This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect/ internet virus?

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 28/12/2010 3:30:40 PM - Run 5
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Aiken\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.81 Gb Total Space | 103.13 Gb Free Space | 46.29% Space Free | Partition Type: NTFS
Drive D: | 10.08 Gb Total Space | 1.74 Gb Free Space | 17.28% Space Free | Partition Type: NTFS
Drive F: | 631.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 49.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: AIKEN-PC | User Name: Aiken | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Aiken\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Windows\System32\lpksetup.exe (Microsoft Corporation)
PRC - C:\Windows\System32\lpremove.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe (Pure Networks, Inc.)
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Aiken\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (nmservice) – C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe (Pure Networks, Inc.)
SRV - (nmraapache) – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe (Pure Networks, Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (lxbs_device) – C:\Windows\System32\lxbscoms.exe (Lexmark International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - ({95808DC4-FA4A-4C74-92FE-5B863F82066B}) – C:\Program Files\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pnarp) – C:\Windows\System32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ask.com/?o=101760&l=dis [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.023.001
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {A6019583-06BC-48DF-9674-1B41F4D8C420}:1.9.1
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c9626}:1.6
FF - prefs.js..extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:0.9
FF - prefs.js..extensions.enabledItems: {241aae70-0022-11de-87af-0800200c9a66}:3.6.30.01.10
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20100112
FF - prefs.js..extensions.enabledItems: [removed]:2.95
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/10/14 21:50:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/16 21:21:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/12/09 23:52:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/27 23:15:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/21 14:20:17 | 000,000,000 | —D | M]

[2010/03/28 12:24:52 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions
[2010/03/28 12:24:52 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2009/05/30 18:23:32 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2009/05/06 18:23:25 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/27 20:32:29 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (ANTHEM) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{07b2a769-ed19-4483-87ce-c643914c9626}
[2009/08/07 14:50:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (Blue Fox) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{241aae70-0022-11de-87af-0800200c9a66}
[2010/01/31 00:55:44 | 000,000,000 | —D | M] (Bloody Red) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{2458abc0-f443-11dd-87af-0800200c9a66}
[2010/01/31 00:55:50 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/01/31 00:55:50 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2009/05/03 19:43:23 | 000,000,000 | —D | M] – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\extensions\[removed]
[2009/05/05 16:27:37 | 000,000,682 | —- | M] () – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\searchplugins\ask.xml
[2010/12/21 12:55:40 | 000,002,568 | —- | M] () – C:\Users\Aiken\AppData\Roaming\Mozilla\Firefox\Profiles\wgv0u3cf.default\searchplugins\askcom.xml
[2010/12/21 14:20:25 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/21 14:20:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/07/02 23:34:44 | 000,083,376 | —- | M] (NHN USA Inc.) – C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2009/08/17 06:42:14 | 000,073,728 | —- | M] (NHN USA Inc. ) – C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
[2008/10/08 03:47:11 | 000,001,618 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\FFToolbar.xml

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Aiken\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe (FrostWire Group)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll (Pure Networks, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Aiken\Desktop\PICS\titmouse\IMG_5045.JPG
O24 - Desktop BackupWallPaper: C:\Users\Aiken\Desktop\PICS\titmouse\IMG_5045.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2002/06/06 01:56:50 | 000,061,440 | R— | M] () - F:\autoplay.exe – [ CDFS ]
O32 - AutoRun File - [2001/07/23 07:25:04 | 000,000,047 | R— | M] () - F:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{028535e8-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535e8-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = G:\nba2k9setup.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = H:\autorun.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\directx\command - "" = H:\DirectX9\dxsetup.exe – File not found
O33 - MountPoints2\{028535e9-591f-11de-b61e-001f16715961}\Shell\setup\command - "" = H:\setup.exe – File not found
O33 - MountPoints2\{028535ea-591f-11de-b61e-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{028535ea-591f-11de-b61e-001f16715961}\Shell\AutoRun\command - "" = I:\nba2k9setup.exe – File not found
O33 - MountPoints2\{b5aa0c73-8b42-11de-90c8-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{b5aa0c73-8b42-11de-90c8-001f16715961}\Shell\AutoRun\command - "" = F:\autoplay.exe – [2002/06/06 01:56:50 | 000,061,440 | R— | M] ()
O33 - MountPoints2\{ce917ddf-bea3-11df-a55d-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{ce917ddf-bea3-11df-a55d-001f16715961}\Shell\AutoRun\command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{f0e38f65-ca79-11de-b6cd-001f16715961}\Shell - "" = AutoRun
O33 - MountPoints2\{f0e38f65-ca79-11de-b6cd-001f16715961}\Shell\AutoRun\command - "" = O:\MediaManager.exe – File not found
O33 - MountPoints2\O\Shell - "" = AutoRun
O33 - MountPoints2\O\Shell\AutoRun\command - "" = O:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/28 00:54:56 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\InstallShield
[2010/12/21 14:27:28 | 000,000,000 | —D | C] – C:\Program Files\ICCup
[2010/12/21 14:20:43 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/12/21 14:20:17 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/12/21 14:20:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/12/21 14:20:17 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/12/21 14:20:17 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/12/21 13:19:18 | 000,139,264 | —- | C] (Blizzard Entertainment) – C:\Windows\War3Unin.exe
[2010/12/21 13:13:33 | 000,000,000 | —D | C] – C:\Program Files\Warcraft III
[2010/12/20 01:29:59 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/12/18 00:34:21 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/17 20:26:34 | 000,000,000 | —D | C] – C:\Users\Aiken\Desktop\GooredFix Backups
[2010/12/16 23:08:34 | 000,094,848 | —- | C] (GMER) – C:\aglcrpow.sys
[2010/12/15 20:11:53 | 002,037,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/15 20:11:40 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/15 20:11:40 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/15 20:11:39 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/15 20:11:35 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/15 20:11:25 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/15 20:11:24 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/15 20:11:24 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/15 20:11:10 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/15 20:11:07 | 000,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/15 20:11:05 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/12/15 20:11:01 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/15 20:11:01 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/15 20:11:01 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/12/15 20:11:00 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/15 20:11:00 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/15 20:11:00 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/12/15 20:11:00 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/15 20:10:41 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/15 00:02:49 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\Malwarebytes
[2010/12/14 23:54:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/14 23:54:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/14 23:54:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/12/14 23:54:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/12 23:50:55 | 000,000,000 | —D | C] – C:\Users\Aiken\Desktop\swan
[2010/12/10 00:09:06 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Local\AVG Security Toolbar
[2010/12/10 00:06:34 | 000,000,000 | —D | C] – C:\msprivate
[2010/12/10 00:02:27 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Roaming\AVG10
[2010/12/09 23:52:46 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2010/12/09 23:52:01 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2010/12/09 23:49:10 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2010/12/09 23:49:10 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2010/12/09 22:52:18 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/12/09 22:26:12 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/12/08 04:12:38 | 000,251,728 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/12/06 22:05:33 | 000,000,000 | —D | C] – C:\Users\Aiken\AppData\Local\{A6019583-06BC-48DF-9674-1B41F4D8C420}
[2010/12/06 22:03:44 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Windows
[2 C:\Users\Aiken\Documents\*.tmp files -> C:\Users\Aiken\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/28 15:16:56 | 102,824,950 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/28 15:08:51 | 000,000,246 | —- | M] () – C:\ProgramData\hpqp.ini
[2010/12/28 15:07:22 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/28 15:07:22 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/28 15:07:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/28 15:07:01 | 2951,077,888 | -HS- | M] () – C:\hiberfil.sys
[2010/12/28 00:12:31 | 000,002,215 | —- | M] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes (2).lnk
[2010/12/28 00:03:48 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAiken.job
[2010/12/27 21:40:58 | 002,248,550 | —- | M] () – C:\Windows\System32\drivers\NIS\1008000.029\Cat.DB
[2010/12/27 18:28:24 | 000,000,790 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2010/12/25 00:43:25 | 001,823,804 | —- | M] () – C:\Users\Aiken\Documents\christmas photos.docx
[2010/12/25 00:24:18 | 000,002,587 | —- | M] () – C:\Users\Aiken\Desktop\Microsoft Office Word 2007 (2).lnk
[2010/12/25 00:18:28 | 000,015,872 | —- | M] () – C:\Users\Aiken\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/21 14:27:33 | 000,001,744 | —- | M] () – C:\Users\Aiken\Desktop\ICCup Launcher.lnk
[2010/12/21 13:33:19 | 000,055,389 | —- | M] () – C:\Windows\War3Unin.dat
[2010/12/21 13:33:19 | 000,001,701 | —- | M] () – C:\Users\Aiken\Desktop\Frozen Throne.lnk
[2010/12/21 13:31:22 | 000,139,264 | —- | M] (Blizzard Entertainment) – C:\Windows\War3Unin.exe
[2010/12/21 13:31:22 | 000,002,829 | —- | M] () – C:\Windows\War3Unin.pif
[2010/12/21 13:21:22 | 000,001,694 | —- | M] () – C:\Users\Aiken\Desktop\Warcraft III.lnk
[2010/12/21 13:13:45 | 000,691,708 | —- | M] () – C:\Windows\System32\perfh00C.dat
[2010/12/21 13:13:45 | 000,617,964 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/21 13:13:45 | 000,135,510 | —- | M] () – C:\Windows\System32\perfc00C.dat
[2010/12/21 13:13:45 | 000,112,698 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/18 00:49:49 | 000,001,356 | —- | M] () – C:\Users\Aiken\AppData\Local\d3d9caps.dat
[2010/12/17 20:12:15 | 000,000,190 | —- | M] () – C:\Users\Aiken\defogger_reenable
[2010/12/16 23:08:34 | 000,094,848 | —- | M] (GMER) – C:\aglcrpow.sys
[2010/12/16 04:02:48 | 000,391,120 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/15 20:37:20 | 001,423,402 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 432.JPG
[2010/12/15 20:26:16 | 001,413,479 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 067.JPG
[2010/12/14 23:54:47 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/13 01:19:48 | 000,010,571 | —- | M] () – C:\Users\Aiken\Documents\In the case of Rv.docx
[2010/12/11 16:51:22 | 003,985,172 | —- | M] () – C:\Users\Aiken\Desktop\YIN FAN KONG 428.JPG
[2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/12/04 16:52:14 | 000,001,748 | —- | M] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/12/02 01:55:40 | 000,016,467 | —- | M] () – C:\Users\Aiken\Documents\The debate between nature vs.docx
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/28 21:40:58 | 000,018,539 | —- | M] () – C:\Users\Aiken\Documents\Notes on Review of Literature.docx
[2 C:\Users\Aiken\Documents\*.tmp files -> C:\Users\Aiken\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/28 15:16:56 | 102,824,950 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/25 00:37:42 | 001,823,804 | —- | C] () – C:\Users\Aiken\Documents\christmas photos.docx
[2010/12/21 14:27:33 | 000,001,744 | —- | C] () – C:\Users\Aiken\Desktop\ICCup Launcher.lnk
[2010/12/21 13:33:19 | 000,001,701 | —- | C] () – C:\Users\Aiken\Desktop\Frozen Throne.lnk
[2010/12/21 13:21:22 | 000,001,694 | —- | C] () – C:\Users\Aiken\Desktop\Warcraft III.lnk
[2010/12/21 13:19:20 | 000,055,389 | —- | C] () – C:\Windows\War3Unin.dat
[2010/12/21 13:19:18 | 000,002,829 | —- | C] () – C:\Windows\War3Unin.pif
[2010/12/17 20:11:44 | 000,000,190 | —- | C] () – C:\Users\Aiken\defogger_reenable
[2010/12/16 23:48:43 | 2951,077,888 | -HS- | C] () – C:\hiberfil.sys
[2010/12/15 20:01:18 | 001,423,402 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 432.JPG
[2010/12/15 20:01:12 | 003,985,172 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 428.JPG
[2010/12/14 23:54:47 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/13 01:12:06 | 000,010,571 | —- | C] () – C:\Users\Aiken\Documents\In the case of Rv.docx
[2010/12/11 23:42:34 | 001,413,479 | —- | C] () – C:\Users\Aiken\Desktop\YIN FAN KONG 067.JPG
[2010/12/09 23:51:46 | 000,000,790 | —- | C] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2010/12/04 16:52:14 | 000,001,748 | —- | C] () – C:\Users\Aiken\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/12/02 01:55:38 | 000,016,467 | —- | C] () – C:\Users\Aiken\Documents\The debate between nature vs.docx
[2010/11/28 21:38:41 | 000,018,539 | —- | C] () – C:\Users\Aiken\Documents\Notes on Review of Literature.docx
[2010/10/14 18:53:56 | 000,001,865 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/07/06 16:04:48 | 000,009,728 | —- | C] () – C:\Windows\System32\uc_karos_launching.dll
[2010/07/03 18:06:22 | 000,000,552 | —- | C] () – C:\Users\Aiken\AppData\Local\d3d8caps.dat
[2009/12/06 13:32:30 | 000,001,456 | —- | C] () – C:\Windows\System32\lxbsprod.ini
[2009/09/27 12:46:37 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\FnF4.txt
[2009/07/19 20:37:29 | 000,000,014 | —- | C] () – C:\Windows\System32\SysEngineDrive1.sys
[2009/05/08 19:29:05 | 000,000,031 | —- | C] () – C:\Windows\GunzLauncher.INI
[2009/04/21 15:43:26 | 000,001,356 | —- | C] () – C:\Users\Aiken\AppData\Local\d3d9caps.dat
[2009/04/16 21:08:42 | 000,015,872 | —- | C] () – C:\Users\Aiken\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/15 22:26:53 | 000,000,021 | —- | C] () – C:\ProgramData\hpqp.txt
[2009/04/15 22:18:13 | 000,027,839 | —- | C] () – C:\ProgramData\nvModes.001
[2009/04/15 21:58:46 | 000,027,839 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\QSwitch.txt
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\DSwitch.txt
[2009/04/15 20:33:36 | 000,000,000 | —- | C] () – C:\Users\Aiken\AppData\Local\AtStart.txt
[2009/03/11 08:41:07 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/03/11 08:40:58 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/03/11 08:40:30 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/03/11 08:39:51 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/03/11 08:37:48 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/03/11 08:37:18 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2008/10/25 05:57:46 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2008/10/25 05:51:48 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2008/10/25 05:49:52 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2008/10/25 05:48:29 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 04:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2002/11/13 09:40:22 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbsvs.dll
[2001/10/26 10:09:46 | 000,332,288 | —- | C] () – C:\Windows\System32\ConfigLib.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Aiken\Documents\YouTube- Bobby Lee & John Cena - MadTV 24 Skit.mp4:TOC.WMV

< End of report >
Hi nuggets4,

Let's try it this way.

Open device manager and right click on the wireless adaptor.
  • click properties
  • click the driver tab
  • click the Uninstall button beside "To uninstall the driver (Advanced)"
  • Reboot
  • Locate the file you downloaded earlier on your desktop
  • right click it and select "Run as Adminstrator" to install it
  • follow the on screen instruction

Working now?
Hi nuggets4,

If no other problems, we can clean up our tools. Keep Defogger, we will use it shortly.

From your desktop, please delete
  • any notepads/logs that we created
  • GMER
  • GooredFix
  • GooredFix Backups
  • RKUnhookerLE.exe
  • Flash_Disinfector.exe
  • Norton_Removal_Tool.exe
Open windows explorer and delete this file C:\aglcrpow.sys

Eset online can be removed via add/remove programs if you wish.


Next

*We'll reset your restore points

  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.
  • Next, go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Choose the option to clean up system restore and Ok it
This will remove all restore points except the most recent one.


Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly as an on demand scanner.


To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

You can delete Defogger now.


Updates and upgrades

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI