This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect/ internet virus?

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I have been having some problems with my vista system. A few days ago I got a antivirus scan popup, realising it was a virus i removed it and scanned with avg.0 From there i began running some AV scans with various programs (AVG, Malwarebytes, MSE). After running them and each one finding this and that and removing the problems, they all comeback clean now. The problem is that if I search for anything on google, when i click a link to say malwarebytes, I get redirected to stopzilla, if i go back and reclick the link I go the to right site. Now my internet has been slowed down significantly, but when my computer is turned off other laptops run quickly and normally. oh lol and they deleted my system restore points >.> … please help me im horrible wiht computers D: I know something about a hijackthis log if you want i can attach one, but should i be in safe mode when i do that? Thanks,
Hi nuggets4, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Adminstrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Right click on the file you downloaded and click "Run as Adminstrator" on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode

Please post back with
  • both OTL log
  • GMER log
Thanks
hi i ran the otl scan and got both notepads but when i ran the gmer file it said that it encountered a problem and had to close the program, i tried it in safe mode too =/ do you still want my otl logs? and if u want i can give u a hijackit log too , thanks
Hi nuggets4,

Please post the OTL logs, no need for the hijackthis log. I'll review them while you try GMER again.

Please try running GMER in safe mode with only the check boxes beside C:\ and Sections checked.

Thanks
OTL logfile created on: 16/12/2010 10:22:05 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Aiken\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.81 Gb Total Space | 104.12 Gb Free Space | 46.73% Space Free | Partition Type: NTFS
Drive D: | 10.08 Gb Total Space | 1.74 Gb Free Space | 17.28% Space Free | Partition Type: NTFS
Drive J: | 778.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: AIKEN-PC | User Name: Aiken | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Aiken\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\FixCleaner\FixCleaner.exe (Slimware Utilities, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe (Pure Networks, Inc.)
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Aiken\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (nmservice) – C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe (Pure Networks, Inc.)
SRV - (nmraapache) – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe (Pure Networks, Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (lxbs_device) – C:\Windows\System32\lxbscoms.exe (Lexmark International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SYMREDRV) – C:\Windows\System32\drivers\NIS\1000000.07D\SYMREDRV.SYS File not found
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\NIS\1005000.087\SYMNDISV.SYS File not found
DRV - (SYMFW) – C:\Windows\System32\Drivers\NIS\1005000.087\SYMFW.SYS File not found
DRV - (SYMDNS) – C:\Windows\System32\drivers\NIS\1000000.07D\SYMDNS.SYS File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.004\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.004\NAVENG.SYS File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (ccHP) – C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NIS\1008000.029\SRTSP.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS (Symantec Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys (Symantec Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - ({95808DC4-FA4A-4C74-92FE-5B863F82066B}) – C:\Program Files\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pnarp) – C:\Windows\System32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ask.com/?o=101760&l=dis [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.023.001
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {A6019583-06BC-48DF-9674-1B41F4D8C420}:1.9.1
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c9626}:1.6
FF - prefs.js..extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:0.9
FF - prefs.js..extensions.enabledItems: {241aae70-0022-11de-87af-0800200c9a66}:3.6.30.01.10
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20100112
FF - prefs.js..extensions.enabledItems: [removed]:2.95
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=FWV5&o=14193&locale=en_US&apn_uid=0F3971E0-DE89-4C17-BCA2-17BD62612DD3&apn_ptnrs=FM&apn_sauid=C8D43456-B9DA-4563-9BA7-4E7119BA88E0&apn_dtid=TES002YYCA&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/04/26 19:13:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/10/14 21:50:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/16 21:21:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/12/09 23:52:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/27 23:15:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/19 18:18:32 | 000,000,000 | —D | M]

[2010/03/28 12:24:52 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions
[2010/03/28 12:24:52 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2009/05/30 18:23:32 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2009/05/06 18:23:25 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/15 23:58:38 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (ANTHEM) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{07b2a769-ed19-4483-87ce-c643914c9626}
[2009/08/07 14:50:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (Blue Fox) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{241aae70-0022-11de-87af-0800200c9a66}
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (Bloody Red) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{2458abc0-f443-11dd-87af-0800200c9a66}
[2010/01/31 00:55:50 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/01/31 00:55:50 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2009/05/03 19:43:23 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2010/11/03 18:20:17 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2009/05/05 16:27:37 | 000,000,682 | —- | M] () – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\searchplugins\ask.xml
[2010/12/16 00:45:53 | 000,002,568 | —- | M] () – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\searchplugins\askcom.xml
[2010/12/16 21:43:25 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2009/07/02 23:34:44 | 000,083,376 | —- | M] (NHN USA Inc.) – C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2009/08/17 06:42:14 | 000,073,728 | —- | M] (NHN USA Inc. ) – C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
[2008/10/08 03:47:11 | 000,001,618 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\FFToolbar.xml

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe ()
O4 - Startup: C:\Users\Aiken\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe (FrostWire Group)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll (Pure Networks, Inc.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Aiken\Desktop\PICS\titmouse\IMG_5045.JPG
O24 - Desktop BackupWallPaper: C:\Users\Aiken\Desktop\PICS\titmouse\IMG_5045.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/08/04 10:54:31 | 000,000,000 | —D | M] - J:\AutoRun – [ CDFS ]
O32 - AutoRun File - [2007/08/04 10:54:31 | 000,700,416 | R— | M] (Electronic Arts Inc.) - J:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2007/08/04 09:09:54 | 000,659,456 | R— | M] (Electronic Arts Inc.) - J:\AutoRunGUI.dll – [ CDFS ]
O32 - AutoRun File - [2007/08/04 11:00:52 | 000,000,152 | R— | M] () - J:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{028535e8-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535e8-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = G:\nba2k9setup.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = H:\autorun.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\directx\command - "" = H:\DirectX9\dxsetup.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\setup\command - "" = H:\setup.exe – File not found
O33 - MountPoints2\{028535ea-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535ea-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = I:\nba2k9setup.exe – File not found
O33 - MountPoints2\{070d673d-6670-11de-927b-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{070d673d-6670-11de-927b-001f16715961}\Shell\AutoRun\command - "" = J:\AutoRun.exe – [2007/08/04 10:54:31 | 000,700,416 | R— | M] (Electronic Arts Inc.)
O33 - MountPoints2\{cd231203-38f5-11de-9d9b-001f16715961}\Shell\AutoRun\command - "" = storage\sys.exe
O33 - MountPoints2\{cd231203-38f5-11de-9d9b-001f16715961}\Shell\opEN\coMmand - "" = storage\sys.exe
O33 - MountPoints2\{ce917ddf-bea3-11df-a55d-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{ce917ddf-bea3-11df-a55d-001f16715961}\Shell\AutoRun\command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{f0e38f65-ca79-11de-b6cd-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{f0e38f65-ca79-11de-b6cd-001f16715961}\Shell\AutoRun\command - "" = O:\MediaManager.exe – File not found
O33 - MountPoints2\O\Shell - "" = AutoRun
O33 - MountPoints2\O\Shell\AutoRun\command - "" = O:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/15 20:11:53 | 002,037,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/15 20:11:40 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/15 20:11:40 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/15 20:11:39 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/15 20:11:35 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/15 20:11:25 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/15 20:11:24 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/15 20:11:24 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/15 20:11:10 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/15 20:11:07 | 000,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/15 20:11:05 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/12/15 20:11:01 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/15 20:11:01 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/15 20:11:01 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/12/15 20:11:00 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/15 20:11:00 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/15 20:11:00 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/12/15 20:11:00 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/15 20:10:41 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/15 00:02:49 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\Malwarebytes
[2010/12/14 23:54:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/14 23:54:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/14 23:54:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/12/14 23:54:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/12 23:50:55 | 000,000,000 | —D | C] – C:\Users\Aiken\Desktop\swan
[2010/12/10 00:09:06 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Local\AVG Security Toolbar
[2010/12/10 00:06:34 | 000,000,000 | —D | C] – C:\msprivate
[2010/12/10 00:02:27 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\AVG10
[2010/12/09 23:52:46 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2010/12/09 23:52:01 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2010/12/09 23:49:10 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2010/12/09 23:49:10 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2010/12/09 22:52:18 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/12/09 22:26:12 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/12/08 04:12:38 | 000,251,728 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/12/06 22:05:33 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Local\{A6019583-06BC-48DF-9674-1B41F4D8C420}
[2010/12/06 22:03:44 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Windows
[2010/12/06 22:03:29 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Server
[2010/12/06 22:03:19 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60
[2010/11/19 18:18:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2010/11/19 18:18:19 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/11/17 23:22:43 | 000,000,000 | —D | C] – C:\Users\Aiken\Desktop\owl
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\Aiken\Documents\*.tmp files -> C:\Users\Aiken\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/16 21:46:02 | 000,000,378 | —- | M] () – C:\Windows\tasks\FixCleaner Startup.job
[2010/12/16 21:43:57 | 000,000,246 | —- | M] () – C:\ProgramData\hpqp.ini
[2010/12/16 21:43:17 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/16 21:43:17 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/16 21:43:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/16 21:42:52 | 2951,098,368 | -HS- | M] () – C:\hiberfil.sys
[2010/12/16 21:22:42 | 000,000,790 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2010/12/16 19:36:36 | 000,001,356 | —- | M] () – C:\Users\Aiken\AppData\Local\d3d9caps.dat
[2010/12/16 18:32:30 | 101,954,944 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/16 16:34:53 | 000,002,215 | —- | M] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes (2).lnk
[2010/12/16 04:02:48 | 000,391,120 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/15 20:37:20 | 001,423,402 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 432.JPG
[2010/12/15 20:26:16 | 001,413,479 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 067.JPG
[2010/12/15 02:01:37 | 000,002,587 | —- | M] () – C:\Users\Aiken\Desktop\Microsoft Office Word 2007 (2).lnk
[2010/12/14 23:54:47 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/13 01:19:48 | 000,010,571 | —- | M] () – C:\Users\Aiken\Documents\In the case of Rv.docx
[2010/12/11 16:51:22 | 003,985,172 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 428.JPG
[2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/12/06 22:05:35 | 000,000,120 | —- | M] () – C:\Users\Aiken\AppData\Local\Wpekiyaloqetuguz.dat
[2010/12/06 22:05:35 | 000,000,000 | —- | M] () – C:\Users\Aiken\AppData\Local\Adiwuhifopawuqew.bin
[2010/12/04 16:52:14 | 000,001,748 | —- | M] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/12/02 01:55:40 | 000,016,467 | —- | M] () – C:\Users\Aiken\Documents\The debate between nature vs.docx
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/28 21:40:58 | 000,018,539 | —- | M] () – C:\Users\Aiken\Documents\Notes on Review of Literature.docx
[2010/11/28 00:40:14 | 000,020,906 | —- | M] () – C:\Users\Aiken\Documents\Review of literature.docx
[2010/11/27 23:42:45 | 000,017,419 | —- | M] () – C:\Users\Aiken\Documents\REVIEW OF LIT WORKS.docx
[2010/11/27 14:01:52 | 000,691,708 | —- | M] () – C:\Windows\System32\perfh00C.dat
[2010/11/27 14:01:52 | 000,617,964 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/27 14:01:52 | 000,135,510 | —- | M] () – C:\Windows\System32\perfc00C.dat
[2010/11/27 14:01:52 | 000,112,698 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/26 07:39:07 | 000,011,543 | —- | M] () – C:\Users\Aiken\Documents\anthro debate.docx
[2010/11/26 07:37:26 | 000,013,854 | —- | M] () – C:\Users\Aiken\Documents\thriller film adaptation.docx
[2010/11/24 20:23:08 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAiken.job
[2010/11/24 01:19:26 | 000,011,059 | —- | M] () – C:\Users\Aiken\Documents\LAW and ORDER.docx
[2010/11/22 01:32:41 | 000,010,765 | —- | M] () – C:\Users\Aiken\Documents\anthro literature.docx
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\Aiken\Documents\*.tmp files -> C:\Users\Aiken\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/16 21:04:27 | 2951,098,368 | -HS- | C] () – C:\hiberfil.sys
[2010/12/16 18:32:30 | 101,954,944 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/15 20:01:18 | 001,423,402 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 432.JPG
[2010/12/15 20:01:12 | 003,985,172 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 428.JPG
[2010/12/14 23:54:47 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/13 01:12:06 | 000,010,571 | —- | C] () – C:\Users\Aiken\Documents\In the case of Rv.docx
[2010/12/11 23:42:34 | 001,413,479 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 067.JPG
[2010/12/09 23:51:46 | 000,000,790 | —- | C] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2010/12/06 22:05:35 | 000,000,120 | —- | C] () – C:\Users\Aiken\AppData\Local\Wpekiyaloqetuguz.dat
[2010/12/06 22:05:35 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\Adiwuhifopawuqew.bin
[2010/12/04 16:52:14 | 000,001,748 | —- | C] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/12/02 01:55:38 | 000,016,467 | —- | C] () – C:\Users\Aiken\Documents\The debate between nature vs.docx
[2010/11/28 21:38:41 | 000,018,539 | —- | C] () – C:\Users\Aiken\Documents\Notes on Review of Literature.docx
[2010/11/27 22:05:40 | 000,017,419 | —- | C] () – C:\Users\Aiken\Documents\REVIEW OF LIT WORKS.docx
[2010/11/27 22:05:28 | 000,020,906 | —- | C] () – C:\Users\Aiken\Documents\Review of literature.docx
[2010/11/26 07:39:05 | 000,011,543 | —- | C] () – C:\Users\Aiken\Documents\anthro debate.docx
[2010/11/26 01:01:28 | 000,013,854 | —- | C] () – C:\Users\Aiken\Documents\thriller film adaptation.docx
[2010/11/24 01:19:25 | 000,011,059 | —- | C] () – C:\Users\Aiken\Documents\LAW and ORDER.docx
[2010/11/22 01:32:40 | 000,010,765 | —- | C] () – C:\Users\Aiken\Documents\anthro literature.docx
[2010/10/14 18:53:56 | 000,001,865 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/07/06 16:04:48 | 000,009,728 | —- | C] () – C:\Windows\System32\uc_karos_launching.dll
[2010/07/03 18:06:22 | 000,000,552 | —- | C] () – C:\Users\Aiken\AppData\Local\d3d8caps.dat
[2009/12/06 13:32:30 | 000,001,456 | —- | C] () – C:\Windows\System32\lxbsprod.ini
[2009/09/27 12:46:37 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\FnF4.txt
[2009/07/19 20:37:29 | 000,000,014 | —- | C] () – C:\Windows\System32\SysEngineDrive1.sys
[2009/06/14 15:05:26 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/05/08 19:29:05 | 000,000,031 | —- | C] () – C:\Windows\GunzLauncher.INI
[2009/04/21 15:43:26 | 000,001,356 | —- | C] () – C:\Users\Aiken\AppData\Local\d3d9caps.dat
[2009/04/16 21:08:42 | 000,014,336 | —- | C] () – C:\Users\Aiken\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/15 22:26:53 | 000,000,021 | —- | C] () – C:\ProgramData\hpqp.txt
[2009/04/15 22:18:13 | 000,027,839 | —- | C] () – C:\ProgramData\nvModes.001
[2009/04/15 21:58:46 | 000,027,839 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\QSwitch.txt
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\DSwitch.txt
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\AtStart.txt
[2009/03/11 08:41:07 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/03/11 08:40:58 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/03/11 08:40:30 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/03/11 08:39:51 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/03/11 08:37:48 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/03/11 08:37:18 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2008/10/25 05:57:46 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2008/10/25 05:51:48 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2008/10/25 05:49:52 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2008/10/25 05:48:29 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 04:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2002/11/13 09:40:22 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbsvs.dll
[2001/10/26 10:09:46 | 000,332,288 | —- | C] () – C:\Windows\System32\ConfigLib.dll

========== LOP Check ==========

[2009/06/24 16:45:39 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\2K Sports
[2010/12/07 02:37:03 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60
[2009/09/10 16:38:58 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Atari
[2010/12/10 00:02:27 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\AVG10
[2010/09/12 13:14:19 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\BitTorrent
[2010/02/24 22:18:16 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\CCH
[2009/06/14 15:13:53 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\DAEMON Tools Lite
[2010/02/22 01:22:46 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\DNA
[2010/10/13 21:45:07 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\FixCleaner
[2010/12/15 02:25:24 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\FrostWire
[2009/09/07 20:47:25 | 000,000,000 | -H-D | M] – C:\Users\Aiken\AppData\Roaming\ijjigame
[2009/05/31 14:23:48 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\IMVUClient
[2009/08/17 18:44:19 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Leadertech
[2010/11/02 22:35:03 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\LimeWire
[2009/05/28 16:38:39 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Nexon
[2010/03/05 14:57:50 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\PlayFirst
[2009/04/16 14:47:28 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\SPORE Creature Creator
[2010/09/16 18:10:50 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\SystemRequirementsLab
[2010/03/28 12:24:45 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\TomTom
[2010/10/23 11:00:04 | 000,000,438 | —- | M] () – C:\Windows\Tasks\FixCleaner Scan.job
[2010/12/16 21:46:02 | 000,000,378 | —- | M] () – C:\Windows\Tasks\FixCleaner Startup.job
[2010/12/16 21:41:28 | 000,032,596 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 21:34:29 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/12/16 21:42:52 | 2951,098,368 | -HS- | M] () – C:\hiberfil.sys
[2010/02/24 21:57:21 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/12/06 13:36:20 | 000,000,100 | —- | M] () – C:\lxbs.log
[2010/02/24 21:57:21 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/16 21:42:48 | 3264,942,080 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 07:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 07:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/09 00:43:12 | 000,316,928 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp092.dll
[2004/05/28 08:00:48 | 000,075,264 | —- | M] () – C:\Windows\System32\spool\prtprocs\w32x86\LXBSPP5C.DLL
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 22:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-16 08:42:29

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Aiken\Documents\YouTube- Bobby Lee & John Cena - MadTV 24 Skit.mp4:TOC.WMV

< End of report >
OTL Extras logfile created on: 16/12/2010 10:22:05 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Aiken\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.81 Gb Total Space | 104.12 Gb Free Space | 46.73% Space Free | Partition Type: NTFS
Drive D: | 10.08 Gb Total Space | 1.74 Gb Free Space | 17.28% Space Free | Partition Type: NTFS
Drive J: | 778.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: AIKEN-PC | User Name: Aiken | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06C4077E-3A9E-419E-93C9-560314682601}" = lport=139 | protocol=6 | dir=in | app=system |
"{38FBBA83-3C76-4457-813E-65B9691C298E}" = rport=445 | protocol=6 | dir=out | app=system |
"{477750E5-3CBC-4BB4-8128-988FB6D0ABB7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{523BC9A2-3DA1-4427-A7D0-9A5E99ECBDD5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6ABB3EE4-4A11-437D-B7AF-163539773B03}" = lport=445 | protocol=6 | dir=in | app=system |
"{A606D8D8-3B70-451D-84CA-8B266D25592A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{AD207AAA-1E28-4306-A23C-139D8D12D91B}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{AF5799AD-C4BE-4AED-9AAE-F5EC8AF51F05}" = lport=138 | protocol=17 | dir=in | app=system |
"{B20B0840-A84E-4902-B68F-7C77E5105988}" = rport=138 | protocol=17 | dir=out | app=system |
"{BB3AF7B5-8BC4-4294-AC51-4C5648CFED5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{C6DA4670-3E22-453A-97FF-0EADB07DC947}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CAC99944-8448-480A-AF87-546AE43538B9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{CC1BC715-7871-4083-9DF8-A03A63142F1C}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{F587575B-E75E-42FB-A3A6-5AF21847E17B}" = rport=137 | protocol=17 | dir=out | app=system |
"{F65C41B7-C7CF-4A71-852E-9C5C39361CDB}" = rport=139 | protocol=6 | dir=out | app=system |
"{F8982CC2-03A2-48BC-B399-A830C39B2A96}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{F94D8995-AC90-4D20-8567-6823F7EC0FD3}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00B9CD07-09C1-452E-9D9D-6305E0D61A9D}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{06EA44CA-E5FC-44B3-AD1C-B86C33737807}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{0BE36C46-88F3-41C2-AF5D-854993025951}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{0E146152-9D02-4630-8555-53363CE8C006}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{12381D15-94EA-4E2B-81E5-84D1F2F6C6A3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{15BC8BDE-8BCE-4201-BDE8-2F317504E6D3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{1705A873-E465-40DC-81FB-0E7DF9BE97B3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe |
"{294F66E0-7C7F-4EF7-A7A1-9B21A0F0523D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{36B6C834-F831-447A-8CEE-9723EFC4C5A0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{3BC5DB0A-68BC-4BCF-9E6B-3C7622D49F22}" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{3D20B3F5-D017-4925-86B9-043B006CB90A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3D3DA056-1E15-4765-8483-6CCCAE1042B6}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{3FC1F058-29CA-474F-AAE6-DD0A7379F108}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{42660784-34FB-47AC-8613-DACDAB51958B}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{46231824-C6AB-4490-8C62-A1875235DEFE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{49345672-4313-481C-A1BC-7081505FC9AF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |
"{49EB2EDA-2805-4F72-B5A6-CB70F6443947}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{522E5819-A6AE-4362-851B-FD3C405021DB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{53DD257F-2245-40E2-8912-FB51EF4F8CBB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{57BC5885-4DD4-4FB1-B993-1375C97E0317}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{57E60748-1290-4011-AB65-6A97CF966045}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{5819A362-0D33-44CD-B475-7CDFD068DB66}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{5ACA5035-6040-45A9-8DF5-8EDC8A9C9C41}" = dir=in | app=c:program filespando networksmedia boosterpmb.exe |
"{5CA2F54E-8C66-4F43-BABC-5B04553BA338}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |
"{5DCBC5FC-BD4D-4607-A69A-6BD6166A54E5}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{639B9D74-132C-47B7-B425-12B2BCE52342}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{639D6663-7572-4E77-896F-D852ABDAD8F3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{63D607BD-D202-427D-B86E-F6702880F864}" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{67B00524-0835-4E08-BE10-D4C6F1297001}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{68BA33D3-A60A-4B5F-A1C8-6047FF43FAD6}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{7018215E-E829-4318-ACDD-D823884A6159}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{72194ED6-62B9-4B67-92D2-E6CA29338C23}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe |
"{7405482B-8CF8-4ACF-A159-18703EE20881}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{742E4871-1751-406A-B7E8-48DAF82CB609}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{77CF7558-6FBE-44FD-9EB6-0E953D0C6FA1}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{7C8F5BE0-FC3F-40E2-99E0-E4295433DD01}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{83978EC5-DDAE-4023-86FD-F8F43C1841B0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{84CFAB30-6704-46B3-A897-A9396D66A64C}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{86BC6020-B48C-40BC-BB04-8C874EA31424}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |
"{87DEBE4C-C91B-430F-915D-68E0D55B6C58}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{8B8AF052-6E44-442F-944F-C3919C6464ED}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{8D1C1D90-3469-4D86-A9C7-A8807ECA4023}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{8D60CFEA-1E8F-4073-A696-281C435C751D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{937D6E9C-CFEB-4960-8071-20AFE4459A27}" = protocol=17 | dir=in | app=c:\users\aiken\appdata\local\temp\purplebean.exe |
"{9505A6F8-F04A-4C3D-8016-AE54A1DDBB30}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{A15CE746-49E6-4C2B-9542-4DF137857A6D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{A635C961-B51D-497E-9C61-C8D7EE269A4E}" = protocol=17 | dir=in | app=c:\program files\ijji\ijji reactor\ijjioptimizer.exe |
"{A66B6397-F426-4671-B6EA-AFE6482C98DF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{AC323BF1-ACA8-4463-A77C-0A01329D0747}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{B4491E6F-8726-4B94-A0DE-A827E8870C69}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{B5E18D63-D57E-487A-937C-FC7741B8BB5A}" = protocol=6 | dir=in | app=c:\program files\ijji\ijji reactor\ijjioptimizer.exe |
"{C08DBC73-781C-4C9B-A0BD-77C7DDFD31B5}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{C823741D-43A1-471E-A903-621226A14675}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{CE5541D3-4FE9-43B6-AF19-EDDF2B1F408C}" = protocol=17 | dir=in | app=c:\program files\pure networks\network magic\nmsrvc.exe |
"{D64B907A-7CED-482F-83F3-5016CD28A70B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{D6B4F3A9-C3D5-4A29-9DE1-243E2C54E70D}" = protocol=6 | dir=in | app=c:\users\aiken\appdata\local\temp\purplebean.exe |
"{D7CA3162-C516-4639-A0F6-C4EB8C1F8CA2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{D9BE3809-A396-4840-9257-BAE1FEF28388}" = protocol=17 | dir=in | app=c:\program files\ijji\ijji reactor\ijjioptimizer.exe |
"{DBE553F5-9F2E-474B-AC34-C59CA8A7A9B0}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{DD6DB483-E0F0-40B8-A452-93D2A25F0F06}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{DD7CE00A-7DBA-4A7F-B249-56E0EA8A00CE}" = protocol=6 | dir=in | app=c:\program files\ijji\ijji reactor\ijjioptimizer.exe |
"{ECFD518F-880D-4E26-A034-E3DE93CB5018}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{EE8A2521-0663-485F-B6B4-2C6862A709E7}" = protocol=6 | dir=in | app=c:\program files\pure networks\network magic\nmsrvc.exe |
"{EF1BF0F8-4B13-4172-8CE2-CF61825F5ED2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F79C059D-C193-4F65-9D48-91AA285073F8}" = dir=in | app=c:\program files\hp\digital imaging\{7e0e61cc-1c99-429d-bea7-c4dd5b898d2a}\setup\hpznui01.exe |
"{FD3C790D-7DC5-40FA-8EB8-2AF2C550CC4E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{FFD44BA5-2D43-454C-9B0C-25183A4F0336}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"TCP Query User{2081C7CD-577F-419F-B16C-41CAACE1FC54}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{36E78087-B2D2-4930-9F4C-2FC7C910ABA8}C:\program files\frostwire\frostwire.exe" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"TCP Query User{4DA53453-86C1-4308-A878-BB76CA994BC8}C:\ijji\english\u_sf\soldierfront.exe" = protocol=6 | dir=in | app=c:\ijji\english\u_sf\soldierfront.exe |
"TCP Query User{4EE1C550-0FA1-40BF-8771-0B1F34EFEFAD}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{5DEF5A0C-877F-4B8F-8B45-D84109C30E9B}C:\programdata\ijjigame\plauncher.exe" = protocol=6 | dir=in | app=c:\programdata\ijjigame\plauncher.exe |
"TCP Query User{6B75FCA6-F2EF-4ACC-ABF5-A5D588535A69}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{763625AC-5DDB-4E47-ADB0-F41DC8CEDB37}C:\users\aiken\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\aiken\program files\dna\btdna.exe |
"TCP Query User{7A7EE6FD-6F54-4473-9924-7A8C6C6CF641}C:\program files\ijji\ijji reactor\reactor.exe" = protocol=6 | dir=in | app=c:\program files\ijji\ijji reactor\reactor.exe |
"TCP Query User{AA491676-7F27-4591-960C-E5EF86756EF7}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{C5872F0A-83F0-4AE6-8F51-00746E803042}C:\program files\pando networks\media booster\pmb.exe" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"TCP Query User{D3940124-3FCC-4DAF-8CD3-D80DD64DA929}C:\ijji\english\u_sf\soldierfront.exe" = protocol=6 | dir=in | app=c:\ijji\english\u_sf\soldierfront.exe |
"TCP Query User{FAADA836-5EBB-4AAD-8794-0B4FC4E00439}C:\users\aiken\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\aiken\program files\dna\btdna.exe |
"UDP Query User{01E363A2-8821-44E5-AD25-2D44A175EB74}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{0E1BE75A-A51C-490E-9A18-7D3EEDF46445}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{14E24E1E-F85E-4AB9-982F-70A27F9CB20D}C:\program files\ijji\ijji reactor\reactor.exe" = protocol=17 | dir=in | app=c:\program files\ijji\ijji reactor\reactor.exe |
"UDP Query User{1AB0AB17-EDFB-4FB7-A9C5-2D71F1A3C54B}C:\program files\frostwire\frostwire.exe" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"UDP Query User{61587DAB-52DB-4438-A3F9-E8EE23002916}C:\ijji\english\u_sf\soldierfront.exe" = protocol=17 | dir=in | app=c:\ijji\english\u_sf\soldierfront.exe |
"UDP Query User{7CBA433C-1489-4950-882C-620034761C66}C:\program files\pando networks\media booster\pmb.exe" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"UDP Query User{9A517288-E6CA-4BC1-BA0F-8C4CF4228BCD}C:\programdata\ijjigame\plauncher.exe" = protocol=17 | dir=in | app=c:\programdata\ijjigame\plauncher.exe |
"UDP Query User{A3B3DE07-327A-4FB7-A083-3B358C4AD528}C:\ijji\english\u_sf\soldierfront.exe" = protocol=17 | dir=in | app=c:\ijji\english\u_sf\soldierfront.exe |
"UDP Query User{D3FAC25F-0B3D-4BC1-99BC-F4196A587D7E}C:\users\aiken\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\aiken\program files\dna\btdna.exe |
"UDP Query User{D4F55B5A-07C3-4D2B-99C2-4AB74525EEA4}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{F9E9380F-CA3B-4107-BA7C-8EFAA4106D1E}C:\users\aiken\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\aiken\program files\dna\btdna.exe |
"UDP Query User{FB1770AD-09D3-49CE-8E35-3619904C1B34}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{0076046B-CC5C-4417-8226-5F6D6A626258}" = CANTAX T1Plus 2009
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1A2A15C2-6780-49c1-B296-503230E9DE00}" = The Sims™ 2 Mansion and Garden Stuff
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.3
"{1B602410-D983-4947-98FE-EE749073D15E}" = GamingHarbor Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 16
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2C464EC1-2B0C-4490-9CAC-D4562DD8377A}" = Soap 3.0 Toolkit
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3A4D5E2D-988D-4ee9-8E7F-3AC200A2B8F5}" = 4500G510nz_Software_Min
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3EA962FB-B79E-4A0C-A0F8-191E9FBF5278}" = AVG 2011
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{451BB54C-8B23-4455-8BDC-14FC7D43E056}" = MSXML4SP2
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5B05FF91-F20C-4832-A8DE-E1912639C17C}" = 4500G510nz
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Sims™ 2 Teen Style Stuff
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Sims™ 2 Kitchen & Bath Interior Design Stuff
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{690879A5-18EF-447B-98D6-B699D51008AB}" = 4500_G510nz_Help
"{6A370610-3778-44AF-9AAC-69B2FD1A3356}" = Microsoft Live Search Toolbar
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = The Sims™ 2 IKEA® Home Stuff
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = The Sims 2
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}" = HP Officejet 4500 G510n-z
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{846DDADA-0239-4B67-A6B1-33658863793B}" = HPTCSSetup
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Sims™ 2 H&M® Fashion Stuff
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86BDCF57-840A-4AC1-A9E4-B57EC5BCB16E}" = FixCleaner
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}" = ijji REACTOR
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B2455727-ED8F-4643-8A6E-F4AB8DE3633D}" = Network
"{B6797F11-4A7D-45F5-8A20-72E9CCD83538}" = UFile Updater 2009
"{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}" = HP User Guides 0118
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D36F4DCA-B6D5-403A-B69D-2439D59FC9A7}" = UFile 2009
"{D5773BFA-5967-4A1C-AD0F-FFFD0D13FC36}" = Network Magic
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F4C68898-EBA5-46A9-82B3-2D30426086BF}" = AVG 2011
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALUpdate_is1" = ALTools Update
"ALZip_is1" = ALZip
"AVG" = AVG 2011
"BlazeDVD 5.0 Professional_is1" = BlazeDVD 5.0 Professional
"CCleaner" = CCleaner (remove only)
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FrostWire" = FrostWire 4.21.1
"Game Booster_is1" = Game Booster
"GamingHarbor Toolbar" = GamingHarbor Toolbar
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HotspotShield" = Hotspot Shield 1.47
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD Ultra
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Lexmark 810 Series" = Lexmark 810 Series
"LimeWire" = LimeWire 5.1.2
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"NIS" = Norton Internet Security
"NVIDIA Drivers" = NVIDIA Drivers
"Plants vs. Zombies" = Plants vs. Zombies
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"TomTom HOME" = TomTom HOME 2.7.3.1894
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = Roblox for Aiken
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 4:16:54 AM | Computer Name = Aiken-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 30/07/2010 9:07:19 PM | Computer Name = Aiken-PC | Source = WinMgmt | ID = 10
Description =

Error - 31/07/2010 2:00:37 AM | Computer Name = Aiken-PC | Source = WinMgmt | ID = 10
Description =

Error - 31/07/2010 11:58:29 AM | Computer Name = Aiken-PC | Source = WinMgmt | ID = 10
Description =

[ OSession Events ]
Error - 06/12/2009 11:39:38 PM | Computer Name = Aiken-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 33115
seconds with 5460 seconds of active time. This session ended with a crash.

Error - 01/11/2010 11:50:29 PM | Computer Name = Aiken-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 13711
seconds with 1740 seconds of active time. This session ended with a crash.


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi nuggets4,

Running GMER with just C:\ checked won't show us much but post the log if one was produced. We'll also try a different program in a bit.


LimeWire, Frostwire, BitTorrent, DNA

You have several P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing them. It's not the programs themselves that are the problem but what can be downloaded with them, usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use them until your computer is cleaned.


Antivirus programs

I see AVG 2011 and Some Symantec (Norton) installed. Are you finished using Norton?



Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.



Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).


Next

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


Please post back with
  • information regarding Symantec Norton)
  • Gooredfix log
  • RootKit Unhooker log
Thanks
RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6001 (Service Pack 1) Number of processors #2 ============================================== >Drivers ============================================== 0x8F000000 C:\Windows\system32\DRIVERS\nvlddmkm.sys 9793536 bytes (NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 186.44 ) 0x8201C000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System) 0x8201C000 PnpManager 3907584 bytes 0x8201C000 RAW 3907584 bytes 0x8201C000 WMIxWDM 3907584 bytes 0x81670000 Win32k 2109440 bytes 0x81670000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x8A40B000 C:\Windows\system32\drivers\ql2300.sys 1277952 bytes (QLogic Corporation, QLogic Fibre Channel Stor Miniport Driver) 0x8AA0A000 C:\Windows\System32\Drivers\Ntfs.sys 1110016 bytes (Microsoft Corporation, NT File System Driver) 0x8A604000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x90004000 C:\Windows\system32\DRIVERS\HSX_DPV.sys 1060864 bytes (Conexant Systems, Inc., HSF_DP driver) 0x8E804000 C:\Windows\system32\DRIVERS\nvmfdx32.sys 1036288 bytes (NVIDIA Corporation, NVIDIA MCP Networking Function Driver.) 0x8A80B000 C:\Windows\System32\drivers\tcpip.sys 954368 bytes (Microsoft Corporation, TCP/IP Driver) 0x8E90E000 C:\Windows\system32\DRIVERS\athr.sys 933888 bytes (Atheros Communications, Inc., Atheros Extensible Wireless LAN device driver) 0x80468000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xA7401000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x8A207000 C:\Windows\system32\drivers\megasr.sys 749568 bytes (LSI Corporation, Inc., LSI MegaRAID Software RAID Driver) 0x90107000 C:\Windows\system32\DRIVERS\HSX_CNXT.sys 741376 bytes (Conexant Systems, Inc., HSF_CNXT driver) 0x912AE000 C:\Windows\system32\drivers\spsys.sys 716800 bytes (Microsoft Corporation, security processor) 0x8260E000 C:\Windows\system32\drivers\iastorv.sys 659456 bytes (Intel Corporation, Intel Matrix Storage Manager driver (base)) 0x8F959000 C:\Windows\System32\drivers\dxgkrnl.sys 651264 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0x8A06C000 C:\Windows\system32\drivers\elxstor.sys 606208 bytes (Emulex, Storport Miniport Driver for LightPulse HBAs) 0x80548000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic) 0x90B08000 C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys 503808 bytes (Symantec Corporation, Common Client Hash Provider Driver) 0x8A16E000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xA2407000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x82745000 C:\Windows\system32\drivers\adp94xx.sys 434176 bytes (Adaptec, Inc., Adaptec Windows SAS/SATA Storport Driver) 0x90A93000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0x8A543000 C:\Windows\system32\drivers\ql40xx.sys 348160 bytes (QLogic Corporation, QLogic iSCSI Storport Miniport Driver) 0x8A3AF000 C:\Windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS 323584 bytes (Symantec Corporation, Symantec Extended File Attributes) 0xA2577000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver) 0x818B0000 C:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0x827AF000 C:\Windows\system32\drivers\adpahci.sys 311296 bytes (Adaptec, Inc., Adaptec Windows SATA Storport Driver) 0x90A47000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090610.006\IDSvix86.sys 311296 bytes (Symantec Corporation, IDS Core Driver) 0x806E1000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x9035B000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x902E1000 C:\Windows\system32\DRIVERS\avgtdix.sys 294912 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0x8060D000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0x90B83000 C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys 270336 bytes (Symantec Corporation, BASH Driver) 0x80427000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x826EF000 C:\Windows\system32\drivers\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x8FB65000 C:\Windows\system32\DRIVERS\HSXHWAZL.sys 253952 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver) 0x8A99D000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x91208000 C:\Windows\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0x90A01000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x8A2E4000 C:\Windows\system32\drivers\uliahci.sys 245760 bytes (ULi Electronics Inc., ULi SATA Controller Driver) 0x8FAD8000 C:\Windows\system32\drivers\CHDRT32.sys 241664 bytes (Conexant Systems Inc., High Definition Audio Function Driver) 0x8A73A000 C:\Windows\system32\drivers\NETIO.SYS 237568 bytes (Microsoft Corporation, Network I/O Subsystem) 0xA24FE000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x8AB21000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x90274000 C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS 212992 bytes (Symantec Corporation, Network Dispatch Driver) 0x8FA93000 C:\Windows\system32\DRIVERS\usbhub.sys 212992 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x823D6000 ACPI_HAL 208896 bytes 0x823D6000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x8A36D000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x90329000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x8A94A000 C:\Windows\system32\DRIVERS\SynTP.sys 196608 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0x8A78C000 C:\Windows\system32\DRIVERS\msiscsi.sys 188416 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x8FB13000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x8A320000 C:\Windows\system32\drivers\ulsata2.sys 180224 bytes (Promise Technology, Inc., Promise SATAII150 Series Windows Drivers) 0x8A70F000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x8FA52000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0x9136D000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0xA7524000 C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 163840 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Driver.) 0xA254F000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x8AB86000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x80664000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x8A006000 C:\Windows\system32\drivers\adpu320.sys 155648 bytes (Adaptec, Inc., Adaptec StorPort Ultra320 SCSI Driver) 0x805D1000 C:\Windows\system32\drivers\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver) 0x8FB40000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x902A8000 C:\Windows\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library) 0x8A7DC000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x807A2000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0x8A5DC000 C:\Windows\system32\drivers\ulsata.sys 135168 bytes (Promise Technology, Inc., Promise Ultra/Sata Series Driver for Win2003) 0x8FBD2000 C:\Windows\System32\Drivers\usbvideo.sys 135168 bytes (Microsoft Corporation, USB Video Class Driver) 0x9020B000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x8A34C000 C:\Windows\system32\drivers\vsmraid.sys 135168 bytes (VIA Technologies Inc.,Ltd, VIA RAID DRIVER FOR AMD-X86-64) 0xA24BF000 C:\Windows\system32\drivers\mrxdav.sys 131072 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xA24DF000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x826B7000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0xA74FD000 C:\Program Files\CyberLink\PowerDVD\000.fcl 118784 bytes (Cyberlink Corp., FCL Driver) 0x8FA33000 C:\Windows\system32\DRIVERS\mcdbus.sys 118784 bytes (MagicISO, Inc., MagicISO SCSI Host Controller) 0xA2474000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x8069A000 C:\Windows\system32\drivers\mpio.sys 114688 bytes (Microsoft Corporation, MultiPath Support Bus-Driver) 0x807CB000 C:\Windows\system32\drivers\adpu160m.sys 110592 bytes (Adaptec, Inc., Adaptec LH Ultra160 Driver (x86)) 0x8A8F4000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x91293000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0x80787000 C:\Windows\system32\drivers\nvraid.sys 110592 bytes (NVIDIA Corporation, NVIDIA® nForce™ RAID Driver) 0x8A132000 C:\Windows\system32\drivers\lsi_fc.sys 106496 bytes (LSI Logic, LSI Logic Fusion-MPT FC Driver (StorPort)) 0x826D5000 C:\Windows\system32\drivers\lsi_scsi.sys 106496 bytes (LSI Logic, LSI Logic Fusion-MPT SCSI Driver (StorPort)) 0x8076D000 C:\Windows\system32\drivers\msdsm.sys 106496 bytes (Microsoft Corporation, Microsoft Device Specific Module) 0xA2491000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x8A774000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x8A14C000 C:\Windows\system32\drivers\lsi_sas.sys 98304 bytes (LSI Logic, LSI Logic Fusion-MPT SAS Driver (StorPort)) 0xA2537000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x90AF1000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x8A7BA000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x8FBB3000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0x8A040000 C:\Windows\system32\drivers\arc.sys 90112 bytes (Adaptec, Inc., Adaptec RAID Storport Driver) 0x8A056000 C:\Windows\system32\drivers\arcsas.sys 90112 bytes (Adaptec, Inc., Adaptec SAS RAID WS03 Driver) 0x91244000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x903A3000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x9025E000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0xA24AA000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8FA0E000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x8AB62000 C:\Windows\system32\drivers\sbp2port.sys 86016 bytes (Microsoft Corporation, SBP-2 Protocol Driver) 0x8A5A5000 C:\Windows\system32\drivers\sisraid4.sys 86016 bytes (Silicon Integrated Systems, SiS AHCI Stor-Miniport Driver) 0x8A02C000 C:\Windows\system32\drivers\djsvs.sys 81920 bytes (Adaptec, Inc., Adaptec Ultra SCSI miniport) 0x807E6000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x902CD000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0x8A927000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver) 0x901C9000 C:\Windows\system32\drivers\nvhda32v.sys 77824 bytes (NVIDIA Corporation, NVIDIA HDMI Audio Driver) 0x913A6000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x901DC000 C:\Windows\system32\drivers\RTSTOR.SYS 77824 bytes (Realtek Semiconductor Corp., Realtek USB Mass Storage Driver for Vista) 0x903D0000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x8A9EA000 C:\Windows\system32\DRIVERS\HDAudBus.sys 73728 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x8ABAD000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x8FAC7000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x8040E000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x8A39F000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x8FBA3000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0x8A10A000 C:\Windows\system32\drivers\iirsp.sys 65536 bytes (Intel Corp./ICP vortex GmbH, Intel/ICP Raid Storport Driver) 0x9135D000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x8075D000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x8FA23000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x8068B000 C:\Windows\system32\drivers\isapnp.sys 61440 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0x91284000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x8AB77000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x806B6000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8A90F000 C:\Windows\system32\DRIVERS\processr.sys 61440 bytes (Microsoft Corporation, Processor Device Driver) 0x8A1DF000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x8A9DB000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x806D2000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0x81900000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x903C2000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x8A2C9000 C:\Windows\system32\drivers\nfrd960.sys 57344 bytes (IBM Corporation, IBM ServeRAID Controller Driver) 0x90247000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x80732000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x9125A000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x901BC000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver) 0x8A2D7000 C:\Windows\system32\drivers\nvstor.sys 53248 bytes (NVIDIA Corporation, NVIDIA® nForce™ Sata Performance Driver) 0x8A598000 C:\Windows\system32\drivers\sisraid2.sys 53248 bytes (Microsoft Corporation, SiS RAID Stor Miniport Driver) 0x8FA86000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x8E901000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver) 0x805C4000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0x8FBF3000 C:\Windows\system32\DRIVERS\avgmfx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0x8A11A000 C:\Windows\system32\drivers\iteatapi.sys 49152 bytes (Integrated Technology Express, Inc., ITE IT8211 ATA/ATAPI SCSI miniport) 0x8A126000 C:\Windows\system32\drivers\iteraid.sys 49152 bytes (Integrated Technology Express, Inc., ITE IT8212 ATA RAID SCSI miniport) 0x8A5BA000 C:\Windows\system32\drivers\symc8xx.sys 49152 bytes (LSI Logic, LSI Logic 8XX SCSI Miniport Driver) 0xA74E9000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x8A1EE000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xA25DD000 C:\Windows\system32\DRIVERS\AVGIDSShim.Sys 45056 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Loader Driver.) 0x91267000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes 0x8273A000 C:\Windows\system32\drivers\hpcisss.sys 45056 bytes (Hewlett-Packard Company, Smart Array Storport Driver) 0x8A93F000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x8A97C000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x8A2BE000 C:\Windows\system32\drivers\mraid35x.sys 45056 bytes (LSI Logic Corporation, MegaRAID RAID Controller Driver for Windows Vista/Longhorn for x86) 0x9023C000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8A7D1000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x8A5C6000 C:\Windows\system32\drivers\sym_hi.sys 45056 bytes (LSI Logic, LSI Logic Hi-Perf SCSI Miniport Driver) 0x8A5D1000 C:\Windows\system32\drivers\sym_u3.sys 45056 bytes (LSI Logic, LSI Logic Ultra160 SCSI Miniport Driver) 0x8E9F2000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x8ABF5000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0xA751A000 C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 40960 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Filter Driver.) 0x806C8000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver) 0x9127A000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x8A100000 C:\Windows\system32\drivers\i2omp.sys 40960 bytes (Microsoft Corporation, I2O Miniport Driver) 0x8A164000 C:\Windows\system32\drivers\megasas.sys 40960 bytes (LSI Corporation, MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x86) 0x82730000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver) 0x8FA7C000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0x91397000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x90A3D000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0xA74DF000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x903E3000 C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect) 0x8A993000 C:\Windows\system32\DRIVERS\usbohci.sys 40960 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0x8ABCC000 C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 36864 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.) 0x8ABBE000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x8FA00000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0x901EF000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xA754E000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x90255000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0x903B9000 C:\Windows\system32\DRIVERS\SymIMv.sys 36864 bytes (Symantec Corporation, NDIS 6.0 Filter Driver for Windows Vista) 0x81890000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8AA00000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x8A91E000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0x80653000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x826AF000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x8041F000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x80755000 C:\Windows\system32\drivers\cmdide.sys 32768 bytes (CMD Technology, Inc., CMD PCI IDE Bus Driver) 0x91272000 C:\Windows\System32\Drivers\dump_atapi.sys 32768 bytes 0x80406000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0x8FBCA000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0x8065C000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x8A98B000 C:\Windows\system32\DRIVERS\nvsmu.sys 32768 bytes (NVIDIA Corporation, NVIDIA nForce™ SMU Microcontroller Driver) 0x9022C000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x90234000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8AB5A000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x807C3000 C:\Windows\system32\drivers\viaide.sys 32768 bytes (VIA Technologies, Inc., VIA Generic PCI IDE Bus Driver) 0x8AB19000 C:\Windows\system32\drivers\wd.sys 32768 bytes (Microsoft Corporation, Microsoft Watchdog Timer Driver) 0xA74F5000 C:\Windows\system32\DRIVERS\xaudio.sys 32768 bytes (Conexant Systems, Inc., Modem Audio Device Driver) 0x80747000 C:\Windows\system32\drivers\aliide.sys 28672 bytes (Acer Laboratories Inc., ALi mini IDE Driver) 0x8074E000 C:\Windows\system32\drivers\amdide.sys 28672 bytes (Microsoft Corporation, AMD IDE Driver) 0x8A400000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x901F8000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x8072B000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0x8F9F8000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x80740000 C:\Windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0x8A800000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0x8ABC7000 C:\Windows\system32\DRIVERS\avgrkx86.sys 20480 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver) 0x8A93A000 C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 20480 bytes (Hewlett-Packard Development Company, L.P., HpqKbFiltr Keyboard Filter Driver) 0x913A1000 C:\Windows\system32\DRIVERS\pnarp.sys 20480 bytes (Pure Networks, Inc., Address Resolution Protocol Driver) 0x8A987000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0xA25E8000 C:\Windows\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface x86 Driver) 0x806C5000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0x8F957000 C:\Windows\system32\DRIVERS\nvBridge.kmd 8192 bytes (NVIDIA Corporation, NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 186.44 ) 0x8FA50000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x8A97A000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) ============================================== >Stealth ============================================== 0x06FB0000 Hidden Image–>ECenter.dll [ EPROCESS 0x89987D90 ] PID: 3276, 1060864 bytes 0x00750000 Hidden Image–>CommonUtility.dll [ EPROCESS 0x89987D90 ] PID: 3276, 110592 bytes 0x009B0000 Hidden Image–>HP.ActiveSupportLibrary.dll [ EPROCESS 0x851DF020 ] PID: 5720, 110592 bytes 0x043E0000 Hidden Image–>ECLibrary.dll [ EPROCESS 0x89987D90 ] PID: 3276, 126976 bytes 0x041E0000 Hidden Image–>SystemStatus.dll [ EPROCESS 0x89987D90 ] PID: 3276, 143360 bytes 0x04190000 Hidden Image–>PCHealthSecurityPillar.dll [ EPROCESS 0x89987D90 ] PID: 3276, 208896 bytes 0x04160000 Hidden Image–>MessagingInterface.dll [ EPROCESS 0x89987D90 ] PID: 3276, 28672 bytes 0x05050000 Hidden Image–>MessagingClients.dll [ EPROCESS 0x89987D90 ] PID: 3276, 28672 bytes 0x05220000 Hidden Image–>RemotingClient.dll [ EPROCESS 0x89987D90 ] PID: 3276, 28672 bytes 0x04170000 Hidden Image–>MessagingMessages.dll [ EPROCESS 0x89987D90 ] PID: 3276, 36864 bytes 0x050C0000 Hidden Image–>Interop.RulesEngineLib.dll [ EPROCESS 0x89987D90 ] PID: 3276, 36864 bytes 0x007F0000 Hidden Image–>CommonInterfaces.dll [ EPROCESS 0x89987D90 ] PID: 3276, 45056 bytes 0x041D0000 Hidden Image–>Content.dll [ EPROCESS 0x89987D90 ] PID: 3276, 45056 bytes 0x04250000 Hidden Image–>HowToPillar.dll [ EPROCESS 0x89987D90 ] PID: 3276, 45056 bytes 0x04290000 Hidden Image–>Content.XmlSerializers.dll [ EPROCESS 0x89987D90 ] PID: 3276, 45056 bytes 0x04150000 Hidden Image–>MessagingServer.dll [ EPROCESS 0x89987D90 ] PID: 3276, 53248 bytes 0x04230000 Hidden Image–>PCAlertsPillar.dll [ EPROCESS 0x89987D90 ] PID: 3276, 69632 bytes AND GooredFix by jpshortstuff (03.07.10.1) Log created at 20:26 on 17/12/2010 (Aiken) Firefox version 3.0.19 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [02:03 16/04/2009] {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [18:46 12/07/2009] {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [23:38 19/09/2009] {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [04:10 22/10/2009] C:\Users\Aiken\Application Data\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\ [removed] [05:55 31/01/2010] [removed] [00:43 04/05/2009] [removed] [04:33 03/11/2010] {07b2a769-ed19-4483-87ce-c643914c9626} [05:55 31/01/2010] {20a82645-c095-46ed-80e3-08825760534b} [19:50 07/08/2009] {241aae70-0022-11de-87af-0800200c9a66} [05:55 31/01/2010] {2458abc0-f443-11dd-87af-0800200c9a66} [05:55 31/01/2010] {DDC359D1-844A-42a7-9AA1-88A850A938A8} [05:55 31/01/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [07:24 06/08/2009] "{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\" [00:13 27/04/2010] "[removed]"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [02:50 15/10/2010] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG10\Firefox\" [04:49 10/12/2010] "avg@igeared"="C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared" [04:51 10/12/2010] -=E.O.F=-
Hi nuggets4,

Are you still using Norton (symantec)?

Is it just FireFox or do you get redirected with Internet Explorer also?

Amongst other things you have been infected with an autorun infection. This will infect any USB device attached to the computer. How many of these devices do you have? and what are they?

*Note- When attaching the USB devices please hold the shift key down to preven it from auto running. Please run the following tool with each usb storage device you have attached to the computer. *

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone, camera, iPod etc. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O33 - MountPoints2\{cd231203-38f5-11de-9d9b-001f16715961}\Shell\AutoRun\command - "" = storage\sys.exe
O33 - MountPoints2\{cd231203-38f5-11de-9d9b-001f16715961}\Shell\opEN\coMmand - "" = storage\sys.exe
[2010/12/06 22:05:35 | 000,000,120 | —- | M] () – C:\Users\Aiken\AppData\Local\Wpekiyaloqetuguz.dat
[2010/12/06 22:05:35 | 000,000,000 | —- | M] () – C:\Users\Aiken\AppData\Local\Adiwuhifopawuqew.bin
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.

:Reg

:Files
c:\storage
k:\storage
o:\storage
g:\storage
h:\storage
i:\storage
ipconfig /flushdns /c

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

  • Right click on OTL.exe and click "Run as Adminstrator to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    winlogon.exe
    kb.dll
    /md5stop
    C:\Users\Public\Documents\Windows\*.* /s
    C:\Users\Public\Documents\Server\*.* /s
    C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60\*.* /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will a two notepad window. OTL.Txt

Please post back with
  • answers to any questions asked
  • OTL fi log
  • OTL.txt
Thanks
norton expired so i use avg now, and the main problem is the slow down of my internet speed by a bunch (400kb to 40), the redirect happens only sometimes though but its annoying as it redirects to stopzilla, and i see a bunch of stop zilla ads everywhere. i think the problem is with both browsers, here are the logs as requested

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cd231203-38f5-11de-9d9b-001f16715961}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd231203-38f5-11de-9d9b-001f16715961}\ not found.
File storage\sys.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cd231203-38f5-11de-9d9b-001f16715961}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd231203-38f5-11de-9d9b-001f16715961}\ not found.
File storage\sys.exe not found.
C:\Users\Aiken\AppData\Local\Wpekiyaloqetuguz.dat moved successfully.
C:\Users\Aiken\AppData\Local\Adiwuhifopawuqew.bin moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
========== REGISTRY ==========
========== FILES ==========
File\Folder c:\storage not found.
File\Folder k:\storage not found.
File\Folder o:\storage not found.
File\Folder g:\storage not found.
File\Folder h:\storage not found.
File\Folder i:\storage not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Aiken\Downloads\cmd.bat deleted successfully.
C:\Users\Aiken\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Aiken
->Temp folder emptied: 108355975 bytes
->Temporary Internet Files folder emptied: 846748 bytes
->Java cache emptied: 48671777 bytes
->FireFox cache emptied: 66913096 bytes
->Flash cache emptied: 50339 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Rachel

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 297597048 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5393475 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 503.00 mb


OTL by OldTimer - Version 3.2.17.3 log created on 12182010_003421

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\JETEBF.tmp not found!

Registry entries deleted on Reboot…

OTL logfile created on: 18/12/2010 12:57:45 AM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Aiken\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.81 Gb Total Space | 87.67 Gb Free Space | 39.35% Space Free | Partition Type: NTFS
Drive D: | 10.08 Gb Total Space | 1.74 Gb Free Space | 17.28% Space Free | Partition Type: NTFS
Drive J: | 778.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: AIKEN-PC | User Name: Aiken | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Aiken\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\FixCleaner\FixCleaner.exe (Slimware Utilities, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe (Pure Networks, Inc.)
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Aiken\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (nmservice) – C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe (Pure Networks, Inc.)
SRV - (nmraapache) – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe (Pure Networks, Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (lxbs_device) – C:\Windows\System32\lxbscoms.exe (Lexmark International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SYMREDRV) – C:\Windows\System32\drivers\NIS\1000000.07D\SYMREDRV.SYS File not found
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\NIS\1005000.087\SYMNDISV.SYS File not found
DRV - (SYMFW) – C:\Windows\System32\Drivers\NIS\1005000.087\SYMFW.SYS File not found
DRV - (SYMDNS) – C:\Windows\System32\drivers\NIS\1000000.07D\SYMDNS.SYS File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.004\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.004\NAVENG.SYS File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (ccHP) – C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NIS\1008000.029\SRTSP.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS (Symantec Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys (Symantec Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - ({95808DC4-FA4A-4C74-92FE-5B863F82066B}) – C:\Program Files\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pnarp) – C:\Windows\System32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ask.com/?o=101760&l=dis [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.023.001
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {A6019583-06BC-48DF-9674-1B41F4D8C420}:1.9.1
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c9626}:1.6
FF - prefs.js..extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:0.9
FF - prefs.js..extensions.enabledItems: {241aae70-0022-11de-87af-0800200c9a66}:3.6.30.01.10
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20100112
FF - prefs.js..extensions.enabledItems: [removed]:2.95
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=FWV5&o=14193&locale=en_US&apn_uid=0F3971E0-DE89-4C17-BCA2-17BD62612DD3&apn_ptnrs=FM&apn_sauid=C8D43456-B9DA-4563-9BA7-4E7119BA88E0&apn_dtid=TES002YYCA&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/04/26 19:13:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/10/14 21:50:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/16 21:21:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/12/09 23:52:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/27 23:15:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/19 18:18:32 | 000,000,000 | —D | M]

[2010/03/28 12:24:52 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions
[2010/03/28 12:24:52 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2009/05/30 18:23:32 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2009/05/06 18:23:25 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/17 00:10:23 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (ANTHEM) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{07b2a769-ed19-4483-87ce-c643914c9626}
[2009/08/07 14:50:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (Blue Fox) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{241aae70-0022-11de-87af-0800200c9a66}
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (Bloody Red) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{2458abc0-f443-11dd-87af-0800200c9a66}
[2010/01/31 00:55:50 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/01/31 00:55:50 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2009/05/03 19:43:23 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2010/11/03 18:20:17 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2009/05/05 16:27:37 | 000,000,682 | —- | M] () – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\searchplugins\ask.xml
[2010/12/17 16:07:43 | 000,002,568 | —- | M] () – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\searchplugins\askcom.xml
[2010/12/18 00:48:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2009/07/02 23:34:44 | 000,083,376 | —- | M] (NHN USA Inc.) – C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2009/08/17 06:42:14 | 000,073,728 | —- | M] (NHN USA Inc. ) – C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
[2008/10/08 03:47:11 | 000,001,618 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\FFToolbar.xml

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Aiken\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe (FrostWire Group)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll (Pure Networks, Inc.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Aiken\Desktop\PICS\titmouse\IMG_5045.JPG
O24 - Desktop BackupWallPaper: C:\Users\Aiken\Desktop\PICS\titmouse\IMG_5045.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/08/04 10:54:31 | 000,000,000 | —D | M] - J:\AutoRun – [ CDFS ]
O32 - AutoRun File - [2007/08/04 10:54:31 | 000,700,416 | R— | M] (Electronic Arts Inc.) - J:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2007/08/04 09:09:54 | 000,659,456 | R— | M] (Electronic Arts Inc.) - J:\AutoRunGUI.dll – [ CDFS ]
O32 - AutoRun File - [2007/08/04 11:00:52 | 000,000,152 | R— | M] () - J:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{028535e8-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535e8-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = G:\nba2k9setup.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = H:\autorun.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\directx\command - "" = H:\DirectX9\dxsetup.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\setup\command - "" = H:\setup.exe – File not found
O33 - MountPoints2\{028535ea-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535ea-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = I:\nba2k9setup.exe – File not found
O33 - MountPoints2\{070d673d-6670-11de-927b-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{070d673d-6670-11de-927b-001f16715961}\Shell\AutoRun\command - "" = J:\AutoRun.exe – [2007/08/04 10:54:31 | 000,700,416 | R— | M] (Electronic Arts Inc.)
O33 - MountPoints2\{ce917ddf-bea3-11df-a55d-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{ce917ddf-bea3-11df-a55d-001f16715961}\Shell\AutoRun\command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{f0e38f65-ca79-11de-b6cd-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{f0e38f65-ca79-11de-b6cd-001f16715961}\Shell\AutoRun\command - "" = O:\MediaManager.exe – File not found
O33 - MountPoints2\O\Shell - "" = AutoRun
O33 - MountPoints2\O\Shell\AutoRun\command - "" = O:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/18 00:34:21 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/17 20:26:34 | 000,000,000 | —D | C] – C:\Users\Aiken\Desktop\GooredFix Backups
[2010/12/16 23:08:34 | 000,094,848 | —- | C] (GMER) – C:\aglcrpow.sys
[2010/12/15 20:11:53 | 002,037,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/15 20:11:40 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/15 20:11:40 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/15 20:11:39 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/15 20:11:35 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/15 20:11:25 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/15 20:11:24 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/15 20:11:24 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/15 20:11:10 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/15 20:11:07 | 000,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/15 20:11:05 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/12/15 20:11:01 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/15 20:11:01 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/15 20:11:01 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/12/15 20:11:00 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/15 20:11:00 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/15 20:11:00 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/12/15 20:11:00 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/15 20:10:41 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/15 00:02:49 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\Malwarebytes
[2010/12/14 23:54:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/14 23:54:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/14 23:54:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/12/14 23:54:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/12 23:50:55 | 000,000,000 | —D | C] – C:\Users\Aiken\Desktop\swan
[2010/12/10 00:09:06 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Local\AVG Security Toolbar
[2010/12/10 00:06:34 | 000,000,000 | —D | C] – C:\msprivate
[2010/12/10 00:02:27 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\AVG10
[2010/12/09 23:52:46 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2010/12/09 23:52:01 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2010/12/09 23:49:10 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2010/12/09 23:49:10 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2010/12/09 22:52:18 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/12/09 22:26:12 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/12/08 04:12:38 | 000,251,728 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/12/06 22:05:33 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Local\{A6019583-06BC-48DF-9674-1B41F4D8C420}
[2010/12/06 22:03:44 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Windows
[2010/12/06 22:03:29 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Server
[2010/12/06 22:03:19 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60
[2010/11/19 18:18:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2010/11/19 18:18:19 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2 C:\Users\Aiken\Documents\*.tmp files -> C:\Users\Aiken\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/18 00:51:38 | 000,000,246 | —- | M] () – C:\ProgramData\hpqp.ini
[2010/12/18 00:50:32 | 000,000,378 | —- | M] () – C:\Windows\tasks\FixCleaner Startup.job
[2010/12/18 00:49:49 | 000,001,356 | —- | M] () – C:\Users\Aiken\AppData\Local\d3d9caps.dat
[2010/12/18 00:48:30 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/18 00:48:30 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/18 00:48:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/18 00:48:13 | 2951,086,080 | -HS- | M] () – C:\hiberfil.sys
[2010/12/17 20:12:15 | 000,000,190 | —- | M] () – C:\Users\Aiken\defogger_reenable
[2010/12/17 16:08:59 | 101,989,619 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/17 16:07:23 | 000,002,215 | —- | M] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes (2).lnk
[2010/12/16 23:08:34 | 000,094,848 | —- | M] (GMER) – C:\aglcrpow.sys
[2010/12/16 21:22:42 | 000,000,790 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2010/12/16 04:02:48 | 000,391,120 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/15 20:37:20 | 001,423,402 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 432.JPG
[2010/12/15 20:26:16 | 001,413,479 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 067.JPG
[2010/12/15 02:01:37 | 000,002,587 | —- | M] () – C:\Users\Aiken\Desktop\Microsoft Office Word 2007 (2).lnk
[2010/12/14 23:54:47 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/13 01:19:48 | 000,010,571 | —- | M] () – C:\Users\Aiken\Documents\In the case of Rv.docx
[2010/12/11 16:51:22 | 003,985,172 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 428.JPG
[2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/12/04 16:52:14 | 000,001,748 | —- | M] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/12/02 01:55:40 | 000,016,467 | —- | M] () – C:\Users\Aiken\Documents\The debate between nature vs.docx
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/28 21:40:58 | 000,018,539 | —- | M] () – C:\Users\Aiken\Documents\Notes on Review of Literature.docx
[2010/11/28 00:40:14 | 000,020,906 | —- | M] () – C:\Users\Aiken\Documents\Review of literature.docx
[2010/11/27 23:42:45 | 000,017,419 | —- | M] () – C:\Users\Aiken\Documents\REVIEW OF LIT WORKS.docx
[2010/11/27 14:01:52 | 000,691,708 | —- | M] () – C:\Windows\System32\perfh00C.dat
[2010/11/27 14:01:52 | 000,617,964 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/27 14:01:52 | 000,135,510 | —- | M] () – C:\Windows\System32\perfc00C.dat
[2010/11/27 14:01:52 | 000,112,698 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/26 07:39:07 | 000,011,543 | —- | M] () – C:\Users\Aiken\Documents\anthro debate.docx
[2010/11/26 07:37:26 | 000,013,854 | —- | M] () – C:\Users\Aiken\Documents\thriller film adaptation.docx
[2010/11/24 20:23:08 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAiken.job
[2010/11/24 01:19:26 | 000,011,059 | —- | M] () – C:\Users\Aiken\Documents\LAW and ORDER.docx
[2010/11/22 01:32:41 | 000,010,765 | —- | M] () – C:\Users\Aiken\Documents\anthro literature.docx
[2 C:\Users\Aiken\Documents\*.tmp files -> C:\Users\Aiken\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/17 20:11:44 | 000,000,190 | —- | C] () – C:\Users\Aiken\defogger_reenable
[2010/12/17 16:08:59 | 101,989,619 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/16 23:48:43 | 2951,086,080 | -HS- | C] () – C:\hiberfil.sys
[2010/12/15 20:01:18 | 001,423,402 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 432.JPG
[2010/12/15 20:01:12 | 003,985,172 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 428.JPG
[2010/12/14 23:54:47 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/13 01:12:06 | 000,010,571 | —- | C] () – C:\Users\Aiken\Documents\In the case of Rv.docx
[2010/12/11 23:42:34 | 001,413,479 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 067.JPG
[2010/12/09 23:51:46 | 000,000,790 | —- | C] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2010/12/04 16:52:14 | 000,001,748 | —- | C] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/12/02 01:55:38 | 000,016,467 | —- | C] () – C:\Users\Aiken\Documents\The debate between nature vs.docx
[2010/11/28 21:38:41 | 000,018,539 | —- | C] () – C:\Users\Aiken\Documents\Notes on Review of Literature.docx
[2010/11/27 22:05:40 | 000,017,419 | —- | C] () – C:\Users\Aiken\Documents\REVIEW OF LIT WORKS.docx
[2010/11/27 22:05:28 | 000,020,906 | —- | C] () – C:\Users\Aiken\Documents\Review of literature.docx
[2010/11/26 07:39:05 | 000,011,543 | —- | C] () – C:\Users\Aiken\Documents\anthro debate.docx
[2010/11/26 01:01:28 | 000,013,854 | —- | C] () – C:\Users\Aiken\Documents\thriller film adaptation.docx
[2010/11/24 01:19:25 | 000,011,059 | —- | C] () – C:\Users\Aiken\Documents\LAW and ORDER.docx
[2010/11/22 01:32:40 | 000,010,765 | —- | C] () – C:\Users\Aiken\Documents\anthro literature.docx
[2010/10/14 18:53:56 | 000,001,865 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/07/06 16:04:48 | 000,009,728 | —- | C] () – C:\Windows\System32\uc_karos_launching.dll
[2010/07/03 18:06:22 | 000,000,552 | —- | C] () – C:\Users\Aiken\AppData\Local\d3d8caps.dat
[2009/12/06 13:32:30 | 000,001,456 | —- | C] () – C:\Windows\System32\lxbsprod.ini
[2009/09/27 12:46:37 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\FnF4.txt
[2009/07/19 20:37:29 | 000,000,014 | —- | C] () – C:\Windows\System32\SysEngineDrive1.sys
[2009/05/08 19:29:05 | 000,000,031 | —- | C] () – C:\Windows\GunzLauncher.INI
[2009/04/21 15:43:26 | 000,001,356 | —- | C] () – C:\Users\Aiken\AppData\Local\d3d9caps.dat
[2009/04/16 21:08:42 | 000,014,336 | —- | C] () – C:\Users\Aiken\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/15 22:26:53 | 000,000,021 | —- | C] () – C:\ProgramData\hpqp.txt
[2009/04/15 22:18:13 | 000,027,839 | —- | C] () – C:\ProgramData\nvModes.001
[2009/04/15 21:58:46 | 000,027,839 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\QSwitch.txt
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\DSwitch.txt
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\AtStart.txt
[2009/03/11 08:41:07 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/03/11 08:40:58 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/03/11 08:40:30 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/03/11 08:39:51 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/03/11 08:37:48 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/03/11 08:37:18 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2008/10/25 05:57:46 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2008/10/25 05:51:48 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2008/10/25 05:49:52 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2008/10/25 05:48:29 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 04:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2002/11/13 09:40:22 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbsvs.dll
[2001/10/26 10:09:46 | 000,332,288 | —- | C] () – C:\Windows\System32\ConfigLib.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 21:34:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\System32\winlogon.exe
[2008/01/20 21:34:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< C:\Users\Public\Documents\Windows\*.* /s >

< C:\Users\Public\Documents\Server\*.* /s >
[2008/01/20 21:34:02 | 000,036,221 | —- | M] () – C:\Users\Public\Documents\Server\hlp.dat

< C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60\*.* /s >
[2010/12/06 22:03:55 | 000,028,842 | —- | M] () – C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60\enemies-names.txt
[2010/12/06 22:03:55 | 000,026,602 | —- | M] () – C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60\local.ini

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/20 21:34:26 | 000,242,744 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2008/01/20 21:34:22 | 000,225,792 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/01/20 22:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /90 >
[2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/11/12 13:19:38 | 000,299,984 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Aiken\Documents\YouTube- Bobby Lee & John Cena - MadTV 24 Skit.mp4:TOC.WMV

< End of report >
Hi nuggets4,

Ok we'll clean up the Norton remnants.

Download the Norton Removal Tool from HERE and save it to your desktop.

Next Right click on Norton_Removal_Tool.exe and chose Run as Administrator to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
2010/12/06 22:03:44 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Windows
[2010/12/06 22:03:29 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Server
[2010/12/06 22:03:19 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\609E32A989A820512E3900B50B486C60

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

  • Right click on OTL.exe and click "Run as Adminstrator to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Near the top click the None button (it may look greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    C:\Users\Aiken\AppData\Local\{A6019583-06BC-48DF-9674-1B41F4D8C420}\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will a two notepad window. OTL.Txt

Please post back with
  • OTL fi log
  • OTL.txt
Any improvement?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI