This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Firefox Running Slow

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL:

OTL logfile created on: 12/14/2010 11:10:08 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 475.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.01 Gb Total Space | 36.44 Gb Free Space | 24.45% Space Free | Partition Type: NTFS

Computer Name: NAVI | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Wireless Select Switch\WLSS.exe (Dell)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe File not found
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (GGSAFERDriver) – C:\Program Files\Garena\plugins\UI\safedrv.sys File not found
DRV - (GarenaPEngine) – C:\DOCUME~1\Owner\LOCALS~1\Temp\NMK11.tmp File not found
DRV - (EMSC) – C:\WINDOWS\System32\DRIVERS\EMSC.SYS File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Mkd2kfNt) – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (Mkd2Nadr) – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (OA012Vid) – C:\WINDOWS\system32\drivers\OA012Vid.sys (Creative Technology Ltd.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (OA012Ufd) – C:\WINDOWS\system32\drivers\OA012Ufd.sys (Creative Technology Ltd.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (rtl8029) Realtek RTL8029(AS) – C:\WINDOWS\system32\drivers\RTL8029.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/aol/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.2
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.6.5
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: multiPostReport@anonymous:1.0.6
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:2.0.6
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2010/12/01 13:45:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/14 10:49:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/14 10:49:47 | 000,000,000 | —D | M]

[2009/10/28 23:40:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/12/13 21:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions
[2010/10/30 16:30:52 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/11 12:13:18 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2010/07/05 13:02:20 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}(2)
[2010/07/05 13:02:16 | 000,000,000 | —D | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}(2)
[2010/12/11 10:52:37 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/22 22:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/08/19 18:49:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/11/01 16:47:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/11/02 23:20:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\multiPostReport@anonymous
[2010/09/11 19:27:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/05/29 19:44:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/04/01 08:36:24 | 000,002,267 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\searchplugins\aim-search.xml
[2010/12/14 10:49:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/05 12:55:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/29 13:43:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/07/05 12:55:29 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions(2)
[2010/07/05 12:25:13 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions(2)\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
[2009/07/17 00:40:12 | 000,704,512 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010/10/29 13:43:41 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2008/04/13 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [HitmanPro35] C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe (SurfRight B.V.)
O4 - HKLM..\Run: [inetsrv] C:\WINDOWS\system32\inetsrv.exe ()
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe (Ulead Systems, Inc.)
O4 - HKLM..\Run: [WLSS] C:\Program Files\Wireless Select Switch\WLSS.exe (Dell)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:45:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{59e1a8d1-3549-11df-b519-0024e8c842b4}\Shell\AutoRun\command - "" = F:\MI.exe – File not found
O33 - MountPoints2\{990ab482-a297-11df-b601-0024e8c842b4}\Shell\AutoRun\command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O33 - MountPoints2\{990ab482-a297-11df-b601-0024e8c842b4}\Shell\Open\Command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O33 - MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\Shell\AutoRun\command - "" = D:\SysAnti.exe – File not found
O33 - MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\Shell\Explore\Command - "" = D:\SysAnti.exe – File not found
O33 - MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\Shell\Open\Command - "" = D:\SysAnti.exe – File not found
O33 - MountPoints2\{da16e39a-0c53-11df-b496-00265e1b4ef5}\Shell\AutoRun\command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O33 - MountPoints2\{da16e39a-0c53-11df-b496-00265e1b4ef5}\Shell\Open\Command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.MPEGacm - C:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - C:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/12/06 13:17:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Asians
[2010/12/01 17:54:34 | 000,012,872 | —- | C] (SurfRight B.V.) – C:\WINDOWS\System32\bootdelete.exe
[2010/12/01 17:45:15 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2010/12/01 17:42:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Hitman Pro
[2010/12/01 13:45:09 | 001,914,832 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2010/12/01 13:45:09 | 000,743,376 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2010/12/01 13:45:09 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2010/12/01 13:28:23 | 000,656,320 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2010/12/01 13:28:23 | 000,338,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2010/12/01 13:28:22 | 000,249,616 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/12/01 13:28:17 | 000,237,632 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/12/01 13:28:17 | 000,159,936 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/12/01 13:28:07 | 000,123,712 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplfw.sys
[2010/12/01 13:28:07 | 000,087,400 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.sys
[2010/12/01 13:28:07 | 000,031,960 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctNdis-DNS.sys
[2010/12/01 13:28:03 | 000,070,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/12/01 13:27:37 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2010/12/01 13:27:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/12/01 13:27:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\PC Tools
[2010/12/01 11:55:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Tools
[2010/11/29 22:33:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Stardock
[2010/11/29 22:33:16 | 000,042,672 | —- | C] (Stardock.Net, Inc) – C:\WINDOWS\System32\wbsys.dll
[2010/11/29 22:33:16 | 000,000,000 | —D | C] – C:\Program Files\Stardock
[2010/11/29 20:35:35 | 000,057,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\redbook.sys
[2010/11/29 20:34:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Alcohol 52%
[2010/11/29 20:26:53 | 000,000,000 | —D | C] – C:\Program Files\Alcohol Soft
[2010/11/29 20:04:04 | 000,000,000 | —D | C] – C:\Program Files\LucasArts
[2010/11/27 16:31:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PopCap Games
[2010/11/27 11:23:03 | 000,000,000 | —D | C] – C:\Program Files\Guild Wars
[2010/11/27 10:52:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Plants vs. Zombies Game Of The Year Edition Final
[2010/11/25 10:54:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Mp3 To Ringtone Gold
[2010/11/25 10:42:23 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2010/11/25 10:41:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Advanced WindowsCare v.2.7 by Saddiq123 TEAM EXILES
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/14 10:49:50 | 000,001,626 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/14 10:37:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1292428093-515967899-1003UA.job
[2010/12/14 08:59:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/13 20:00:06 | 000,010,055 | —- | M] () – C:\WINDOWS\msvrc20.dll
[2010/12/13 20:00:06 | 000,000,410 | —- | M] () – C:\WINDOWS\tasks\AwcProUpdate.job
[2010/12/13 16:30:01 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\Advanced WindowsCare V2 Pro.job
[2010/12/13 10:04:06 | 000,016,968 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/12/12 21:22:35 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/11 11:49:10 | 000,072,192 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/11 11:37:02 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1292428093-515967899-1003Core.job
[2010/12/09 21:16:39 | 000,000,025 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/12/03 12:57:03 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/01 20:14:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/01 17:54:34 | 000,012,872 | —- | M] (SurfRight B.V.) – C:\WINDOWS\System32\bootdelete.exe
[2010/12/01 12:01:15 | 000,574,986 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/11/29 22:40:39 | 000,000,000 | —- | M] () – C:\WINDOWS\WB.ini
[2010/11/29 20:40:26 | 000,000,466 | —- | M] () – C:\Documents and Settings\Owner\My Documents\ax_files.xml
[2010/11/27 16:27:09 | 000,100,869 | —- | M] () – C:\Documents and Settings\Owner\My Documents\mali.JPG
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/01 17:45:17 | 000,016,968 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/12/01 13:45:10 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/12/01 13:45:09 | 000,002,052 | —- | C] () – C:\WINDOWS\UDB.zip
[2010/12/01 13:45:09 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2010/12/01 13:45:09 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2010/12/01 13:45:09 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2010/12/01 12:01:00 | 000,574,986 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/11/29 23:01:34 | 000,000,197 | —- | C] () – C:\Documents and Settings\Owner\activate.log
[2010/11/29 22:40:39 | 000,000,000 | —- | C] () – C:\WINDOWS\WB.ini
[2010/11/29 20:37:14 | 000,000,466 | —- | C] () – C:\Documents and Settings\Owner\My Documents\ax_files.xml
[2010/11/27 16:33:49 | 000,000,025 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/11/27 16:27:08 | 000,100,869 | —- | C] () – C:\Documents and Settings\Owner\My Documents\mali.JPG
[2010/11/26 17:01:29 | 000,000,058 | —- | C] () – C:\Documents and Settings\Owner\gifts.txt
[2010/11/25 10:43:52 | 000,000,410 | —- | C] () – C:\WINDOWS\tasks\AwcProUpdate.job
[2010/11/25 10:43:52 | 000,000,398 | —- | C] () – C:\WINDOWS\tasks\Advanced WindowsCare V2 Pro.job
[2010/11/25 10:42:24 | 000,010,055 | —- | C] () – C:\WINDOWS\msvrc20.dll
[2010/05/02 18:14:18 | 000,009,244 | —- | C] () – C:\WINDOWS\hpdj3600.ini
[2010/03/21 18:59:38 | 000,007,420 | —- | C] () – C:\WINDOWS\UA000106.DLL
[2010/03/21 18:58:05 | 000,209,040 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/03/21 18:58:05 | 000,204,944 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/03/21 18:58:05 | 000,196,752 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/03/21 18:58:05 | 000,196,752 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/03/21 18:58:05 | 000,192,656 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/03/21 18:58:05 | 000,024,720 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2009/10/28 23:17:30 | 000,072,192 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/28 00:32:45 | 000,577,536 | —- | C] () – C:\WINDOWS\System32\EMSC.DLL
[2009/10/28 00:31:14 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/10/28 00:28:14 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2009/10/28 00:28:13 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2009/10/27 15:24:21 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/25 17:58:25 | 000,062,304 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2007/05/09 19:35:54 | 000,057,126 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini

========== LOP Check ==========

[2009/10/29 01:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2010/04/29 12:22:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\CanonBJ
[2009/10/28 09:24:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Citrix
[2010/12/13 10:04:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Hitman Pro
[2010/03/21 18:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\InterVideo
[2010/11/27 16:31:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PopCap Games
[2010/12/14 10:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/03/21 19:00:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
[2010/04/02 22:39:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2010/06/20 15:12:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/22 14:36:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/29 01:05:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2010/05/10 21:21:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2010/11/29 23:19:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2010/01/19 20:41:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Facebook
[2010/05/06 12:02:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FreeFLVConverter
[2010/05/25 22:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrimaStudio
[2010/10/03 17:55:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LolClient
[2010/09/28 22:34:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ManyCam
[2009/11/23 22:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\RenPy
[2010/10/30 08:58:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TeamViewer
[2010/03/21 21:27:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ulead Systems
[2010/12/13 16:30:01 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job
[2010/12/13 20:00:06 | 000,000,410 | —- | M] () – C:\WINDOWS\Tasks\AwcProUpdate.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/25 17:45:49 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/10/28 09:52:57 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/04/25 17:45:49 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/08/06 22:44:32 | 000,004,244 | RH– | M] () – C:\dell.sdr
[2009/10/27 21:55:58 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2008/04/25 17:45:49 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/09/22 22:19:52 | 000,001,399 | -H– | M] () – C:\IPH.PH
[2008/04/25 17:45:49 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/04/13 15:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 15:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/14 08:59:26 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2010/12/06 10:53:11 | 000,038,586 | —- | M] () – C:\TDSSKiller.2.4.10.1_06.12.2010_10.52.39_log.txt
[2010/12/06 10:59:31 | 000,038,702 | —- | M] () – C:\TDSSKiller.2.4.10.1_06.12.2010_10.58.38_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/10/27 23:35:52 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/03/17 04:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2009/03/17 04:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 02:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2006/10/09 12:00:00 | 000,094,208 | —- | M] () – C:\WINDOWS\Dream Aquarium.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/10/27 15:22:42 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/27 15:22:42 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/27 15:22:41 | 000,909,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/27 23:36:37 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/27 23:44:19 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/27 23:44:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-07 09:31:56

========== Alternate Data Streams ==========

@Alternate Data Stream - 213 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:430C6D84

< End of report >



OTL Extras:

OTL Extras logfile created on: 12/14/2010 11:10:08 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 475.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.01 Gb Total Space | 36.44 Gb Free Space | 24.45% Space Free | Partition Type: NTFS

Computer Name: NAVI | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"23166:TCP" = 23166:TCP:*:Enabled:BitComet 23166 TCP
"23166:UDP" = 23166:UDP:*:Enabled:BitComet 23166 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"8380:TCP" = 8380:TCP:*:Enabled:League of Legends Launcher
"8380:UDP" = 8380:UDP:*:Enabled:League of Legends Launcher
"6897:TCP" = 6897:TCP:*:Enabled:League of Legends Launcher
"6897:UDP" = 6897:UDP:*:Enabled:League of Legends Launcher

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe – File not found
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – File not found
"C:\Program Files\Dell Video Chat\DellVideoChat.exe" = C:\Program Files\Dell Video Chat\DellVideoChat.exe:*:Enabled:Dell Video Chat – (Dell Inc. and SightSpeed Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – (Veoh Networks)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe" = C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application – (TeamViewer GmbH)
"C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby – File not found
"C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\WINDOWS\system32\winver.exe" = C:\WINDOWS\system32\winver.exe:*:Enabled:winver – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{065A7AFE-195D-4DFB-A4B2-A83842C0F79F}" = Wireless Select Switch
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{28999392-5871-4A39-863A-D2A6EA3260AF}" = League of Legends
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{302188C7-ADCF-4328-8E2E-FE9DCC2F40BD}" = Hauppauge TV Tuner Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = VideoStudio
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced WindowsCare V2 Pro_is1" = Advanced WindowsCare Pro 2.7.0
"AIM_7" = AIM 7
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"BitTorrent" = BitTorrent
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"Browser Defender_is1" = Browser Defender 3.0
"CamStudio" = CamStudio
"Creative OA012" = Integrated Webcam Driver (1.01.01.0116)
"Dream Aquarium_is1" = Dream Aquarium
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.2
"Garena" = Garena 2010
"GOM Player" = GOM Player
"Guild Wars" = Guild Wars
"HDMI" = Intel® Graphics Media Accelerator Driver
"HitmanPro35" = Hitman Pro 3.5
"InstallShield_{065A7AFE-195D-4DFB-A4B2-A83842C0F79F}" = Wireless Select Switch
"InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = Corel VideoStudio 12
"IntenseRO Full Client v3" = IntenseRO Full Client v3
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.16)" = Mozilla Firefox (3.5.16)
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Spyware Doctor" = Spyware Doctor 8.0
"SynTPDeinstKey" = Dell Touchpad
"TeamViewer 5" = TeamViewer 5
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VLC media player 1.1.4
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/9/2010 4:20:55 AM | Computer Name = NAVI | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 12/9/2010 4:20:57 AM | Computer Name = NAVI | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 12/9/2010 4:20:58 AM | Computer Name = NAVI | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 12/9/2010 4:21:08 AM | Computer Name = NAVI | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 12/9/2010 4:21:08 AM | Computer Name = NAVI | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 12/9/2010 4:25:39 AM | Computer Name = NAVI | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 12/9/2010 4:25:40 AM | Computer Name = NAVI | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 12/9/2010 4:25:40 AM | Computer Name = NAVI | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 12/9/2010 6:43:44 PM | Computer Name = NAVI | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 12/14/2010 2:30:05 PM | Computer Name = NAVI | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.3989, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

[ System Events ]
Error - 12/11/2010 2:48:19 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
EMSC

Error - 12/11/2010 3:16:42 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7034
Description = The PC Tools Security Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 12/11/2010 3:16:47 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7034
Description = The PC Tools Auxiliary Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 12/13/2010 1:23:34 AM | Computer Name = NAVI | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
EMSC

Error - 12/13/2010 2:02:46 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
EMSC

Error - 12/13/2010 8:26:41 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
EMSC

Error - 12/13/2010 9:53:33 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
EMSC

Error - 12/14/2010 12:59:39 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
EMSC

Error - 12/14/2010 12:59:52 PM | Computer Name = NAVI | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 12/14/2010 2:26:22 PM | Computer Name = NAVI | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).


< End of report >



Hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:35 AM, on 12/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Wireless Select Switch\WLSS.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [WLSS] C:\Program Files\Wireless Select Switch\WLSS.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [inetsrv] C:\WINDOWS\system32\inetsrv.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe
O4 - HKLM\..\Run: [HitmanPro35] "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" /scan:boot
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 7522 bytes



DDS:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:14:36.10 on Tue 12/14/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.440 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Wireless Select Switch\WLSS.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe
C:\Documents and Settings\Owner\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
mURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [WLSS] c:\program files\wireless select switch\WLSS.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [inetsrv] c:\windows\system32\inetsrv.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [UVS12 Preload] c:\program files\corel\corel videostudio 12\uvPL.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PCTools FGuard] c:\program files\pc tools security\bdt\FGuard.exe
mRun: [HitmanPro35] "c:\program files\hitman pro 3.5\HitmanPro35.exe" /scan:boot
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\r34fv2pl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;=
FF - component: c:\program files\pc tools security\bdt\firefox\platform\winnt_x86-msvc\components\libheuristic.dll
FF - plugin: c:\documents and settings\owner\application data\facebook\npfbplugin_1_0_0.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-12-1 237632]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2010-12-1 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2010-12-1 656320]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\pc tools security\bdt\BDTUpdateService.exe [2010-12-1 235472]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [2009-10-28 133472]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [2009-10-28 271328]
S0 cerc6;cerc6; [x]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\emsc.sys –> c:\windows\system32\drivers\EMSC.SYS [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-10-28 1684736]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\owner\locals~1\temp\nmk11.tmp –> c:\docume~1\owner\locals~1\temp\NMK11.tmp [?]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-10-27 14336]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena\plugins\ui\safedrv.sys –> c:\program files\garena\plugins\ui\safedrv.sys [?]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-24 133632]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-24 79360]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2010-12-1 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2010-12-1 1145304]

=============== Created Last 30 ================

2010-12-01 17:54 12,872 a——- c:\windows\system32\bootdelete.exe
2010-12-01 17:45 16,968 a——- c:\windows\system32\drivers\hitmanpro35.sys
2010-12-01 17:45 –d—– c:\program files\Hitman Pro 3.5
2010-12-01 17:42 –d—– c:\docume~1\alluse~1.win\applic~1\Hitman Pro
2010-12-01 13:45 767,952 a——- c:\windows\BDTSupport.dll
2010-12-01 13:45 1,914,832 a——- c:\windows\PCTBDCore.dll
2010-12-01 13:45 743,376 a——- c:\windows\PCTBDRes.dll
2010-12-01 13:45 149,456 a——- c:\windows\SGDetectionTool.dll
2010-12-01 13:45 2,052 a——- c:\windows\UDB.zip
2010-12-01 13:45 882 a——- c:\windows\RegSDImport.xml
2010-12-01 13:45 879 a——- c:\windows\RegISSImport.xml
2010-12-01 13:45 131 a——- c:\windows\IDB.zip
2010-12-01 13:28 656,320 a——- c:\windows\system32\drivers\pctEFA.sys
2010-12-01 13:28 338,880 a——- c:\windows\system32\drivers\pctDS.sys
2010-12-01 13:28 249,616 a——- c:\windows\system32\drivers\pctgntdi.sys
2010-12-01 13:28 237,632 a——- c:\windows\system32\drivers\PCTCore.sys
2010-12-01 13:28 159,936 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2010-12-01 13:28 123,712 a——- c:\windows\system32\drivers\pctplfw.sys
2010-12-01 13:28 87,400 a——- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2010-12-01 13:28 31,960 a——- c:\windows\system32\drivers\pctNdis-DNS.sys
2010-12-01 13:28 70,536 a——- c:\windows\system32\drivers\pctplsg.sys
2010-12-01 13:27 –d—– c:\program files\PC Tools Security
2010-12-01 13:27 –d—– c:\program files\common files\PC Tools
2010-12-01 13:27 –d—– c:\docume~1\owner\applic~1\PC Tools
2010-12-01 12:01 574,986 a——- c:\windows\system32\drivers\Cat.DB
2010-12-01 11:55 –d—– c:\docume~1\alluse~1.win\applic~1\PC Tools
2010-11-29 22:40 0 ——– c:\windows\WB.ini
2010-11-29 22:33 –d—– c:\program files\Stardock
2010-11-29 22:33 42,672 ——– c:\windows\system32\wbsys.dll
2010-11-29 20:35 57,600 ac—— c:\windows\system32\dllcache\redbook.sys
2010-11-29 20:35 57,600 a——- c:\windows\system32\drivers\redbook.sys
2010-11-29 20:26 –d—– c:\program files\Alcohol Soft
2010-11-29 20:04 –d—– c:\program files\LucasArts
2010-11-27 16:33 25 a——- c:\windows\popcinfot.dat
2010-11-27 16:31 –d—– c:\docume~1\alluse~1.win\applic~1\PopCap Games
2010-11-27 11:23 –d—– c:\program files\Guild Wars
2010-11-25 10:42 10,055 a——- c:\windows\msvrc20.dll
2010-11-25 10:42 –d—– c:\program files\IObit

==================== Find3M ====================

2010-10-29 13:43 472,808 a——- c:\windows\system32\deployJava1.dll
2010-09-18 11:23 974,848 a——- c:\windows\system32\mfc42u.dll
2010-09-17 22:53 974,848 a——- c:\windows\system32\mfc42.dll
2010-09-17 22:53 954,368 a——- c:\windows\system32\mfc40.dll
2010-09-17 22:53 953,856 a——- c:\windows\system32\mfc40u.dll
2010-02-13 12:27 61,224 a——- c:\documents and settings\owner\GoToAssistDownloadHelper.exe
2004-08-03 19:26 45,056 a–shr– c:\windows\system32\inetsrv.exe

============= FINISH: 11:15:49.84 ===============



DDS Attach:



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 10/28/2009 12:39:22 AM
System Uptime: 12/14/2010 8:59:07 AM (3 hours ago)

Motherboard: Dell Inc. | | CN0Y53
Processor: Intel® Atom™ CPU N270 @ 1.60GHz | U1 | 1596/533mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 36.408 GiB free.
E: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: COMPAL Embedded System Control
Device ID: ACPI\CPL0002\2&DABA3FF;&0
Manufacturer: COMPAL
Name: COMPAL Embedded System Control
PNP Device ID: ACPI\CPL0002\2&DABA3FF;&0
Service: EMSC

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8102E/RTL8103E Family PCI-E Fast Ethernet NIC
Device ID: PCI\VEN_10EC&DEV;_8136&SUBSYS;_02F41028&REV;_02\4&2803E7C1&0&00E2
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8102E/RTL8103E Family PCI-E Fast Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV;_8136&SUBSYS;_02F41028&REV;_02\4&2803E7C1&0&00E2
Service: RTLE8023xp

==== System Restore Points ===================

RP299: 11/12/2010 1:31:27 PM - System Checkpoint
RP300: 11/14/2010 11:23:07 AM - System Checkpoint
RP301: 11/15/2010 2:01:01 PM - System Checkpoint
RP302: 11/16/2010 5:56:00 PM - System Checkpoint
RP303: 11/17/2010 8:58:31 PM - System Checkpoint
RP304: 11/19/2010 12:22:16 AM - System Checkpoint
RP305: 11/20/2010 12:38:43 AM - System Checkpoint
RP306: 11/23/2010 2:02:26 PM - System Checkpoint
RP307: 11/24/2010 8:34:53 PM - System Checkpoint
RP308: 11/25/2010 10:44:17 AM - Advanced WindowsCare RestorePoint
RP309: 11/26/2010 6:12:07 PM - System Checkpoint
RP310: 11/28/2010 12:07:00 PM - System Checkpoint
RP311: 11/29/2010 4:08:16 PM - System Checkpoint
RP312: 11/29/2010 8:04:11 PM - Installed Star Wars JK II Jedi Outcast
RP313: 11/29/2010 8:24:01 PM - SPTD setup V1.74
RP314: 11/29/2010 8:42:05 PM - Removed Star Wars JK II Jedi Outcast
RP315: 11/29/2010 8:42:40 PM - Removed Safari
RP316: 11/29/2010 8:43:40 PM - Removed Ragnarok Online
RP317: 12/1/2010 7:13:43 PM - System Checkpoint
RP318: 12/6/2010 1:37:33 PM - System Checkpoint
RP319: 12/7/2010 1:31:50 AM - Software Distribution Service 3.0
RP320: 12/9/2010 11:19:02 PM - System Checkpoint
RP321: 12/11/2010 12:07:23 PM - System Checkpoint
RP322: 12/14/2010 11:11:08 AM - OTL Restore Point

==== Installed Programs ======================

Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.1
Adobe Shockwave Player 11.5
Advanced WindowsCare Pro 2.7.0
AIM 7
Amazon MP3 Downloader 1.0.10
Apple Application Support
Apple Mobile Device Support
Apple Software Update
BitTorrent
Bonjour
Browser Defender 3.0
CamStudio
Canon MP250 series MP Drivers
Corel VideoStudio 12
Dell Driver Download Manager
Dell Resource CD
Dell Touchpad
Dell Wireless WLAN Card Utility
Download Updater (AOL LLC)
Dream Aquarium
Facebook Plug-In
Free YouTube to iPod Converter version 3.2
Garena 2010
GOM Player
Google Talk Plugin
Guild Wars
Hauppauge TV Tuner Driver
Hitman Pro 3.5
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Integrated Webcam Driver (1.01.01.0116)
Intel® Graphics Media Accelerator Driver
IntenseRO Full Client v3
iTunes
Java Auto Updater
Java™ 6 Update 22
League of Legends
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.5.16)
MSVCRT
QuickTime
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB2288953)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
Spyware Doctor 8.0
SUPERAntiSpyware
TeamViewer 5
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Outlook 2007 Junk Email Filter (KB2443839)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB980182)
Veoh Web Player
VideoStudio
VLC media player 1.1.4
WebFldrs XP
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
WinRAR archiver
Wireless Select Switch
Yahoo! Messenger

==== Event Viewer Messages From Past Week ========

12/9/2010 2:39:06 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 00265E1B4EF5 has been denied by the DHCP server 10.100.254.26 (The DHCP Server sent a DHCPNACK message).
12/9/2010 2:38:32 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: EMSC
12/9/2010 12:21:06 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00265E1B4EF5. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
12/9/2010 10:16:31 AM, error: ipnathlp [31008] - The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
12/9/2010 10:16:26 AM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 00265E1B4EF5 has been denied by the DHCP server 10.81.28.5 (The DHCP Server sent a DHCPNACK message).
12/14/2010 10:26:22 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
12/11/2010 11:16:47 AM, error: Service Control Manager [7034] - The PC Tools Auxiliary Service service terminated unexpectedly. It has done this 1 time(s).
12/11/2010 11:16:42 AM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).

==== End Of File ===========================
Hi Malicent, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

You have an autorun infection. This infection will infect all removeable usb devices. What are drives D:\ and F:\ ?

I'm going to give you 2 OTL fixes. Please follow the steps in the order posted.

Please remove any usb storage device you may have attached to the computer.

First, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKLM..\Run: [inetsrv] C:\WINDOWS\system32\inetsrv.exe ()
O33 - MountPoints2\{59e1a8d1-3549-11df-b519-0024e8c842b4}\Shell\AutoRun\command - "" = F:\MI.exe – File not found
O33 - MountPoints2\{990ab482-a297-11df-b601-0024e8c842b4}\Shell\AutoRun\command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O33 - MountPoints2\{990ab482-a297-11df-b601-0024e8c842b4}\Shell\Open\Command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O33 - MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\Shell\AutoRun\command - "" = D:\SysAnti.exe – File not found
O33 - MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\Shell\Explore\Command - "" = D:\SysAnti.exe – File not found
O33 - MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\Shell\Open\Command - "" = D:\SysAnti.exe – File not found
O33 - MountPoints2\{da16e39a-0c53-11df-b496-00265e1b4ef5}\Shell\AutoRun\command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O33 - MountPoints2\{da16e39a-0c53-11df-b496-00265e1b4ef5}\Shell\Open\Command - "" = D:\.\Recycled\Driveinfo.exe – File not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

:Reg

:Files
c:\Driveinfo.exe /s
d:\Driveinfo.exe /s
f:\Driveinfo.exe /s
c:\SysAnti.exe /s
D:\SysAnti.exe /s
f:\SysAnti.exe /s
F:\MI.exe /s
F:\MI.exe /s
F:\MI.exe /s

:Commands
[emptytemp]
[createrestorepoint]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

*Note- When attaching the USB devices please hold the shift key down to prevent it from auto running. Please run the following tool with each drive attached to the computer. *

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone, camera, iPod etc. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Run the following OTL fix with each usb drive attached. Run it as many time as you need to.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
c:\Driveinfo.exe /s
d:\Driveinfo.exe /s
f:\Driveinfo.exe /s
c:\SysAnti.exe /s
D:\SysAnti.exe /s
f:\SysAnti.exe /s
F:\MI.exe /s
c:\MI.exe /s
d:\MI.exe /s

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix

Last step

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows. OTL.Txt.

Please post back with
  • OTL fix log
  • OTL fix log from each run with a USB device attached.
  • New OTL.txt

How's the computer?

Thanks
Hi oldman, the usb devices are a playstation portable and an ipod shuffle.






OTL FIX LOG:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\inetsrv deleted successfully.
C:\WINDOWS\system32\inetsrv.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{59e1a8d1-3549-11df-b519-0024e8c842b4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59e1a8d1-3549-11df-b519-0024e8c842b4}\ not found.
File F:\MI.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{990ab482-a297-11df-b601-0024e8c842b4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{990ab482-a297-11df-b601-0024e8c842b4}\ not found.
File D:\.\Recycled\Driveinfo.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{990ab482-a297-11df-b601-0024e8c842b4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{990ab482-a297-11df-b601-0024e8c842b4}\ not found.
File D:\.\Recycled\Driveinfo.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\ not found.
File D:\SysAnti.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\ not found.
File D:\SysAnti.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad3aacd2-c386-11de-90c2-0024e8c842b4}\ not found.
File D:\SysAnti.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da16e39a-0c53-11df-b496-00265e1b4ef5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da16e39a-0c53-11df-b496-00265e1b4ef5}\ not found.
File D:\.\Recycled\Driveinfo.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da16e39a-0c53-11df-b496-00265e1b4ef5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da16e39a-0c53-11df-b496-00265e1b4ef5}\ not found.
File D:\.\Recycled\Driveinfo.exe not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
========== REGISTRY ==========
========== FILES ==========
File\Folder c:\Driveinfo.exe not found.
File\Folder d:\Driveinfo.exe not found.
File\Folder f:\Driveinfo.exe not found.
File\Folder c:\SysAnti.exe not found.
File\Folder D:\SysAnti.exe not found.
File\Folder f:\SysAnti.exe not found.
File\Folder F:\MI.exe not found.
File\Folder F:\MI.exe not found.
File\Folder F:\MI.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
->Flash cache emptied: 321 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Jae
->Temp folder emptied: 99941767 bytes
->Temporary Internet Files folder emptied: 28062199 bytes
->Java cache emptied: 25587794 bytes
->Flash cache emptied: 539 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32969 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 82886842 bytes
->Flash cache emptied: 2965 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 274377372 bytes
->Flash cache emptied: 50320 bytes

User: Owner
->Temp folder emptied: 5382444 bytes
->Temporary Internet Files folder emptied: 4270562 bytes
->Java cache emptied: 29918044 bytes
->FireFox cache emptied: 72626643 bytes
->Flash cache emptied: 210488 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1192281171 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 132034644 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,858.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.17.3 log created on 12162010_170303

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\WF5ETW8N\dref=http%253A%252F%252Fwww.aim[1].adp%253Flocale%253Den-US%2526magic%253D93306448%2526width%253D234%2526height%253D60%2526sn%253Dxj%252520%252520%252520%252520%252520Jae not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\AVWAPF1B\dref=http%253A%252F%252Fwww.aim[1].adp%253Flocale%253Den-US%2526magic%253D93306448%2526width%253D234%2526height%253D60%2526sn%253Dxj%252520%252520%252520%252520%252520Jae not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JIX3QYE\dref=http%253A%252F%252Fwww.aim[1].adp%253Flocale%253Den-US%2526magic%253D93306448%2526width%253D234%2526height%253D60%2526sn%253Dxj%252520%252520%252520%252520%252520Jae not found!

Registry entries deleted on Reboot…






OTL WITH USB DEVICES:


========== SERVICES/DRIVERS ==========
========== FILES ==========
File\Folder c:\Driveinfo.exe not found.
d:\Recycled\Driveinfo.exe moved successfully.
File\Folder f:\Driveinfo.exe not found.
File\Folder c:\SysAnti.exe not found.
File\Folder D:\SysAnti.exe not found.
File\Folder f:\SysAnti.exe not found.
File\Folder F:\MI.exe not found.
File\Folder c:\MI.exe not found.
File\Folder d:\MI.exe not found.

OTL by OldTimer - Version 3.2.17.3 log created on 12162010_173615




NEW OTL:



OTL logfile created on: 12/16/2010 5:47:24 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 561.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.01 Gb Total Space | 36.39 Gb Free Space | 24.42% Space Free | Partition Type: NTFS
Drive D: | 966.99 Mb Total Space | 676.60 Mb Free Space | 69.97% Space Free | Partition Type: FAT32
Drive F: | 3.78 Gb Total Space | 1.06 Gb Free Space | 27.97% Space Free | Partition Type: FAT32

Computer Name: NAVI | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Wireless Select Switch\WLSS.exe (Dell)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll (Microsoft Corporation)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)


========== Driver Services (SafeList) ==========

DRV - (USBAAPL) – C:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (GGSAFERDriver) – C:\Program Files\Garena\plugins\UI\safedrv.sys File not found
DRV - (GarenaPEngine) – C:\DOCUME~1\Owner\LOCALS~1\Temp\NMK11.tmp File not found
DRV - (EMSC) – C:\WINDOWS\System32\DRIVERS\EMSC.SYS File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Mkd2kfNt) – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (Mkd2Nadr) – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (OA012Vid) – C:\WINDOWS\system32\drivers\OA012Vid.sys (Creative Technology Ltd.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (OA012Ufd) – C:\WINDOWS\system32\drivers\OA012Ufd.sys (Creative Technology Ltd.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (rtl8029) Realtek RTL8029(AS) – C:\WINDOWS\system32\drivers\RTL8029.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/aol/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.2
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.6.5
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: multiPostReport@anonymous:1.0.6
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&query;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/14 13:03:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/14 17:14:33 | 000,000,000 | —D | M]

[2009/10/28 23:40:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/12/16 17:38:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions
[2010/10/30 16:30:52 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/11 12:13:18 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2010/07/05 13:02:20 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}(2)
[2010/12/14 18:00:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/07/05 13:02:16 | 000,000,000 | —D | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}(2)
[2010/12/11 10:52:37 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/22 22:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/08/19 18:49:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/11/01 16:47:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/11/02 23:20:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\multiPostReport@anonymous
[2010/09/11 19:27:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/05/29 19:44:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\extensions\[removed]
[2010/04/01 08:36:24 | 000,002,267 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r34fv2pl.default\searchplugins\aim-search.xml
[2010/12/16 17:38:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/05 12:55:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/29 13:43:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/07/05 12:55:29 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions(2)
[2010/07/05 12:25:13 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions(2)\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
[2009/07/17 00:40:12 | 000,704,512 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010/10/29 13:43:41 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2008/04/13 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [HitmanPro35] C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe (SurfRight B.V.)
O4 - HKLM..\Run: [WLSS] C:\Program Files\Wireless Select Switch\WLSS.exe (Dell)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:45:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/12/16 17:34:17 | 000,000,000 | RHSD | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2007/06/13 03:23:08 | 000,000,087 | RHS- | M] () - D:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2010/12/16 17:34:18 | 000,000,000 | RHSD | M] - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/16 17:34:17 | 000,000,000 | RHSD | C] – C:\autorun.inf
[2010/12/16 17:03:03 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/15 08:46:50 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/15 08:46:45 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/12/15 08:43:39 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/12/14 22:46:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GE.Final.by.Celes-Network.PRX.version-ANiMeX
[2010/12/14 22:33:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\KHBBS
[2010/12/14 19:18:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Youtube Mp3s
[2010/12/14 18:00:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers
[2010/12/14 18:00:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\DVDVideoSoft
[2010/12/14 17:22:34 | 000,520,192 | —- | C] (YAMAHA CORPORATION) – C:\WINDOWS\System32\wscma2u.exe
[2010/12/14 17:22:33 | 000,000,000 | —D | C] – C:\Program Files\AnMing
[2010/12/06 13:17:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Asians
[2010/12/01 17:54:34 | 000,012,872 | —- | C] (SurfRight B.V.) – C:\WINDOWS\System32\bootdelete.exe
[2010/12/01 17:45:15 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2010/12/01 17:42:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Hitman Pro
[2010/12/01 13:28:23 | 000,656,320 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2010/12/01 13:28:23 | 000,338,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2010/12/01 13:28:22 | 000,249,616 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/12/01 13:28:17 | 000,237,632 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/12/01 13:28:17 | 000,159,936 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/12/01 13:28:07 | 000,123,712 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplfw.sys
[2010/12/01 13:28:07 | 000,087,400 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.sys
[2010/12/01 13:28:07 | 000,031,960 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctNdis-DNS.sys
[2010/12/01 13:28:03 | 000,070,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/12/01 13:27:37 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2010/12/01 13:27:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/12/01 13:27:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\PC Tools
[2010/12/01 11:55:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Tools
[2010/11/29 22:33:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Stardock
[2010/11/29 22:33:16 | 000,042,672 | —- | C] (Stardock.Net, Inc) – C:\WINDOWS\System32\wbsys.dll
[2010/11/29 22:33:16 | 000,000,000 | —D | C] – C:\Program Files\Stardock
[2010/11/29 20:35:35 | 000,057,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\redbook.sys
[2010/11/29 20:26:53 | 000,000,000 | —D | C] – C:\Program Files\Alcohol Soft
[2010/11/29 20:04:04 | 000,000,000 | —D | C] – C:\Program Files\LucasArts
[2010/11/27 16:31:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PopCap Games
[2010/11/27 11:23:03 | 000,000,000 | —D | C] – C:\Program Files\Guild Wars
[2010/11/27 10:52:36 | 000,000,000 | —D | C] – C:\Program Files\Plants vs. Zombies Game Of The Year Edition Final
[2010/11/25 10:54:12 | 000,000,000 | —D | C] – C:\Program Files\Mp3 To Ringtone Gold
[2010/11/25 10:42:23 | 000,000,000 | —D | C] – C:\Program Files\IObit
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/16 17:30:56 | 000,016,968 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/12/16 17:26:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/16 17:26:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/15 08:43:29 | 000,581,240 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/12/15 03:27:08 | 000,295,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/15 03:09:57 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/12/14 20:52:17 | 000,072,192 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/14 17:24:45 | 000,000,254 | —- | M] () – C:\WINDOWS\MP3trt.ini
[2010/12/14 17:21:43 | 000,000,025 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/12/14 10:49:50 | 000,001,626 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/13 20:00:06 | 000,010,055 | —- | M] () – C:\WINDOWS\msvrc20.dll
[2010/12/03 12:57:03 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/01 17:54:34 | 000,012,872 | —- | M] (SurfRight B.V.) – C:\WINDOWS\System32\bootdelete.exe
[2010/11/29 22:40:39 | 000,000,000 | —- | M] () – C:\WINDOWS\WB.ini
[2010/11/29 20:40:26 | 000,000,466 | —- | M] () – C:\Documents and Settings\Owner\My Documents\ax_files.xml
[2010/11/18 10:12:44 | 000,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\isign32.dll
[2010/11/18 10:12:44 | 000,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\isign32.dll
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/14 22:33:14 | 1084,981,248 | —- | C] () – C:\Documents and Settings\Owner\Desktop\God Eater.iso
[2010/12/14 17:22:37 | 000,000,254 | —- | C] () – C:\WINDOWS\MP3trt.ini
[2010/12/14 17:22:34 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\ammpp.dll
[2010/12/14 17:22:34 | 000,193,536 | —- | C] () – C:\WINDOWS\System32\atomid.exe
[2010/12/14 17:22:34 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\a1.dll
[2010/12/14 17:22:34 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\anming.ocx
[2010/12/01 17:45:17 | 000,016,968 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/12/01 12:01:00 | 000,581,240 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/11/29 22:40:39 | 000,000,000 | —- | C] () – C:\WINDOWS\WB.ini
[2010/11/29 20:37:14 | 000,000,466 | —- | C] () – C:\Documents and Settings\Owner\My Documents\ax_files.xml
[2010/11/27 16:33:49 | 000,000,025 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/11/25 10:42:24 | 000,010,055 | —- | C] () – C:\WINDOWS\msvrc20.dll
[2010/05/02 18:14:18 | 000,009,244 | —- | C] () – C:\WINDOWS\hpdj3600.ini
[2010/03/21 18:59:38 | 000,007,420 | —- | C] () – C:\WINDOWS\UA000106.DLL
[2009/10/28 23:17:30 | 000,072,192 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/28 00:32:45 | 000,577,536 | —- | C] () – C:\WINDOWS\System32\EMSC.DLL
[2009/10/28 00:31:14 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/10/28 00:28:14 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2009/10/28 00:28:13 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2009/10/27 15:24:21 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/25 17:58:25 | 000,062,304 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2007/05/09 19:35:54 | 000,057,126 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 207 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:430C6D84

< End of report >
Hi Malicent,

How is FireFox now?

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :contents
    D:\autorun.inf
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

P;ease post back with
  • SystemLook log
  • MBAM log

Thanks
Hey oldman, Firefox is working very smoothly now! Thanks a lot for your help. SystemLook 04.09.10 by jpshortstuff Log created at 21:08 on 16/12/2010 by Owner Administrator - Elevation successful ========== contents ========== D:\autorun.inf - Unable to open file. -= EOF =- And here is Malwarebytes report: Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5340 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 12/16/2010 9:19:46 PM mbam-log-2010-12-16 (21-19-46).txt Scan type: Quick scan Objects scanned: 178260 Time elapsed: 5 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi Malicent,

Please download ZipIt from here:
Download
  • Double-click ZipIt! to run it.
  • Then copy the content of the following codebox into the textfield:

    D:\autorun.inf
  • Then, just click the Zip button.
  • When finished, and if successful, a new zip file will have been created on your Desktop. You will be notified of what the file name is when the process has been completed.
Please attach the zip file to your next reply.


One more scan to make sure nothing is lurking in the background.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

Please post bak with
  • the zip file
  • ESET log
Thanks
Hey Oldman, I've been trying to run ESET via IE. But the browser slows down immensely and the scan freezes up.. I've tried for the past two days now, sorry for the late reply. Any other alternatives?
Hi ESET has changed a bit. It will now work with FireFox. So try using firefox, the set up is very similar as IE. Don't forget to disable your antivirus program.
Oldman, Attached is the Zipit file. There was one piece of malware found when I ran ESET. It was detected when the scan was at 99% of completion: C:\_OTL\MovedFiles\12162010_173615\d_Recycled\Driveinfo.exe Win32/Small.NAL worm Thanks again for everything.

Attachments:

Hi Malicent, Don't worry about that file, we already have it quarantined and it will be removed when we clean up the tools. Where there any other detections? The zip file was empty. Can you have a look in the copy owner.zip you have on your desktop and see if there is a file in it?
I removed that empty zip file and tried to make another one. I no longer have a D: drive when I plug in my PSP or iPod. It's automatically E: and F: now. So I tried plugging my PSP in which was drive F:, but after running ZipIt no new 'owner' file would come up..
Hi Malicent,

I see you are using HitManpro for an antivirus program. Did you purchace this or are you using the trial version?

Try this

Open windows explorer (right click the Start button and click Explore)

At the top of windows explorer, click tools, folder options, click the
view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok

Have a look in E:\ and F:\ for a file named autorun.inf. It will have a creation date of 2007/06/13 . If you find it open it with notepad and copy and paste it's contents in your next reply.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI