This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojans, Malware, Avira rendered helpless, and a misbehaving computer

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the last few weeks, my laptop has been not 'responding' frequently, although it returns to normal function after a few minutes.
I use the free version of Avira and have it set to run a weekly scan. All of my software is up to date.
In addition to trying to clean my system, I would also like to know if backing up my files (word documents, music, pictures) to a thumbdrive could infect the thumbdrive. Before i started backing up my files, i used Avira to scan the files i needed to save and nothing was turned up, but Avira is now no longer working properly so I do not trust its scans.
Using specific scans I think i have identified at least some of the problem files but they are of the type i cannot delete and wouldnt delete for fear of screwing up my computer. They are OS(C:) > Windows > winsxs file names: rundll.exe and wepexRi
Avira flagged these as suspicious when directly scanned.

Avira displays its status as "Service Stopped" I ran a full system scan, which detected more of the above trojans and requested that i restart my computer and run the scan again.

I would like to note that I have a new, blank harddrive that I intended to install eventually (not even out of the box yet), but i want to make sure that i am not going to infect it accidentally right off the bat.

Over the last couple days, Avira found several malware and a ridiculous number of trojans. I cannot tell if there are multiple copies or duplicated reports, but there were only three names listed:
TR/Kazy (about 10 of this one)
TR/Dldr.Carberp.C.8 (dozens of this one)
TR/ATRAPS.Gen (about 8 of this one)

I really appreciate any help you can provide.


here are the OTL logs:





OTL logfile created on: 1/17/2011 8:59:45 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Users\Zoe\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 57.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.15 Gb Total Space | 40.69 Gb Free Space | 18.32% Space Free | Partition Type: NTFS

Computer Name: BIDULE | User Name: Zoe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Zoe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Zoe\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WLSetupSvc) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://blackle.com/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {5F590AA2-1221-4113-A6F4-A4BB62414FAC}:0.45.6.20100202.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.11
FF - prefs.js..extensions.enabledItems: {A1EAC5D0-D2E8-4DBA-9C39-065A2FBE5A6E}:1.9.1

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/12 01:18:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/12/12 01:18:41 | 000,000,000 | —D | M]

[2010/04/13 16:59:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Zoe\AppData\Roaming\Mozilla\Extensions
[2011/01/17 11:25:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions
[2010/12/29 14:01:29 | 000,000,000 | —D | M] (Stylish) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/07/07 14:53:47 | 000,000,000 | —D | M] (SmoothWheel (mozdev.org)) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2010/12/19 15:39:10 | 000,000,000 | —D | M] (Speed Dial) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/11/19 16:58:30 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/19 16:58:29 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/07/21 15:58:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{dd30bf68-268a-4815-ad48-8740b774c764}
[2010/11/19 16:58:29 | 000,000,000 | —D | M] (FoxTab) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/09/14 16:42:30 | 000,000,000 | —D | M] (Personas) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\[removed]
[2010/07/07 15:34:42 | 000,000,000 | —D | M] (QuickDrag) – C:\Users\Zoe\AppData\Roaming\Mozilla\Firefox\Profiles\bfh7xjc9.default\extensions\[removed]
[2010/04/13 16:59:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/16 11:24:49 | 000,000,000 | —D | M] (XULRunner) – C:\USERS\ZOE\APPDATA\LOCAL\{A1EAC5D0-D2E8-4DBA-9C39-065A2FBE5A6E}

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKCU..\Run: [Wjipatax] C:\Users\Zoe\AppData\Local\afocaben.DLL (MPC-HC Team)
O4 - Startup: C:\Users\Zoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MiniMinder.lnk = C:\Program Files (x86)\MiniMind\MiniMind.exe (Vellosoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/01/17 20:56:59 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Zoe\Desktop\OTL.exe
[2011/01/17 20:06:00 | 000,000,000 | —D | C] – C:\avrescue
[2011/01/17 11:27:05 | 000,000,000 | —D | C] – C:\Users\Zoe\AppData\Roaming\Avira
[2011/01/17 11:26:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/01/17 11:26:19 | 000,116,568 | —- | C] (Avira GmbH) – C:\Windows\SysNative\drivers\avipbb.sys
[2011/01/17 11:26:19 | 000,081,072 | —- | C] (Avira GmbH) – C:\Windows\SysNative\drivers\avgntflt.sys
[2011/01/17 11:26:19 | 000,051,992 | —- | C] (AVIRA GmbH) – C:\Windows\SysWow64\drivers\avgntdd.sys
[2011/01/17 11:26:19 | 000,017,016 | —- | C] (AVIRA GmbH) – C:\Windows\SysWow64\drivers\avgntmgr.sys
[2011/01/17 11:26:18 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2011/01/16 11:45:01 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/01/16 11:24:49 | 000,000,000 | —D | C] – C:\Users\Zoe\AppData\Local\{A1EAC5D0-D2E8-4DBA-9C39-065A2FBE5A6E}
[2011/01/12 17:34:41 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/01/12 17:34:41 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/01/12 17:34:41 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/01/12 17:34:41 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/01/12 17:34:41 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/01/12 17:34:41 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/01/12 17:34:40 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/01/12 17:34:38 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/01/12 17:34:37 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/01/12 17:34:37 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/01/12 17:34:37 | 000,470,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/01/12 17:34:37 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/01/12 17:34:37 | 000,283,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/01/12 17:34:37 | 000,258,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/01/12 17:34:37 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/01/12 17:34:37 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/01/12 17:34:36 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/01/12 17:34:36 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/01/12 17:34:36 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/01/12 17:34:36 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/01/12 17:33:54 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/01/12 17:33:54 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/01/06 22:57:16 | 000,000,000 | —D | C] – C:\Users\Zoe\Desktop\Fallout 3 Full DLC Pack
[2010/12/27 03:04:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2010/12/27 03:02:24 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2010/12/27 03:02:24 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2010/12/27 03:02:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2010/12/26 20:24:11 | 000,044,544 | —- | C] (Absolute Software Corp.) – C:\Windows\SysWow64\agremove.exe
[2010/12/25 18:11:07 | 000,000,000 | —D | C] – C:\Users\Zoe\Documents\My Games
[2010/12/25 18:11:07 | 000,000,000 | —D | C] – C:\Users\Zoe\AppData\Local\Fallout3
[2010/12/25 18:10:50 | 000,178,800 | —- | C] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt_x64.dll
[2010/12/25 17:53:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bethesda Softworks
[2010/12/25 17:53:36 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2010/12/25 17:53:36 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2010/12/25 17:53:36 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2010/12/25 17:53:36 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2010/12/25 17:53:35 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2010/12/25 17:53:35 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2010/12/25 17:53:35 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2010/12/25 17:53:35 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2010/12/25 17:53:26 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2010/12/25 17:53:26 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2010/12/25 17:53:26 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2010/12/25 17:53:26 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2010/12/25 17:53:25 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2010/12/25 17:53:25 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2010/12/25 17:53:25 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2010/12/25 17:53:25 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2010/12/25 17:53:25 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2010/12/25 17:53:25 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2010/12/25 17:53:24 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2010/12/25 17:53:24 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2010/12/25 17:53:23 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2010/12/25 17:53:23 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2010/12/25 17:53:21 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2010/12/25 17:53:21 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2010/12/25 17:53:21 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2010/12/25 17:53:21 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2010/12/25 17:53:20 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2010/12/25 17:53:20 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2010/12/25 17:53:17 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2010/12/25 17:53:17 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2010/12/25 17:53:16 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2010/12/25 17:53:16 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2010/12/25 17:53:16 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2010/12/25 17:53:16 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2010/12/25 17:53:15 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2010/12/25 17:53:15 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2010/12/25 17:53:14 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2010/12/25 17:53:14 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2010/12/25 17:53:14 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2010/12/25 17:53:14 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2010/12/25 17:53:14 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2010/12/25 17:53:14 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2010/12/25 17:53:13 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2010/12/25 17:53:13 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2010/12/25 17:53:12 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2010/12/25 17:53:12 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2010/12/25 17:53:09 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2010/12/25 17:53:09 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2010/12/25 17:53:08 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2010/12/25 17:53:08 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2010/12/25 17:53:07 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2010/12/25 17:53:06 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2010/12/25 17:53:06 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2010/12/25 17:53:04 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2010/12/25 17:53:04 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2010/12/25 17:53:04 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2010/12/25 17:53:04 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2010/12/25 17:53:03 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2010/12/25 17:53:03 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2010/12/25 17:53:02 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2010/12/25 17:53:02 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2010/12/25 17:53:02 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2010/12/25 17:53:02 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2010/12/25 17:52:57 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2010/12/25 17:52:57 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2010/12/25 17:52:55 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2010/12/25 17:52:55 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2010/12/25 17:52:54 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2010/12/25 17:52:54 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2010/12/25 17:52:53 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2010/12/25 17:52:53 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2010/12/25 17:52:53 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2010/12/25 17:52:53 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2010/12/25 17:52:51 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2010/12/25 17:52:51 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2010/12/25 17:52:32 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2010/12/25 17:52:32 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2010/12/25 17:52:30 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2010/12/25 17:52:30 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2010/12/25 17:52:30 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2010/12/25 17:52:30 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2010/12/25 17:52:29 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2010/12/25 17:52:29 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2010/12/25 17:52:28 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2010/12/25 17:52:28 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2010/12/25 17:52:26 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2010/12/25 17:52:26 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2010/12/25 17:52:25 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2010/12/25 17:52:25 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2010/12/25 17:52:24 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2010/12/25 17:52:24 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2010/12/25 17:52:23 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2010/12/25 17:52:23 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2010/12/25 17:49:31 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2010/12/25 17:49:31 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2010/12/25 17:49:28 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2010/12/25 17:48:53 | 000,000,000 | —D | C] – C:\Windows\SysWow64\xlive
[2010/12/25 17:45:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010/12/25 16:51:09 | 000,000,000 | —D | C] – C:\Users\Zoe\AppData\Local\Electronic Arts
[2010/12/25 16:50:48 | 000,000,000 | RH-D | C] – C:\Users\Zoe\AppData\Roaming\SecuROM
[2010/12/24 22:57:04 | 000,000,000 | —D | C] – C:\Users\Zoe\Documents\Electronic Arts
[2010/12/24 22:57:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Electronic Arts
[2010/12/24 22:57:02 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2010/12/24 22:57:02 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2010/12/24 22:57:02 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2010/12/24 22:57:02 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2010/12/24 22:57:02 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2010/12/24 22:57:02 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2010/12/24 22:57:01 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2010/12/24 22:57:01 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2009/07/13 15:24:58 | 000,225,280 | —- | C] (MPC-HC Team) – C:\Users\Zoe\AppData\Local\afocaben.dll
[2009/07/13 15:24:58 | 000,090,112 | —- | C] (Progressive Networks) – C:\Users\Zoe\AppData\Local\wepexRi.dll

========== Files - Modified Within 30 Days ==========

[2011/01/17 20:57:05 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Zoe\Desktop\OTL.exe
[2011/01/17 20:35:05 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3183000670-4136661450-1976081033-1000UA.job
[2011/01/17 19:48:48 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/01/17 19:48:48 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/01/17 19:48:48 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/01/17 19:11:17 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/17 19:11:16 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/17 19:03:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/01/17 19:03:14 | 2384,744,448 | -HS- | M] () – C:\hiberfil.sys
[2011/01/17 18:15:07 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3183000670-4136661450-1976081033-1000Core.job
[2011/01/17 11:20:45 | 000,000,000 | —- | M] () – C:\Users\Zoe\AppData\Local\Xfehevoy.bin
[2011/01/17 11:20:44 | 000,000,120 | —- | M] () – C:\Users\Zoe\AppData\Local\Vdebehihevurijan.dat
[2011/01/16 12:30:00 | 000,017,885 | —- | M] () – C:\Users\Zoe\Documents\Odysseus.docx
[2011/01/07 23:39:26 | 000,050,373 | —- | M] () – C:\Users\Zoe\Documents\Facebook code.docx
[2010/12/26 20:24:24 | 000,044,544 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\agremove.exe
[2010/12/26 19:02:55 | 000,017,408 | —- | M] () – C:\Windows\SysNative\rpcnetp.exe
[2010/12/25 18:23:26 | 000,001,728 | —- | M] () – C:\Users\Zoe\Desktop\Fallout3 - Shortcut.lnk
[2010/12/25 18:10:50 | 000,178,800 | —- | M] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt_x64.dll
[2010/12/23 22:37:07 | 000,107,004 | —- | M] () – C:\Users\Zoe\Desktop\wasp.jpg
[2010/12/23 22:37:02 | 000,014,846 | —- | M] () – C:\Users\Zoe\Desktop\wasp_by_nephlmpng.jpg

========== Files Created - No Company Name ==========

[2011/01/15 16:57:52 | 000,017,885 | —- | C] () – C:\Users\Zoe\Documents\Odysseus.docx
[2011/01/11 20:02:25 | 000,000,000 | —- | C] () – C:\Users\Zoe\AppData\Local\Xfehevoy.bin
[2011/01/11 20:02:24 | 000,000,120 | —- | C] () – C:\Users\Zoe\AppData\Local\Vdebehihevurijan.dat
[2011/01/07 23:33:45 | 000,050,373 | —- | C] () – C:\Users\Zoe\Documents\Facebook code.docx
[2010/12/25 18:23:26 | 000,001,728 | —- | C] () – C:\Users\Zoe\Desktop\Fallout3 - Shortcut.lnk
[2010/12/23 22:37:07 | 000,107,004 | —- | C] () – C:\Users\Zoe\Desktop\wasp.jpg
[2010/12/23 22:37:02 | 000,014,846 | —- | C] () – C:\Users\Zoe\Desktop\wasp_by_nephlmpng.jpg
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/10/08 09:01:06 | 000,000,003 | —- | C] () – C:\ProgramData\AbsoluteNotifier.txt
[2010/09/14 15:15:35 | 000,021,840 | —- | C] () – C:\Windows\SysWow64\SIntfNT.dll
[2010/09/14 15:15:35 | 000,017,212 | —- | C] () – C:\Windows\SysWow64\SIntf32.dll
[2010/09/14 15:15:35 | 000,012,067 | —- | C] () – C:\Windows\SysWow64\SIntf16.dll
[2010/09/04 16:10:05 | 000,006,729 | —- | C] () – C:\Users\Zoe\AppData\Roaming\UserTile.png
[2009/07/13 15:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 13:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2005/02/05 11:46:00 | 000,004,608 | —- | C] () – C:\Windows\fgexec.dll

========== LOP Check ==========

[2010/07/31 21:05:06 | 000,000,000 | —D | M] – C:\Users\Zoe\AppData\Roaming\desksware
[2010/04/29 19:03:22 | 000,000,000 | —D | M] – C:\Users\Zoe\AppData\Roaming\Facebook
[2010/12/05 13:35:42 | 000,000,000 | —D | M] – C:\Users\Zoe\AppData\Roaming\HTML Executable
[2010/08/08 17:14:33 | 000,000,000 | —D | M] – C:\Users\Zoe\AppData\Roaming\Laconic Software
[2010/07/31 22:25:30 | 000,000,000 | —D | M] – C:\Users\Zoe\AppData\Roaming\SanDisk
[2009/07/13 21:08:49 | 000,017,398 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/11 09:17:08 | 000,005,231 | RH– | M] () – C:\dell.sdr
[2011/01/17 19:03:14 | 2384,744,448 | -HS- | M] () – C:\hiberfil.sys
[2006/12/01 20:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/01/17 19:03:10 | 3179,663,360 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/07/26 11:47:46 | 002,766,336 | —- | M] (Laconic Software) – C:\Windows\freefire.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/13 16:57:19 | 000,000,221 | -HS- | M] () – C:\Users\Zoe\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/12/04 15:28:09 | 005,490,375 | —- | M] (Blizzard Entertainment) – C:\Users\Zoe\Desktop\LODPatch_112a.exe
[2011/01/17 20:57:05 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Zoe\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~







OTL Extras logfile created on: 1/17/2011 8:59:45 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Users\Zoe\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 57.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.15 Gb Total Space | 40.69 Gb Free Space | 18.32% Space Free | Partition Type: NTFS

Computer Name: BIDULE | User Name: Zoe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{33F8EAD4-B6EC-498B-B487-696B973D1C0C}" = Windows Live Messenger
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{621AF8B2-75D2-4074-BA44-79178A617255}" = Windows Live installer
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Diablo II" = Diablo II
"Digital Editions" = Adobe Digital Editions
"Free Fire Screensaver" = Free Fire Screensaver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Messenger Plus! Live" = Messenger Plus! Live
"MiniMinder_is1" = MiniMinder 8.3
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MySpaceIM" = MySpaceIM
"Steam App 12900" = Audiosurf
"Steam App 3590" = Plants vs. Zombies
"Steam App 49900" = Plain Sight
"Super Mario 3 : Mario Forever" = Super Mario 3 : Mario Forever
"VLC media player" = VLC media player 1.1.2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"Sansa Updater" = Sansa Updater

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/9/2011 7:02:09 PM | Computer Name = Bidule | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid. .

Error - 1/9/2011 7:02:09 PM | Computer Name = Bidule | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid. .

Error - 1/9/2011 7:02:09 PM | Computer Name = Bidule | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid. .

Error - 1/9/2011 7:02:09 PM | Computer Name = Bidule | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid. .

Error - 1/9/2011 7:02:09 PM | Computer Name = Bidule | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid. .

Error - 1/9/2011 7:02:09 PM | Computer Name = Bidule | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid. .

Error - 1/9/2011 8:24:52 PM | Computer Name = Bidule | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc100 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x02ad423e Faulting process id: 0xc08 Faulting application
start time: 0x01cbb05caeff1b57 Faulting application path: C:\Windows\SysWOW64\svchost.exe
Faulting
module path: unknown Report Id: 0a4189d7-1c50-11e0-8e38-0025646eaa0d

Error - 1/9/2011 11:00:01 PM | Computer Name = Bidule | Source = Windows Backup | ID = 4103
Description =

Error - 1/9/2011 11:25:02 PM | Computer Name = Bidule | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 1/12/2011 10:01:03 PM | Computer Name = Bidule | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 1/3/2011 1:58:25 AM | Computer Name = Bidule | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Encrypted volume check: Volume information on F: cannot be read.

Error - 1/3/2011 7:49:14 PM | Computer Name = Bidule | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 1/3/2011 9:11:57 PM | Computer Name = Bidule | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Encrypted volume check: Volume information on F: cannot be read.

Error - 1/5/2011 10:50:53 PM | Computer Name = Bidule | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 1/5/2011 10:51:35 PM | Computer Name = Bidule | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 1/5/2011 10:52:20 PM | Computer Name = Bidule | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 1/9/2011 12:13:39 AM | Computer Name = Bidule | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 1/12/2011 9:17:27 PM | Computer Name = Bidule | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:53:30 AM on ?1/?12/?2011 was unexpected.

Error - 1/13/2011 10:57:46 PM | Computer Name = Bidule | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 1/13/2011 10:57:46 PM | Computer Name = Bidule | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053


< End of report >
Hello, HelplessLaptop
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI