This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I cannot runIE or any .exe files on my laptop

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi , Hopefully you guys can help me out, As of 02-18-2011 , i can no longer access the internet of any other programs on my computer , every program i click generates a message saying "do you want to run or save this file" , no matter what choice I make either RUN or SAVE I immediatly get the same message again. i cannot run anything on the computer so I cannot do a scan , i cannot download and run HIJACK THIS. Right now I am completely stuck I even tried to run some programs in SAFEMODE and they would also not run , I received the same massage "do you want to run or save this file" again. I was also getting this message when i tried go to a link: "This file does not have a program associated with it for performing this action. Create an associaton in the Set Associations control panel." Please help me with this problem . thank you Sam
Hello babbagene and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

If you are unable to connect to the internet with the infected machine you will need to find a clean machine to download the requried tools. Once downloaded, transfer them to the infected system by burning them to disk/using a USB thumb drive.

If you choose to use a thumb drive for the transfer, and if the clean system runs on XP, please download and run the following tool first to reduce the chances of cross infection:

  • Please download Flash Disinfector


    • Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
    • Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
    • The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
    • Wait until Flash disinfector has finished scanning and then exit the program.
    • Reboot your computer.

    If the clean system runs on Vista/Win7, use this one:

  • AutoRun Eater


    • Dowlnload Autorun Eater and save it to your desktop.
    • Plug all of your removable storage devices into the machine (USB sticks etc) and run the tool.

    Download and transfer the following to the infected machine:

  • rkill


    • Please download rkill (Courtesy of Bleepingcomputer.com).
    • There are 5 different versions of this tool. If one of them will not run, please try the next one in the list.
    • Note: Vista and Windows 7 Users must right click and select "Run as Administrator" to run the tool.
    • Note: You only need to get one of the tools to run, not all of them.


    1. rkill.exe
    2. rkill.com
    3. rkill.scr
    4. WiNlOgOn.exe
    5. uSeRiNiT.exe

    Note: You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.

    Run rkill repeatedly until it's able to do it's job. This may take a few tries.

    You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.
  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Right click on the DDS icon and select "Run as Administrator" to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click on GMER.exe and select "Run as Administrator" to run the program. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the DDS logs and GMER log in your next reply. If you have any touble with the scans let me know.
Hi Jon Tom , thank you for your assistance , i will download the programs the cd using a working computer,at that point i need to load them into the infected computer ,correct? i will post when I have completed this step . Thank you so much regards Sam
I have downloaded autoruneater and rkill to my desktop on my windows 7 working computer,i am not clear on what i need to do next, I do NOT hace a usb thumb device , can i just burn the programs onto a cd-rw, if so can you guide me. Thank you Sam PS-I did not run any of the programs on the working computer
Hello babbagene

Autorun Eater is only needed if you are going to use a USB Thumb drive to transfer the required tools to the infected machine.

As you do not have a thumb drive handy you do not need to worry about autorun eater :)

i am not clear on what i need to do next
can i just burn the programs onto a cd-rw, if so can you guide me.

Burning disks is certainly possible, just a little less convenient than using a thumb drive. Lets give it a try:


Download all of the different versions of rkill to your Win7 desktop, then download DDS and GMER in the same way. Make sure that they are all on your desktop (so you can find them easily).

Once you have downloaded the tools, you need to copy (burn) them to disk (Note: You must have a drive capable of burning information to a CD in order to create the disk).

You may already have software installed that can do this for you (such as nero for example).

Some general information about how to burn a disk can be found here.


If the infected machine runs on vista/XP, it may be better to Choose the Mastered format method rather than the Live File format method for the disk you create (instructions are provided in the link).

Once the required tools have been burned to disk, put the disk in the infected system and copy the programs to the desktop.

Begin with rKill (instructions provided previously), then follow with DDS and GMER.

When the DDS logs and GMER logs are produced make sure you save them. If you are unable to connect to the internet using the infected system you will need to burn the log files and post the back here from your Win7 machine.

If the infected system does not have a CD burner (or if the malware on the machine prevents you from using it) we will need to get hold of a thumb drive.

Give the above a try and let me know how you get on :)
hi , once again i would like to thank you for all your help. I ran rkill but the program was kind of in a loop as it kept File download Security Warning and asking me if i want to run or save this file?
NAME:iexplore.exe
TYPE:EXE File, 150KB
From:C:\Users\babbagene\AppData\Local\Temp\Rar…
It was constantly doing this however in the backround I did get thnis log from rkill, here it is:

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 02/20/2011 at 1:39:24.
Operating System: Windows Vista ™ Home Premium


Processes terminated by Rkill or while it was running:



Rkill completed on 02/20/2011 at 1:39:24.



After this I ran DDS also with the same results of the FILE SECURITY Warning popping up constantly,however i did mange to get a report,here it is:



DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 1:43:06.81 on Sun 02/20/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.2040 [GMT -5:00]

AV: Norton Security Suite *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Security Suite *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Users\babbagene\Desktop\rkill.com
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\babbagene\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
uSearch Bar = hxxp://www.google.com
mStart Page = hxxp://search.foxtab.com/?s=0&chnl=irn&cd=2XzutCtN2Y1L1QzutDtDtBtBtCyDtByDzyyBtDyCtN0C0Czu0U0StN0D0TzutBtDtCtCtDtBt
CtA&cr=1294908807
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
mSearch Bar = hxxp://www.google.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - c:\program files\vshare\vshare_toolbar.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\3.8.0.41\IPSBHO.DLL
BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\program files\iwin games\iWinGamesHookIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - c:\program files\vshare\vshare_toolbar.dll
TB: {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - No File
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [cdloader] "c:\users\babbagene\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C)" -"http://www.freegames.net/play323-Flip-or-Flop-game.html"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://www.opentopia.com/support/activex/AxisCamControl.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/armhelper.ocx
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://www.vexcast.com/download/vexcast.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton security suite\engine\3.8.0.41\CoIEPlg.dll
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - c:\program files\vshare\vshare_toolbar.dll

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-3-2 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-3-2 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-3-2 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20110218.003\IDSvix86.sys [2011-2-18 353912]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2010-9-27 176408]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\3.8.0.41\ccSvcHst.exe [2010-3-2 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-1-21 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0308000.029\symndisv.sys [2010-3-2 48688]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Symantec Core LC;Symantec Core LC; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2011-02-20 04:57:04 ——– d–h–w- c:\windows\PIF
2011-02-18 07:06:40 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{c8ac04e0-7493-4fe5-86af-13b9501d324b}\mpengine.dll
2011-02-18 00:14:59 0 —-a-w- c:\users\babbag~1\appdata\local\Llirahu.bin
2011-02-18 00:14:58 ——– d—–w- c:\users\babbag~1\appdata\local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}
2011-02-12 05:40:16 ——– d—–w- c:\users\babbag~1\appdata\roaming\Friday's games
2011-02-09 19:43:06 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-09 19:43:03 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-09 19:43:03 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-09 19:43:02 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-09 19:43:00 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-01-31 02:04:53 ——– d—–w- c:\users\babbag~1\appdata\roaming\SpinTop Games
2011-01-27 18:45:29 ——– d—–w- c:\users\babbag~1\appdata\roaming\BitZipper

==================== Find3M ====================

2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 —-a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
2011-01-04 16:36:39 21258 —-a-w- c:\windows\cscmondump.bin
2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-18 06:27:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-18 06:22:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-18 06:22:27 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-18 06:22:11 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-12-18 06:22:11 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-12-18 05:25:26 385024 —-a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-12-14 14:49:23 1169408 —-a-w- c:\windows\system32\sdclt.exe

============= FINISH: 1:43:34.82 ===============


When I tried to run GMER I also got the same Security Warnings as mentioned above however this program would NOT run. I notice that many of my Icons on the desktop only display the letter instaed of a picture.
I hope this info helps you out1
Regards
Sam
Hello babbagene

Thank you for the log. Lets see if we can get GMER to run this way:

  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
    • If GMER does not produce a log please try running it from Safe Mode.

    • How to use the F8 method to Start Your Computer in Safe Mode

    • Restart your computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
    • Use the arrow keys to select the Safe mode menu item.
    • Press Enter.

    • If GMER in safe mode does not work, please try Rootkit Unhooker:

  • Rootkit Unhooker


    • Please Download Rootkit Unhooker and Save it to your desktop.
    • Right click on RKUnhookerLE.exe and select "Run as administrator" to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth. Uncheck the rest, then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • Save the report somewhere where you can find it. Click Close.

    Copy the entire contents of the report and paste it in your next reply here.

    Note: You may get the following warning, just click OK and continue.

    "Rootkit Unhooker has detected a parasite inside itself!
    It is recommended to remove parasite, okay?"


    Please provide the GMER/Rootkit Unhooker log in your next reply. If you are still having trouble, come back and let me know.
I tried as you said , but neither program will run, I cannot run any exe files . As soon as I start my infected computer up it goes thru 17 programs with each one giving the message 'File Download -security Warning: here are the 17 programsthat seem to be trying to open at startup: RtHDVCpl.exe wmpnscfg.exe nmapp.exe HPAdvisor.exe ehtray.exe Qttask.exe kbdStub.exe MSASCui.exe nmctxth.exe hpwuSchd2.exe realsched.exe cdloader2.exe rundll32.exe hpsysdrv.exe AdobeARM.exe reader_sl.exe rundll32.exe Each of the above happen at each startup ,and whethet i choose to RUN or SAVE , it does not matter ,they never load I justy get taken back to the original Security Warning Message. i really cannot seem to rum anything on the infected computer evn in the Safemode option. Regards Sam I recently ran CCCleaner and cleaned registry and then also ran Eusing Free registry Cleaner and cleaned registry (however I did not back it up)DUMB!! However the computer seemed to work aFTER THOSE ACTIONS WERE TAKEN ,But I am not positive.
Hello babbagene

I cannot run any exe files

The malware on your system is interfering with our tools. Lets see of the following helps:


  • exeHelper


    • Please download exeHelper by clicking here and save the file (called exeHelper.com) to your desktop.
    • Double click on exeHelper.com to run the fix.
    • A black window should pop up. Press any key to close once the fix is completed.
    • Post the contents of log.txt (it Will be created in the directory where you ran exeHelper.com).
    • NOTE: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    After running exeHelper, please try to run GMER (.exe file) again. If you are still unable to open any .exe files after trying exeHelper we shall have to try a different scan:

  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.scr) to your desktop.
    • Close all open windows on your computer then Double click on the OTL.scr icon to run the program.
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.
hi I was still not able to run GMER , however I WAS able to run the alternatives scans you sent me , here are the results:

exeHelper by Raktor
Build 20100414
Run at 07:40:52 on 02/21/11
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–


OTL logfile created on: 2/21/2011 8:09:42 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\babbagene\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 325.11 Gb Total Space | 236.24 Gb Free Space | 72.66% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.34 Gb Free Space | 13.12% Space Free | Partition Type: NTFS
Drive E: | 536.31 Mb Total Space | 529.75 Mb Free Space | 98.78% Space Free | Partition Type: UDF

Computer Name: SAM | User Name: babbagene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/21 07:51:28 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\babbagene\Desktop\OTL.scr
PRC - [2010/09/27 10:36:24 | 000,176,408 | —- | M] (iWin Inc.) – C:\Program Files\iWin Games\iWinTrusted.exe
PRC - [2010/03/02 17:05:50 | 000,117,640 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/12/12 18:06:40 | 000,642,856 | —- | M] (Cisco Systems, Inc.) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2007/06/20 09:04:54 | 000,693,600 | —- | M] (Microsoft® Corporation) – C:\Program Files\Microsoft Works\WksWP.exe
PRC - [2007/06/20 09:04:52 | 000,095,584 | —- | M] (Microsoft® Corporation) – C:\Program Files\Microsoft Works\WkDStore.exe
PRC - [2007/06/20 09:04:52 | 000,091,488 | —- | M] (Microsoft® Corporation) – C:\Program Files\Microsoft Works\wkgdcach.exe


========== Modules (SafeList) ==========

MOD - [2011/02/21 07:51:28 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\babbagene\Desktop\OTL.scr
MOD - [2010/08/31 10:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (Symantec Core LC)
SRV - [2011/01/20 08:44:03 | 000,797,184 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\System32\FntCache.dll – (FontCache)
SRV - [2010/09/27 10:36:24 | 000,176,408 | —- | M] (iWin Inc.) [Auto | Running] – C:\Program Files\iWin Games\iWinTrusted.exe – (iWinTrusted)
SRV - [2010/03/18 12:16:28 | 000,753,504 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe – (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/02 17:05:50 | 000,117,640 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe – (N360)
SRV - [2008/12/12 18:06:40 | 000,642,856 | —- | M] (Cisco Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2008/01/20 21:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2010/12/16 04:00:00 | 001,360,760 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110220.002\NAVEX15.SYS – (NAVEX15)
DRV - [2010/12/16 04:00:00 | 000,086,008 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110220.002\NAVENG.SYS – (NAVENG)
DRV - [2010/11/08 19:50:30 | 000,353,912 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20110218.003\IDSvix86.sys – (IDSVix86)
DRV - [2010/07/26 11:14:46 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/07/26 11:14:46 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/03/02 17:06:04 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/03/02 17:05:52 | 000,310,320 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS – (SymEFA)
DRV - [2010/03/02 17:05:52 | 000,308,272 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS – (SRTSP)
DRV - [2010/03/02 17:05:52 | 000,217,136 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS – (SYMTDI)
DRV - [2010/03/02 17:05:52 | 000,089,904 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS – (SYMFW)
DRV - [2010/03/02 17:05:52 | 000,048,688 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS – (SYMNDISV)
DRV - [2010/03/02 17:05:52 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/03/02 17:05:52 | 000,025,648 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\SymIMV.sys – (SymIM)
DRV - [2010/03/02 17:05:51 | 000,482,432 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys – (ccHP)
DRV - [2010/03/02 17:05:51 | 000,259,632 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys – (BHDrvx86)
DRV - [2009/04/10 23:42:54 | 000,073,216 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/12/12 18:05:18 | 000,026,416 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\purendis.sys – (purendis)
DRV - [2008/12/12 18:05:18 | 000,024,880 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\pnarp.sys – (pnarp)
DRV - [2008/07/03 16:03:48 | 002,152,088 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/05/22 13:49:00 | 007,465,312 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/05/08 04:05:18 | 000,266,752 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2008/05/08 04:04:16 | 000,661,504 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2008/05/08 04:03:18 | 000,980,992 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSX_DP.sys – (HSF_DP)
DRV - [2008/01/29 07:55:00 | 001,042,464 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2008/01/25 14:02:04 | 000,132,128 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvrd32.sys – (nvrd32)
DRV - [2008/01/25 14:02:02 | 000,140,832 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvstor32.sys – (nvstor32)
DRV - [2008/01/20 21:23:27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/20 21:23:27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/20 21:23:27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/20 21:23:26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/20 21:23:26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/20 21:23:26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/20 21:23:25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/20 21:23:25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/20 21:23:24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/20 21:23:24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/20 21:23:24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/20 21:23:23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/20 21:23:23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/20 21:23:23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/20 21:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/20 21:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/20 21:23:23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/20 21:23:22 | 000,342,584 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/20 21:23:21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/20 21:23:21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/20 21:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/20 21:23:20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/20 21:23:00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/20 21:23:00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/20 21:23:00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/10/18 10:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/10/12 10:53:10 | 000,013,312 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvsmu.sys – (nvsmu)
DRV - [2006/11/02 04:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 04:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 04:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 04:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 04:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 03:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2005/12/12 11:27:00 | 000,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.foxtab.com/?s=0&chnl;=irn…p;cr=1294908807

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/09 12:35:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/04/26 17:17:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}: C:\Users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}\ [2011/02/17 19:14:58 | 000,000,000 | —D | M]

[2009/06/20 16:26:09 | 000,000,000 | —D | M] (No name found) – C:\Users\babbagene\AppData\Roaming\Mozilla\Extensions
[2009/06/20 16:26:09 | 000,000,000 | —D | M] (No name found) – C:\Users\babbagene\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\3.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (no name) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [cdloader] C:\Users\babbagene\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\RunOnce: [Shockwave Updater] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} https://kingsisle.hs.llnwd.net/e1/static/th…ameLauncher.CAB (Wizard101GameLauncher)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://www.opentopia.com/support/activex/AxisCamControl.cab (CamImage Class)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://www.vexcast.com/download/vexcast.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Security Suite\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe ()
O20 - HKCU Winlogon: Shell - (Explorer.exe) - Explorer.exe ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\img32.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\img32.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/19 15:31:27 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{95c3256d-58b0-11de-8530-002215259706}\Shell\AutoRun\command - "" = K:\autorun.exe
O33 - MountPoints2\{95c3256d-58b0-11de-8530-002215259706}\Shell\phone\command - "" = K:\autorun.exe
O33 - MountPoints2\{bf5b52fe-7e09-11de-b990-002215259706}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WillPolo.vbs
O33 - MountPoints2\{d1bcce71-5a07-11de-9eae-002215259706}\Shell\AutoRun\command - "" = L:\RUNDLL32.EXE
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\autorun.exe
O33 - MountPoints2\K\Shell\phone\command - "" = K:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/02/21 07:53:40 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\babbagene\Desktop\OTL.scr
[2011/02/19 23:57:04 | 000,000,000 | -H-D | C] – C:\Windows\PIF
[2011/02/17 20:39:03 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2011/02/17 19:14:58 | 000,000,000 | —D | C] – C:\Users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}
[2011/02/12 00:40:16 | 000,000,000 | —D | C] – C:\Users\babbagene\AppData\Roaming\Friday's games
[2011/02/09 14:43:06 | 002,039,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/02/09 14:43:03 | 003,602,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/02/09 14:43:02 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/02/09 14:42:40 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/02/09 14:42:40 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/02/09 14:42:40 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/02/09 14:42:40 | 000,797,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2011/02/09 14:42:40 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/02/09 14:42:39 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/02/09 14:42:39 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/02/09 14:42:39 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/02/09 14:42:39 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/02/09 14:42:39 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/02/09 14:42:39 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/02/09 14:42:39 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/02/09 14:42:38 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/02/09 14:42:38 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/02/09 14:42:38 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/02/09 14:42:38 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/02/09 14:42:38 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/02/09 14:42:38 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/02/09 14:42:37 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/02/09 14:42:37 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/02/09 14:42:37 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/02/09 14:42:37 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/02/09 14:42:33 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/02/09 14:42:33 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/02/09 14:42:33 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/02/09 14:42:16 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/02/09 14:42:16 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/02/09 14:42:16 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/02/09 14:42:16 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/02/09 14:42:16 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/02/09 14:42:15 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/02/09 14:42:15 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/02/09 14:42:15 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/02/09 14:42:15 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/02/09 14:42:15 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/02/09 14:42:15 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/02/09 14:42:15 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/02/09 14:42:15 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/02/09 14:42:15 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/02/09 14:42:15 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/02/09 14:42:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/02/09 14:42:15 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/02/09 14:42:06 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/02/09 14:42:05 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/01/30 21:04:53 | 000,000,000 | —D | C] – C:\Users\babbagene\AppData\Roaming\SpinTop Games
[2011/01/27 14:11:01 | 000,000,000 | —D | C] – C:\Users\babbagene\AppData\Roaming\CyberLink
[2011/01/27 14:11:01 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/01/27 13:45:29 | 000,000,000 | —D | C] – C:\Users\babbagene\AppData\Roaming\BitZipper
[2011/01/24 13:44:06 | 000,000,000 | —D | C] – C:\Users\babbagene\Documents\ToDo3
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/21 08:01:05 | 000,007,812 | —- | M] () – C:\Users\babbagene\AppData\Roaming\wklnhst.dat
[2011/02/21 07:51:28 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\babbagene\Desktop\OTL.scr
[2011/02/21 07:37:20 | 000,294,400 | —- | M] () – C:\Users\babbagene\Desktop\exeHelper.com
[2011/02/21 07:37:06 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/21 07:37:06 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/21 07:34:08 | 000,000,430 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4F74C39B-E843-46E1-9C70-C9134C90FBF5}.job
[2011/02/21 07:32:29 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/21 07:32:29 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/21 07:32:27 | 000,000,314 | —- | M] () – C:\Windows\tasks\BearShareNAG.job
[2011/02/21 07:32:27 | 000,000,306 | —- | M] () – C:\Windows\tasks\iMeshNAG.job
[2011/02/21 07:32:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/21 07:32:16 | 3085,377,536 | -HS- | M] () – C:\hiberfil.sys
[2011/02/20 14:07:33 | 000,133,632 | —- | M] () – C:\Users\babbagene\Documents\RKUnhookerLE.EXE
[2011/02/20 14:07:33 | 000,133,632 | —- | M] () – C:\Users\babbagene\Desktop\RKUnhookerLE.EXE
[2011/02/20 01:12:19 | 000,296,448 | —- | M] () – C:\Users\babbagene\Desktop\gmerexe.exe
[2011/02/20 00:24:04 | 000,034,816 | —- | M] () – C:\Users\babbagene\Documents\dds.wps
[2011/02/19 23:38:55 | 000,288,107 | —- | M] () – C:\Users\babbagene\Documents\gmer.zip
[2011/02/19 23:38:55 | 000,288,107 | —- | M] () – C:\Users\babbagene\Desktop\gmer.zip
[2011/02/19 23:35:22 | 000,624,128 | —- | M] () – C:\Users\babbagene\Desktop\dds.scr
[2011/02/19 23:28:56 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\WiNlOgOn.exe
[2011/02/19 23:28:41 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\iExplore.exe
[2011/02/19 23:27:51 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\eXplorer.exe
[2011/02/19 23:27:39 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\rkill.scr
[2011/02/19 23:27:27 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\rkill.exe
[2011/02/19 16:02:33 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\uSeRiNiT.exe
[2011/02/19 15:32:08 | 000,721,253 | —- | M] () – C:\Users\babbagene\Desktop\rkill.com
[2011/02/19 03:53:00 | 000,000,452 | —- | M] () – C:\Windows\tasks\COMODO System Cleaner Update.job
[2011/02/18 15:09:50 | 000,000,911 | —- | M] () – C:\Users\babbagene\Desktop\magicJack.lnk
[2011/02/17 19:14:59 | 000,000,120 | —- | M] () – C:\Users\babbagene\AppData\Local\Hxozuyoya.dat
[2011/02/17 19:14:59 | 000,000,000 | —- | M] () – C:\Users\babbagene\AppData\Local\Llirahu.bin
[2011/02/14 20:00:00 | 000,000,554 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - babbagene.job
[2011/02/14 18:12:23 | 000,019,968 | —- | M] () – C:\Users\babbagene\Documents\error.wps
[2011/02/12 00:25:41 | 000,001,505 | —- | M] () – C:\Users\babbagene\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/12 00:25:41 | 000,001,481 | —- | M] () – C:\Users\Public\Desktop\Game Manager.lnk
[2011/02/12 00:25:41 | 000,001,184 | —- | M] () – C:\Users\Public\Desktop\More Great Games.lnk
[2011/02/10 11:34:22 | 000,292,775 | —- | M] () – C:\Users\babbagene\Documents\scan0001.jpg
[2011/02/10 03:23:32 | 000,307,392 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/02/08 04:46:03 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForbabbagene.job
[2011/01/28 16:22:47 | 000,093,696 | —- | M] () – C:\Users\babbagene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/21 07:40:09 | 000,294,400 | —- | C] () – C:\Users\babbagene\Desktop\exeHelper.com
[2011/02/20 14:13:32 | 000,133,632 | —- | C] () – C:\Users\babbagene\Documents\RKUnhookerLE.EXE
[2011/02/20 14:10:44 | 000,133,632 | —- | C] () – C:\Users\babbagene\Desktop\RKUnhookerLE.EXE
[2011/02/20 13:57:54 | 3085,377,536 | -HS- | C] () – C:\hiberfil.sys
[2011/02/20 13:57:54 | 3085,377,536 | -HS- | C] () –
[2011/02/20 01:15:27 | 000,296,448 | —- | C] () – C:\Users\babbagene\Desktop\gmerexe.exe
[2011/02/20 00:36:40 | 000,288,107 | —- | C] () – C:\Users\babbagene\Documents\gmer.zip
[2011/02/20 00:24:04 | 000,034,816 | —- | C] () – C:\Users\babbagene\Documents\dds.wps
[2011/02/20 00:06:54 | 000,000,370 | —- | C] () – \rkill.log
[2011/02/20 00:01:11 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\rkill.scr
[2011/02/20 00:01:11 | 000,288,107 | —- | C] () – C:\Users\babbagene\Desktop\gmer.zip
[2011/02/20 00:01:10 | 000,624,128 | —- | C] () – C:\Users\babbagene\Desktop\dds.scr
[2011/02/20 00:01:09 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\WiNlOgOn.exe
[2011/02/20 00:01:09 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\rkill.com
[2011/02/20 00:01:08 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\uSeRiNiT.exe
[2011/02/20 00:01:08 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\rkill.exe
[2011/02/20 00:01:08 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\iExplore.exe
[2011/02/20 00:01:08 | 000,721,253 | —- | C] () – C:\Users\babbagene\Desktop\eXplorer.exe
[2011/02/17 19:14:59 | 000,000,120 | —- | C] () – C:\Users\babbagene\AppData\Local\Hxozuyoya.dat
[2011/02/17 19:14:59 | 000,000,000 | —- | C] () – C:\Users\babbagene\AppData\Local\Llirahu.bin
[2011/02/14 18:12:23 | 000,019,968 | —- | C] () – C:\Users\babbagene\Documents\error.wps
[2011/01/30 12:38:47 | 000,292,775 | —- | C] () – C:\Users\babbagene\Documents\scan0001.jpg
[2010/04/26 17:57:57 | 000,000,109 | —- | C] () – \mbam-error.txt
[2010/02/25 05:07:56 | 000,000,257 | —- | C] () – C:\Windows\cdplayer.ini
[2010/02/23 09:49:46 | 000,000,510 | —- | C] () – C:\Windows\WORDPAD.INI
[2009/09/18 06:58:19 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/20 21:11:10 | 000,001,107 | -H– | C] () – \IPH.PH
[2009/06/30 09:10:16 | 000,000,000 | RHS- | C] () – \MSDOS.SYS
[2009/06/30 09:10:16 | 000,000,000 | RHS- | C] () – \IO.SYS
[2009/06/25 23:48:19 | 000,001,449 | —- | C] () – \InstallHelper.log
[2009/06/20 23:11:30 | 000,093,696 | —- | C] () – C:\Users\babbagene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/15 19:20:07 | 000,007,812 | —- | C] () – C:\Users\babbagene\AppData\Roaming\wklnhst.dat
[2009/06/15 07:47:28 | 000,000,594 | —- | C] () – \updatedatfix.log
[2009/06/15 07:39:48 | 000,000,574 | —- | C] () – \RHDSetup.log
[2009/06/14 01:58:09 | 000,000,680 | —- | C] () – C:\Users\babbagene\AppData\Local\d3d9caps.dat
[2009/06/14 01:37:00 | 3399,237,632 | -HS- | C] () –
[2008/06/19 16:08:00 | 000,008,192 | R-S- | C] () – \BOOTSECT.BAK
[2008/06/19 16:07:59 | 000,333,257 | RHS- | C] () – \bootmgr
[2008/06/19 15:16:22 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/06/19 15:16:22 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/11/07 07:12:28 | 000,232,960 | —- | C] () – \VC_RED.MSI
[2007/11/07 07:09:22 | 001,442,522 | —- | C] () – \VC_RED.cab
[2007/11/07 07:03:18 | 000,562,688 | —- | C] () – \install.exe
[2007/11/07 07:03:18 | 000,097,296 | —- | C] () – \install.res.1036.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | C] () – \install.res.3082.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | C] () – \install.res.1031.dll
[2007/11/07 07:03:18 | 000,095,248 | —- | C] () – \install.res.1040.dll
[2007/11/07 07:03:18 | 000,091,152 | —- | C] () – \install.res.1033.dll
[2007/11/07 07:03:18 | 000,081,424 | —- | C] () – \install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | —- | C] () – \install.res.1042.dll
[2007/11/07 07:03:18 | 000,076,304 | —- | C] () – \install.res.1028.dll
[2007/11/07 07:03:18 | 000,075,792 | —- | C] () – \install.res.2052.dll
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.3082.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.1040.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.1031.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | C] () – \eula.1028.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | C] () – \eula.1033.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | C] () – \vcredist.bmp
[2007/11/07 07:00:40 | 000,001,110 | —- | C] () – \globdata.ini
[2007/11/07 07:00:40 | 000,000,843 | —- | C] () – \install.ini
[2007/11/07 07:00:40 | 000,000,118 | —- | C] () – \eula.1041.txt
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:23:09 | 000,000,074 | —- | C] () – \autoexec.bat
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:08 | 000,000,010 | —- | C] () – \config.sys

========== LOP Check ==========

[2010/07/13 00:00:38 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Absolute Poker
[2009/07/20 21:13:00 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\acccore
[2010/07/23 22:47:43 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Awem
[2010/03/08 23:01:23 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\AzuazGames
[2010/01/13 23:39:21 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Big Fish Games
[2011/01/30 22:54:24 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\BitZipper
[2009/11/29 01:38:40 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\blg
[2010/07/29 00:30:07 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Boolat Games
[2010/02/15 22:31:44 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Boomzap
[2009/12/09 22:02:47 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\ChaYoWo Games
[2009/11/04 21:34:23 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Dekovir
[2010/06/22 23:56:17 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\ERS G-Studio
[2010/08/17 22:10:09 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Flipopia
[2010/07/11 01:09:53 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Floodlight Games
[2011/02/12 00:40:16 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Friday's games
[2010/11/11 17:55:30 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\FrostWire
[2010/12/21 22:40:29 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Fugazo
[2010/01/28 23:31:35 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\GameHouse
[2010/08/18 02:11:24 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\GetRightToGo
[2010/08/10 01:23:14 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Gogii
[2009/12/29 01:12:34 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\iWin
[2010/02/17 13:39:52 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Ludia
[2010/06/24 22:14:04 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Magic3
[2010/07/13 00:36:46 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Mariaglorum
[2011/02/19 00:33:02 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\mjusbsp
[2010/07/28 01:09:17 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Mutant Arcade
[2009/11/21 23:42:06 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\MysteryStudio
[2010/11/02 14:05:44 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Oberon Media
[2009/12/21 22:45:20 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\OtherSide Realm of Eons
[2009/08/31 00:01:36 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\PingTesterDataBas
[2010/04/25 21:28:49 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\PlayFirst
[2009/11/21 22:36:26 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Playrix Entertainment
[2010/10/11 21:53:46 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Pogo Games
[2009/09/30 16:14:05 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Princess Isabella
[2010/02/17 13:22:11 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SBTT
[2010/03/21 19:17:05 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Scholastic
[2009/09/20 20:24:57 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SecretIslandEng
[2010/01/02 00:26:32 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SerpentOfIsis
[2010/01/27 22:34:58 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SevenSails
[2010/05/14 22:51:17 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SE_logs
[2010/07/10 00:42:02 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Skunk Studios
[2009/06/14 01:58:40 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Snapfish
[2010/07/27 01:12:21 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SpinTop
[2011/01/30 21:04:53 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\SpinTop Games
[2009/06/15 19:20:08 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\Template
[2009/08/26 00:07:51 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\V-Games
[2009/12/27 21:58:25 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\WildTangent
[2009/06/15 07:38:33 | 000,000,000 | —D | M] – C:\Users\babbagene\AppData\Roaming\WinBatch
[2011/02/21 07:32:27 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\BearShareNAG.job
[2011/02/21 07:32:27 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\iMeshNAG.job
[2011/02/20 19:27:29 | 000,032,562 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2011/02/21 07:34:08 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{4F74C39B-E843-46E1-9C70-C9134C90FBF5}.job

========== Purity Check ==========



========== Custom Scans ==========


< SYSTEMDRIVE%\*.exe
>



< MD5 for: AGP440.SYS >
[2008/01/20 21:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\drivers\AGP440.sys
[2008/01/20 21:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/20 21:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/20 21:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/20 21:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/11 01:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\System32\drivers\atapi.sys
[2009/04/11 01:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 01:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/20 21:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/20 21:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 04:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\WINDOWS\System32\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/01/13 00:30:08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/20 21:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\System32\drivers\iaStorV.sys
[2008/01/20 21:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/20 21:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/11 01:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\WINDOWS\System32\netlogon.dll
[2009/04/11 01:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/20 21:24:05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVRD32.SYS >
[2008/01/25 14:02:04 | 000,132,128 | —- | M] (NVIDIA Corporation) MD5=0D15327134E5871C922760ACD7449E84 – C:\WINDOWS\System32\drivers\nvrd32.sys
[2008/01/25 14:02:04 | 000,132,128 | —- | M] (NVIDIA Corporation) MD5=0D15327134E5871C922760ACD7449E84 – C:\WINDOWS\System32\DriverStore\FileRepository\nvrd32.inf_e2a5b24c\nvrd32.sys

< MD5 for: NVSTOR.SYS >
[2006/11/02 04:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/20 21:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\System32\drivers\nvstor.sys
[2008/01/20 21:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/20 21:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: NVSTOR32.SYS >
[2008/01/25 14:02:04 | 000,140,832 | —- | M] (NVIDIA Corporation) MD5=7DF63192BCF9C20EC2F7492E7F7544F9 – C:\WINDOWS\System32\DriverStore\FileRepository\nvrd32.inf_e2a5b24c\nvstor32.sys
[2008/01/25 14:02:02 | 000,140,832 | —- | M] (NVIDIA Corporation) MD5=FA7B8ECA6E845B244B7E30A9DCD82C6C – C:\hp\DRIVERS\nvidia_storage\nvstor32.sys
[2008/01/25 14:02:02 | 000,140,832 | —- | M] (NVIDIA Corporation) MD5=FA7B8ECA6E845B244B7E30A9DCD82C6C – C:\WINDOWS\System32\drivers\nvstor32.sys
[2008/01/25 14:02:02 | 000,140,832 | —- | M] (NVIDIA Corporation) MD5=FA7B8ECA6E845B244B7E30A9DCD82C6C – C:\WINDOWS\System32\DriverStore\FileRepository\nvstor32.inf_b55bb8a8\nvstor32.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 21:24:50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 01:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\WINDOWS\System32\scecli.dll
[2009/04/11 01:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s

>


< %systemroot%\system32\*.dll /lockedfiles
>

[2009/04/11 01:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\rsaenh.dll
[2009/04/11 01:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\SLC.dll
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles

>


< %systemroot%\system32\drivers\*.sys /lockedfiles

>


< %systemroot%\System32\config\*.sav

>

[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /90

>

[2011/01/20 11:37:37 | 000,638,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\dxgkrnl.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:71FA8B7F
@Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:84151293
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:50DD4118
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:7B125E06
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:6F0B6A5A
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:D48500F8
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:CA0CE093
@Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:848CC150
@Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:260575F1
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:BF6C81B2
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:35FAD15D
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:588B60C7
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:2495D97A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:61B54B15
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:91FFEC32
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:B8EB1B99
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F216755A
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:96646EC1
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:C76CFF82
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:40EE25BB
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A8C08E7E
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:0FA1EAA7
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5CE91C67
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:206470A5
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D8D58038
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:89C6F032
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:19C3BC3A
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D563DFD3
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A774141A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E0AE69BE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BE40C8A2
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BDCD8531
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5AF0DC60
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:268BA8AB
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:8DED4A5E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:EB42AC3C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FC2D0F32
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:29629382
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:73AFBB96
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:02387389
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:8776F88E
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:68EF6203
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:D34167E3
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:2342AE46
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:24FECE50
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D31BE97C
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:B6FD7157
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:38F6DFA8
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C10DE48F
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:A4BF246C
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:726D640A
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:114BD271

< End of report >
OTL Extras logfile created on: 2/21/2011 8:09:42 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\babbagene\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 325.11 Gb Total Space | 236.24 Gb Free Space | 72.66% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.34 Gb Free Space | 13.12% Space Free | Partition Type: NTFS
Drive E: | 536.31 Mb Total Space | 529.75 Mb Free Space | 98.78% Space Free | Partition Type: UDF

Computer Name: SAM | User Name: babbagene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1F32B98E-BC4B-4EAD-A0C7-D0B600B1F23D}" = rport=445 | protocol=6 | dir=out | app=system |
"{24E14EF2-4592-48BE-855B-7D1F8C0DC3D4}" = lport=137 | protocol=17 | dir=in | app=system |
"{263CE8BE-A36C-4260-ADF5-1B5FB5CA2FA3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{2CE0F803-CB2F-433D-B76A-9703DBA5C266}" = lport=138 | protocol=17 | dir=in | app=system |
"{46186DB0-F687-4B06-9CE5-AC1815954F26}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{615644E1-1DF8-4C6E-92C6-587FD9CCAA9E}" = rport=138 | protocol=17 | dir=out | app=system |
"{67508F1A-B902-4030-B917-EC64433A1EBA}" = rport=139 | protocol=6 | dir=out | app=system |
"{811BEA1E-9443-4EA4-ADA7-1AD807C3B27B}" = lport=139 | protocol=6 | dir=in | app=system |
"{85F8BDF5-C7EA-45AC-9172-1B45C38EE226}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{AA0C86D5-42ED-4EAF-B38A-0AE10D72B8B3}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{AB6738F5-68BD-409B-94B0-6E092A03B8FC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BDD0994C-CDA3-4D53-A1B0-3667F8DEE2B1}" = rport=137 | protocol=17 | dir=out | app=system |
"{DECCFA03-A457-40C3-ADCC-61BFF36EE0C7}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01347E7A-FC54-431E-8F74-D6A6F305574D}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{0A7D0CDB-FD73-4D33-8D8E-79C29E63D52B}" = protocol=6 | dir=in | app=c:\program files\pplive\ppva\crashreporter.exe |
"{1CF0E905-6DE2-478A-97C2-90FEA8474691}" = protocol=17 | dir=in | app=c:\program files\pplive\pptv\pplive.exe |
"{1D838C55-9B12-42E7-ADE8-1641851B4720}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{1E99F684-3CFB-47BE-BC48-272A9002DD6B}" = protocol=6 | dir=in | app=c:\program files\pplive\ppva\flvpick.exe |
"{1FB696A9-D589-4A23-9B6C-81B6B6E33DB1}" = protocol=6 | dir=in | app=c:\program files\iwin games\webupdater.exe |
"{28FBABFA-7C6D-49A5-9B3D-D08C98D431EA}" = protocol=17 | dir=in | app=c:\program files\iwin games\iwingames.exe |
"{298C8BE5-89C0-40CA-9F64-3387C5EBD1D8}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{2FE11889-E765-4660-A111-A42B633AF201}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{32B2AF63-17F4-4623-85AD-39346375FA26}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{3725D06C-0D0B-4735-A24A-1118A1AD205D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{37FA36BF-7437-4589-9903-000341C9A153}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{396C414C-0508-4D89-AC87-ECC983F754BF}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{3E87A028-E7FC-4BF6-9FB2-1D65BFEC340F}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{4247C704-23C6-47D5-9B25-73C61F0F72F8}" = protocol=17 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe |
"{425DA650-48F7-4242-A935-8DC4098147A3}" = protocol=6 | dir=in | app=c:\program files\pplive\pptv\ppliveu.exe |
"{4406C261-E5F7-454C-9592-BCC8F2806663}" = protocol=6 | dir=in | app=c:\program files\pplive\ppva\ppvadownload.exe |
"{45867A3D-F8AC-4391-A81A-48F476CD8F5C}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{48ADFD43-02F0-4389-8D03-F672662A3990}" = protocol=17 | dir=in | app=c:\program files\pplive\ppva\ppliveva_u.exe |
"{4ABF3B2B-E7DC-4CD1-B5CF-613BC863A07C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4B50C84D-181A-4EF4-9B5A-B9B9AB68A9E4}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{5320A9A5-CF63-4472-BB86-CBD7C6F191C0}" = protocol=17 | dir=in | app=c:\program files\pplive\pptv\ppliveu.exe |
"{54A6192C-5BF3-4A19-AD48-5DA1B26AF062}" = protocol=17 | dir=in | app=c:\program files\pplive\pplive.exe |
"{56FA398B-2881-4898-95E7-F684C79CB98A}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{58879F94-0774-407F-91DA-3706516335D5}" = protocol=6 | dir=in | app=c:\users\babbagene\appdata\roaming\mjusbsp\magicjack.exe |
"{5C38FFD4-F041-47F6-A4D9-EFEA23F1693D}" = protocol=6 | dir=in | app=c:\program files\pplive\ppva\ppliveva.exe |
"{5F2A6204-76EC-4331-BDF0-D1448DB08041}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{66A0B223-20A5-491D-A50B-78E97E8451E3}" = protocol=17 | dir=in | app=c:\program files\pplive\ppva\flvpick.exe |
"{66ADEC47-3331-4F4F-AC01-99D14F9420AA}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{6AAF1521-3BB1-4FD3-B1FC-89DFBA0970CA}" = protocol=6 | dir=in | app=c:\program files\pplive\pptv\pplive.exe |
"{6EBB1B05-5F9A-4228-8C85-716D3740F7E9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{744F1C0F-3C3B-41D3-B3CC-24844054DB9B}" = protocol=17 | dir=in | app=c:\program files\pplive\ppva\downloadprogress.exe |
"{75746183-AFC4-4FF1-9221-1FD571249C9C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{757F8D87-A215-48BB-80F8-F8DF1E9C9C6B}" = protocol=17 | dir=in | app=c:\users\babbagene\appdata\roaming\mjusbsp\magicjack.exe |
"{7A28BBFA-6D30-4E65-8788-6EC0DF00506B}" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{8AB42EDB-E318-4CD0-B21F-4026401240F9}" = protocol=6 | dir=in | app=c:\program files\pplive\pplive.exe |
"{8B7F8D6D-90D4-4916-8E6C-E29FAC3AB2D4}" = protocol=17 | dir=in | app=c:\program files\pplive\ppva\crashreporter.exe |
"{944D6C8F-A8CF-41A3-B61B-413B72BFDA28}" = protocol=17 | dir=in | app=c:\program files\pplive\ppva\ppvadownload.exe |
"{95518A6B-FB2C-458D-96C9-0A65F9B7A451}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{96E42891-9729-4873-92C2-6802E08C3757}" = protocol=6 | dir=in | app=c:\program files\pplive\ppva\ppliveva_u.exe |
"{99B501BA-8BE4-40A2-94F2-620EBA53DBD8}" = protocol=17 | dir=in | app=c:\program files\pplive\ppva\ppliveva.exe |
"{9A7347C3-B98C-4774-AAFE-B5487428C515}" = protocol=17 | dir=in | app=c:\users\babbagene\appdata\roaming\mjusbsp\magicjack.exe |
"{9AA01E69-859C-40F0-BA1A-A50C137EAC60}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{A9D928FE-20C5-48A6-90C3-E8B71FE18440}" = protocol=6 | dir=in | app=c:\program files\pplive\ppva\downloadprogress.exe |
"{ACC9D24E-4357-4331-BDF6-5F8301A22EF4}" = protocol=17 | dir=in | app=c:\program files\sogouexplorer\sogouexplorer.exe |
"{B60BB5D5-6D7E-410F-866E-11D9A2109F2E}" = protocol=17 | dir=in | app=c:\program files\iwin games\webupdater.exe |
"{B9A9D54C-4AD0-407B-A494-735A1658D46A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{C748351B-6E44-4A75-9A65-B857B0F247B7}" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{D5B4FAE7-9D64-4C72-8D44-481C124CFA82}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E3AB8CC7-716B-429E-965D-053A8148E50C}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{E45BFC7D-CF26-4488-98E5-BEBFD16EFCC4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E4FC3CCB-89E8-414E-8937-8BE4DE2E5A79}" = protocol=6 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe |
"{E7EDB7A6-854E-4657-B01D-0EBDB5280C37}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{E8C86EDB-550B-4656-BB9A-EAC6C8D840D4}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{E95A2AC9-BA78-4A32-BDFD-784219D68EB4}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F1196C37-0DA2-40D3-8986-451FE318E660}" = protocol=6 | dir=in | app=c:\program files\iwin games\iwingames.exe |
"{F3002D04-6563-4226-89A9-292115CF9EFE}" = protocol=6 | dir=in | app=c:\program files\sogouexplorer\sogouexplorer.exe |
"{F7227D84-DA0B-417A-80ED-6FB77B5E9CF8}" = protocol=6 | dir=in | app=c:\users\babbagene\appdata\roaming\mjusbsp\magicjack.exe |
"{FC084A77-4265-41E0-8086-CBE0C7AA2993}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{034F8C89-C4F4-4731-A32B-F4294C04729F}" = HP Photosmart All-In-One Software 9.0
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0CA14F11-6F47-4613-8E40-6AC088E464A0}" = Cisco Network Magic
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 18
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3B1A4366-8DFA-4582-91F6-27F7A4714FCC}" = Pure Networks Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8927E07C-97F7-4A54-88FB-D976F50DD46E}" = Turbo Lister 2
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A7D48BF6-8ED8-4B91-8267-34CDE7807D05}_is1" = HP Demo
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B34E4B72-37C6-4f79-A5B3-008EEFC6EA8B}" = PS_AIO_02_Software_min
"{B7E5D642-E74E-40a4-B5C7-6AB6EE916814}" = PS_AIO_02_ProductContext
"{BAFFEF7F-08B3-45b3-B215-418175C4E9DD}" = c5200_Help
"{BC10649A-983B-494e-AD1F-DE0BF717D701}" = PS_AIO_02_Software
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C708333C-B1B9-43be-B797-49FEC7A8D15B}" = C5200
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D1E03284-66FD-4292-8239-504CEC5B0CC3}" = C5200_doccd
"{E0810CC2-4B5B-4439-B1D0-452306AF2D64}" = HP Active Support Library
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F31E534B-4199-4552-8154-5C130710D68E}" = HP Total Care Advisor
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FDDB69BB-2F9A-4830-A579-ABBB7C5AF9A8}" = muvee autoProducer 6.1
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"CBE 122239_is1" = CBE2_1
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"N360" = Norton Security Suite
"Network MagicUninstall" = Network Magic
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.88
"Savings Bond Wizard" = Savings Bond Wizard
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Veetle TV" = Veetle TV 0.9.18
"ViewpointMediaPlayer" = Viewpoint Media Player
"vShare" = vShare Plugin
"WildTangent hp Master Uninstall" = HP Games
"WT083676" = Samantha Swift 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"magicJack" = magicJack
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/19/2011 1:11:01 AM | Computer Name = Sam | Source = WinMgmt | ID = 10
Description =

Error - 2/19/2011 1:22:39 AM | Computer Name = Sam | Source = WinMgmt | ID = 10
Description =

Error - 2/19/2011 1:35:52 AM | Computer Name = Sam | Source = WinMgmt | ID = 10
Description =

Error - 2/19/2011 1:48:12 AM | Computer Name = Sam | Source = WinMgmt | ID = 10
Description =

Error - 2/19/2011 2:23:26 AM | Computer Name = Sam | Source = EventSystem | ID = 4609
Description =

Error - 2/19/2011 2:23:55 AM | Computer Name = Sam | Source = WinMgmt | ID = 10
Description =

Error - 2/19/2011 2:59:10 AM | Computer Name = Sam | Source = WinMgmt | ID = 10
Description =

Error - 2/19/2011 3:02:36 AM | Computer Name = Sam | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.19019 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1e2c Start Time: 01cbd002ca850b8f Termination Time: 32

Error - 2/19/2011 3:29:08 AM | Computer Name = Sam | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.19019 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 161c Start Time: 01cbd00426be5eaf Termination Time: 32

Error - 2/19/2011 5:06:03 AM | Computer Name = Sam | Source = VSS | ID = 8194
Description =

[ Media Center Events ]
Error - 6/21/2010 6:58:23 PM | Computer Name = Sam | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.SqmFlushSession failed; Win32 GetLastError
returned 0D Process: DefaultDomain Object Name: Media Center Guide

[ System Events ]
Error - 2/20/2011 2:55:05 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7001
Description =

Error - 2/20/2011 2:55:05 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7001
Description =

Error - 2/20/2011 2:59:24 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7000
Description =

Error - 2/20/2011 3:00:14 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7022
Description =

Error - 2/20/2011 3:32:58 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7000
Description =

Error - 2/20/2011 3:33:55 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7022
Description =

Error - 2/20/2011 3:43:58 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7000
Description =

Error - 2/20/2011 3:44:09 PM | Computer Name = Sam | Source = Service Control Manager | ID = 7022
Description =

Error - 2/21/2011 8:33:54 AM | Computer Name = Sam | Source = Service Control Manager | ID = 7000
Description =

Error - 2/21/2011 8:34:05 AM | Computer Name = Sam | Source = Service Control Manager | ID = 7022
Description =


< End of report >
Hello babbagene

Glad you managed to get OTL running :thumbup:

I was still not able to run GMER

It looks as though exeHelper has fixed your damaged file associations……could you clarify something for me please? When you say that GMER would not run, did it open and crash, or were you simply unable to open the program?

  • Please open OTL

    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
      O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
      O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
      O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
      O2 - BHO: (no name) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
      O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - No CLSID value found.
      O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
      O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
      O4 - HKCU..\RunOnce: [Shockwave Updater] File not found
      O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://www.vexcast.com/download/vexcast.cab (Reg Error: Key error.)
      O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
      O33 - MountPoints2\{95c3256d-58b0-11de-8530-002215259706}\Shell\AutoRun\command - "" = K:\autorun.exe
      O33 - MountPoints2\{95c3256d-58b0-11de-8530-002215259706}\Shell\phone\command - "" = K:\autorun.exe
      O33 - MountPoints2\{bf5b52fe-7e09-11de-b990-002215259706}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WillPolo.vbs
      O33 - MountPoints2\{d1bcce71-5a07-11de-9eae-002215259706}\Shell\AutoRun\command - "" = L:\RUNDLL32.EXE
      O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\autorun.exe
      O33 - MountPoints2\K\Shell\phone\command - "" = K:\autorun.exe
      [2011/02/17 19:14:59 | 000,000,120 | —- | M] () – C:\Users\babbagene\AppData\Local\Hxozuyoya.dat
      [2011/02/17 19:14:59 | 000,000,000 | —- | M] () – C:\Users\babbagene\AppData\Local\Llirahu.bin
      [2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:71FA8B7F
      @Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:84151293
      @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:50DD4118
      @Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:7B125E06
      @Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:FED25C29
      @Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:737160C1
      @Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:0E22C5DB
      @Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:6F0B6A5A
      @Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:D48500F8
      @Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:CA0CE093
      @Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:848CC150
      @Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:69AF9D20
      @Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:260575F1
      @Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:BF6C81B2
      @Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:35FAD15D
      @Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:588B60C7
      @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:2495D97A
      @Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:61B54B15
      @Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:91FFEC32
      @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:B8EB1B99
      @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
      @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F84B8DB5
      @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F216755A
      @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:96646EC1
      @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:C76CFF82
      @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A02025CE
      @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:40EE25BB
      @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A8C08E7E
      @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:0FA1EAA7
      @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5CE91C67
      @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:206470A5
      @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D8D58038
      @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:89C6F032
      @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:19C3BC3A
      @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D563DFD3
      @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A774141A
      @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E0AE69BE
      @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BE40C8A2
      @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BDCD8531
      @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5AF0DC60
      @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:268BA8AB
      @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:8DED4A5E
      @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:EB42AC3C
      @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FC2D0F32
      @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
      @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:29629382
      @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0AC32449
      @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:73AFBB96
      @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:02387389
      @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:8776F88E
      @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:68EF6203
      @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:D34167E3
      @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:2342AE46
      @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:24FECE50
      @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D31BE97C
      @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:B6FD7157
      @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:38F6DFA8
      @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C10DE48F
      @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:A4BF246C
      @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:726D640A
      @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:E51234A9
      @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:114BD271
      
      :Files
      C:\Program Files\vShare
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

    Lets check to see if the following program will run:

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the OTL log and the MBAM log in your next reply.

    If MBAM will not open please let me know.
Hi, as far as GMER not being able to run , i mean the program simply would not open ,i think cause it was a ZIp file or because it was an EXE file. i am now continuing with the further streps that you instructed me. Thank you Sam
hi I ran the OTL Scan and was able to get a LOG for you , however after the reboot I was still not able to run any programs. Here is the Logfile: All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ deleted successfully. C:\Program Files\vShare\vshare_toolbar.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\ deleted successfully. C:\Program Files\iWin Games\iWinGamesHookIE.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{043C5167-00BB-4324-AF7E-62013FAEDACF} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found. File C:\Program Files\vShare\vshare_toolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{9D425283-D487-4337-BAB6-AB8354A81457} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{043C5167-00BB-4324-AF7E-62013FAEDACF} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found. File C:\Program Files\vShare\vshare_toolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HP Health Check Scheduler deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater deleted successfully. Starting removal of ActiveX control {D4003189-95B1-4A2F-9A87-F2B03665960D} C:\Windows\Downloaded Program Files\vjocx.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D4003189-95B1-4A2F-9A87-F2B03665960D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4003189-95B1-4A2F-9A87-F2B03665960D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D4003189-95B1-4A2F-9A87-F2B03665960D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4003189-95B1-4A2F-9A87-F2B03665960D}\ not found. Starting removal of ActiveX control {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} C:\ProgramData\webex\ieatgpc.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. File C:\Program Files\vShare\vshare_toolbar.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\vsharechrome\ deleted successfully. File C:\Program Files\vShare\vshare_toolbar.dll not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{95c3256d-58b0-11de-8530-002215259706}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95c3256d-58b0-11de-8530-002215259706}\ not found. File K:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{95c3256d-58b0-11de-8530-002215259706}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95c3256d-58b0-11de-8530-002215259706}\ not found. File K:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf5b52fe-7e09-11de-b990-002215259706}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf5b52fe-7e09-11de-b990-002215259706}\ not found. File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WillPolo.vbs not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1bcce71-5a07-11de-9eae-002215259706}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d1bcce71-5a07-11de-9eae-002215259706}\ not found. File L:\RUNDLL32.EXE not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully. File K:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found. File K:\autorun.exe not found. C:\Users\babbagene\AppData\Local\Hxozuyoya.dat moved successfully. C:\Users\babbagene\AppData\Local\Llirahu.bin moved successfully. C:\Windows\System32\SETDB1D.tmp deleted successfully. C:\Windows\System32\SETE235.tmp deleted successfully. C:\Windows\msdownld.tmp folder deleted successfully. ADS C:\ProgramData\TEMP:71FA8B7F deleted successfully. ADS C:\ProgramData\TEMP:84151293 deleted successfully. ADS C:\ProgramData\TEMP:50DD4118 deleted successfully. ADS C:\ProgramData\TEMP:7B125E06 deleted successfully. ADS C:\ProgramData\TEMP:FED25C29 deleted successfully. ADS C:\ProgramData\TEMP:737160C1 deleted successfully. ADS C:\ProgramData\TEMP:0E22C5DB deleted successfully. ADS C:\ProgramData\TEMP:6F0B6A5A deleted successfully. ADS C:\ProgramData\TEMP:D48500F8 deleted successfully. ADS C:\ProgramData\TEMP:CA0CE093 deleted successfully. ADS C:\ProgramData\TEMP:848CC150 deleted successfully. ADS C:\ProgramData\TEMP:69AF9D20 deleted successfully. ADS C:\ProgramData\TEMP:260575F1 deleted successfully. ADS C:\ProgramData\TEMP:BF6C81B2 deleted successfully. ADS C:\ProgramData\TEMP:35FAD15D deleted successfully. ADS C:\ProgramData\TEMP:588B60C7 deleted successfully. ADS C:\ProgramData\TEMP:2495D97A deleted successfully. ADS C:\ProgramData\TEMP:61B54B15 deleted successfully. ADS C:\ProgramData\TEMP:91FFEC32 deleted successfully. ADS C:\ProgramData\TEMP:B8EB1B99 deleted successfully. ADS C:\ProgramData\TEMP:32A82570 deleted successfully. ADS C:\ProgramData\TEMP:F84B8DB5 deleted successfully. ADS C:\ProgramData\TEMP:F216755A deleted successfully. ADS C:\ProgramData\TEMP:96646EC1 deleted successfully. ADS C:\ProgramData\TEMP:C76CFF82 deleted successfully. ADS C:\ProgramData\TEMP:A02025CE deleted successfully. ADS C:\ProgramData\TEMP:40EE25BB deleted successfully. ADS C:\ProgramData\TEMP:A8C08E7E deleted successfully. ADS C:\ProgramData\TEMP:0FA1EAA7 deleted successfully. ADS C:\ProgramData\TEMP:5CE91C67 deleted successfully. ADS C:\ProgramData\TEMP:206470A5 deleted successfully. ADS C:\ProgramData\TEMP:D8D58038 deleted successfully. ADS C:\ProgramData\TEMP:89C6F032 deleted successfully. ADS C:\ProgramData\TEMP:19C3BC3A deleted successfully. ADS C:\ProgramData\TEMP:D563DFD3 deleted successfully. ADS C:\ProgramData\TEMP:A774141A deleted successfully. ADS C:\ProgramData\TEMP:E0AE69BE deleted successfully. ADS C:\ProgramData\TEMP:BE40C8A2 deleted successfully. ADS C:\ProgramData\TEMP:BDCD8531 deleted successfully. ADS C:\ProgramData\TEMP:5AF0DC60 deleted successfully. ADS C:\ProgramData\TEMP:268BA8AB deleted successfully. ADS C:\ProgramData\TEMP:8DED4A5E deleted successfully. ADS C:\ProgramData\TEMP:EB42AC3C deleted successfully. ADS C:\ProgramData\TEMP:FC2D0F32 deleted successfully. ADS C:\ProgramData\TEMP:50636E35 deleted successfully. ADS C:\ProgramData\TEMP:29629382 deleted successfully. ADS C:\ProgramData\TEMP:0AC32449 deleted successfully. ADS C:\ProgramData\TEMP:73AFBB96 deleted successfully. ADS C:\ProgramData\TEMP:02387389 deleted successfully. ADS C:\ProgramData\TEMP:8776F88E deleted successfully. ADS C:\ProgramData\TEMP:68EF6203 deleted successfully. ADS C:\ProgramData\TEMP:D34167E3 deleted successfully. ADS C:\ProgramData\TEMP:2342AE46 deleted successfully. ADS C:\ProgramData\TEMP:24FECE50 deleted successfully. ADS C:\ProgramData\TEMP:D31BE97C deleted successfully. ADS C:\ProgramData\TEMP:B6FD7157 deleted successfully. ADS C:\ProgramData\TEMP:38F6DFA8 deleted successfully. ADS C:\ProgramData\TEMP:C10DE48F deleted successfully. ADS C:\ProgramData\TEMP:A4BF246C deleted successfully. ADS C:\ProgramData\TEMP:726D640A deleted successfully. ADS C:\ProgramData\TEMP:E51234A9 deleted successfully. ADS C:\ProgramData\TEMP:114BD271 deleted successfully. ========== FILES ========== C:\Program Files\vShare\skin folder moved successfully. C:\Program Files\vShare\radio folder moved successfully. C:\Program Files\vShare folder moved successfully. File\Folder :Commands not found. File\Folder [purity] not found. File\Folder [emptytemp] not found. File\Folder [emptyflash] not found. File\Folder [start explorer] not found. File\Folder [Reboot] not found. OTL by OldTimer - Version 3.2.20.6 log created on 02212011_202009 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hello babbagene

Thank you for the log.

i think cause it was a ZIp file or because it was an EXE file

Most likely because it is an executable (.exe) file. Lets see if we can reset your file associations:


  • SREng


    • Download SREng from here.
    • Extract it to Desktop and double click SREngLdr.EXE to run it (NOTE: you may need to rename it to SREng.com)
    • Select System Repair from the left pane.
    • Click on File Association.
    • Select all entries that have an Error status click [Repair].
    • Refer to this image for an example:

      [external image: Posted Image]
    • Close SREng.

    If the associations are able to be repaired you will be able to follow with ComboFix:

  • Combofix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI