- c:\windows\system32\nmwcdcls.dll
2010-10-10 20:10:16 ——– d—–w- c:\program files\ESET
2010-10-10 19:13:51 ——– d—–w- c:\program files\eMule
2010-10-07 19:33:42 ——– d—–w- c:\program files\GNU
2010-10-03 11:07:45 ——– d—–w- c:\windows\system32\NtmsData
2010-10-03 06:17:55 ——– d—–w- c:\docume~1\alluse~1\applic~1\SRSLabs
2010-10-02 17:13:50 ——– d—–w- c:\program files\SRSLabs
2010-10-02 17:13:50 ——– d—–w- c:\program files\common files\SRS

==================== Find3M ====================

2010-10-31 13:58:01 17488 —-a-w- c:\windows\gdrv.sys
2010-10-31 11:37:46 17488 —-a-w- c:\windows\etdrv.sys
2010-09-27 08:50:44 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-09-27 08:49:26 53632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2010-09-27 08:49:18 87424 —-a-w- c:\windows\system32\LMIinit.dll
2010-09-27 08:49:18 29568 —-a-w- c:\windows\system32\LMIport.dll
2010-08-27 12:07:26 592 —-a-w- c:\windows\chgkey.vbs
2010-08-15 09:20:45 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-08-15 09:20:45 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-02 20:44:00 2564 —-a-w- c:\windows\system32\ASOROSet.bin

============= FINISH: 20:26:41.32 ===============

Edit: Moving to the Malware forum - Z
Hi dkshifat,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'm not seeing any obvious malware that might be the cause of your problem.

Let's try this…

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thank you so much for helping me Tomk. I have been facing this problem for quit a few months and tried reinstalling my Windows but the problem keep happening. But I don't see other problem other then the shut down of my PC…Now hopefully your help will work out. And i will let you know if face any problem…And Thanks again…Shifat Shahriar
dkshifat, I don't know if we will find the cause of your problem here in the malware forum… but once I have your log to review… maybe we will know more.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI