This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Adware" infected laptop

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Step 1. Please tell us what issues you're having with your computer.

*Windows Setup API is blocked from starting up.
*Random chats from Java
*Clicking a link from a search engine like Google will redirect me to a different site like Myspace,a job search engine,etc.
*Random pop-ups from Windows Internet Explorer asking me if I "want to close this window",because a webpage is "trying to". I always exit out of this window.
*File Security Warnings telling me that a file named bct from p.briling.com is trying to download itself onto my laptop. I always tell it to cancel.
*A Random window poping up and asking me to press "CTRL + D". I also always exit out of this window.
*Random sounds coming from nowhere. They sound like ads. (EX: "Congratulations,you've won a free X!")
*Random pop-up ads in an IE browser. Like a banner for a website.
*IE randomly opens up to a website page.

I don't use IE,I use Firefox.

"Tell us if you're having any problems, and please be specific. Let us know what you've already done to fix it (if anything)."

I have tried to run multiple cleaning or anti-something programs.
*Avast! Anti-Virus (scan)
*Spybot: Search and Destory (scan + immunization)
*Advanced SystemCare Free Spyware (Scan,Registry Fix,Junk Files clean,System Optimization,Security Defense,Disk Defragment and Security Analyzer)
*IObit Security 360 (scan)
*Rootkit Buster (scan)
*CCleaner (scan)
*Doing the above in Safemode

So far they have found
*win32.fraudload.edt
*Microsoft.WindowsSecurityCenter_Disabled
*Right Media
*Multiple Tracking Cookies
*Many of my files with ZONE$DATA attached to them and considered "Stream or File" (Rootkit Buster)
*Multiple "hidden files"(Rootkit Buster)
*Something with XML at the end of it. I've forgotten the exact name but it doesn't appear in scans anymore…

This is all I can remember so far.
I "fixed" or "deleted" the problems these programs found,but when I scanned again the files were found AGAIN and I was still experiencing the same problems.

Hijackthis Log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:02:19 PM, on 12/26/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Game Booster\GameBox.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\IObit\IObit Security 360\is360tray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\System32\notepad.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Users\KIKIWI~1\AppData\Local\Temp\Wzd.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\Users\Kiki Wiki\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\KIKIWI~1\AppData\Local\Temp\Wzd.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111T\wlan111t.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0B386B45-B2CF-4525-82FE-D3489C2D26C9} - http://www.latale.com/Launcher/ActozWebLauncher.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: TipCtrl - Unknown owner - C:\Program Files\uTIPu\TipCtrl.exe (file missing)
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

–
End of file - 9647 bytes
Hi Somethingsimple, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Right click on the file you downloaded and click "Run as Administrator" to run it. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode


Next

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

Next

Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • MBRCheck log
  • both OTL logs
Thanks
Thank you for the reply! Here are the logs you asked for.

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-27 16:01:07
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK1637GSX rev.DL030M
Running: s3jb5ryb.exe; Driver: C:\Users\KIKIWI~1\AppData\Local\Temp\kglirkod.sys


—- System - GMER 1.0.15 —-

INT 0x52 ? 86340BF8
INT 0x72 ? 86340BF8
INT 0x72 ? 86340BF8
INT 0x92 ? 84A30BF8
INT 0xA2 ? 84A30BF8
INT 0xB2 ? 84A30BF8
INT 0xB2 ? 84A30BF8
INT 0xB2 ? 84A30BF8
INT 0xB3 ? 86340BF8

—- Kernel code sections - GMER 1.0.15 —-

? System32\Drivers\spsw.sys The system cannot find the path specified. !
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8F406000, 0x205494, 0xE8000020]
.text USBPORT.SYS!DllUnload 8FF6F41B 5 Bytes JMP 863401D8
.text acv11a1z.SYS 8B17D000 22 Bytes [82, 53, 1C, 82, 6C, 52, 1C, …]
.text acv11a1z.SYS 8B17D017 181 Bytes [00, 32, 07, F0, 8A, 3D, 05, …]
.text acv11a1z.SYS 8B17D0CE 73 Bytes [00, 00, 00, 00, 01, C2, 03, …]
.text acv11a1z.SYS 8B17D118 185 Bytes [3F, 48, 3E, 8A, 3C, CC, 3D, …]
.text acv11a1z.SYS 8B17D1D2 22 Bytes [E0, C2, E2, 84, E3, 46, E6, …]
.text …

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\Explorer.EXE[3352] kernel32.dll!CreateProcessW 76CE1BF3 6 Bytes JMP 5F0D0F5A
.text C:\Windows\Explorer.EXE[3352] kernel32.dll!CreateProcessA 76CE1C28 6 Bytes JMP 5F0A0F5A
.text C:\Windows\Explorer.EXE[3352] kernel32.dll!LoadLibraryExW 76D09109 6 Bytes JMP 5F070F5A
.text C:\Windows\Explorer.EXE[3352] ADVAPI32.dll!CreateProcessAsUserW 77011EE9 6 Bytes JMP 5F100F5A
.text C:\Windows\Explorer.EXE[3352] ADVAPI32.dll!CreateProcessWithLogonW 770580C1 6 Bytes JMP 5F040F5A

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 853C41F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 84A321F8
Device \Driver\usbohci \Device\USBPDO-0 863481F8
Device \Driver\sptd \Device\2152195219 spsw.sys
Device \Driver\usbohci \Device\USBPDO-1 863481F8
Device \Driver\usbohci \Device\USBPDO-2 863481F8
Device \Driver\usbohci \Device\USBPDO-3 863481F8
Device \Driver\usbohci \Device\USBPDO-4 863481F8

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbehci \Device\USBPDO-5 8633F1F8
Device \Driver\volmgr \Device\HarddiskVolume1 84A321F8
Device \Driver\volmgr \Device\HarddiskVolume2 84A321F8
Device \Driver\cdrom \Device\CdRom0 8633E1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 853C31F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3 853C31F8
Device \Driver\atapi \Device\Ide\IdePort0 853C31F8
Device \Driver\atapi \Device\Ide\IdePort1 853C31F8
Device \Driver\atapi \Device\Ide\IdePort2 853C31F8
Device \Driver\atapi \Device\Ide\IdePort3 853C31F8
Device \Driver\cdrom \Device\CdRom1 8633E1F8
Device \Driver\cdrom \Device\CdRom2 8633E1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 86B85500
Device \Driver\Smb \Device\NetbiosSmb 86D20500
Device \Driver\PCI_PNP7201 \Device\0000004e spsw.sys
Device \Driver\iScsiPrt \Device\RaidPort0 863C31F8

AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\netbt \Device\NetBT_Tcpip_{940AB514-CF60-4CF9-A04B-5887F4D92A41} 86B85500
Device \Driver\usbohci \Device\USBFDO-0 863481F8
Device \Driver\usbohci \Device\USBFDO-1 863481F8
Device \Driver\usbohci \Device\USBFDO-2 863481F8
Device \Driver\netbt \Device\NetBT_Tcpip_{A4F030BC-DB9B-4FAF-8BB5-6940A10227D9} 86B85500
Device \Driver\usbohci \Device\USBFDO-3 863481F8
Device \Driver\usbohci \Device\USBFDO-4 863481F8
Device \Driver\usbehci \Device\USBFDO-5 8633F1F8
Device \Driver\acv11a1z \Device\Scsi\acv11a1z1Port5Path0Target1Lun0 863C0500
Device \Driver\acv11a1z \Device\Scsi\acv11a1z1Port5Path0Target0Lun0 863C0500
Device \Driver\acv11a1z \Device\Scsi\acv11a1z1 863C0500
Device \FileSystem\cdfs \Cdfs 85C3C1F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0x14 0x82 0x43 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD1 0x73 0xD7 0xFD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x22 0x2D 0x94 0x15 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x8D 0x07 0x0B …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0x14 0x82 0x43 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD1 0x73 0xD7 0xFD …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x22 0x2D 0x94 0x15 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x8D 0x07 0x0B …

—- Files - GMER 1.0.15 —-

File C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ILBVJL5\blogger[1].htm 0 bytes
File C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ILBVJL5\navbar[2].g 0 bytes

—- EOF - GMER 1.0.15 —-


MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: TOSHIBA
BIOS Manufacturer: TOSHIBA
System Manufacturer: TOSHIBA
System Product Name: Satellite A215
Logical Drives Mask: 0x0000003c

Kernel Drivers (total 150):
0x81E05000 \SystemRoot\system32\ntkrnlpa.exe
0x821BE000 \SystemRoot\system32\hal.dll
0x8060C000 \SystemRoot\system32\kdcom.dll
0x80613000 \SystemRoot\system32\PSHED.dll
0x80624000 \SystemRoot\system32\BOOTVID.dll
0x8062C000 \SystemRoot\system32\CLFS.SYS
0x8066D000 \SystemRoot\system32\CI.dll
0x8074D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x807C9000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8AE02000 \SystemRoot\System32\Drivers\spsw.sys
0x8AEF5000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8AEFE000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x8AF24000 \SystemRoot\system32\drivers\acpi.sys
0x8AF6A000 \SystemRoot\system32\drivers\msisadrv.sys
0x8AF72000 \SystemRoot\system32\drivers\pci.sys
0x8AF99000 \SystemRoot\System32\drivers\partmgr.sys
0x8AFA8000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8AFAB000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8AFB5000 \SystemRoot\system32\drivers\volmgr.sys
0x8B007000 \SystemRoot\System32\drivers\volmgrx.sys
0x8B051000 \SystemRoot\system32\drivers\pciide.sys
0x8B058000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8B066000 \SystemRoot\system32\DRIVERS\pcmcia.sys
0x8B093000 \SystemRoot\System32\drivers\mountmgr.sys
0x8B0A3000 \SystemRoot\system32\drivers\atapi.sys
0x8B0AB000 \SystemRoot\system32\drivers\ataport.SYS
0x8B0C9000 \SystemRoot\system32\drivers\fltmgr.sys
0x8B0FB000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B10B000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B206000 \SystemRoot\system32\drivers\ndis.sys
0x8B311000 \SystemRoot\system32\drivers\msrpc.sys
0x8B33C000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B40C000 \SystemRoot\System32\drivers\tcpip.sys
0x8B4F6000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B607000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B717000 \SystemRoot\system32\drivers\volsnap.sys
0x8B750000 \SystemRoot\system32\DRIVERS\TVALZ_O.SYS
0x8B755000 \SystemRoot\System32\Drivers\spldr.sys
0x8B75D000 \SystemRoot\System32\Drivers\mup.sys
0x8B76C000 \SystemRoot\System32\drivers\ecache.sys
0x8B793000 \SystemRoot\system32\drivers\disk.sys
0x8B7A4000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B7C5000 \SystemRoot\system32\drivers\crcdisk.sys
0x8B7DB000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8B7E4000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x8F405000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x8F918000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8F9B9000 \SystemRoot\System32\drivers\watchdog.sys
0x8B511000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x8FE06000 \SystemRoot\system32\DRIVERS\athr.sys
0x8FF35000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8FF3F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8FF7D000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8FF8C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8FFA4000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8B552000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8FFAA000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8FFBD000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8FFC8000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8FFFA000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F9C5000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8FFFC000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8F9D0000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8F9E0000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8B377000 \SystemRoot\system32\drivers\tifm21.sys
0x8B5DF000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8B17C000 \SystemRoot\System32\Drivers\acv11a1z.SYS
0x8F9EE000 \SystemRoot\system32\DRIVERS\dfmirage.sys
0x8B3C4000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0x8FE00000 \SystemRoot\system32\DRIVERS\wacomvhid.sys
0x8B3E5000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F9F5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8AFC4000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x9040D000 \SystemRoot\system32\DRIVERS\storport.sys
0x9044E000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x90459000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x90470000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x9047B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x9049E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x904AD000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x904C1000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x904D6000 \SystemRoot\system32\DRIVERS\termdd.sys
0x904E6000 \SystemRoot\system32\DRIVERS\swenum.sys
0x904E8000 \SystemRoot\system32\DRIVERS\ks.sys
0x90512000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x9051C000 \SystemRoot\system32\DRIVERS\umbus.sys
0x90529000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x9055E000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x90566000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys
0x9056E000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x90805000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x90921000 \SystemRoot\system32\drivers\modem.sys
0x90A02000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x90D15000 \SystemRoot\system32\drivers\portcls.sys
0x90D42000 \SystemRoot\system32\drivers\drmk.sys
0x90D67000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x90D70000 \SystemRoot\System32\Drivers\Null.SYS
0x90D77000 \SystemRoot\System32\Drivers\Beep.SYS
0x90D7E000 \SystemRoot\System32\drivers\vga.sys
0x90D8A000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x90D92000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90D9A000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90DA5000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90DB3000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x90DBC000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90DD2000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x90DDD000 \SystemRoot\system32\DRIVERS\smb.sys
0x9092E000 \SystemRoot\system32\drivers\afd.sys
0x90DF1000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x90976000 \SystemRoot\System32\DRIVERS\netbt.sys
0x909A8000 \SystemRoot\system32\DRIVERS\pacer.sys
0x909BE000 \SystemRoot\system32\DRIVERS\netbios.sys
0x909CC000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x9057F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90DF6000 \SystemRoot\system32\drivers\nsiproxy.sys
0x909DF000 \??\C:\Windows\system32\drivers\elrawdsk.sys
0x909E3000 \SystemRoot\System32\Drivers\dfsc.sys
0x905BB000 \SystemRoot\System32\Drivers\aswSP.SYS
0x99050000 \SystemRoot\System32\win32k.sys
0x905E9000 \SystemRoot\System32\drivers\Dxapi.sys
0x8B1E4000 \SystemRoot\system32\DRIVERS\monitor.sys
0x99270000 \SystemRoot\System32\TSDDD.dll
0x99290000 \SystemRoot\System32\cdd.dll
0x992A0000 \SystemRoot\System32\ATMFD.DLL
0x807D6000 \SystemRoot\system32\drivers\luafv.sys
0x9BC0F000 \SystemRoot\system32\DRIVERS\aswMonFlt.sys
0x9BC26000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x9BC31000 \SystemRoot\system32\drivers\spsys.sys
0x9BCE1000 \SystemRoot\system32\DRIVERS\AegisP.sys
0x9BCE5000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9BCF5000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9BD1F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9BD29000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9BD3C000 \SystemRoot\system32\drivers\HTTP.sys
0x9BDA9000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9BDC6000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9BDDF000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9F201000 \SystemRoot\system32\drivers\mrxdav.sys
0x9F222000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9F241000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9F27A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9F292000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9F2BA000 \SystemRoot\System32\DRIVERS\srv.sys
0x9F320000 \SystemRoot\system32\drivers\peauth.sys
0x9F308000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9F312000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9BDF4000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xCA80F000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xCA825000 \??\C:\Users\KIKIWI~1\AppData\Local\Temp\kglirkod.sys
0x77510000 \Windows\System32\ntdll.dll

Processes (total 67):
0 System Idle Process
4 System
488 C:\Windows\System32\smss.exe
556 csrss.exe
616 C:\Windows\System32\wininit.exe
628 csrss.exe
660 C:\Windows\System32\services.exe
672 C:\Windows\System32\lsass.exe
684 C:\Windows\System32\lsm.exe
724 C:\Windows\System32\winlogon.exe
864 C:\Windows\System32\svchost.exe
936 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\Ati2evxx.exe
1056 C:\Windows\System32\svchost.exe
1092 C:\Windows\System32\svchost.exe
1108 C:\Windows\System32\svchost.exe
1216 C:\Windows\System32\audiodg.exe
1240 C:\Windows\System32\svchost.exe
1264 C:\Windows\System32\SLsvc.exe
1308 C:\Windows\System32\svchost.exe
1408 C:\Windows\System32\Ati2evxx.exe
1480 C:\Program Files\WTouch\WTouchService.exe
1532 C:\Windows\System32\wisptis.exe
1540 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
1700 C:\Windows\System32\svchost.exe
1848 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
340 C:\Windows\System32\taskeng.exe
372 C:\Windows\System32\spoolsv.exe
512 C:\Windows\System32\svchost.exe
856 C:\Windows\System32\rundll32.exe
780 C:\Windows\System32\agrsmsvc.exe
2060 C:\Windows\System32\svchost.exe
2080 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
2096 C:\Program Files\Bonjour\mDNSResponder.exe
2184 C:\Program Files\IObit\IObit Security 360\is360srv.exe
2260 C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
2312 C:\Windows\System32\svchost.exe
2328 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2372 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2412 C:\Windows\System32\svchost.exe
2456 C:\Windows\System32\Pen_Tablet.exe
2508 C:\Windows\System32\svchost.exe
2548 C:\Windows\System32\SearchIndexer.exe
3328 C:\Program Files\Alwil Software\Avast5\Setup\avast.setup
888 C:\Windows\System32\dwm.exe
1400 C:\Windows\System32\wisptis.exe
1620 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
3352 C:\Windows\explorer.exe
3488 C:\Windows\System32\taskeng.exe
3744 C:\Windows\System32\WTablet\Pen_TabletUser.exe
1996 C:\Windows\System32\Pen_Tablet.exe
2140 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3908 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
4084 C:\Program Files\NETGEAR\WG111T\wlan111t.exe
3372 C:\Program Files\Windows Media Player\wmpnscfg.exe
1040 C:\Windows\System32\wbem\unsecapp.exe
2668 WmiPrvSE.exe
4988 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
5240 C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
2996 C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe
6080 C:\Program Files\WTouch\WTouchUser.exe
4400 C:\Windows\System32\SearchProtocolHost.exe
2700 C:\Windows\System32\SearchFilterHost.exe
1596 C:\Windows\System32\notepad.exe
2120 C:\Program Files\Mozilla Firefox\firefox.exe
4684 C:\Program Files\Mozilla Firefox\plugin-container.exe
4424 C:\Users\Kiki Wiki\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)

PhysicalDrive0 Model Number: TOSHIBAMK1637GSX, Rev: DL030M

Size Device Name MBR Status
——————————————–
149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!

OTL logfile created on: 12/27/2010 4:07:08 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Kiki Wiki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 55.21 Gb Free Space | 37.41% Space Free | Partition Type: NTFS

Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kiki Wiki\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe (Windows ® Codename Longhorn DDK provider)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files\WTouch\WTouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Alwil Software\Avast5\Setup\avast.setup (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Windows\System32\wisptis.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)


========== Modules (SafeList) ==========

MOD - C:\Users\Kiki Wiki\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TipCtrl) – C:\Program Files\uTIPu\TipCtrl.exe File not found
SRV - (Akamai) – C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll ()
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (IS360service) – C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV - (TabletServicePen) – C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Driver Services (SafeList) ==========

DRV - (XDva296) – C:\Windows\System32\XDva296.sys File not found
DRV - (XDva285) – C:\Windows\System32\XDva285.sys File not found
DRV - (XDva277) – C:\Windows\System32\XDva277.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (wacmoumonitor) – C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (RsFx0103) – C:\Windows\System32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\elrawdsk.sys (EldoS Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (dfmirage) – C:\Windows\System32\drivers\dfmirage.sys (DemoForge, LLC)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (AR5523) – C:\Windows\System32\drivers\WG11TND5.sys (NETGEAR, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 91 DF 33 37 A1 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.87
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\Firefox [2010/12/03 21:53:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/12/03 21:53:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/21 20:42:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/21 20:42:16 | 000,000,000 | —D | M]

[2010/06/22 13:57:06 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions
[2010/06/22 13:57:06 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/26 15:53:43 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions
[2010/11/03 20:32:23 | 000,000,000 | —D | M] (FireShot) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2010/04/26 19:00:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/11 08:58:19 | 000,000,000 | —D | M] (No name found) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/12/23 09:15:11 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/12/11 12:28:28 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/03/16 00:06:51 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]
[2010/12/24 12:28:48 | 000,001,820 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\bing.xml
[2010/09/02 20:51:39 | 000,002,059 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\daemon-search.xml
[2010/12/24 12:29:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/03 19:09:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/04 12:15:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/28 09:37:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/09/24 23:02:40 | 000,098,304 | —- | M] (OGPlanet Inc.) – C:\Program Files\Mozilla Firefox\plugins\npOGPPlugin.dll

O1 HOSTS File: ([2010/12/25 20:52:45 | 000,428,340 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14749 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [JP595IR86O] C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe (Windows ® Codename Longhorn DDK provider)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0B386B45-B2CF-4525-82FE-D3489C2D26C9} http://www.latale.com/Launcher/ActozWebLauncher.cab (Reg Error: Value error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Reg Error: Value error.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} http://www.yoyogames.com/downloads/activex/YoYo.cab (YYGInstantPlay Control)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{512a183b-b7c1-11df-947b-0016d4fe31a5}\Shell - "" = AutoRun
O33 - MountPoints2\{512a183b-b7c1-11df-947b-0016d4fe31a5}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{685596cf-1044-11df-b409-0016d4fe31a5}\Shell - "" = AutoRun
O33 - MountPoints2\{685596cf-1044-11df-b409-0016d4fe31a5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{c62d17cc-5fc6-11de-b885-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c62d17cc-5fc6-11de-b885-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/27 16:03:54 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Kiki Wiki\Desktop\OTL.exe
[2010/12/26 17:58:58 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HijackThis.exe
[2010/12/25 21:52:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/12/25 20:48:56 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys
[2010/12/25 20:48:56 | 000,056,400 | —- | C] (trend_company_name) – C:\Windows\System32\drivers\tmrkb.sys
[2010/12/25 11:50:00 | 001,912,872 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HousecallLauncher.exe
[2010/12/25 11:10:37 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\TMRBLog
[2010/12/25 11:09:42 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\log
[2010/12/25 11:09:35 | 002,486,352 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\RootkitBuster.exe
[2010/12/25 10:09:40 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Apps
[2010/12/24 15:20:17 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/12/24 15:20:17 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/12/24 11:31:25 | 000,098,392 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/12/24 11:27:43 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Sunbelt Software
[2010/12/24 11:26:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/12/24 11:26:12 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/12/23 09:48:49 | 000,241,664 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\Wbegua.exe
[2010/12/16 13:10:27 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010/12/16 13:02:10 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2010/12/16 12:45:53 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\Adobe CS5
[2010/12/16 11:45:30 | 001,228,400 | —- | C] (Adobe Systems Incorporated) – C:\Users\Kiki Wiki\Photoshop_12_LS1.exe
[2010/12/16 11:41:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Akamai
[2010/12/14 15:03:23 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/14 15:02:42 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/14 15:02:26 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/14 15:02:15 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/12/14 15:02:13 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/12/14 15:02:13 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/14 15:02:13 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/14 15:02:13 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/14 15:02:12 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/14 15:02:12 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/14 15:02:11 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/14 15:02:11 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/14 15:02:11 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/12/14 15:02:11 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/12/14 15:02:11 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/12/14 15:02:11 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/12/14 15:02:11 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/14 15:02:11 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/14 15:02:11 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/14 15:02:06 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/14 15:02:06 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/14 15:02:06 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/14 15:00:37 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/14 15:00:35 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/14 15:00:35 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/14 14:59:11 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/03 21:53:12 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/11/29 17:38:30 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/11/28 10:30:38 | 000,089,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SQSRVRES.DLL
[2010/11/28 10:30:38 | 000,072,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.2.4000.0.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/27 16:03:54 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Kiki Wiki\Desktop\OTL.exe
[2010/12/27 16:02:25 | 000,080,384 | —- | M] () – C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
[2010/12/27 16:00:50 | 000,000,300 | -H– | M] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/27 15:47:53 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/27 15:47:53 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/27 14:10:31 | 000,296,448 | —- | M] () – C:\Users\Kiki Wiki\Desktop\s3jb5ryb.exe
[2010/12/27 14:04:41 | 000,000,378 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2010/12/27 11:47:58 | 000,000,312 | -HS- | M] () – C:\Windows\tasks\lwmcdovil.job
[2010/12/27 11:47:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/27 11:47:47 | 3621,830,656 | -HS- | M] () – C:\hiberfil.sys
[2010/12/26 17:59:00 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HijackThis.exe
[2010/12/25 21:52:24 | 000,000,775 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/12/25 20:52:45 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/12/25 20:50:17 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys
[2010/12/25 20:50:17 | 000,056,400 | —- | M] (trend_company_name) – C:\Windows\System32\drivers\tmrkb.sys
[2010/12/25 17:34:14 | 000,007,268 | —- | M] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2010/12/25 11:50:09 | 001,912,872 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HousecallLauncher.exe
[2010/12/25 10:23:21 | 000,000,036 | —- | M] () – C:\Users\Kiki Wiki\AppData\Local\housecall.guid.cache
[2010/12/25 09:40:20 | 000,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2010/12/25 09:40:20 | 000,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2010/12/24 19:36:06 | 003,630,896 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/24 19:31:07 | 000,000,118 | —- | M] () – C:\Windows\wininit.ini
[2010/12/24 19:23:24 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101225-205245.backup
[2010/12/24 17:53:58 | 000,000,139 | —- | M] () – C:\Users\Kiki Wiki\Desktop\IObit Freeware.url
[2010/12/24 17:53:57 | 000,001,009 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/12/24 17:53:57 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/12/24 15:37:09 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101224-192324.backup
[2010/12/24 15:36:34 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101224-153709.backup
[2010/12/24 15:20:32 | 000,001,050 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/24 15:20:32 | 000,001,026 | —- | M] () – C:\Users\Kiki Wiki\Desktop\Spybot - Search & Destroy.lnk
[2010/12/24 11:31:25 | 000,098,392 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/12/23 09:48:38 | 000,241,664 | —- | M] (Windows ® Codename Longhorn DDK provider) – C:\Windows\Wbegua.exe
[2010/12/23 09:48:38 | 000,061,440 | RHS- | M] () – C:\Windows\System32\rasgcwh.dll
[2010/12/23 09:15:18 | 000,000,872 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2010/12/23 09:15:18 | 000,000,860 | —- | M] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/12/23 09:15:18 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/12/22 18:23:37 | 000,000,132 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/21 21:28:22 | 000,000,629 | —- | M] () – C:\Windows\System32\mapisvc.inf
[2010/12/21 20:53:44 | 000,001,635 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/21 20:41:59 | 000,001,697 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/16 14:31:19 | 000,705,454 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/16 14:31:19 | 000,142,764 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/16 12:45:39 | 001,228,400 | —- | M] (Adobe Systems Incorporated) – C:\Users\Kiki Wiki\Photoshop_12_LS1.exe
[2010/12/16 12:45:35 | 1026,293,791 | —- | M] () – C:\Users\Kiki Wiki\Photoshop_12_LS1.7z
[2010/12/14 19:55:40 | 000,007,918 | —- | M] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2010/12/07 18:05:04 | 002,486,352 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\RootkitBuster.exe
[2010/11/29 17:38:30 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/27 16:02:22 | 000,080,384 | —- | C] () – C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
[2010/12/27 14:10:28 | 000,296,448 | —- | C] () – C:\Users\Kiki Wiki\Desktop\s3jb5ryb.exe
[2010/12/25 21:52:24 | 000,000,775 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/12/25 20:45:19 | 3621,830,656 | -HS- | C] () – C:\hiberfil.sys
[2010/12/25 10:23:21 | 000,000,036 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\housecall.guid.cache
[2010/12/25 09:37:48 | 000,001,905 | —- | C] () – C:\Windows\diagwrn.xml
[2010/12/25 09:37:48 | 000,001,905 | —- | C] () – C:\Windows\diagerr.xml
[2010/12/24 19:33:49 | 000,000,300 | -H– | C] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/24 19:31:07 | 000,000,118 | —- | C] () – C:\Windows\wininit.ini
[2010/12/24 17:54:09 | 000,000,378 | —- | C] () – C:\Windows\tasks\AWC Startup.job
[2010/12/24 17:53:58 | 000,000,139 | —- | C] () – C:\Users\Kiki Wiki\Desktop\IObit Freeware.url
[2010/12/24 17:53:57 | 000,001,009 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/12/24 17:53:57 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/12/24 15:20:32 | 000,001,050 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/24 15:20:32 | 000,001,026 | —- | C] () – C:\Users\Kiki Wiki\Desktop\Spybot - Search & Destroy.lnk
[2010/12/23 09:48:38 | 000,061,440 | RHS- | C] () – C:\Windows\System32\rasgcwh.dll
[2010/12/23 09:48:38 | 000,000,312 | -HS- | C] () – C:\Windows\tasks\lwmcdovil.job
[2010/12/23 09:15:18 | 000,000,872 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2010/12/23 09:15:18 | 000,000,860 | —- | C] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/12/23 09:15:18 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/12/21 20:53:44 | 000,001,635 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/21 20:41:59 | 000,001,697 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/16 19:18:10 | 000,000,132 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/16 11:45:30 | 1026,293,791 | —- | C] () – C:\Users\Kiki Wiki\Photoshop_12_LS1.7z
[2010/12/14 19:55:40 | 000,007,918 | —- | C] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2010/11/13 21:46:21 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/09/02 20:51:26 | 000,691,696 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2010/03/17 22:21:41 | 000,000,032 | —- | C] () – C:\Windows\System32\Video Converter.dll
[2010/03/17 00:17:00 | 000,000,032 | —- | C] () – C:\Windows\System32\Cool Motion.dll
[2009/12/03 09:27:30 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/08 16:01:46 | 000,000,552 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d8caps.dat
[2009/09/06 08:45:35 | 000,005,632 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/15 11:26:15 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2009/07/15 11:10:50 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2009/07/15 11:10:49 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2009/07/15 11:10:49 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2009/07/15 11:10:49 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2009/07/08 18:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/06/24 10:01:03 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/23 17:12:10 | 000,651,264 | —- | C] () – C:\Windows\System32\libeay32.dll
[2009/06/23 17:12:10 | 000,147,456 | —- | C] () – C:\Windows\System32\ssleay32.dll
[2009/06/23 08:45:17 | 000,007,268 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2008/06/03 03:35:18 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/07/23 19:21:29 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Bitsoft
[2010/02/15 11:43:59 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\CheckPoint
[2010/09/02 21:01:42 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DAEMON Tools Lite
[2010/09/04 10:02:46 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DAEMON Tools Pro
[2010/12/24 12:00:52 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DNA
[2010/02/14 14:45:17 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DriverCure
[2010/10/11 08:29:36 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoft
[2010/06/04 21:54:40 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/04/26 21:20:26 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\FinalMediaPlayer
[2010/06/06 21:04:15 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\FireShot
[2010/06/05 03:58:19 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\GetRightToGo
[2010/12/14 19:55:40 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\gtk-2.0
[2009/08/08 22:52:32 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Handy Uninstaller
[2010/11/18 15:19:14 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\IObit
[2009/07/15 15:36:37 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\iolo
[2010/02/27 16:09:46 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Lingoes
[2010/06/21 00:05:13 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Northcode
[2010/05/23 20:29:14 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\REAPER
[2009/06/24 22:33:40 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\TeamViewer
[2010/10/14 15:11:27 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\WTouch
[2010/12/27 14:04:41 | 000,000,378 | —- | M] () – C:\Windows\Tasks\AWC Startup.job
[2010/12/27 11:47:58 | 000,000,312 | -HS- | M] () – C:\Windows\Tasks\lwmcdovil.job
[2010/12/27 08:56:51 | 000,032,572 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/12/27 16:00:50 | 000,000,300 | -H– | M] () – C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/07/26 10:53:58 | 000,487,424 | —- | M] (http://aegisknight.org/) – C:\audiere.dll
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/06/23 01:22:46 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/04/11 10:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 10:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 10:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 10:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 10:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 10:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 10:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 10:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 10:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2008/04/11 10:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/12/27 11:47:47 | 3621,830,656 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 10:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2010/02/15 11:41:18 | 000,000,197 | —- | M] () – C:\INSTALL.LOG
[2008/04/11 08:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 08:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 08:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 08:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 08:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 08:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 08:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/09/15 15:50:42 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/09/15 15:50:42 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/27 11:47:45 | 3935,436,800 | -HS- | M] () – C:\pagefile.sys
[2008/04/11 10:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 10:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 10:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/06/24 10:12:29 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/06/23 15:26:37 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 03:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-16 17:54:22

========== Files - Unicode (All) ==========
[2010/09/13 17:41:50 | 002,004,992 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park ?A DAY IN THE LIFE?.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park 『A DAY IN THE LIFE』.mp3
[2010/09/13 17:41:48 | 006,051,840 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - ??- ???.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - シド- ミルク.mp3
[2010/09/13 17:41:48 | 003,035,136 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. ???? ????????.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. 初音ミク ブログと同音質版.mp3
[2010/09/13 17:41:47 | 004,376,576 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - ???? - sm4459602 - HQ.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - 星間飛行 - sm4459602 - HQ.mp3
[2010/09/11 11:21:45 | 004,376,576 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - ???? - sm4459602 - HQ.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - 星間飛行 - sm4459602 - HQ.mp3
[2010/09/11 11:14:33 | 006,051,840 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - ??- ???.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - シド- ミルク.mp3
[2010/09/11 11:10:49 | 003,035,136 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. ???? ????????.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. 初音ミク ブログと同音質版.mp3
[2010/09/11 11:02:53 | 002,004,992 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park ?A DAY IN THE LIFE?.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park 『A DAY IN THE LIFE』.mp3

< End of report >

OTL Extras logfile created on: 12/27/2010 4:07:08 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Kiki Wiki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 55.21 Gb Free Space | 37.41% Space Free | Partition Type: NTFS

Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04C19692-20E1-4212-9EC5-BA3B0898AEFE}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{0AE4A5DE-D6F9-41DD-9D46-9C255DF6BF6B}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{41789F26-9455-4A9A-B441-0C4B522D258D}" = lport=49160 | protocol=6 | dir=in | name=akamai netsession interface |
"{483EFD29-6B80-4904-AA3D-9BADF25571AE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{56155B2B-C965-40F1-B73A-6359F77DB7A9}" = lport=51775 | protocol=6 | dir=in | name=akamai netsession interface |
"{6C83C253-696C-4417-AE22-226950AB733E}" = lport=2869 | protocol=6 | dir=in | name=tcp 2869 |
"{8E494691-5429-4D01-89A3-592A97EFAF43}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D6A4A9DB-8182-4BA1-B95A-EE4A5F4E3523}" = lport=1900 | protocol=17 | dir=in | name=udp 1900 |
"{DB0CD793-2C48-4635-9C42-D59C305F31A9}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E2ADC45-7928-4A97-8513-B718D272717C}" = protocol=6 | dir=in | app=c:\nexon\poptag\ca.exe |
"{2862ED87-0797-4CF3-8F48-008D4C92834A}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{3DA7EA6F-3BAC-4489-AE94-D9D52E223C3D}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{3DF5BD29-C425-42C6-83AF-367A069230F8}" = protocol=6 | dir=in | app=c:\program files\ogplanet\lostsaga\autoupgrade.exe |
"{3E264563-5FEF-4ACC-9367-B0B9DF2FB56D}" = protocol=17 | dir=in | app=c:\program files\ogplanet\lostsaga\lostsaga.exe |
"{3F0FFBB6-F6E3-438F-9B98-76DECAE4AB5E}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{431493B4-9B99-4B16-92FC-89069BC71471}" = protocol=6 | dir=in | app=c:\nexon\poptag\nmcosrv.exe |
"{453A58D9-DDD0-476F-8261-FEB7ED954AF7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4CEBF241-1E82-4388-BC3E-A4C8033C15EC}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{4F6C11E6-88AE-4496-ADB7-A0FA354A2B61}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5569E7BF-3837-4F82-93EF-9EFFD125C23F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{5981CFE7-F262-45AC-AA04-A13AB750EC1D}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{6F965EE9-2D21-4922-8433-F88E03E7E869}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{73B1934C-7C0F-4B65-B2DE-4230D7989F08}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{7A4CBD17-0092-488A-A36F-BBDD84803751}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{7EEF8BE4-FD27-45AE-9FA6-714F992D1F55}" = protocol=6 | dir=in | app=c:\program files\ogplanet\lostsaga\lostsaga.exe |
"{7F7C4808-8B88-445B-8CAE-EDBDF1AC35B3}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{822DEF79-01C9-4CFA-93C2-4080423BF5C6}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{A09EE0DE-2834-4FBD-B3CB-30E1B6650A66}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A1EA4971-F2D3-4125-8E07-521FAC2D3194}" = protocol=17 | dir=in | app=c:\nexon\poptag\ca.exe |
"{B6C574B2-5DB4-45F0-B7A5-7AA25277C937}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B9ED01BF-4D7F-4EC9-A8A3-80F811CB0DC1}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{BD75B57D-A891-424A-BE17-F816FD272B6D}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{D41944FB-2C67-4AE1-8307-092FAAFB0E38}" = protocol=17 | dir=in | app=c:\nexon\poptag\nmcosrv.exe |
"{D642394C-11D1-4283-95C8-09D22866D6E4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D9D384DE-64DF-44F3-826D-F576D54E54D8}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{E903D496-ECC7-4C94-9C13-40877EF09835}" = protocol=17 | dir=in | app=c:\program files\ogplanet\lostsaga\autoupgrade.exe |
"{F0DFD4F9-EF22-43F5-B971-EBDA59F1B309}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{F1E8B8B5-0551-4DA5-B81A-5C5C9FB20868}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{F6822CCE-3EDC-4C86-A7D9-BB3859440770}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{FE24A2CB-4790-48B5-BEE7-9198B1BE5077}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"TCP Query User{3EAC2078-9A66-4AD4-AE6B-780BC06D6267}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"TCP Query User{4ED94695-FA36-4606-8DAD-DC9380B270BE}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{62D90031-3B72-4156-9231-93F7C7E4E2FB}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"TCP Query User{69F4FC7B-3B72-4C25-B223-366307CE31AD}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{A2852FBB-D8E9-4484-9D25-70E0ACB37E0C}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{44306FEC-FA9A-4298-91D1-41657AD40C3B}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{4B8847F1-04F4-4D64-8CD3-26C1E307CB62}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"UDP Query User{BDDEAC7F-81D9-42A3-924F-D40698E57906}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"UDP Query User{E55CCD6C-32A8-4822-AC56-9AD164E98E02}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{F0E4708C-DBA1-4903-AD39-8A466FE4451B}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02EE107B-8D95-4949-8935-4DEBE8F08BE3}" = Bing Bar Platform
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB03}" = La Tale
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26119A24-8F74-4F62-A278-AB3984B12C04}" = Microsoft Web Platform Installer 2.0 RC
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 22
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros for Acer Driver v7.6.0.239_Foxconn Installation Program
"{29BB979E-63CC-439C-8B9B-D628949BA889}" = N.E.O.Online
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{51123D42-6B9C-4B93-900C-29F9EC5963C9}" = NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5AE3D9F1-9E9E-4015-8787-E22705AA32C5}" = msxml4
"{5B161932-9D42-4D5E-858D-29BF4C670944}" = Microsoft SQL Server 2008 Setup Support Files
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{94317163-C5D1-4FCE-A0D9-F48FE06A7D7D}" = Microsoft SQL Server 2008 Native Client
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E989D16F-0B39-4E74-8BD5-149BEE1477FE}" = Microsoft SQL Server 2008 RsFx Driver
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1C60F3E-70CF-42BF-8FEC-7B101A8C4868}" = IrisOnline
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F7B05784-334C-4F76-8BAB-30ABEB7FD534}" = TIPCI
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"7-Zip" = 7-Zip 9.17 beta
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Akamai" = Akamai NetSession Interface
"Alarm_is1" = Alarm
"All ATI Software" = ATI - Software Uninstall Utility
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"FormatFactory" = FormatFactory 2.40
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free Studio_is1" = Free Studio version 4.8
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9
"Game Booster_is1" = Game Booster
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HyperCam 2" = HyperCam 2
"InstallShield_{F7B05784-334C-4F76-8BAB-30ABEB7FD534}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"IObit Security 360_is1" = IObit Security 360
"IsoBuster_is1" = IsoBuster 2.5
"LameACM" = LameACM
"Legend of Edda" = Legend of Edda USA_v1.0
"Lingoes Translator_is1" = Lingoes 2.6.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"OGPlanet Game Launcher US" = OGPlanet Game Launcher
"Pen Tablet Driver" = Bamboo
"Revo Uninstaller" = Revo Uninstaller 1.89
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 5" = TeamViewer 5
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Traverso_is1" = Traverso 0.49.1
"Uninstall_is1" = Uninstall 1.0.0.1
"VisualRoute" = VisualRoute
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 7/15/2009 12:50:09 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 12:50:12 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 12:50:12 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:08 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:08 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:09 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:09 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:38 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:38 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

Error - 7/15/2009 2:12:44 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 8/3/2010 4:00:59 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/4/2010 4:00:59 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/4/2010 4:01:20 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/5/2010 4:00:41 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/5/2010 4:01:01 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/5/2010 9:36:17 PM | Computer Name = KikiWiki-PC | Source = Application Hang | ID = 1002
Description = The program sparkle.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 2f44 Start Time: 01cb3507b1548a61 Termination Time: 6

Error - 8/6/2010 4:00:08 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/6/2010 4:00:28 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/6/2010 4:58:04 AM | Computer Name = KikiWiki-PC | Source = EventSystem | ID = 4621
Description =

Error - 8/6/2010 4:58:09 AM | Computer Name = KikiWiki-PC | Source = IS360service | ID = 0
Description =

[ System Events ]
Error - 12/27/2010 11:51:40 AM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 12/27/2010 11:51:52 AM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 12/27/2010 11:53:00 AM | Computer Name = KikiWiki-PC | Source = WMPNetworkSvc | ID = 866297
Description =

Error - 12/27/2010 11:53:22 AM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/27/2010 11:53:22 AM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/27/2010 2:47:32 PM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 12/27/2010 2:47:45 PM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 12/27/2010 2:49:22 PM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/27/2010 2:49:22 PM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/27/2010 4:58:27 PM | Computer Name = KikiWiki-PC | Source = WMPNetworkSvc | ID = 866297
Description =


< End of report >
Hi Somethingsimple,

BitTorrent DNA
You have BitTorrent DNA, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself but what can be downloaded with it usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall BitTorrent DNA, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Please download DeFogger to your desktop.

Right click DeFogger and select "run as Administrator" to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.



We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe
    C:\Windows\Wbegua.exe
    C:\Windows\System32\rasgcwh.dll

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKCU..\Run: [JP595IR86O] C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe (Windows ® Codename Longhorn DDK provider)
[2010/12/27 16:00:50 | 000,000,300 | -H– | M] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/27 11:47:58 | 000,000,312 | -HS- | M] () – C:\Windows\tasks\lwmcdovil.job

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log




Next

Open OTL again if it's closed
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UnCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open anotepad windows. OTL.Txt, no Extra.txt this time.

Please post back with
  • VirScan results
  • OTL fix log
  • OTL.txt
How's the computer?

Thanks
I stopped using my laptop as soon as I posted this thread,and I'm only turning it on to check back here :huh:.
So after doing the steps in your 2nd post,should I use my laptop for a few hours and see if my problems continue/how my laptop is acting?
After the OTL reboot,I noticed automatically that Windows API isn't blocked from starting anymore.
And should I uninstall bittorrent after getting help,or can I uninstall it now?

File Information
VirSCAN.org Scanned Report :
Scanned time : 2010/12/27 19:35:11 (MST)
Scanner results: 22% Scanner(s) (8/36) found malware!
File Name : Wzd.exe
File Size : 252928 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 1b7bd40c34a7a78df72537c0a598b2f1
SHA1 : e24ab310d57a2d77b494227904e50f508892862d
Online report : http://virscan.org/report/9886122c01107005…2fe9ddc2ec.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.1.0.2 20101228024137 2010-12-28 5.39 Trojan-Downloader.Win32.Renos!IK
AhnLab V3 2010.12.17.05 2010.12.17 2010-12-17 1.59 -
AntiVir 8.2.4.131 7.11.0.144 2010-12-22 0.28 -
Antiy 2.0.18 20101221.6716246 2010-12-21 0.12 -
Arcavir 2010 201012280924 2010-12-28 0.08 Heur.W32
Authentium 5.1.1 201012221600 2010-12-22 1.64 -
AVAST! 4.7.4 101222-1 2010-12-22 0.03 -
AVG 8.5.850 271.1.1/3332 2010-12-23 0.27 -
BitDefender 7.90123.6478295 7.35283 2010-12-23 5.95 -
ClamAV 0.96.3 12428 2010-12-23 0.07 -
Comodo 4.0 7208 2010-12-27 1.09 -
CP Secure 1.3.0.5 2010.12.28 2010-12-28 0.07 -
Dr.Web 5.0.2.3300 2010.12.23 2010-12-23 10.53 -
F-Prot 4.4.4.56 20101222 2010-12-22 1.59 -
F-Secure 7.02.73807 2010.12.23.01 2010-12-23 1.06 -
Fortinet 4.2.254 12.723 2010-12-27 0.21 -
GData 21.1413/21.571 20101228 2010-12-28 8.23 Win32:MalOb-EA [Cryp] [Engine:B]
ViRobot 20101227 2010.12.27 2010-12-27 0.38 -
Ikarus T3.1.32.15.0 2010.12.23.77402 2010-12-23 5.01 -
JiangMin 13.0.900 2010.12.27 2010-12-27 1.84 -
Kaspersky 5.5.10 2010.12.22 2010-12-22 0.09 -
KingSoft 2009.2.5.15 2010.12.28.9 2010-12-28 0.82 -
McAfee 5400.1158 6205 2010-12-22 18.36 -
Microsoft 1.6402 2010.12.28 2010-12-28 3.95 TrojanDownloader:Win32/Renos.LX
Norman 6.06.12 6.06.00 2010-12-19 12.01 -
Panda 9.05.01 2010.12.27 2010-12-27 2.52 -
Trend Micro 9.120-1004 7.718.05 2010-12-22 0.04 -
Quick Heal 11.00 2010.12.27 2010-12-27 1.01 -
Rising 20.0 22.80.00.00 2010-12-27 1.48 Trojan.Win32.Generic.5254BDED
Sophos 3.14.1 4.60 2010-12-28 3.05 Mal/EncPk-NS
Sunbelt 3.9.2464.2 7852 2010-12-27 0.68 VirTool.Win32.Obfuscator.hg!b1 (v)
Symantec 1.3.0.24 20101227.002 2010-12-27 0.06 -
nProtect 20101225.01 9426873 2010-12-25 16.66 Gen:Variant.Kazy.6445
The Hacker 6.7.0.1 v00106 2010-12-27 0.42 -
VBA32 3.12.14.2 20101221.1312 2010-12-21 3.33 -
VirusBuster 4.5.11.10 10.130.51/1998622 2010-12-22 2.90 -

VirSCAN.org Scanned Report :
Scanned time : 2010/12/27 19:39:01 (MST)
Scanner results: 22% Scanner(s) (8/36) found malware!
File Name : Wbegua.exe
File Size : 241664 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 9b9fd4c4d7b79df2b3ee4cf9ce4e4a8b
SHA1 : 4909210ee7a054f0b35982bbb04a245c9039c7bb
Online report : http://virscan.org/report/8a1169b498fc8597…0336afb95d.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.1.0.2 20101228024137 2010-12-28 5.03 Trojan-Downloader.Win32.Renos!IK
AhnLab V3 2010.12.17.05 2010.12.17 2010-12-17 1.44 -
AntiVir 8.2.4.131 7.11.0.144 2010-12-22 0.28 -
Antiy 2.0.18 20101221.6716246 2010-12-21 0.12 -
Arcavir 2010 201012280924 2010-12-28 0.07 Heur.W32
Authentium 5.1.1 201012221600 2010-12-22 2.10 -
AVAST! 4.7.4 101222-1 2010-12-22 0.02 -
AVG 8.5.850 271.1.1/3332 2010-12-23 0.28 -
BitDefender 7.90123.6478295 7.35283 2010-12-23 6.02 -
ClamAV 0.96.3 12428 2010-12-23 0.07 -
Comodo 4.0 7208 2010-12-27 0.97 MalCrypt.Indus!
CP Secure 1.3.0.5 2010.12.28 2010-12-28 0.07 -
Dr.Web 5.0.2.3300 2010.12.23 2010-12-23 10.20 -
F-Prot 4.4.4.56 20101222 2010-12-22 2.11 -
F-Secure 7.02.73807 2010.12.23.01 2010-12-23 0.14 -
Fortinet 4.2.254 12.723 2010-12-27 0.24 -
GData 21.1413/21.571 20101228 2010-12-28 7.36 Trojan-Downloader.Win32.CodecPack.abbl [Engine:A]
ViRobot 20101227 2010.12.27 2010-12-27 0.42 -
Ikarus T3.1.32.15.0 2010.12.23.77402 2010-12-23 5.09 -
JiangMin 13.0.900 2010.12.27 2010-12-27 1.38 -
Kaspersky 5.5.10 2010.12.22 2010-12-22 0.09 -
KingSoft 2009.2.5.15 2010.12.28.9 2010-12-28 0.72 -
McAfee 5400.1158 6205 2010-12-22 18.35 -
Microsoft 1.6402 2010.12.28 2010-12-28 4.54 TrojanDownloader:Win32/Renos.LX
Norman 6.06.12 6.06.00 2010-12-19 10.01 -
Panda 9.05.01 2010.12.27 2010-12-27 2.91 -
Trend Micro 9.120-1004 7.718.05 2010-12-22 0.04 -
Quick Heal 11.00 2010.12.27 2010-12-27 2.54 -
Rising 20.0 22.80.00.00 2010-12-27 5.01 Trojan.Win32.Generic.5254C0B1
Sophos 3.14.1 4.60 2010-12-28 3.05 Mal/EncPk-NS
Sunbelt 3.9.2464.2 7852 2010-12-27 0.68 Trojan.Win32.Generic!SB.0
Symantec 1.3.0.24 20101227.002 2010-12-27 0.09 -
nProtect 20101225.01 9426873 2010-12-25 40.09 -
The Hacker 6.7.0.1 v00106 2010-12-27 0.42 -
VBA32 3.12.14.2 20101221.1312 2010-12-21 3.32 -
VirusBuster 4.5.11.10 10.130.51/1998622 2010-12-22 2.79 -

I do not have "permission" to upload the C:\Windows\System32\rasgcwh.dll file.

OTL fix log

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\JP595IR86O deleted successfully.
C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe moved successfully.
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job moved successfully.
C:\Windows\Tasks\lwmcdovil.job moved successfully.
========== COMMANDS ==========


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 1547668 bytes
->Temporary Internet Files folder emptied: 1705364 bytes
->FireFox cache emptied: 3922351 bytes
->Flash cache emptied: 434 bytes

User: Kiki Wiki
->Temp folder emptied: 48000411 bytes
->Temporary Internet Files folder emptied: 188777760 bytes
->Java cache emptied: 52512323 bytes
->FireFox cache emptied: 107624995 bytes
->Flash cache emptied: 17704 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8439142 bytes
RecycleBin emptied: 421961 bytes

Total Files Cleaned = 394.00 mb


OTL by OldTimer - Version 3.2.18.0 log created on 12272010_195259

Files\Folders moved on Reboot…
File\Folder C:\Users\Kiki Wiki\AppData\Local\Temp\~DF863.tmp not found!
File\Folder C:\Users\Kiki Wiki\AppData\Local\Temp\~DFAC6.tmp not found!
File\Folder C:\Users\Kiki Wiki\AppData\Local\Temp\~DFB43.tmp not found!
File\Folder C:\Users\Kiki Wiki\AppData\Local\Temp\~DFBA3.tmp not found!
File\Folder C:\Users\Kiki Wiki\AppData\Local\Temp\~DFC42.tmp not found!
File\Folder C:\Users\Kiki Wiki\AppData\Local\Temp\~DFCC5.tmp not found!
C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WAY1YQG1\ads[2].htm moved successfully.
C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RTK58ZWJ\ads[2].htm moved successfully.
C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJKH31DC\ads[3].htm moved successfully.
C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
C:\Windows\temp\_asw_aisI.tm~a01132\setup.lok moved successfully.

Registry entries deleted on Reboot…

OTL logfile created on: 12/27/2010 8:02:24 PM - Run 2
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Kiki Wiki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 52.76 Gb Free Space | 35.75% Space Free | Partition Type: NTFS

Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kiki Wiki\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\IObit\Game Booster\GameBox.exe (IObit)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files\WTouch\WTouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Alwil Software\Avast5\Setup\avast.setup (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Windows\System32\wisptis.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)


========== Modules (SafeList) ==========

MOD - C:\Users\Kiki Wiki\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TipCtrl) – C:\Program Files\uTIPu\TipCtrl.exe File not found
SRV - (Akamai) – C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll ()
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (IS360service) – C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV - (TabletServicePen) – C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Driver Services (SafeList) ==========

DRV - (XDva296) – C:\Windows\System32\XDva296.sys File not found
DRV - (XDva285) – C:\Windows\System32\XDva285.sys File not found
DRV - (XDva277) – C:\Windows\System32\XDva277.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (wacmoumonitor) – C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (RsFx0103) – C:\Windows\System32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\elrawdsk.sys (EldoS Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (dfmirage) – C:\Windows\System32\drivers\dfmirage.sys (DemoForge, LLC)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (AR5523) – C:\Windows\System32\drivers\WG11TND5.sys (NETGEAR, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 91 DF 33 37 A1 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.87
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\Firefox [2010/12/03 21:53:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/12/03 21:53:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/21 20:42:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/21 20:42:16 | 000,000,000 | —D | M]

[2010/06/22 13:57:06 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions
[2010/06/22 13:57:06 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/27 16:28:38 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions
[2010/11/03 20:32:23 | 000,000,000 | —D | M] (FireShot) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2010/04/26 19:00:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/11 08:58:19 | 000,000,000 | —D | M] (No name found) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/12/23 09:15:11 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/12/11 12:28:28 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/03/16 00:06:51 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]
[2010/12/24 12:28:48 | 000,001,820 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\bing.xml
[2010/09/02 20:51:39 | 000,002,059 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\daemon-search.xml
[2010/12/24 12:29:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/03 19:09:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/04 12:15:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/28 09:37:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/09/24 23:02:40 | 000,098,304 | —- | M] (OGPlanet Inc.) – C:\Program Files\Mozilla Firefox\plugins\npOGPPlugin.dll

O1 HOSTS File: ([2010/12/25 20:52:45 | 000,428,340 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14749 more lines…
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0B386B45-B2CF-4525-82FE-D3489C2D26C9} http://www.latale.com/Launcher/ActozWebLauncher.cab (Reg Error: Value error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Reg Error: Value error.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} http://www.yoyogames.com/downloads/activex/YoYo.cab (YYGInstantPlay Control)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{512a183b-b7c1-11df-947b-0016d4fe31a5}\Shell - "" = AutoRun
O33 - MountPoints2\{512a183b-b7c1-11df-947b-0016d4fe31a5}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{685596cf-1044-11df-b409-0016d4fe31a5}\Shell - "" = AutoRun
O33 - MountPoints2\{685596cf-1044-11df-b409-0016d4fe31a5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{c62d17cc-5fc6-11de-b885-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c62d17cc-5fc6-11de-b885-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/27 19:52:59 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/27 16:03:54 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Kiki Wiki\Desktop\OTL.exe
[2010/12/26 17:58:58 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HijackThis.exe
[2010/12/25 21:52:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/12/25 20:48:56 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys
[2010/12/25 20:48:56 | 000,056,400 | —- | C] (trend_company_name) – C:\Windows\System32\drivers\tmrkb.sys
[2010/12/25 11:50:00 | 001,912,872 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HousecallLauncher.exe
[2010/12/25 11:10:37 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\TMRBLog
[2010/12/25 11:09:42 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\log
[2010/12/25 11:09:35 | 002,486,352 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\RootkitBuster.exe
[2010/12/25 10:09:40 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Apps
[2010/12/24 15:20:17 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/12/24 15:20:17 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/12/24 11:31:25 | 000,098,392 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/12/24 11:27:43 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Sunbelt Software
[2010/12/24 11:26:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/12/24 11:26:12 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/12/23 09:48:49 | 000,241,664 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\Wbegua.exe
[2010/12/16 13:10:27 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010/12/16 13:02:10 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2010/12/16 12:45:53 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\Adobe CS5
[2010/12/16 11:45:30 | 001,228,400 | —- | C] (Adobe Systems Incorporated) – C:\Users\Kiki Wiki\Photoshop_12_LS1.exe
[2010/12/16 11:41:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Akamai
[2010/12/14 15:03:23 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/14 15:02:42 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/14 15:02:26 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/14 15:02:15 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/12/14 15:02:13 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/12/14 15:02:13 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/14 15:02:13 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/14 15:02:13 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/14 15:02:12 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/14 15:02:12 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/14 15:02:11 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/14 15:02:11 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/14 15:02:11 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/12/14 15:02:11 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/12/14 15:02:11 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/12/14 15:02:11 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/12/14 15:02:11 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/14 15:02:11 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/14 15:02:11 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/14 15:02:06 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/14 15:02:06 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/14 15:02:06 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/14 15:00:37 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/14 15:00:35 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/14 15:00:35 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/14 14:59:11 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/03 21:53:12 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/11/29 17:38:30 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/11/28 10:30:38 | 000,089,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SQSRVRES.DLL
[2010/11/28 10:30:38 | 000,072,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.2.4000.0.dll

========== Files - Modified Within 30 Days ==========

[2010/12/27 19:57:20 | 000,000,378 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2010/12/27 19:57:14 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/27 19:57:14 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/27 19:57:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/27 19:57:01 | 3619,778,560 | -HS- | M] () – C:\hiberfil.sys
[2010/12/27 19:25:53 | 000,000,020 | —- | M] () – C:\Users\Kiki Wiki\defogger_reenable
[2010/12/27 19:24:52 | 000,050,477 | —- | M] () – C:\Users\Kiki Wiki\Desktop\Defogger.exe
[2010/12/27 16:03:54 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Kiki Wiki\Desktop\OTL.exe
[2010/12/27 16:02:25 | 000,080,384 | —- | M] () – C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
[2010/12/27 14:10:31 | 000,296,448 | —- | M] () – C:\Users\Kiki Wiki\Desktop\s3jb5ryb.exe
[2010/12/26 17:59:00 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HijackThis.exe
[2010/12/25 21:52:24 | 000,000,775 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/12/25 20:52:45 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/12/25 20:50:17 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys
[2010/12/25 20:50:17 | 000,056,400 | —- | M] (trend_company_name) – C:\Windows\System32\drivers\tmrkb.sys
[2010/12/25 17:34:14 | 000,007,268 | —- | M] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2010/12/25 11:50:09 | 001,912,872 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HousecallLauncher.exe
[2010/12/25 10:23:21 | 000,000,036 | —- | M] () – C:\Users\Kiki Wiki\AppData\Local\housecall.guid.cache
[2010/12/25 09:40:20 | 000,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2010/12/25 09:40:20 | 000,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2010/12/24 19:36:06 | 003,630,896 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/24 19:31:07 | 000,000,118 | —- | M] () – C:\Windows\wininit.ini
[2010/12/24 19:23:24 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101225-205245.backup
[2010/12/24 17:53:58 | 000,000,139 | —- | M] () – C:\Users\Kiki Wiki\Desktop\IObit Freeware.url
[2010/12/24 17:53:57 | 000,001,009 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/12/24 17:53:57 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/12/24 15:37:09 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101224-192324.backup
[2010/12/24 15:36:34 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101224-153709.backup
[2010/12/24 15:20:32 | 000,001,050 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/24 15:20:32 | 000,001,026 | —- | M] () – C:\Users\Kiki Wiki\Desktop\Spybot - Search & Destroy.lnk
[2010/12/24 11:31:25 | 000,098,392 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/12/23 09:48:38 | 000,241,664 | —- | M] (Windows ® Codename Longhorn DDK provider) – C:\Windows\Wbegua.exe
[2010/12/23 09:48:38 | 000,061,440 | RHS- | M] () – C:\Windows\System32\rasgcwh.dll
[2010/12/23 09:15:18 | 000,000,872 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2010/12/23 09:15:18 | 000,000,860 | —- | M] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/12/23 09:15:18 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/12/22 18:23:37 | 000,000,132 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/21 21:28:22 | 000,000,629 | —- | M] () – C:\Windows\System32\mapisvc.inf
[2010/12/21 20:53:44 | 000,001,635 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/21 20:41:59 | 000,001,697 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/16 14:31:19 | 000,705,454 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/16 14:31:19 | 000,142,764 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/16 12:45:39 | 001,228,400 | —- | M] (Adobe Systems Incorporated) – C:\Users\Kiki Wiki\Photoshop_12_LS1.exe
[2010/12/16 12:45:35 | 1026,293,791 | —- | M] () – C:\Users\Kiki Wiki\Photoshop_12_LS1.7z
[2010/12/14 19:55:40 | 000,007,918 | —- | M] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2010/12/07 18:05:04 | 002,486,352 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\RootkitBuster.exe
[2010/11/29 17:38:30 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts

========== Files Created - No Company Name ==========

[2010/12/27 19:25:36 | 000,000,020 | —- | C] () – C:\Users\Kiki Wiki\defogger_reenable
[2010/12/27 19:24:51 | 000,050,477 | —- | C] () – C:\Users\Kiki Wiki\Desktop\Defogger.exe
[2010/12/27 16:02:22 | 000,080,384 | —- | C] () – C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
[2010/12/27 14:10:28 | 000,296,448 | —- | C] () – C:\Users\Kiki Wiki\Desktop\s3jb5ryb.exe
[2010/12/25 21:52:24 | 000,000,775 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/12/25 20:45:19 | 3619,778,560 | -HS- | C] () – C:\hiberfil.sys
[2010/12/25 10:23:21 | 000,000,036 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\housecall.guid.cache
[2010/12/25 09:37:48 | 000,001,905 | —- | C] () – C:\Windows\diagwrn.xml
[2010/12/25 09:37:48 | 000,001,905 | —- | C] () – C:\Windows\diagerr.xml
[2010/12/24 19:31:07 | 000,000,118 | —- | C] () – C:\Windows\wininit.ini
[2010/12/24 17:54:09 | 000,000,378 | —- | C] () – C:\Windows\tasks\AWC Startup.job
[2010/12/24 17:53:58 | 000,000,139 | —- | C] () – C:\Users\Kiki Wiki\Desktop\IObit Freeware.url
[2010/12/24 17:53:57 | 000,001,009 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/12/24 17:53:57 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/12/24 15:20:32 | 000,001,050 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/24 15:20:32 | 000,001,026 | —- | C] () – C:\Users\Kiki Wiki\Desktop\Spybot - Search & Destroy.lnk
[2010/12/23 09:48:38 | 000,061,440 | RHS- | C] () – C:\Windows\System32\rasgcwh.dll
[2010/12/23 09:15:18 | 000,000,872 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2010/12/23 09:15:18 | 000,000,860 | —- | C] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/12/23 09:15:18 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/12/21 20:53:44 | 000,001,635 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/21 20:41:59 | 000,001,697 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/16 19:18:10 | 000,000,132 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/16 11:45:30 | 1026,293,791 | —- | C] () – C:\Users\Kiki Wiki\Photoshop_12_LS1.7z
[2010/12/14 19:55:40 | 000,007,918 | —- | C] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2010/11/13 21:46:21 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/03/17 22:21:41 | 000,000,032 | —- | C] () – C:\Windows\System32\Video Converter.dll
[2010/03/17 00:17:00 | 000,000,032 | —- | C] () – C:\Windows\System32\Cool Motion.dll
[2009/12/03 09:27:30 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/08 16:01:46 | 000,000,552 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d8caps.dat
[2009/09/06 08:45:35 | 000,005,632 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/15 11:26:15 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2009/07/15 11:10:50 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2009/07/15 11:10:49 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2009/07/15 11:10:49 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2009/07/15 11:10:49 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2009/07/08 18:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/06/24 10:01:03 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/23 17:12:10 | 000,651,264 | —- | C] () – C:\Windows\System32\libeay32.dll
[2009/06/23 17:12:10 | 000,147,456 | —- | C] () – C:\Windows\System32\ssleay32.dll
[2009/06/23 08:45:17 | 000,007,268 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2008/06/03 03:35:18 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== Files - Unicode (All) ==========
[2010/09/13 17:41:50 | 002,004,992 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park ?A DAY IN THE LIFE?.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park 『A DAY IN THE LIFE』.mp3
[2010/09/13 17:41:48 | 006,051,840 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - ??- ???.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - シド- ミルク.mp3
[2010/09/13 17:41:48 | 003,035,136 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. ???? ????????.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. 初音ミク ブログと同音質版.mp3
[2010/09/13 17:41:47 | 004,376,576 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - ???? - sm4459602 - HQ.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - 星間飛行 - sm4459602 - HQ.mp3
[2010/09/11 11:21:45 | 004,376,576 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - ???? - sm4459602 - HQ.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - 星間飛行 - sm4459602 - HQ.mp3
[2010/09/11 11:14:33 | 006,051,840 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - ??- ???.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - シド- ミルク.mp3
[2010/09/11 11:10:49 | 003,035,136 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. ???? ????????.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. 初音ミク ブログと同音質版.mp3
[2010/09/11 11:02:53 | 002,004,992 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park ?A DAY IN THE LIFE?.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park 『A DAY IN THE LIFE』.mp3

< End of report >
Hi Somethingsimple,

Let's run this next tool before you try the computer too much.

And should I uninstall bittorrent after getting help,or can I uninstall it now?

You can uninstall bittorrent now. While you are there uninstall this old vulnerable versions of java.

Java™ 6 Update 7

Next

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
Thanks
I seem to be having a problem with Combofix. It says that Avast and IObit Security 360 are still running their real time protection scanners,even though I just went into both programs and turned off the shields manually. Are they still running in the background or something?
Hi Somethingsimple,


Try this with Avast
  • left click on the "a" icon
  • click settings in the upper right corner
  • click troubleshooting
  • uncheck enable avast self defence module
Try setting the shields to disabled now
  • right click the "a" icon
  • highlight avast shields controls
  • set it to one hour
  • confirm any warnings

I don't use IoBit but I think it can be disabled from the user's interface under the Protection heading.
Hi Somethingsimple,

Boot into safe mode and run it from there. If combofix reboots the computer boot back to safe mode, let combofix finish, and save the log. Reboot to normal windows and post the log here.

To boot to safe mode
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Tried safe mode,still picked up Avast and IObit EDIT: Do I have disable "Teatimer" in spybot: S&D also? Because I can't do the "Uncheck the "TeaTimer" box and "OK" any prompts." step from "How to Disable your Security Programs",since Teatimer isn't listed on system startup list.
I ran it as an administrator. It's still saying that I do not have permission and that I need an "administrator prompt" to continue. But for some reason,it did NOT warn me this time that Avast/IObit was still scanning in the background.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI