This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer may be infected but I'm not certain

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi

my computer has been running erratically. Trying to print web pages seems slow and some things like firefox search bar work sometime and not others. Same goes for the magnifier on my mouse. It works OK until I start me browser and then I get a black window.
I think it may be infected but am not sure.
Here are the results of the OTL scan

OTL Extras logfile created on: 19/02/2011 9:43:33 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\John Niarhos\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 71.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 147.96 Gb Free Space | 79.42% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 185.93 Gb Free Space | 99.80% Space Free | Partition Type: NTFS

Computer Name: YOUR-6D410B054D | User Name: John Niarhos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = Mega Zipper.CHM] – C:\Program Files\Mega Zipper\MegaZipper.exe ()
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\MagicTune Premium\MagicTune.exe" = C:\Program Files\MagicTune Premium\MagicTune.exe:*:Enabled:MagicTune – (SEC)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{00F93853-D9D3-4795-A89E-84CCBA0205C9}" = Microsoft IntelliPoint 8.0
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{04260560-6C52-7C12-298C-8A29FD2284AE}" = Catalyst Control Center Localization Spanish
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07F58BB0-50D4-4477-B491-A97B2AD059B6}" = TOSHIBA Hotkey Utility
"{0B94281F-A5CC-7C91-6AAB-76F29C41806A}" = Catalyst Control Center Localization Italian
"{11120101-BA9E-11D6-A50F-006067797177}" = Cashflow Manager 4
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX850_series" = Canon MX850 series
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{1A710772-32E0-0E0A-D9A5-670655CF0F5C}" = CCC Help Chinese Traditional
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{220B0574-3E04-1BE9-710E-DF23A44C920A}" = CCC Help Chinese Standard
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 24
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{2C38F661-26B7-445D-B87D-B53FE2D3BD42}" = TOSHIBA PC Diagnostic Tool
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{400830CA-F056-4BBE-80A3-9DF9CA4FB889}" = TOSHIBA Direct Disc Writer
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{482BDA81-0780-9149-2B2F-21AACA2E15A1}" = CCC Help Korean
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CC2D001-090C-E37D-BB21-0C9CB654D193}" = CCC Help Portuguese
"{50AAF762-73BA-6D7C-481D-3B1A23F2B184}" = Catalyst Control Center Graphics Full New
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.02
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{6174D68D-196F-0CB7-D1FA-868C4B45F547}" = CCC Help Swedish
"{61B84435-7A82-4F5C-87EC-1071EC28D72D}" = TOSHIBA Utilities
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{66B4C110-8BEB-49B5-824E-C70AEEB20ECD}" = ScanSoft OmniPage SE 4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"{69E5255D-9D43-4CFF-8984-843ABD7753B7}" = Catalyst Control Center - Branding
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{6E63C63B-D644-3B5D-3FD9-629DEE3E7BBB}" = CCC Help Dutch
"{6F7E59D1-4F0F-43F8-D282-5F67D235B6CE}" = Catalyst Control Center Graphics Full Existing
"{717C6297-BAA4-F49F-34CA-BB0C9A0D331D}" = CCC Help Spanish
"{747DF5B6-4FA5-3DC1-21EA-B01C197C0E72}" = ccc-utility
"{820F2857-E930-1E6A-BAFE-0666B5851B57}" = Catalyst Control Center Localization French
"{83A1BA2D-D03E-D3F8-9CDE-05FC0D6D1FAE}" = Catalyst Control Center Localization German
"{83EC8AE9-53A6-474D-95AF-8F5116CC9C4E}" = 3D Home Architect Design Suite Deluxe 8
"{87E27EB9-5E08-3EB2-5941-88B4F9256183}" = ccc-core-preinstall
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8F7AC250-4D7D-431D-AC4E-94FB78EA3F8B}" = TOSHIBA Power Saver
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{94D65DA0-AC72-349D-2F79-381D94D63A0F}" = Catalyst Control Center Localization Chinese Standard
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9B099E16-644C-D946-8E3C-F8F744094D6F}" = CCC Help Japanese
"{9F1B60E0-7F93-11D6-A50F-006067797177}" = Cashflow Manager 4
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A2075A09-28AA-4D30-9BCC-82EAD9FA51BD}" = TrueSuite Access Manager
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{A6DFF720-F825-6EED-7693-0B0312C21ACE}" = Catalyst Control Center Localization Swedish
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E15591-C319-C9E2-9BF9-038E82EC585A}" = CCC Help English
"{AB12CEB4-2967-3912-282B-442C26EA95B1}" = CCC Help German
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AF3879DB-85B6-0DD7-A285-23AAD5A441F5}" = CCC Help Italian
"{B05FDD11-388E-2E22-9E7A-0C0E4E38ABF2}" = Skins
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{C02A6D5F-0FE1-46DE-B483-2BD33A226BCF}" = TOSHIBA TouchPad ON/Off Utility
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C30535DA-0A1D-1905-9DAC-E8C249D756EB}" = Catalyst Control Center Localization Portuguese
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCC95E35-22F5-EA4F-B04B-7BC3F22717BF}" = Catalyst Control Center Localization Japanese
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.20
"{D33F418E-8C03-0F54-B390-D730E6FE057B}" = Catalyst Control Center Localization Dutch
"{D4F1983F-D926-9CD1-3CB0-F1BAB26A0A46}" = Catalyst Control Center Graphics Light
"{D6044256-A309-43B5-9833-D3FAFE2AD24D}" = MagicTune Premium
"{D962EFF3-F1FD-1A36-368D-0896BF8480B9}" = Catalyst Control Center Localization Korean
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.2.336
"{DE4C9C7B-E842-E01D-50B8-244C988577D0}" = CCC Help French
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E36E864B-BFB6-440A-9A23-2B0BEDE59A92}" = MultiScreen
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EC99A6DA-D504-5249-E8D6-7F71ADB4B7FA}" = ccc-core-static
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F24165DA-E482-86B1-A7CE-5D55EFE25AAF}" = Catalyst Control Center Core Implementation
"{F27E9988-623D-DCD5-395C-53508BE45B43}" = Catalyst Control Center Localization Chinese Traditional
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"7-Zip" = 7-Zip 9.07 beta
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ATI Display Driver" = ATI Display Driver
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"FTDICOMM" = USB to Serial (RS232) Converter Drivers
"Home Winemaster 2008" = Home Winemaster 2008 V9.3.3.0
"InstallShield_{2C38F661-26B7-445D-B87D-B53FE2D3BD42}" = TOSHIBA PC Diagnostic Tool
"InstallShield_{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"InstallShield_{83EC8AE9-53A6-474D-95AF-8F5116CC9C4E}" = 3D Home Architect Design Suite Deluxe 8
"InstallShield_{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Mega Zipper" = Mega Zipper 1.0
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MP Navigator EX 1.1" = Canon MP Navigator EX 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.7.6.2056
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoneAlarm Extreme Security" = ZoneAlarm Extreme Security

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dulux MyColour4" = Dulux MyColour4

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 18/02/2011 3:31:44 AM | Computer Name = YOUR-6D410B054D | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 18/02/2011 3:31:44 AM | Computer Name = YOUR-6D410B054D | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4281

Error - 18/02/2011 3:31:44 AM | Computer Name = YOUR-6D410B054D | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4281

Error - 18/02/2011 7:00:31 AM | Computer Name = YOUR-6D410B054D | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 18/02/2011 7:00:31 AM | Computer Name = YOUR-6D410B054D | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 12531516

Error - 18/02/2011 7:00:31 AM | Computer Name = YOUR-6D410B054D | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 12531516

Error - 18/02/2011 8:45:44 AM | Computer Name = YOUR-6D410B054D | Source = COM | ID = 10023
Description = The application-specific access security descriptor for the COM Server
application C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe is invalid.
It contains Access Control Entries with permissions that are invalid. The requested
action was therefore not performed. The application set this security permission
programmatically; to modify this security permission contact the application vendor.

Error - 18/02/2011 9:34:52 AM | Computer Name = YOUR-6D410B054D | Source = COM | ID = 10023
Description = The application-specific access security descriptor for the COM Server
application C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe is invalid.
It contains Access Control Entries with permissions that are invalid. The requested
action was therefore not performed. The application set this security permission
programmatically; to modify this security permission contact the application vendor.

Error - 18/02/2011 4:20:14 PM | Computer Name = YOUR-6D410B054D | Source = COM | ID = 10023
Description = The application-specific access security descriptor for the COM Server
application C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe is invalid.
It contains Access Control Entries with permissions that are invalid. The requested
action was therefore not performed. The application set this security permission
programmatically; to modify this security permission contact the application vendor.

Error - 18/02/2011 4:51:03 PM | Computer Name = YOUR-6D410B054D | Source = COM | ID = 10023
Description = The application-specific access security descriptor for the COM Server
application C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe is invalid.
It contains Access Control Entries with permissions that are invalid. The requested
action was therefore not performed. The application set this security permission
programmatically; to modify this security permission contact the application vendor.

[ System Events ]
Error - 18/02/2011 9:32:52 AM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7034
Description = The MagicTuneEngine service terminated unexpectedly. It has done
this 1 time(s).

Error - 18/02/2011 9:35:05 AM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7000
Description = The Authentec memory manager service service failed to start due to
the following error: %%2

Error - 18/02/2011 9:35:07 AM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
atapi PCIIde

Error - 18/02/2011 10:20:38 AM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7034
Description = The MagicTuneEngine service terminated unexpectedly. It has done
this 1 time(s).

Error - 18/02/2011 4:19:32 PM | Computer Name = YOUR-6D410B054D | Source = Dhcp | ID = 1002
Description = The IP address lease 10.1.1.2 for the Network Card with network address
001E3378818F has been denied by the DHCP server 10.1.1.1 (The DHCP Server sent a
DHCPNACK message).

Error - 18/02/2011 4:20:29 PM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7000
Description = The Authentec memory manager service service failed to start due to
the following error: %%2

Error - 18/02/2011 4:20:31 PM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
atapi PCIIde

Error - 18/02/2011 4:49:00 PM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7034
Description = The MagicTuneEngine service terminated unexpectedly. It has done
this 1 time(s).

Error - 18/02/2011 4:51:14 PM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7000
Description = The Authentec memory manager service service failed to start due to
the following error: %%2

Error - 18/02/2011 4:51:15 PM | Computer Name = YOUR-6D410B054D | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
atapi PCIIde


< End of report >
OTL logfile created on: 19/02/2011 9:43:33 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\John Niarhos\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 71.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 147.96 Gb Free Space | 79.42% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 185.93 Gb Free Space | 99.80% Space Free | Partition Type: NTFS

Computer Name: YOUR-6D410B054D | User Name: John Niarhos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\John Niarhos\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\MagicTune Premium\MagicTune.exe (SEC)
PRC - C:\Program Files\MultiScreen\MultiScreen.exe ()
PRC - C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe ()
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
PRC - C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\MagicTune Premium\GammaTray.exe ()
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\John Niarhos\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\mfc42.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\CheckPoint\ZAForceField\AK\icsak.dll (Check Point Software Technologies)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\Program Files\MultiScreen\ServiceHook.dll ()
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Authentec memory manager) – File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TODDSrv) – C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FingerprintServer) – C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
SRV - (MagicTuneEngine) – C:\Program Files\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) – C:\WINDOWS\System32\DRIVERS\kl1.sys (Kaspersky Lab)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (MagicTune) – C:\WINDOWS\system32\drivers\MTiCtwl.sys (Samsung Electronics, Inc. )
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (AlfaFF) – C:\WINDOWS\system32\Drivers\AlfaFF.sys (Alfa Corporation)
DRV - (RTHDMIAzAudService) – C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (UVCFTR) – C:\WINDOWS\system32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (FwLnk) – C:\WINDOWS\system32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdudf) – C:\WINDOWS\system32\drivers\tdudf.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\WINDOWS\system32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (trudf) – C:\WINDOWS\system32\drivers\trudf.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (FTSER2K) USB to Serial (RS232) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) USB to Serial (RS232) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2

FF - HKLM\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/08 14:34:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/19 00:12:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/19 00:12:10 | 000,000,000 | —D | M]

[2011/02/18 23:47:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions
[2009/12/30 17:24:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions\[removed]
[2011/02/19 00:25:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions
[2011/02/19 00:25:17 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/19 00:17:58 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/19 00:23:54 | 000,000,000 | —D | M] (ImTranslator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2011/02/19 00:16:47 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/19 00:12:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/01 10:15:28 | 000,000,000 | —D | M] (Map status indicator) – C:\PROGRAM FILES\TOMTOM HOME 2\XUL\EXTENSIONS\[removed]

O1 HOSTS File: ([2009/09/15 14:36:51 | 000,329,949 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11302 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe ()
O4 - HKLM..\Run: [FingerPrintNotifer] C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [MultiScreen] C:\Program Files\MultiScreen\MultiScreen.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GammaTray.lnk = C:\Program Files\MagicTune Premium\GammaTray.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\ATFUS: DllName - C:\WINDOWS\system32\FpWinLogonNp.dll - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/26 12:46:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7f0272b9-f50f-11de-964b-00216b469a86}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe
O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell - "" = AutoRun
O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
O33 - MountPoints2\{b63ea508-f0ba-11dd-947f-00216b469a86}\Shell\AutoRun\command - "" = setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (76011798628663296)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/19 09:39:52 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe
[2011/02/19 00:12:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/02/19 00:12:10 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/02/16 20:57:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\John Niarhos\Recent
[2011/02/16 20:25:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/02/16 20:25:35 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/16 20:25:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/16 20:25:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/01/22 01:14:37 | 000,439,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2008/06/27 04:22:10 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\DLLVGA.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/19 09:39:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe
[2011/02/19 09:16:01 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/19 07:37:28 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/02/19 07:23:02 | 000,000,144 | —- | M] () – C:\WINDOWS\System32\pdfl.dat
[2011/02/19 07:21:20 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/19 07:21:03 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/19 07:20:52 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/02/19 07:20:36 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/19 00:12:14 | 000,001,631 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/19 00:12:14 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/18 23:10:46 | 000,581,825 | —- | M] () – C:\Documents and Settings\John Niarhos\J & B Niarhos 2010.11.BC4
[2011/02/10 16:24:20 | 000,000,803 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/02/10 16:02:22 | 000,330,688 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/10 13:49:06 | 000,001,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/02 21:40:39 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/02 21:40:38 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/02 21:40:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/02 21:40:23 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/02/02 19:19:39 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/01/28 23:30:31 | 000,000,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/01/22 01:14:37 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/22 01:14:37 | 000,439,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/19 00:12:14 | 000,001,631 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/19 00:12:14 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/22 16:54:05 | 000,001,057 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\vso_ts_preview.xml
[2010/09/06 19:11:08 | 000,000,099 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2010/02/03 21:01:47 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2009/11/04 10:13:57 | 000,001,018 | —- | C] () – C:\WINDOWS\_ISENV31.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/14 15:17:00 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2009/06/11 15:14:04 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2009/06/11 15:12:00 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/06/11 14:58:41 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\CNCFLfNL.DLL
[2009/06/10 17:19:55 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2009/05/04 13:02:35 | 000,000,000 | —- | C] () – C:\WINDOWS\ToDisc.INI
[2009/05/04 12:28:55 | 000,009,216 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/02 11:21:55 | 000,005,632 | R— | C] () – C:\WINDOWS\System32\CNMVSya.DLL
[2009/02/02 11:20:46 | 000,000,356 | R— | C] () – C:\WINDOWS\System32\CNCASv50.ini
[2009/02/02 11:19:52 | 000,000,462 | R— | C] () – C:\WINDOWS\System32\CNCMP50.INI
[2009/02/02 10:15:26 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/02/02 09:59:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2009/02/02 09:59:03 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2009/02/02 09:59:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2009/02/02 09:59:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2009/02/02 09:59:03 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2009/02/02 09:59:03 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2009/02/02 09:42:53 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2009/02/02 09:42:53 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2009/02/02 09:42:53 | 000,010,150 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2009/02/02 09:42:53 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2009/02/01 21:39:30 | 000,000,089 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\FASTWiz.log
[2008/06/27 05:26:23 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/06/27 04:22:10 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TCtrlIO.dll
[2008/06/26 13:53:06 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2008/06/26 12:53:24 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2008/06/26 12:31:49 | 000,002,392 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/06/26 05:37:15 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/12/21 16:46:32 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/11/11 10:12:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cadsoft
[2009/03/09 20:46:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/07/12 14:11:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/12/07 16:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2009/02/02 11:28:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/03/06 13:01:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/09/28 16:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2009/06/11 15:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/11/04 16:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/30 17:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/10/22 17:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/10/23 16:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/06 15:45:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/09 10:54:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/17 17:51:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/23 21:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/16 14:34:41 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\#ISW.FS#
[2009/02/05 14:46:04 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ABIG
[2010/09/28 16:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\AnvSoft
[2010/09/02 13:48:46 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Canon
[2010/05/26 14:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\CheckPoint
[2009/11/05 10:52:50 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ColorSchemer
[2010/10/22 16:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\InterVideo
[2009/04/08 21:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\LimeWire
[2010/05/29 16:27:38 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\MailFrontier
[2010/09/28 16:15:48 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\OpenCandy
[2009/06/11 15:11:56 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ScanSoft
[2009/11/04 11:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\SmartDraw
[2009/12/30 17:24:10 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\TomTom
[2008/06/26 13:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\toshiba
[2009/07/12 14:11:54 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Uniblue
[2010/10/22 19:44:38 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Vso
[2011/02/19 07:20:52 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/06/26 12:46:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/01 09:04:25 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2008/06/26 12:46:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/09 17:54:33 | 000,000,450 | —- | M] () – C:\InstallHelper.log
[2008/06/26 12:46:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/06/26 12:46:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:30:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:30:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/19 07:20:29 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/12/05 06:32:37 | 000,002,215 | —- | M] () – C:\rollback.ini
[2008/06/26 13:44:44 | 000,000,086 | —- | M] () – C:\setup.log

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/06/26 12:46:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/22 06:30:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD94.DLL
[2007/10/29 06:30:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD98.DLL
[2002/09/30 06:30:00 | 000,013,824 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDya.DLL
[2007/05/22 06:30:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP94.DLL
[2007/10/29 06:30:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP98.DLL
[2002/09/30 06:30:00 | 000,046,080 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPya.DLL
[2008/07/06 22:36:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 21:20:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/12/08 18:34:46 | 000,045,056 | —- | M] (TOSHIBA) – C:\WINDOWS\cfdemo.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/01/04 23:29:02 | 000,001,762 | -H– | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/06/26 05:36:16 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/06/26 05:36:16 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/06/26 05:36:15 | 000,925,696 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/26 12:47:08 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/02 09:45:43 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/06/26 12:53:07 | 000,000,079 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/04/17 11:32:31 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\John Niarhos\Desktop\ATF_Cleaner.exe
[2009/04/17 11:36:51 | 002,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\John Niarhos\Desktop\mbam-setup.exe
[2011/02/19 09:39:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-18 12:18:16

========== Files - Unicode (All) ==========
[2009/05/02 08:57:36 | 000,086,528 | —- | M] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
[2009/02/22 20:14:32 | 000,000,162 | -H– | M] ()(C:\Documents and Settings\John Niarhos\My Documents\~$??? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\~$コーラ ヨーヨー.doc
[2009/02/22 20:14:32 | 000,000,162 | -H– | C] ()(C:\Documents and Settings\John Niarhos\My Documents\~$??? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\~$コーラ ヨーヨー.doc
[2009/02/17 11:52:35 | 000,086,528 | —- | C] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc

< End of report >






Any assistance would be greatly appreciated

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, MSB146

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

I'm seeing two possible security software which may or may not be the cause. There are traces of Kaspersky driver installed in your system and ZoneAlarm Extreme Security.

Assuming that you bought ZA, have you actually properly remove Kas with its removal tool?

—————————————————————————————————

Let's do a couple of scans just to be sure.

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

On your next reply please post :
GMER log
ESET log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
sorry Conspire, I am not sure if the previous posts will show the logs properly so I'll post the Gmer in 2 because its so large ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=d95d937709facd45bbb51bd34f87a5a9 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-20 03:45:33 # local_time=2011-02-20 02:15:33 (+0930, Cen. Australia Daylight Time) # country="Australia" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16776869 100 77 14703049 18546161 0 0 # scanned=75618 # found=4 # cleaned=0 # scan_time=6015 C:\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{05B64610-ED45-40AC-89A3-507F6B6A25B9}\Registry Reviver.msi a variant of Win32/SlowPCfighter application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\John Niarhos\Application Data\OpenCandy\OpenCandy_86307C4674BA43DBBA6D16D9DC4F7649\p1v1_PPIRegistryReviver_w.exe a variant of Win32/SlowPCfighter application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\John Niarhos\Application Data\OpenCandy\OpenCandy_86307C4674BA43DBBA6D16D9DC4F7649\PPIRegistryReviverSetup.exe a variant of Win32/SlowPCfighter application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\John Niarhos\My Documents\LimeWire\Saved\tantra lounge - best track ever.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (unable to clean) 00000000000000000000000000000000 I
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xA4418F12] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwReplyPort [0xA454E32A] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xA454E1F0] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xA43FAE84] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xA441A07E] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwResumeThread [0xA4550028] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwSaveKey [0xA454B1FE] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xA43FB5B8] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwSetContextThread [0xA454CC76] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xA43F5B98] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwSetInformationToken [0xA454E86C] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xA4419BA6] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwSetSystemInformation [0xA454FC90] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0xA4416BA8] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwSuspendProcess [0xA454FD74] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwSuspendThread [0xA454FE9C] SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xA44110A6] SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA16D3620] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwTerminateThread [0xA454C80E] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xA454FA06] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xA454C998] Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) IoIsOperationSynchronous —- Kernel code sections - GMER 1.0.15 —- .text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF84 5 Bytes JMP A45419D4 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) .text ntkrnlpa.exe!IoIsOperationSynchronous 804EF912 5 Bytes JMP A4541DAE \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wxp_x86]/Kaspersky Lab) .text ntkrnlpa.exe!ZwCallbackReturn + 2C9C 80504538 12 Bytes [BE, BA, 3F, A4, 82, FF, 40, …] {MOV ESI, 0x82a43fba; INC DWORD [EAX-0x5c]; STOSB ; ADD EAX, [ECX-0x5c]} .text ntkrnlpa.exe!ZwCallbackReturn + 2CAC 80504548 16 Bytes [3C, A8, 41, A4, FE, DE, 54, …] .text ntkrnlpa.exe!ZwCallbackReturn + 2D68 80504604 12 Bytes [08, F2, 54, A4, 58, 85, 41, …] {OR DL, DH; PUSH ESP; MOVSB ; POP EAX; TEST [ECX-0x5c], EAX; XCHG ESI, EAX; XCHG [ECX-0x5c], EAX} .text ntkrnlpa.exe!ZwCallbackReturn + 2EE4 80504780 16 Bytes [1E, 96, 41, A4, 12, 8F, 41, …] .text ntkrnlpa.exe!ZwCallbackReturn + 2F7C 80504818 4 Bytes CALL FAF2EC71 .text … .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
The logs are too long to fit into one post, that's why you had difficulty posting it. But no worries about that, I've downloaded the attachment.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
    DRV - (kl1) – C:\WINDOWS\System32\DRIVERS\kl1.sys (Kaspersky Lab)
    
    :Files
    C:\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{05B64610-ED45-40AC-89A3-507F6B6A25B9}\Registry Reviver.msi
    C:\Documents and Settings\John Niarhos\Application Data\OpenCandy\OpenCandy_86307C4674BA43DBBA6D16D9DC4F7649\p1v1_PPIRegistryReviver_w.exe
    C:\Documents and Settings\John Niarhos\Application Data\OpenCandy\OpenCandy_86307C4674BA43DBBA6D16D9DC4F7649\PPIRegistryReviverSetup.exe
    C:\Documents and Settings\John Niarhos\My Documents\LimeWire\Saved\tantra lounge - best track ever.mp3
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [CLEARALLRESTOREPOINTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log and( don't check the boxes beside LOP Check or Purity this time )
===================================================

On your next reply please post :
OTL fix log
Fresh OTL log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thank you Conspire.
here are the 2 logs

All processes killed
========== OTL ==========
Error: Unable to stop service KLIF!
Unable to delete service\driver key KLIF.
File move failed. C:\WINDOWS\system32\drivers\klif.sys scheduled to be moved on reboot.
Error: Unable to stop service kl1!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kl1 deleted successfully.
File move failed. C:\WINDOWS\system32\drivers\kl1.sys scheduled to be moved on reboot.
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{05B64610-ED45-40AC-89A3-507F6B6A25B9}\Registry Reviver.msi moved successfully.
C:\Documents and Settings\John Niarhos\Application Data\OpenCandy\OpenCandy_86307C4674BA43DBBA6D16D9DC4F7649\p1v1_PPIRegistryReviver_w.exe moved successfully.
C:\Documents and Settings\John Niarhos\Application Data\OpenCandy\OpenCandy_86307C4674BA43DBBA6D16D9DC4F7649\PPIRegistryReviverSetup.exe moved successfully.
C:\Documents and Settings\John Niarhos\My Documents\LimeWire\Saved\tantra lounge - best track ever.mp3 moved successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 56502 bytes

User: John Niarhos
->Flash cache emptied: 4869 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: John Niarhos
->Temp folder emptied: 195172928 bytes
->Temporary Internet Files folder emptied: 127437 bytes
->Java cache emptied: 7929 bytes
->FireFox cache emptied: 39660964 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 2014815 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 3871628 bytes

User: NetworkService
->Temp folder emptied: 1982704 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 1178691 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1197817254 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1896 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,375.00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.20.6 log created on 02202011_200928

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\system32\drivers\klif.sys scheduled to be moved on reboot.
File move failed. C:\WINDOWS\system32\drivers\kl1.sys scheduled to be moved on reboot.

Registry entries deleted on Reboot…





OTL logfile created on: 20/02/2011 8:18:16 PM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\John Niarhos\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 152.32 Gb Free Space | 81.76% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 185.93 Gb Free Space | 99.80% Space Free | Partition Type: NTFS

Computer Name: YOUR-6D410B054D | User Name: John Niarhos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\John Niarhos\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\MagicTune Premium\MagicTune.exe (SEC)
PRC - C:\Program Files\MultiScreen\MultiScreen.exe ()
PRC - C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe ()
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
PRC - C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\MagicTune Premium\GammaTray.exe ()
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\John Niarhos\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\mfc42.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\CheckPoint\ZAForceField\AK\icsak.dll (Check Point Software Technologies)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\Program Files\MultiScreen\ServiceHook.dll ()
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Authentec memory manager) – File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TODDSrv) – C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FingerprintServer) – C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
SRV - (MagicTuneEngine) – C:\Program Files\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (MagicTune) – C:\WINDOWS\system32\drivers\MTiCtwl.sys (Samsung Electronics, Inc. )
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (AlfaFF) – C:\WINDOWS\system32\Drivers\AlfaFF.sys (Alfa Corporation)
DRV - (RTHDMIAzAudService) – C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (UVCFTR) – C:\WINDOWS\system32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (FwLnk) – C:\WINDOWS\system32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdudf) – C:\WINDOWS\system32\drivers\tdudf.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\WINDOWS\system32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (trudf) – C:\WINDOWS\system32\drivers\trudf.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (FTSER2K) USB to Serial (RS232) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) USB to Serial (RS232) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/08 14:34:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/20 17:34:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/20 17:34:46 | 000,000,000 | —D | M]

[2011/02/20 17:34:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions
[2009/12/30 17:24:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions\[removed]
[2011/02/19 20:49:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions
[2011/02/19 00:25:17 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/19 00:17:58 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/19 00:23:54 | 000,000,000 | —D | M] (ImTranslator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2011/02/19 00:16:47 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/19 20:50:09 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/20 17:38:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions
[2011/02/20 17:37:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/20 17:37:51 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/20 17:38:09 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/20 17:38:13 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/20 17:34:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/09/15 14:36:51 | 000,329,949 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11302 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe ()
O4 - HKLM..\Run: [FingerPrintNotifer] C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [MultiScreen] C:\Program Files\MultiScreen\MultiScreen.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GammaTray.lnk = C:\Program Files\MagicTune Premium\GammaTray.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\ATFUS: DllName - C:\WINDOWS\system32\FpWinLogonNp.dll - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/26 12:46:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7f0272b9-f50f-11de-964b-00216b469a86}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe
O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell - "" = AutoRun
O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
O33 - MountPoints2\{b63ea508-f0ba-11dd-947f-00216b469a86}\Shell\AutoRun\command - "" = setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/20 20:09:28 | 000,000,000 | —D | C] – C:\_OTL
[2011/02/20 17:34:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/02/20 17:34:44 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/02/20 16:09:38 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/02/19 09:51:59 | 000,000,000 | —D | C] – C:\Documents and Settings\John Niarhos\My Documents\Whatthetech
[2011/02/19 09:50:45 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\John Niarhos\Desktop\HiJackThis.exe
[2011/02/19 09:39:52 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe
[2011/02/16 20:57:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\John Niarhos\Recent
[2011/02/16 20:25:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/02/16 20:25:35 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/16 20:25:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/16 20:25:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/01/22 01:14:37 | 000,439,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2008/06/27 04:22:10 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\DLLVGA.dll

========== Files - Modified Within 30 Days ==========

[2011/02/20 20:16:40 | 000,000,144 | —- | M] () – C:\WINDOWS\System32\pdfl.dat
[2011/02/20 20:16:15 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/20 20:14:13 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/20 20:13:38 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/02/20 20:13:37 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/20 20:13:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/20 17:34:48 | 000,001,631 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/20 17:34:48 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/20 15:41:25 | 000,006,500 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\Gmer.zipx
[2011/02/20 15:13:24 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/02/20 11:25:58 | 369,229,824 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/02/20 09:32:10 | 002,672,312 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\esetsmartinstaller_enu.exe
[2011/02/20 09:26:52 | 000,296,448 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\y1lrbiv5.exe
[2011/02/19 09:52:42 | 000,359,929 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\dds.scr
[2011/02/19 09:50:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\John Niarhos\Desktop\HiJackThis.exe
[2011/02/19 09:39:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe
[2011/02/18 23:10:46 | 000,581,825 | —- | M] () – C:\Documents and Settings\John Niarhos\J & B Niarhos 2010.11.BC4
[2011/02/10 16:24:20 | 000,000,803 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/02/10 16:02:22 | 000,330,688 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/10 13:49:06 | 000,001,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/02 21:40:39 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/02 21:40:38 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/02 21:40:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/02 21:40:23 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/02/02 19:19:39 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/01/28 23:30:31 | 000,000,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/01/22 01:14:37 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/22 01:14:37 | 000,439,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll

========== Files Created - No Company Name ==========

[2011/02/20 17:34:48 | 000,001,631 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/20 17:34:48 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/20 14:44:01 | 000,006,500 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\Gmer.zipx
[2011/02/20 09:31:55 | 002,672,312 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\esetsmartinstaller_enu.exe
[2011/02/20 09:26:43 | 000,296,448 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\y1lrbiv5.exe
[2011/02/19 09:52:42 | 000,359,929 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\dds.scr
[2010/10/22 16:54:05 | 000,001,057 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\vso_ts_preview.xml
[2010/09/06 19:11:08 | 000,000,099 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2010/02/03 21:01:47 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2009/11/04 10:13:57 | 000,001,018 | —- | C] () – C:\WINDOWS\_ISENV31.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/14 15:17:00 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2009/06/11 15:14:04 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2009/06/11 15:12:00 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/06/11 14:58:41 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\CNCFLfNL.DLL
[2009/06/10 17:19:55 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2009/05/04 13:02:35 | 000,000,000 | —- | C] () – C:\WINDOWS\ToDisc.INI
[2009/05/04 12:28:55 | 000,009,216 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/02 11:21:55 | 000,005,632 | R— | C] () – C:\WINDOWS\System32\CNMVSya.DLL
[2009/02/02 11:20:46 | 000,000,356 | R— | C] () – C:\WINDOWS\System32\CNCASv50.ini
[2009/02/02 11:19:52 | 000,000,462 | R— | C] () – C:\WINDOWS\System32\CNCMP50.INI
[2009/02/02 10:15:26 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/02/02 09:59:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2009/02/02 09:59:03 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2009/02/02 09:59:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2009/02/02 09:59:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2009/02/02 09:59:03 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2009/02/02 09:59:03 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2009/02/02 09:42:53 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2009/02/02 09:42:53 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2009/02/02 09:42:53 | 000,010,150 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2009/02/02 09:42:53 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2009/02/01 21:39:30 | 000,000,089 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\FASTWiz.log
[2008/06/27 05:26:23 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/06/27 04:22:10 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TCtrlIO.dll
[2008/06/26 13:53:06 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2008/06/26 12:53:24 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2008/06/26 12:31:49 | 000,002,392 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/06/26 05:37:15 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/12/21 16:46:32 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Unicode (All) ==========
[2009/05/02 08:57:36 | 000,086,528 | —- | M] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
[2009/02/22 20:14:32 | 000,000,162 | -H– | M] ()(C:\Documents and Settings\John Niarhos\My Documents\~$??? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\~$コーラ ヨーヨー.doc
[2009/02/22 20:14:32 | 000,000,162 | -H– | C] ()(C:\Documents and Settings\John Niarhos\My Documents\~$??? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\~$コーラ ヨーヨー.doc
[2009/02/17 11:52:35 | 000,086,528 | —- | C] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc

< End of report >
Hi,

I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@echo off
sc stop KLIF
sc delete KLIF
sc stop kl1
sc delete kl1
if exist C:\WINDOWS\system32\drivers\klif.sys attrib -s -h -r C:\WINDOWS\system32\drivers\klif.sys
if exist C:\WINDOWS\system32\drivers\klif.sys del /f /q C:\WINDOWS\system32\drivers\klif.sys
if exist C:\WINDOWS\System32\DRIVERS\kl1.sys attrib -s -h -r C:\WINDOWS\System32\DRIVERS\kl1.sys
if exist C:\WINDOWS\System32\DRIVERS\kl1.sys del /f /q C:\WINDOWS\System32\DRIVERS\kl1.sys
del /Q %0

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "fix.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]

Double click on fix.bat & allow it to run. A small black screen may briefly flash on and off, that's normal.

===================================================

Remove any attached USB drive on your computer before proceeding.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O33 - MountPoints2\{7f0272b9-f50f-11de-964b-00216b469a86}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe
    O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell - "" = AutoRun
    O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{aa1058a1-1f41-11df-9690-00216b469a86}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
    O33 - MountPoints2\{b63ea508-f0ba-11dd-947f-00216b469a86}\Shell\AutoRun\command - "" = setupSNK.exe
    
    :Commands
    [REBOOT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log and( don't check the boxes beside LOP Check or Purity this time )
===================================================
On your next reply please post :
Fix OTL log
Fresh OTL log
Feedback on the machine's behaviour


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi

Have completed the above procedures but no fix log was created.
Here is the OTL log.
I continue to have issues with firefox and need to open it in safe mode because normally it will not show any of my toolbars. Have tried to uninstall/install to no avail. I dont know if these issues are related to any infections.


OTL logfile created on: 21/02/2011 6:48:39 AM - Run 3
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\John Niarhos\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 153.23 Gb Free Space | 82.24% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 185.93 Gb Free Space | 99.80% Space Free | Partition Type: NTFS

Computer Name: YOUR-6D410B054D | User Name: John Niarhos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\John Niarhos\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\MagicTune Premium\MagicTune.exe (SEC)
PRC - C:\Program Files\MultiScreen\MultiScreen.exe ()
PRC - C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe ()
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
PRC - C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\MagicTune Premium\GammaTray.exe ()
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\John Niarhos\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\mfc42.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\CheckPoint\ZAForceField\AK\icsak.dll (Check Point Software Technologies)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\Program Files\MultiScreen\ServiceHook.dll ()
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Authentec memory manager) – File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TODDSrv) – C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FingerprintServer) – C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
SRV - (MagicTuneEngine) – C:\Program Files\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (MagicTune) – C:\WINDOWS\system32\drivers\MTiCtwl.sys (Samsung Electronics, Inc. )
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (AlfaFF) – C:\WINDOWS\system32\Drivers\AlfaFF.sys (Alfa Corporation)
DRV - (RTHDMIAzAudService) – C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (UVCFTR) – C:\WINDOWS\system32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (FwLnk) – C:\WINDOWS\system32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdudf) – C:\WINDOWS\system32\drivers\tdudf.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\WINDOWS\system32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (trudf) – C:\WINDOWS\system32\drivers\trudf.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (FTSER2K) USB to Serial (RS232) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) USB to Serial (RS232) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/08 14:34:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/20 17:34:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/20 17:34:46 | 000,000,000 | —D | M]

[2011/02/20 17:34:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions
[2009/12/30 17:24:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions\[removed]
[2011/02/19 20:49:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions
[2011/02/19 00:25:17 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/19 00:17:58 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/19 00:23:54 | 000,000,000 | —D | M] (ImTranslator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2011/02/19 00:16:47 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/19 20:50:09 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/20 17:38:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions
[2011/02/20 17:37:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/20 17:37:51 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/20 17:38:09 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/20 20:28:34 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\u9skrmmm.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/20 17:34:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/09/15 14:36:51 | 000,329,949 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11302 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe ()
O4 - HKLM..\Run: [FingerPrintNotifer] C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [MultiScreen] C:\Program Files\MultiScreen\MultiScreen.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GammaTray.lnk = C:\Program Files\MagicTune Premium\GammaTray.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\ATFUS: DllName - C:\WINDOWS\system32\FpWinLogonNp.dll - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/26 12:46:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/20 20:09:28 | 000,000,000 | —D | C] – C:\_OTL
[2011/02/20 17:34:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/02/20 17:34:44 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/02/20 16:09:38 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/02/19 09:51:59 | 000,000,000 | —D | C] – C:\Documents and Settings\John Niarhos\My Documents\Whatthetech
[2011/02/19 09:50:45 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\John Niarhos\Desktop\HiJackThis.exe
[2011/02/19 09:39:52 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe
[2011/02/16 20:57:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\John Niarhos\Recent
[2011/02/16 20:25:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/02/16 20:25:35 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/16 20:25:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/16 20:25:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2008/06/27 04:22:10 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\DLLVGA.dll

========== Files - Modified Within 30 Days ==========

[2011/02/21 06:47:37 | 000,000,144 | —- | M] () – C:\WINDOWS\System32\pdfl.dat
[2011/02/21 06:45:41 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/21 06:45:24 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/21 06:45:20 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/02/21 06:45:03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/20 21:16:01 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/20 20:42:55 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/02/20 17:34:48 | 000,001,631 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/20 17:34:48 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/20 15:41:25 | 000,006,500 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\Gmer.zipx
[2011/02/20 11:25:58 | 369,229,824 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/02/20 09:32:10 | 002,672,312 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\esetsmartinstaller_enu.exe
[2011/02/20 09:26:52 | 000,296,448 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\y1lrbiv5.exe
[2011/02/19 09:52:42 | 000,359,929 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\dds.scr
[2011/02/19 09:50:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\John Niarhos\Desktop\HiJackThis.exe
[2011/02/19 09:39:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Niarhos\Desktop\OTL.exe
[2011/02/18 23:10:46 | 000,581,825 | —- | M] () – C:\Documents and Settings\John Niarhos\J & B Niarhos 2010.11.BC4
[2011/02/10 16:24:20 | 000,000,803 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/02/10 16:02:22 | 000,330,688 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/10 13:49:06 | 000,001,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/02 21:40:39 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/02 21:40:38 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/02 21:40:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/02 21:40:23 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/02/02 19:19:39 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/01/28 23:30:31 | 000,000,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk

========== Files Created - No Company Name ==========

[2011/02/20 17:34:48 | 000,001,631 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/20 17:34:48 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/20 14:44:01 | 000,006,500 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\Gmer.zipx
[2011/02/20 09:31:55 | 002,672,312 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\esetsmartinstaller_enu.exe
[2011/02/20 09:26:43 | 000,296,448 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\y1lrbiv5.exe
[2011/02/19 09:52:42 | 000,359,929 | —- | C] () – C:\Documents and Settings\John Niarhos\Desktop\dds.scr
[2010/10/22 16:54:05 | 000,001,057 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\vso_ts_preview.xml
[2010/09/06 19:11:08 | 000,000,099 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2010/02/03 21:01:47 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2009/11/04 10:13:57 | 000,001,018 | —- | C] () – C:\WINDOWS\_ISENV31.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/14 15:17:00 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2009/06/11 15:14:04 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2009/06/11 15:12:00 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/06/11 14:58:41 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\CNCFLfNL.DLL
[2009/06/10 17:19:55 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2009/05/04 13:02:35 | 000,000,000 | —- | C] () – C:\WINDOWS\ToDisc.INI
[2009/05/04 12:28:55 | 000,009,216 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/02 11:21:55 | 000,005,632 | R— | C] () – C:\WINDOWS\System32\CNMVSya.DLL
[2009/02/02 11:20:46 | 000,000,356 | R— | C] () – C:\WINDOWS\System32\CNCASv50.ini
[2009/02/02 11:19:52 | 000,000,462 | R— | C] () – C:\WINDOWS\System32\CNCMP50.INI
[2009/02/02 10:15:26 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/02/02 09:59:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2009/02/02 09:59:03 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2009/02/02 09:59:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2009/02/02 09:59:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2009/02/02 09:59:03 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2009/02/02 09:59:03 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2009/02/02 09:42:53 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2009/02/02 09:42:53 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2009/02/02 09:42:53 | 000,010,150 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2009/02/02 09:42:53 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2009/02/01 21:39:30 | 000,000,089 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\FASTWiz.log
[2008/06/27 05:26:23 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/06/27 04:22:10 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TCtrlIO.dll
[2008/06/26 13:53:06 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2008/06/26 12:53:24 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2008/06/26 12:31:49 | 000,002,392 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/06/26 05:37:15 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/12/21 16:46:32 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Unicode (All) ==========
[2009/05/02 08:57:36 | 000,086,528 | —- | M] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
[2009/02/22 20:14:32 | 000,000,162 | -H– | M] ()(C:\Documents and Settings\John Niarhos\My Documents\~$??? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\~$コーラ ヨーヨー.doc
[2009/02/22 20:14:32 | 000,000,162 | -H– | C] ()(C:\Documents and Settings\John Niarhos\My Documents\~$??? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\~$コーラ ヨーヨー.doc
[2009/02/17 11:52:35 | 000,086,528 | —- | C] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc

< End of report >
Allow me to clarify your problem. You did a reinstallation on your toolbars or the firefox as a whole? Exactly which toolbars that you need to use?
I dont use zonealarm toolbar and am not sure if i need it. I do use bookmark toolbar and foxlingo toolbar. Whe I turned on my computer this morning the toolbars werent there. Only after disabling forcefield toolbar is firefox showing the toolbars. Starting to think its a zonealarm issue

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI