This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

gamevance/pop-up advertising

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok b4 you all start saying oh use this and this scanner or go to add/remove programs, first let me explain. i ran norton, sypbot, malwarebytes, and superantispyware and where some of em took away parts of it i still get the green highlighted pop-ups and theres nothing in the add/remove programs under control panel for me to remove it. also, tried to tool on the site it did nothing nor did contacting them. i also tried doing the manual removal but cant seem to find any of the hkeys or files associated with it so am at a loss of how to get rid of it.

thanks in advance-tell me what logs to do

OTL logfile created on: 12/11/2010 11:10:08 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 372.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.01 Gb Total Space | 156.28 Gb Free Space | 86.34% Space Free | Partition Type: NTFS
Drive D: | 5.28 Gb Total Space | 2.12 Gb Free Space | 40.05% Space Free | Partition Type: FAT32
Drive E: | 339.35 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: YOUR-836B4C207F | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\zHotkey.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\NetRatingsNetSight\NetSight\meter1\nphooks.dll (The Nielsen Company)
MOD - C:\Program Files\NetRatingsNetSight\NetSight\meter1\communication.dll ()
MOD - C:\Program Files\NetRatingsNetSight\NetSight\meter1\nscore.dll (The Nielsen Company)
MOD - C:\Program Files\NetRatingsNetSight\NetSight\nsmmc.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMFW.SYS File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101211.006\navex15.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101211.006\naveng.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20101210.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1201000.025\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (NielGfx) – C:\WINDOWS\system32\drivers\nielgfx.sys (The Nielsen Company)
DRV - (nielprt) – C:\WINDOWS\system32\DRIVERS\nielprt.sys (The Nielsen Company)
DRV - (nnrnstdi) – C:\WINDOWS\System32\drivers\nnrnstdi.sys (The Nielsen Company)
DRV - (km_filter) – C:\WINDOWS\system32\drivers\km_filter.sys (The Nielsen Company)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (iaStor) – C:\WINDOWS\SYSTEM32\DRIVERS\IASTOR.SYS (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = search.net-studio.org
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.msn.com
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files\PageRage\tbPage.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.msn.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:0.9.11
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/09 12:59:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/10/09 13:00:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2010/10/09 21:22:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\Firefox [2010/11/20 23:51:11 | 000,000,000 | —D | M]

[2009/08/24 17:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/08/04 12:03:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2d1vdo8q.default\extensions
[2010/04/26 21:27:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2d1vdo8q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/17 21:25:46 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2d1vdo8q.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/04/26 21:27:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2d1vdo8q.default\extensions\[removed]
[2010/02/27 18:47:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2d1vdo8q.default\extensions\[removed]

O1 HOSTS File: ([2010/12/07 22:45:24 | 000,426,615 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14694 more lines…
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PageRage Toolbar) - {9565115D-C7D6-46D3-BD63-B67B481A4368} - C:\Program Files\PageRage\tbPage.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Bing Bar] C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\emachines.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\emachines.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/17 03:41:16 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/02/11 06:02:56 | 000,000,047 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2005/03/01 12:30:22 | 000,253,952 | R— | M] (BASE77) - E:\Autorun.exe – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.clmp3enc - C:\Program Files\CyberLink\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2010/12/11 17:59:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2010/12/11 17:59:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/12/11 17:51:39 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/12/07 22:24:50 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/12/07 22:24:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/12/07 21:42:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/12/06 15:54:31 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/06 15:54:31 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/06 15:54:31 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/11/27 03:20:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/11/23 22:05:52 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2010/11/23 22:05:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\IObit
[2010/11/23 21:46:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/11/23 20:36:47 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2010/11/22 22:05:47 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/11/22 21:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PageRage
[2010/11/21 16:39:22 | 000,000,000 | —D | C] – C:\Program Files\Yontoo Layers Client
[2010/11/21 16:39:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2010/11/21 03:05:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\webkit
[2010/11/21 03:05:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\com.w3i.musicoasis
[2010/11/21 02:52:49 | 000,015,360 | —- | C] (The Nielsen Company) – C:\WINDOWS\System32\drivers\nnrnstdi.sys
[2010/11/21 02:52:48 | 000,010,368 | —- | C] (The Nielsen Company) – C:\WINDOWS\System32\drivers\km_filter.sys
[2010/11/21 02:52:20 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsgXP_2k3.dll
[2010/11/21 02:51:57 | 001,112,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WdfCoInstaller01007.dll
[2010/11/21 02:51:55 | 000,024,192 | —- | C] (The Nielsen Company) – C:\WINDOWS\System32\drivers\nielprt.sys
[2010/11/21 02:51:55 | 000,009,088 | —- | C] (The Nielsen Company) – C:\WINDOWS\System32\drivers\nielgfx.sys
[2010/11/21 02:47:15 | 000,000,000 | —D | C] – C:\Program Files\NetRatingsNetSight
[2010/11/21 00:42:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Yahoo
[2010/11/20 23:57:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2010/11/20 23:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2010/11/20 23:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Yahoo!
[2010/11/20 23:57:09 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2010/11/20 23:51:10 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/11/20 22:08:34 | 000,000,000 | —D | C] – C:\Downloads
[2010/11/20 22:04:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\BITS
[2010/11/20 22:04:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\FlashGet
[2010/11/20 22:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\FlashGetBHO
[2010/11/20 22:02:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\FlashgetSetup
[2010/11/20 20:41:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\WhiteSmoke
[2010/11/20 20:41:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\whitesmoketoolbar
[2010/11/20 20:32:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\The Weather Channel
[2010/11/20 20:25:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
[2010/11/20 20:25:01 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/11/20 20:24:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\PageRage
[2010/11/20 20:24:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\ConduitEngine
[2010/11/20 20:24:34 | 000,000,000 | —D | C] – C:\Program Files\ConduitEngine
[2010/11/20 20:24:04 | 000,000,000 | —D | C] – C:\Program Files\PageRage
[2010/11/13 21:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/11/13 17:00:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\NPE
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/11 22:49:32 | 000,000,117 | —- | M] () – C:\Documents and Settings\Owner\jagex_runescape_preferences2.dat
[2010/12/11 22:48:32 | 000,000,046 | —- | M] () – C:\Documents and Settings\Owner\jagex_runescape_preferences.dat
[2010/12/11 22:46:01 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3390818253-114616658-2560447463-1006UA.job
[2010/12/11 22:46:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3390818253-114616658-2560447463-1006Core.job
[2010/12/11 21:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/12/11 21:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/12/11 19:30:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/11 19:30:33 | 937,046,016 | -HS- | M] () – C:\hiberfil.sys
[2010/12/11 17:51:47 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/12/11 15:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/12/11 15:41:09 | 000,426,615 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2010/12/11 15:41:09 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.smr
[2010/12/11 15:34:19 | 000,000,199 | RHS- | M] () – C:\boot.ini
[2010/12/11 12:00:00 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\PerfectOptimizer_home.job
[2010/12/11 09:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/12/11 09:37:33 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/07 22:45:24 | 000,426,615 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/07 22:25:05 | 000,000,951 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/07 22:25:05 | 000,000,933 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/12/07 21:58:29 | 000,616,124 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/12/07 21:41:41 | 000,507,360 | —- | M] () – C:\Documents and Settings\Owner\Desktop\sdsetup_aff.exe
[2010/12/07 18:58:45 | 000,000,682 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SwiftKit.lnk
[2010/12/06 21:36:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/05 12:15:29 | 000,014,450 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Basic facts.docx
[2010/12/05 11:38:41 | 000,002,515 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2007.lnk
[2010/12/04 10:48:25 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2010/12/04 10:48:25 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/30 16:57:34 | 000,000,488 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/11/29 03:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/11/27 05:01:41 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/23 22:07:03 | 000,000,892 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/11/23 22:07:03 | 000,000,153 | —- | M] () – C:\Documents and Settings\Owner\Desktop\IObit Freeware.url
[2010/11/23 22:07:02 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2010/11/23 21:39:16 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/22 22:06:54 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/21 18:22:04 | 002,359,350 | —- | M] () – C:\untitled.bmp
[2010/11/21 02:52:37 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_nielprt_01007.Wdf
[2010/11/21 02:52:35 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/11/20 23:56:33 | 000,000,248 | —- | M] () – C:\WINDOWS\System32\secustat.dat
[2010/11/20 22:08:23 | 000,000,025 | —- | M] () – C:\WINDOWS\libem.INI
[2010/11/20 22:04:00 | 000,000,305 | —- | M] () – C:\WINDOWS\System32\secushr.dat
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/11 17:51:47 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/12/07 22:25:05 | 000,000,951 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/07 22:25:05 | 000,000,933 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/12/07 21:58:14 | 000,616,124 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/12/07 21:42:03 | 000,507,360 | —- | C] () – C:\Documents and Settings\Owner\Desktop\sdsetup_aff.exe
[2010/12/07 18:58:45 | 000,000,682 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SwiftKit.lnk
[2010/12/05 12:15:29 | 000,014,450 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Basic facts.docx
[2010/11/30 16:55:47 | 000,000,488 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/11/23 22:07:03 | 000,000,892 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/11/23 22:07:03 | 000,000,153 | —- | C] () – C:\Documents and Settings\Owner\Desktop\IObit Freeware.url
[2010/11/23 22:07:02 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2010/11/23 21:44:29 | 000,000,362 | —- | C] () – C:\WINDOWS\tasks\PerfectOptimizer_home.job
[2010/11/23 21:39:15 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/22 22:06:54 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/21 18:22:01 | 002,359,350 | —- | C] () – C:\untitled.bmp
[2010/11/21 02:52:37 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_nielprt_01007.Wdf
[2010/11/21 02:52:35 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/11/20 22:08:23 | 000,000,025 | —- | C] () – C:\WINDOWS\libem.INI
[2010/11/20 22:04:02 | 000,000,248 | —- | C] () – C:\WINDOWS\System32\secustat.dat
[2010/11/20 22:04:00 | 000,000,305 | —- | C] () – C:\WINDOWS\System32\secushr.dat
[2010/10/05 16:23:27 | 000,001,940 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/05 16:18:23 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/03/12 21:32:24 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2010/01/01 18:12:15 | 000,007,680 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/24 16:49:07 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/08/24 16:21:30 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2009/08/24 16:21:30 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2009/08/24 16:21:30 | 000,011,776 | —- | C] () – C:\WINDOWS\HIDMNT.dll
[2009/08/24 16:20:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2009/08/24 16:14:33 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/06/21 03:48:15 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/17 03:24:58 | 000,001,442 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/06/17 03:24:57 | 000,000,495 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2006/06/16 20:31:45 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/05 22:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll

========== LOP Check ==========

[2009/08/24 17:05:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/26 18:02:35 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJFax
[2010/07/03 20:45:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2010/03/18 17:21:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/11/27 03:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2009/08/24 16:21:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/03/18 17:17:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/11/23 21:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/09/07 19:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/03/18 11:50:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/11/30 17:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/07 18:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SwiftKit
[2010/11/21 16:39:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2010/12/07 23:08:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/01/03 18:52:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Toolbar4
[2009/08/24 16:23:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/11/08 22:03:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/10/17 00:11:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/02 17:41:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/23 19:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/11/20 23:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BITS
[2010/11/21 03:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.w3i.musicoasis
[2009/10/17 10:08:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CrystalApp
[2009/10/17 08:57:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CrystalSpace
[2010/03/18 17:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DriverCure
[2010/11/20 22:04:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FlashGet
[2010/11/20 22:04:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FlashGetBHO
[2010/11/20 22:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FlashgetSetup
[2010/03/17 21:32:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FOG Downloader
[2010/11/23 22:05:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2009/10/17 09:32:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlaneShift
[2009/08/24 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2010/03/16 22:36:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony Online Entertainment
[2010/11/20 20:42:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WhiteSmoke
[2010/11/20 23:46:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\whitesmoketoolbar
[2010/12/11 21:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2010/11/29 03:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2010/12/11 09:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2010/12/11 15:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2010/12/11 21:57:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/12/11 12:00:00 | 000,000,362 | —- | M] () – C:\WINDOWS\Tasks\PerfectOptimizer_home.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/08/24 16:12:46 | 000,000,002 | —- | M] () – C:\AUDIT_INSTALL_IN_PROGRESS
[2006/06/17 03:41:16 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/12/11 15:34:19 | 000,000,199 | RHS- | M] () – C:\boot.ini
[2010/11/23 22:00:43 | 000,003,785 | —- | M] () – C:\CD3rdPartyWrapper.log
[2006/06/17 03:41:16 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/12/11 19:30:33 | 937,046,016 | -HS- | M] () – C:\hiberfil.sys
[2006/06/17 03:41:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/08/24 16:26:14 | 000,001,209 | -H– | M] () – C:\IPH.PH
[2010/12/11 09:32:57 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2006/06/17 03:41:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/21 02:47:17 | 000,000,439 | —- | M] () – C:\nsinst.log
[2004/08/10 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/08/24 15:48:58 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/11 19:30:32 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys
[2009/08/24 16:13:19 | 000,000,090 | —- | M] () – C:\powerdvd.log
[2009/08/24 16:31:31 | 000,000,000 | —- | M] () – C:\REQUEST_OEMRESET_ENDUSER
[2009/08/24 16:20:40 | 000,000,499 | —- | M] () – C:\RHDSetup.log
[2010/11/21 18:22:04 | 002,359,350 | —- | M] () – C:\untitled.bmp
[2009/08/24 16:05:09 | 000,000,002 | RHS- | M] () – C:\USER

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 13:00:00 | 000,000,067 | —- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/03/16 23:00:00 | 000,022,528 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7W.DLL
[2009/04/25 04:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9P.DLL
[2006/03/16 23:00:00 | 000,065,024 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7W.DLL
[2009/04/25 04:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9P.DLL
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2004/03/22 16:17:08 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/06/16 20:30:11 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/06/16 20:30:11 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/06/16 20:30:11 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/08/24 15:55:50 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/24 16:02:12 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/06/17 03:46:25 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/04/22 11:48:05 | 010,261,832 | —- | M] () – C:\Documents and Settings\Owner\Desktop\mx330swin101ej.exe
[2010/12/07 21:41:41 | 000,507,360 | —- | M] () – C:\Documents and Settings\Owner\Desktop\sdsetup_aff.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 00:21:30

========== Alternate Data Streams ==========

@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEB15613
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >

—————————————————————————
OTL Extras logfile created on: 12/11/2010 11:10:08 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 372.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.01 Gb Total Space | 156.28 Gb Free Space | 86.34% Space Free | Partition Type: NTFS
Drive D: | 5.28 Gb Total Space | 2.12 Gb Free Space | 40.05% Space Free | Partition Type: FAT32
Drive E: | 339.35 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: YOUR-836B4C207F | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"58419:TCP" = 58419:TCP:*:Enabled:Pando Media Booster
"58419:UDP" = 58419:UDP:*:Enabled:Pando Media Booster
"2898:UDP" = 2898:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2899:UDP" = 2899:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2912:UDP" = 2912:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2913:UDP" = 2913:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2921:UDP" = 2921:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2923:UDP" = 2923:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2920:UDP" = 2920:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2922:UDP" = 2922:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2927:UDP" = 2927:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"2926:UDP" = 2926:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (America Online, Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Documents and Settings\Owner\My Documents\Downloads\flashget_493.exe" = C:\Documents and Settings\Owner\My Documents\Downloads\flashget_493.exe:*:Enabled:fg_ol_setup – (Flashget)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02EE107B-8D95-4949-8935-4DEBE8F08BE3}" = Bing Bar Platform
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1700" = Canon iP1700
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX330_series" = Canon MX330 series MP Drivers
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Solution
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}" = Multimedia Keyboard Driver
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"ATI Display Driver" = ATI Display Driver
"Canon iP1700 User Registration" = Canon iP1700 User Registration
"CanonMyPrinter" = Canon My Printer
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = Soft Data Fax Modem with SmartCP
"conduitEngine" = Conduit Engine
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"Google Desktop" = Google Desktop
"Higher Score on the ACT_is1" = Higher Score on the ACT
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HyperCam 2" = HyperCam 2
"ie8" = Windows Internet Explorer 8
"InstallShield_{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2006b" = Microsoft Money 2006
"NAV" = Norton AntiVirus
"NetSight" = Nielsen
"PageRage Toolbar" = PageRage Toolbar
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"RealPlayer 6.0" = RealPlayer Basic
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"whitesmoketoolbar" = WhiteSmoke Toolbar
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"SwiftKit" = SwiftKit

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/9/2010 6:32:13 PM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/9/2010 6:32:13 PM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 66376031

Error - 12/9/2010 6:32:13 PM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 66376031

Error - 12/10/2010 9:38:31 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2010 9:38:31 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30291734

Error - 12/10/2010 9:38:31 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30291734

Error - 12/10/2010 9:38:47 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2010 9:38:47 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30307391

Error - 12/10/2010 9:38:47 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30307391

Error - 12/10/2010 5:55:36 PM | Computer Name = YOUR-836B4C207F | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x00004d8a.

[ Application Events ]
Error - 12/9/2010 6:32:13 PM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/9/2010 6:32:13 PM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 66376031

Error - 12/9/2010 6:32:13 PM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 66376031

Error - 12/10/2010 9:38:31 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2010 9:38:31 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30291734

Error - 12/10/2010 9:38:31 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30291734

Error - 12/10/2010 9:38:47 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2010 9:38:47 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30307391

Error - 12/10/2010 9:38:47 AM | Computer Name = YOUR-836B4C207F | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30307391

Error - 12/10/2010 5:55:36 PM | Computer Name = YOUR-836B4C207F | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x00004d8a.

[ System Events ]
Error - 11/26/2010 1:01:43 AM | Computer Name = YOUR-836B4C207F | Source = DCOM | ID = 10010
Description = The server {DC0C2640-1415-4644-875C-6F4D769839BA} did not register
with DCOM within the required timeout.

Error - 11/26/2010 1:02:15 AM | Computer Name = YOUR-836B4C207F | Source = DCOM | ID = 10010
Description = The server {DC0C2640-1415-4644-875C-6F4D769839BA} did not register
with DCOM within the required timeout.

Error - 11/26/2010 1:02:48 AM | Computer Name = YOUR-836B4C207F | Source = DCOM | ID = 10010
Description = The server {DC0C2640-1415-4644-875C-6F4D769839BA} did not register
with DCOM within the required timeout.

Error - 11/26/2010 7:49:01 PM | Computer Name = YOUR-836B4C207F | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.100 on
the Network Card with network address 0019D10BE9A6.

Error - 11/29/2010 10:59:58 PM | Computer Name = YOUR-836B4C207F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 ACPIEC adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint
asc
asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
iaStor
ini910u
IntelIde
mraid35x
Pcmcia
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde

Error - 11/30/2010 6:56:23 PM | Computer Name = YOUR-836B4C207F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 ACPIEC adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint
asc
asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
iaStor
ini910u
IntelIde
mraid35x
Pcmcia
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde

Error - 11/30/2010 6:58:09 PM | Computer Name = YOUR-836B4C207F | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the szserver service.

Error - 12/8/2010 12:41:12 AM | Computer Name = YOUR-836B4C207F | Source = Service Control Manager | ID = 7034
Description = The PC Tools Security Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 12/9/2010 9:39:56 PM | Computer Name = YOUR-836B4C207F | Source = Service Control Manager | ID = 7034
Description = The SSDP Discovery Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 12/9/2010 9:40:39 PM | Computer Name = YOUR-836B4C207F | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.


< End of report >
Hi wills,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
DRV - (NielGfx) – C:\WINDOWS\system32\drivers\nielgfx.sys (The Nielsen Company)
DRV - (nielprt) – C:\WINDOWS\system32\DRIVERS\nielprt.sys (The Nielsen Company)
DRV - (nnrnstdi) – C:\WINDOWS\System32\drivers\nnrnstdi.sys (The Nielsen Company)
DRV - (km_filter) – C:\WINDOWS\system32\drivers\km_filter.sys (The Nielsen Company)
O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
O32 - AutoRun File - [2004/02/11 06:02:56 | 000,000,047 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2005/03/01 12:30:22 | 000,253,952 | R— | M] (BASE77) - E:\Autorun.exe – [ CDFS ]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEB15613
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

:files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.

Also please post your Malwarebytes' log.
All processes killed
========== PROCESSES ==========
========== OTL ==========
No active process named AWC.exe was found!
No active process named NielsenOnline.exe was found!
No active process named TeaTimer.exe was found!
Service NielGfx stopped successfully!
Service NielGfx deleted successfully!
C:\WINDOWS\system32\drivers\nielgfx.sys moved successfully.
Error: Unable to stop service nielprt!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nielprt deleted successfully.
C:\WINDOWS\system32\drivers\nielprt.sys moved successfully.
Error: Unable to stop service nnrnstdi!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nnrnstdi deleted successfully.
C:\WINDOWS\system32\drivers\nnrnstdi.sys moved successfully.
Error: Unable to stop service km_filter!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\km_filter deleted successfully.
C:\WINDOWS\system32\drivers\km_filter.sys moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NielsenOnline deleted successfully.
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 3 deleted successfully.
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\LinkResolveIgnoreLinkInfo deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoResolveSearch deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\LinkResolveIgnoreLinkInfo deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoFind deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLogOff deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSetFolders deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\DisallowRun deleted successfully.
File move failed. E:\AUTORUN.INF scheduled to be moved on reboot.
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{472734EA-242A-422b-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422b-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Classes\exefile\ not found.
HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
ADS C:\Documents and Settings\All Users\Application Data\TEMP:BEB15613 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Owner\My Documents\Downloads\cmd.bat deleted successfully.
C:\Documents and Settings\Owner\My Documents\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 57704 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 671642595 bytes

User: Owner
->Temp folder emptied: 1422668 bytes
->Temporary Internet Files folder emptied: 185174870 bytes
->Java cache emptied: 78148 bytes
->FireFox cache emptied: 28640391 bytes
->Google Chrome cache emptied: 63312526 bytes
->Flash cache emptied: 1363 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 346641 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 98304 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 91233296 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 994.00 mb


OTL by OldTimer - Version 3.2.17.3 log created on 12132010_192016

Files\Folders moved on Reboot…
File move failed. E:\AUTORUN.INF scheduled to be moved on reboot.
File move failed. E:\Autorun.exe scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_37c.dat moved successfully.

Registry entries deleted on Reboot…
——————————————
will post mbam log in a bit when i do scan, also still get gamevance pop-ups :( so maybe need to get a new log? since that one was a couple of days old.
ok issues appeared after doing that. firstly, will have to reinstall itunes as it no longer opens, secondly i cant hear sound out of my speakers anymore, thirdly the internet runs slower and opening stuff takes longer, and processing stuff takes longer so maybe that wasnt it? edit: when i say processing i mean like removing a program from control panel for instance, or opening stuff, and basically it likes to freeze up or takes 10 mins to open
running mbam scan right now, will post new and old logs when its done- thanks again p.s. if we could solve the issues im facing at the moment (slow computer and speaker issues) asap id greatly appreciate it since i have to do some online research that involves sound for a report.
mbam log 12-11 ————————- Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/11/2010 11:02:55 AM mbam-log-2010-12-11 (11-02-55).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 208306 Time elapsed: 1 hour(s), 21 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Owner\My Documents\Downloads\PerfectOptimizer.exe (PUP.PerfectOptimizer) -> Quarantined and deleted successfully. —————————— new mbam log (12-13) ————————— Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5309 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/13/2010 8:44:39 PM mbam-log-2010-12-13 (20-44-39).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 208610 Time elapsed: 50 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 15 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\Owner\application data\whitesmoketoolbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\weather (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoke (PUP.WhiteSmoke) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\secushr.dat (Malware.Trace) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\dtx.ini (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\exeArgs.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\guid.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\preferences.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\stat.log (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\stats.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\uninstallie.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\uninstallstatie.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\weatherbutton_prefs.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\weather\7efd64867d2dc80f0d2a48fb5d0219cc (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\weather\b73cbdc3c4533ce8f0697af501a4e9a3 (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\weather\forecasts_cache.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoketoolbar\weather\observations_cache.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\whitesmoke\stat.log (PUP.WhiteSmoke) -> Quarantined and deleted successfully.
ok reinstalled the realtek audio driver… nothing changed and it says its still damaged so is there something in your deal for otl that might have damaged it?
wills,

We've done nothing that should have effected ITunes or your sound.

Let's dig a bit deeper.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ok getting ready to do combofix and itunes comes up but it says its detected a problem with my audio configuration (in the driver details all sound devices have the yellow triangle with exclamation and it says it successfully loaded the driver device for this hardware but cannot find the hardware devide(code41)… that is for all sound devices :( )
When you get back to your computer… please try to get the results for me.

Please:
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here
ok looked for it where u suggested i didnt find combofix.txt but found combofix so i tried right clicking on it and it didnt have an open with just open option which led back to the beginning stage after clicking on my computer
there is not one. i checked every folder under it and tried using search for combofix and combofix.txt and didnt find it. edit: also, is there anyway we can fix my sound? it didnt stop working or have problems until after i ran otl with the code for what to remove. so should i just try to reformat if i have the stuff to fix everything?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI