This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer running slowly am I infected?

50 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

That's a good sign

Run RogueKiller

Close all running programs and run RogueKiller once again. 1. For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
2. When prompted, type 2 and then press Enter
3. The RKreport.txt will be generated next to RogueKiller.exe (on the desktop, if that is where you saved the program
4. If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.

When you've done this, please follow the previous instructions to run Malwarebytes and post both logs in your reply

Satchfan
Hi,

Good news n bad lol!

Here's the RK report but yet again whatever it is stopped the malaware loading however it did seem to go a bit further this time before the stop message appeared.

RogueKiller V4.3.6 by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRKgmailcom
Feedback: http://www.sur-la-toile.com/discussion-193…-Remontees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Administrator [Admin rights]
Mode: Remove – Date : 04/02/2011 17:15:36

Bad processes: 2
[APPDT/TMP/DESKTOP] LGxJuggkBGegHQ.exe – c:\programdata\lgxjuggkbgeghq.exe -> KILLED
[APPDT/TMP/DESKTOP] 45473544.exe – c:\programdata\45473544.exe -> KILLED

Registry Entries: 3
[APPDT/TMP/DESKTOP] HKCU\[…]\Run : LGxJuggkBGegHQ (C:\ProgramData\LGxJuggkBGegHQ.exe) -> DELETED
[HJPOL] HKLM\[…]\System : DisableTaskMgr (1) -> DELETED
[HJ] HKCU\[…]\ActiveDesktop : NoChangingWallPaper (1) -> REPLACED (0)

HOSTS File:
127.0.0.1 localhost
::1 localhost


Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Andrew

I think we need to run something a bit stronger but before that I need to see what security is currently installed on your computer.

Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Satchfan
Hi here are the results…

Results of screen317's Security Check version 0.99.10
Windows Vista Service Pack 2 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
AVG 2011
ZoneAlarm
ZoneAlarm Toolbar
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 22
Out of date Java installed!
Adobe Flash Player 10.2.152.32
Adobe Reader 9.4.3
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.14) Firefox Out of Date!
Mozilla Thunderbird (3.1.7) Thunderbird Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
Zone Labs ZoneAlarm zlclient.exe
``````````End of Log````````````
Hi Andrew

Uninstall AVG 2011

The tool you are going to run won’t work if AVG is installed. We need to uninstall it for now so please don’t use the Internet except to download tools that I request until I give the all clear to re-install it.1. Click Start, Control Panel, Programs, and then Programs and Features.
2. Click on AVG 2011 and then Uninstall.
If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

Run AVG removal tool

There will still be some remnants of AVG on your computer even after the uninstall so please download and run AVG Removal Tool from here

===================================================

When all this is complete:

Download and run ComboFix

Download Combofix from either of the links below. You must rename it to mytool before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
  • Double click on the renamed ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt in your next reply.

Satchfan
Try this:

Assuming that you renamed it to mytool.exe - if not, replace that part with the name you gave it.

Click Start,Run - then copy/paste the following bolded text into the run box & click OK.

"%userprofile%\desktop\mytool.exe" /killall
Still no joy - followed the start run typed in and as before a very small box opens saying combo a green bar runs across it all the way then nothing happens. SO odd, sorry.
OK, let's try something else

Run TDSSKiller

Please read carefully and follow these steps.
  • download TDSSKiller and save it to your Desktop
  • extract its contents to your desktop
  • once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan

    if an infected file is detected, ensure Cure is selected,then click on Continue
    if a suspicious file is detected, the default action will be Skip, click on Continue

  • it may ask you to reboot the computer to complete the process. Click on Reboot Now
  • if no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here
  • if a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Satchfan
Hooray this one ran here's the log………. 2011/04/03 23:22:11.0366 4700 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28 2011/04/03 23:22:13.0379 4700 ================================================================================ 2011/04/03 23:22:13.0379 4700 SystemInfo: 2011/04/03 23:22:13.0379 4700 2011/04/03 23:22:13.0379 4700 OS Version: 6.0.6002 ServicePack: 2.0 2011/04/03 23:22:13.0379 4700 Product type: Workstation 2011/04/03 23:22:13.0379 4700 ComputerName: ANDREW-PC 2011/04/03 23:22:13.0379 4700 UserName: Administrator 2011/04/03 23:22:13.0379 4700 Windows directory: C:\Windows 2011/04/03 23:22:13.0379 4700 System windows directory: C:\Windows 2011/04/03 23:22:13.0379 4700 Processor architecture: Intel x86 2011/04/03 23:22:13.0379 4700 Number of processors: 4 2011/04/03 23:22:13.0379 4700 Page size: 0x1000 2011/04/03 23:22:13.0379 4700 Boot type: Normal boot 2011/04/03 23:22:13.0379 4700 ================================================================================ 2011/04/03 23:22:13.0660 4700 Initialize success 2011/04/03 23:22:22.0708 3404 ================================================================================ 2011/04/03 23:22:22.0708 3404 Scan started 2011/04/03 23:22:22.0708 3404 Mode: Manual; 2011/04/03 23:22:22.0708 3404 ================================================================================ 2011/04/03 23:22:23.0144 3404 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/04/03 23:22:23.0207 3404 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2011/04/03 23:22:23.0269 3404 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2011/04/03 23:22:23.0300 3404 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2011/04/03 23:22:23.0347 3404 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2011/04/03 23:22:23.0441 3404 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2011/04/03 23:22:23.0488 3404 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2011/04/03 23:22:23.0534 3404 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/04/03 23:22:23.0581 3404 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2011/04/03 23:22:23.0644 3404 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2011/04/03 23:22:23.0722 3404 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2011/04/03 23:22:23.0753 3404 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2011/04/03 23:22:23.0800 3404 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2011/04/03 23:22:23.0893 3404 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2011/04/03 23:22:23.0956 3404 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2011/04/03 23:22:24.0002 3404 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/04/03 23:22:24.0080 3404 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/04/03 23:22:24.0158 3404 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/04/03 23:22:24.0205 3404 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2011/04/03 23:22:24.0299 3404 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2011/04/03 23:22:24.0314 3404 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/04/03 23:22:24.0346 3404 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/04/03 23:22:24.0392 3404 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/04/03 23:22:24.0424 3404 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/04/03 23:22:24.0439 3404 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/04/03 23:22:24.0470 3404 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/04/03 23:22:24.0502 3404 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/04/03 23:22:24.0533 3404 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/04/03 23:22:24.0595 3404 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/04/03 23:22:24.0642 3404 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2011/04/03 23:22:24.0689 3404 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/04/03 23:22:24.0720 3404 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2011/04/03 23:22:24.0751 3404 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 2011/04/03 23:22:24.0767 3404 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2011/04/03 23:22:24.0829 3404 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2011/04/03 23:22:24.0876 3404 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2011/04/03 23:22:24.0938 3404 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/04/03 23:22:25.0001 3404 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/04/03 23:22:25.0063 3404 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/04/03 23:22:25.0219 3404 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/04/03 23:22:25.0282 3404 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/04/03 23:22:25.0344 3404 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2011/04/03 23:22:25.0391 3404 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2011/04/03 23:22:25.0453 3404 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/04/03 23:22:25.0500 3404 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/04/03 23:22:25.0531 3404 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2011/04/03 23:22:25.0578 3404 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/04/03 23:22:25.0625 3404 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/04/03 23:22:25.0656 3404 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/04/03 23:22:25.0672 3404 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/04/03 23:22:25.0718 3404 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys 2011/04/03 23:22:25.0750 3404 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/04/03 23:22:25.0781 3404 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2011/04/03 23:22:25.0812 3404 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/04/03 23:22:25.0906 3404 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 2011/04/03 23:22:25.0968 3404 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/04/03 23:22:25.0999 3404 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/04/03 23:22:26.0015 3404 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/04/03 23:22:26.0077 3404 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/04/03 23:22:26.0108 3404 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2011/04/03 23:22:26.0171 3404 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/04/03 23:22:26.0202 3404 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2011/04/03 23:22:26.0218 3404 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/04/03 23:22:26.0280 3404 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2011/04/03 23:22:26.0327 3404 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/04/03 23:22:26.0374 3404 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/04/03 23:22:26.0389 3404 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/04/03 23:22:26.0436 3404 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/04/03 23:22:26.0483 3404 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2011/04/03 23:22:26.0514 3404 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/04/03 23:22:26.0545 3404 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/04/03 23:22:26.0561 3404 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2011/04/03 23:22:26.0639 3404 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/04/03 23:22:26.0748 3404 ISWKL (2e41433579de4381f1b0f7b30b013ddc) C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys 2011/04/03 23:22:26.0779 3404 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/04/03 23:22:26.0826 3404 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/04/03 23:22:26.0857 3404 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/04/03 23:22:26.0935 3404 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/04/03 23:22:26.0982 3404 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/04/03 23:22:27.0091 3404 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/04/03 23:22:27.0138 3404 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2011/04/03 23:22:27.0169 3404 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2011/04/03 23:22:27.0216 3404 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2011/04/03 23:22:27.0263 3404 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/04/03 23:22:27.0294 3404 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2011/04/03 23:22:27.0372 3404 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2011/04/03 23:22:27.0403 3404 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/04/03 23:22:27.0419 3404 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/04/03 23:22:27.0434 3404 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/04/03 23:22:27.0466 3404 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/04/03 23:22:27.0481 3404 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/04/03 23:22:27.0528 3404 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2011/04/03 23:22:27.0544 3404 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/04/03 23:22:27.0575 3404 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/04/03 23:22:27.0653 3404 MRV6X32P (7e7370bf64462a09d5e82fcf4a481d78) C:\Windows\system32\DRIVERS\MRVW13B.sys 2011/04/03 23:22:27.0700 3404 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/04/03 23:22:27.0762 3404 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/04/03 23:22:27.0793 3404 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/04/03 23:22:27.0809 3404 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/04/03 23:22:27.0840 3404 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 2011/04/03 23:22:27.0871 3404 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2011/04/03 23:22:27.0918 3404 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/04/03 23:22:27.0949 3404 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/04/03 23:22:27.0980 3404 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/04/03 23:22:28.0012 3404 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/04/03 23:22:28.0027 3404 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/04/03 23:22:28.0058 3404 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/04/03 23:22:28.0074 3404 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/04/03 23:22:28.0105 3404 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/04/03 23:22:28.0121 3404 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/04/03 23:22:28.0183 3404 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/04/03 23:22:28.0230 3404 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/04/03 23:22:28.0261 3404 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/04/03 23:22:28.0277 3404 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/04/03 23:22:28.0339 3404 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/04/03 23:22:28.0402 3404 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/04/03 23:22:28.0402 3404 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/04/03 23:22:28.0448 3404 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/04/03 23:22:28.0495 3404 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/04/03 23:22:28.0558 3404 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/04/03 23:22:28.0589 3404 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/04/03 23:22:28.0760 3404 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/04/03 23:22:28.0807 3404 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/04/03 23:22:28.0823 3404 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/04/03 23:22:28.0885 3404 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys 2011/04/03 23:22:30.0679 3404 nvlddmkm (6ef47521dce982602a25afb41dd13d4f) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2011/04/03 23:22:31.0178 3404 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2011/04/03 23:22:31.0225 3404 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2011/04/03 23:22:31.0272 3404 nvstor32 (dc5f166422beebf195e3e4bb8ab4ee22) C:\Windows\system32\DRIVERS\nvstor32.sys 2011/04/03 23:22:31.0366 3404 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2011/04/03 23:22:31.0459 3404 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/04/03 23:22:31.0522 3404 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/04/03 23:22:31.0537 3404 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/04/03 23:22:31.0568 3404 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/04/03 23:22:31.0631 3404 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/04/03 23:22:31.0693 3404 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 2011/04/03 23:22:31.0724 3404 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/04/03 23:22:31.0771 3404 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/04/03 23:22:31.0849 3404 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/04/03 23:22:31.0896 3404 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2011/04/03 23:22:31.0974 3404 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/04/03 23:22:32.0036 3404 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2011/04/03 23:22:32.0083 3404 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/04/03 23:22:32.0099 3404 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/04/03 23:22:32.0146 3404 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/04/03 23:22:32.0177 3404 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/04/03 23:22:32.0208 3404 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/04/03 23:22:32.0239 3404 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/04/03 23:22:32.0286 3404 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/04/03 23:22:32.0317 3404 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/04/03 23:22:32.0395 3404 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2011/04/03 23:22:32.0426 3404 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/04/03 23:22:32.0458 3404 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/04/03 23:22:32.0504 3404 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/04/03 23:22:32.0536 3404 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/04/03 23:22:32.0582 3404 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/04/03 23:22:32.0614 3404 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys 2011/04/03 23:22:32.0660 3404 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys 2011/04/03 23:22:32.0676 3404 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/04/03 23:22:32.0723 3404 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2011/04/03 23:22:32.0738 3404 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2011/04/03 23:22:32.0770 3404 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2011/04/03 23:22:32.0785 3404 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/04/03 23:22:32.0816 3404 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2011/04/03 23:22:32.0863 3404 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2011/04/03 23:22:32.0879 3404 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2011/04/03 23:22:32.0926 3404 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/04/03 23:22:32.0957 3404 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/04/03 23:22:33.0019 3404 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys 2011/04/03 23:22:33.0035 3404 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys 2011/04/03 23:22:33.0066 3404 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys 2011/04/03 23:22:33.0097 3404 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/04/03 23:22:33.0128 3404 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/04/03 23:22:33.0160 3404 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/04/03 23:22:33.0206 3404 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/04/03 23:22:33.0284 3404 t3 (5f5d2ca8d3e15b183e6bdf59c370b39a) C:\Windows\system32\drivers\t3.sys 2011/04/03 23:22:33.0362 3404 Tcpip (6a10afce0b38371064be41c1fbfd3c6b) C:\Windows\system32\drivers\tcpip.sys 2011/04/03 23:22:33.0394 3404 Tcpip6 (6a10afce0b38371064be41c1fbfd3c6b) C:\Windows\system32\DRIVERS\tcpip.sys 2011/04/03 23:22:33.0425 3404 tcpipreg (9bf343f4c878d6ad6922b2c5a4fefe0d) C:\Windows\system32\drivers\tcpipreg.sys 2011/04/03 23:22:33.0456 3404 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/04/03 23:22:33.0472 3404 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/04/03 23:22:33.0503 3404 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/04/03 23:22:33.0550 3404 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/04/03 23:22:33.0596 3404 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/04/03 23:22:33.0612 3404 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/04/03 23:22:33.0674 3404 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/04/03 23:22:33.0706 3404 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2011/04/03 23:22:33.0752 3404 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/04/03 23:22:33.0799 3404 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2011/04/03 23:22:33.0830 3404 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2011/04/03 23:22:33.0862 3404 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/04/03 23:22:33.0893 3404 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/04/03 23:22:33.0940 3404 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/04/03 23:22:33.0986 3404 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 2011/04/03 23:22:34.0080 3404 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys 2011/04/03 23:22:34.0142 3404 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/04/03 23:22:34.0174 3404 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/04/03 23:22:34.0220 3404 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/04/03 23:22:34.0267 3404 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/04/03 23:22:34.0314 3404 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys 2011/04/03 23:22:34.0345 3404 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/04/03 23:22:34.0376 3404 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2011/04/03 23:22:34.0392 3404 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/04/03 23:22:34.0454 3404 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/04/03 23:22:34.0517 3404 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/04/03 23:22:34.0548 3404 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/04/03 23:22:34.0564 3404 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2011/04/03 23:22:34.0595 3404 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2011/04/03 23:22:34.0626 3404 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2011/04/03 23:22:34.0642 3404 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/04/03 23:22:34.0704 3404 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/04/03 23:22:34.0766 3404 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/04/03 23:22:34.0829 3404 Vsdatant (6be75cfce25e42e79c0757c60d88fecb) C:\Windows\system32\DRIVERS\vsdatant.sys 2011/04/03 23:22:34.0860 3404 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2011/04/03 23:22:34.0907 3404 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/04/03 23:22:34.0954 3404 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/04/03 23:22:34.0969 3404 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/04/03 23:22:35.0000 3404 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2011/04/03 23:22:35.0063 3404 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/04/03 23:22:35.0156 3404 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 2011/04/03 23:22:35.0203 3404 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 2011/04/03 23:22:35.0234 3404 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/04/03 23:22:35.0297 3404 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/04/03 23:22:35.0359 3404 ================================================================================ 2011/04/03 23:22:35.0359 3404 Scan finished 2011/04/03 23:22:35.0359 3404 ================================================================================
Hi Andrew

Good news that the program ran but unfortunately there was nothing “bad” showing up in it.

Let’s try another analysis tool.

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Logs to include with next post:

OTL.txt
Extras.txt


Thanks

Satchfan
hi ty here's a log……….

OTL logfile created on: 04/04/2011 10:07:43 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Administrator
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 57.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 230.46 Gb Free Space | 49.48% Space Free | Partition Type: NTFS
Drive E: | 581.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ANDREW-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Administrator\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Administrator\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcp80.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (vsmon) – C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Media Toolbox 6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (t3) – C:\Windows\System32\drivers\t3.sys (Creative Technology Ltd.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (MRV6X32P) – C:\Windows\System32\drivers\MRVW13B.sys (Marvell Semiconductor, Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKLM\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo!"
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/07 14:47:43 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/02 23:00:33 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/22 09:41:15 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/01/31 23:20:12 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions
[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/27 13:53:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions
[2011/02/06 09:59:22 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/31 23:08:32 | 000,000,000 | -H-D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2011/02/07 14:47:43 | 000,000,000 | -H-D | M] (ZoneAlarm Security Engine) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2010/12/03 18:47:02 | 000,001,538 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 18:47:02 | 000,000,947 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 18:47:02 | 000,000,769 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/04/07 14:59:38 | 000,000,872 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.gif
[2011/02/16 19:31:31 | 000,000,199 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.src

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | -H– | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [SPIRunE] C:\Windows\System32\SpiRunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | -H– | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/14 11:44:42 | 000,000,085 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MATHSWATCH_Foundation_GCSE.exe – [2009/06/14 11:44:42 | 000,411,232 | R— | M] (TechSmith Corporation)
O33 - MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\Shell - "" = AutoRun
O33 - MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.IV41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/04 10:05:23 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/04 10:03:10 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{A34D152F-16D7-436E-B4E7-0CE11E0F1EBF}
[2011/04/04 10:02:52 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2011/04/03 23:21:57 | 000,000,000 | —D | C] – C:\Users\Administrator\tdsskiller
[2011/04/03 18:31:13 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2011/04/03 15:35:56 | 001,090,912 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:41:06 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{78EB8057-2B37-4E81-A487-74F19944D270}
[2011/04/02 09:39:20 | 000,000,000 | -H-D | C] – C:\Users\Administrator\RK_Quarantine
[2011/04/02 09:29:26 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{805C14E6-AA7B-4D3C-BE40-6F40DCA36B11}
[2011/04/01 11:06:06 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{7A0F5FB6-8BEC-4F9F-944D-DEB0FD832895}
[2011/04/01 10:57:39 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{73813386-9006-4EB5-BD8C-A921C07E10B6}
[2011/03/31 22:23:19 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/03/31 22:15:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{9A1CCCB4-25D3-4CAF-8C6F-30CAB69455C7}
[2011/03/31 00:41:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
[2011/03/31 00:31:48 | 000,546,304 | -H– | C] (TFTC) – C:\ProgramData\LGxJuggkBGegHQ.exe
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Program Files\Trend Micro
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/03/23 14:51:05 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/23 14:51:05 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/09 10:03:35 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 10:03:35 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 10:03:35 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/09 10:03:35 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/04 10:05:25 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/04 10:02:54 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.001
[2011/04/04 10:02:36 | 000,000,896 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/04 10:02:32 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/04 10:02:32 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/04 10:02:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/04 10:02:27 | 3218,493,440 | -HS- | M] () – C:\hiberfil.sys
[2011/04/03 23:49:00 | 000,000,900 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/03 23:20:11 | 001,263,721 | —- | M] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 23:19:00 | 000,000,938 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500UA.job
[2011/04/03 16:03:40 | 004,310,402 | —- | M] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:51:19 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:35:57 | 001,090,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:48:57 | 000,879,081 | —- | M] () – C:\Users\Administrator\SecurityCheck.exe
[2011/04/02 17:19:33 | 000,000,886 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500Core.job
[2011/04/02 17:15:12 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/04/02 17:14:02 | 001,058,816 | —- | M] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 18:26:55 | 341,400,810 | -H– | M] () – C:\Windows\MEMORY.DMP
[2011/03/31 22:21:55 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:20:16 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.exe
[2011/03/31 13:05:54 | 000,000,579 | -H– | M] () – C:\Users\Administrator\Desktop\Windows Repair.lnk
[2011/03/31 13:05:50 | 000,000,328 | -H– | M] () – C:\ProgramData\45473544
[2011/03/31 13:05:47 | 000,467,968 | -H– | M] () – C:\ProgramData\45473544.exe
[2011/03/31 12:41:54 | 000,000,328 | -H– | M] () – C:\ProgramData\46522120
[2011/03/31 12:13:06 | 000,000,344 | -H– | M] () – C:\ProgramData\45670152
[2011/03/31 08:36:25 | 000,000,336 | -H– | M] () – C:\ProgramData\43835144
[2011/03/31 07:00:17 | 000,070,656 | -H– | M] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/31 06:59:55 | 000,611,664 | -H– | M] () – C:\Windows\System32\perfh009.dat
[2011/03/31 06:59:55 | 000,109,112 | -H– | M] () – C:\Windows\System32\perfc009.dat
[2011/03/31 00:40:58 | 000,000,336 | -H– | M] () – C:\ProgramData\48619272
[2011/03/31 00:31:46 | 000,546,304 | -H– | M] (TFTC) – C:\ProgramData\LGxJuggkBGegHQ.exe
[2011/03/30 21:22:05 | 000,002,539 | -H– | M] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2011/03/29 07:04:24 | 000,002,281 | -H– | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/03/28 16:55:39 | 000,002,231 | -H– | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/03/26 01:20:13 | 000,002,082 | -H– | M] () – C:\Users\Administrator\Desktop\Google Chrome.lnk
[2011/03/26 01:20:13 | 000,002,044 | -H– | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/03/22 09:41:17 | 000,001,887 | -H– | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/03 23:20:09 | 001,263,721 | —- | C] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 15:58:43 | 004,310,402 | —- | C] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.001
[2011/04/02 09:38:31 | 001,058,816 | —- | C] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 21:21:15 | 3218,493,440 | -HS- | C] () – C:\hiberfil.sys
[2011/03/31 22:21:53 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:17:18 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.exe
[2011/03/31 13:05:54 | 000,000,579 | -H– | C] () – C:\Users\Administrator\Desktop\Windows Repair.lnk
[2011/03/31 13:05:50 | 000,000,328 | -H– | C] () – C:\ProgramData\45473544
[2011/03/31 13:05:47 | 000,467,968 | -H– | C] () – C:\ProgramData\45473544.exe
[2011/03/31 12:41:54 | 000,000,328 | -H– | C] () – C:\ProgramData\46522120
[2011/03/31 12:26:10 | 000,879,081 | —- | C] () – C:\Users\Administrator\SecurityCheck.exe
[2011/03/31 12:13:06 | 000,000,344 | -H– | C] () – C:\ProgramData\45670152
[2011/03/31 08:36:25 | 000,000,336 | -H– | C] () – C:\ProgramData\43835144
[2011/03/31 07:00:47 | 000,070,656 | -H– | C] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/31 00:40:58 | 000,000,336 | -H– | C] () – C:\ProgramData\48619272
[2011/03/30 21:21:03 | 000,002,539 | -H– | C] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2011/01/31 23:08:54 | 000,000,000 | -H– | C] () – C:\Windows\nsreg.dat
[2010/12/21 13:40:50 | 000,000,527 | -H– | C] () – C:\Windows\eReg.dat
[2010/07/25 18:40:19 | 000,003,584 | -H– | C] () – C:\Users\Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/14 10:48:32 | 000,000,210 | -H– | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/07/10 11:46:25 | 000,134,044 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/04 16:00:13 | 000,004,626 | -H– | C] () – C:\Windows\System32\AudioDrv.ini
[2010/05/04 16:00:01 | 000,000,049 | RH– | C] () – C:\Windows\System32\ctzapxx.ini
[2010/05/03 17:01:54 | 000,073,728 | -H– | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/05/03 17:01:53 | 000,148,480 | -H– | C] () – C:\Windows\System32\APOMngr.DLL
[2010/05/03 17:00:04 | 000,004,984 | -H– | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/04/26 11:49:48 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/04/26 11:49:47 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/04/24 16:49:11 | 000,000,376 | -H– | C] () – C:\Windows\ODBC.INI
[2010/04/24 08:38:08 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/04/22 17:23:00 | 000,000,680 | -H– | C] () – C:\Users\Administrator\AppData\Local\d3d9caps.dat
[2009/08/26 05:29:28 | 000,150,016 | -H– | C] () – C:\Windows\System32\OemSpiE.dll
[2009/08/03 15:07:42 | 000,403,816 | -H– | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H– | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/15 08:22:48 | 000,032,914 | -H– | C] () – C:\Windows\System32\t3.ini
[2009/01/14 02:47:24 | 000,001,436 | -H– | C] () – C:\Windows\CfgHPSp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg05Sp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg04Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg03Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg02Sp.ini
[2009/01/14 02:47:24 | 000,001,000 | -H– | C] () – C:\Windows\Cfg01Sp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPHp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPDO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg05DO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg04DO.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg05Hp.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg04Hp.ini
[2009/01/14 02:47:24 | 000,000,818 | -H– | C] () – C:\Windows\Cfg01APR.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01DO.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01Mic.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01LI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPFMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPDI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04DI.ini
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,305,584 | -H– | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,611,664 | -H– | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | -H– | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,109,112 | -H– | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | -H– | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | -H– | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | -H– | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | -H– | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | -H– | C] () – C:\Windows\System32\mlang.dat
[2003/01/07 15:05:08 | 000,002,695 | -H– | C] () – C:\Windows\System32\OUTLPERF.INI
[1997/06/14 01:56:08 | 000,056,832 | -H– | C] () – C:\Windows\System32\iyvu9_32.dll

========== LOP Check ==========

[2011/02/16 19:31:51 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Artifex Mundi
[2010/10/15 10:34:33 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\AVG10
[2010/04/22 17:39:24 | 000,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\CheckPoint
[2011/02/15 00:15:43 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Flood Light Games
[2010/12/22 00:44:50 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\GetRightToGo
[2010/08/01 22:12:38 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\iCopyExpert
[2011/01/10 22:55:33 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Oberonv1000
[2010/11/17 21:43:10 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\ShinyTales
[2011/01/31 23:20:12 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Thunderbird
[2011/01/27 11:27:41 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Windows Live Writer
[2011/04/03 23:57:24 | 000,032,648 | -H– | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/30 17:53:25 | 000,124,093 | -H– | M] () – C:\aaw7boot.log
[2006/09/18 22:43:36 | 000,000,024 | -H– | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/04/23 02:13:50 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | -H– | M] () – C:\config.sys
[2010/05/04 16:21:15 | 000,007,236 | -H– | M] () – C:\CTSUFile.txt
[2011/04/04 10:02:27 | 3218,493,440 | -HS- | M] () – C:\hiberfil.sys
[2010/08/13 16:55:16 | 000,000,258 | -H– | M] () – C:\INSTALL.LOG
[2010/05/22 17:23:54 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/22 17:23:54 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/04/04 10:02:26 | 3534,176,256 | -HS- | M] () – C:\pagefile.sys
[2011/04/01 21:19:33 | 000,011,855 | -H– | M] () – C:\rkill.log
[2011/04/03 23:25:04 | 000,057,446 | —- | M] () – C:\TDSSKiller.2.4.21.0_03.04.2011_23.22.11_log.txt
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | -H– | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | -H– | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | -H– | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/06/06 07:33:36 | 000,037,665 | -H– | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/09/02 16:17:50 | 000,196,608 | -H– | M] (Eastman Kodak Company) – C:\Windows\System32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2007/04/09 13:23:54 | 000,028,552 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | -H– | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 04:14:18 | 016,846,848 | -H– | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:14:08 | 000,106,496 | -H– | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:14:18 | 000,020,480 | -H– | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | -H– | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | -H– | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/03 11:51:07 | 000,000,286 | -HS- | M] () – C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-04 09:06:53

========== Alternate Data Streams ==========

@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:97F0A1F8
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:77271429
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8C885EDD
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:DD3F5AF4
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A2947BEA

< End of report >


EXTRAS REPORT


OTL Extras logfile created on: 21/12/2010 20:58:06 - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Administrator\Pictures
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 244.22 Gb Free Space | 52.43% Space Free | Partition Type: NTFS
Drive D: | 574.44 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 464.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ANDREW-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3955E427-117A-4BE6-AB63-8E4D06F6BFBF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{45E4AA99-64CD-404B-9BE6-8CA3A0D1821D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{810817B0-8C1C-4CE9-845C-A119B17B1F30}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{D0C76E71-DF0B-4FA4-B5EE-52B79F5E9ED0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{101E6024-0C73-41BD-B1ED-8F861C864BCB}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{11932108-C0A2-4AA3-9AA0-6D4DCBA6C63F}" = protocol=6 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe |
"{1237E594-8406-4C0C-A795-1AC2398AFB5F}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{2EEFD7D6-4A2E-4284-A8C4-F9321D6352DC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{54D2EC83-993C-472D-9F78-29C967AF62CC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{55F71A2C-E322-45A0-8033-889230AC6203}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{5B04AF36-920A-4FCA-9282-B20D45A5C92B}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{65EEDF06-A856-4C09-B195-9F9BA413991A}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{6DBDD273-1135-4397-9472-75084E1BEF72}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{705B05E4-2F0A-450F-8517-DD1ACCD61472}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{78C60F0C-556D-4CFE-A35F-F004D3AA6391}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{83C9E410-81B6-481A-8687-01104ABC698B}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{92CD49EB-3602-441C-8483-94532E3B5208}" = protocol=17 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe |
"{9AFFEDD3-7D93-4790-A447-61FAA9AFBBD6}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{BF262C90-DBE3-421B-8840-89F6B4907CF5}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{C0C87586-D34E-4330-8B48-714BC3E0F72A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F0B5F759-9B25-4CE5-9FF0-6C310403AAC7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FD567F4C-4AE5-4217-900C-C8FE55AF07A7}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0323CB96-221A-4042-84A3-93EDE47099FC}" = AVG 2011
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C9D0200-FA32-44B7-BBB3-7C03F700C4A0}" = Sound Blaster X-Fi
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F50AF3B-8997-4916-0095-99D63DDB785A}" = Harry Potter TM
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4EB34322-B940-46EB-810E-68E71A819269}" = AVG 2011
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{704BA20C-E4D5-4265-92B4-9768345AB76B}" = AVG 2011
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119438363}" = Downtown Secrets
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5770FD5-7345-47E0-BEB8-54522270D58F}" = AVG 2011
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F1A14CB2-A048-45A6-AFDA-3571296E1D76}" = Creative Media Toolbox 6
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Activision_StarTrekArmadaUninstallKey" = Star Trek: Armada
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adware Professional 5.0_is1" = Adware Professional v5.0
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"ALchemy" = Creative ALchemy
"AudioCS" = Creative Audio Control Panel
"AVG" = AVG 2011
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"Diagnostics 4_5" = Creative Diagnostics
"Edraw Mind Map_is1" = Edraw Mind Map V4
"Host OpenAL" = Host OpenAL
"iCopyExpert_is1" = iCopyExpert 3.1.2
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSPUB5" = Microsoft Publisher 98
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Uninstaller_B4736000_Creative Media Toolbox 6" = Creative Media Toolbox 6 (Shared Components)
"WinLiveSuite" = Windows Live Essentials
"ZoneAlarm" = ZoneAlarm
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21/11/2010 15:06:58 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 21/11/2010 15:45:25 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/11/2010 04:41:34 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/11/2010 12:38:16 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/11/2010 13:49:13 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/11/2010 15:14:49 | Computer Name = Andrew-PC | Source = EventSystem | ID = 4622
Description =

Error - 22/11/2010 15:14:49 | Computer Name = Andrew-PC | Source = EventSystem | ID = 4622
Description =

Error - 23/11/2010 05:08:12 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 23/11/2010 10:17:26 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =

Error - 23/11/2010 11:04:56 | Computer Name = Andrew-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18975 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14e8 Start Time: 01cb8b1952997896 Termination Time: 16

[ System Events ]
Error - 19/12/2010 04:22:47 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 19/12/2010 08:15:27 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 19/12/2010 08:29:27 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 19/12/2010 08:29:54 | Computer Name = Andrew-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:28:36 on 19/12/2010 was unexpected.

Error - 20/12/2010 05:28:08 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 20/12/2010 11:38:34 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 21/12/2010 03:57:14 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 21/12/2010 03:59:06 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 21/12/2010 06:56:28 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 21/12/2010 08:31:02 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =


< End of report >
Andrew

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    [2011/01/31 23:08:32 | 000,000,000 | -H-D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
    File not found (No name found) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
    O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found
    O33 - MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MATHSWATCH_Foundation_GCSE.exe – [2009/06/14 11:44:42 | 000,411,232 | R— | M] (TechSmith Corporation)
    O33 - MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\Shell - "" = AutoRun
    O33 - MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
    O33 - MountPoints2\K\Shell - "" = AutoRun
    O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
    [2011/03/31 00:41:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
    [2011/03/31 00:31:48 | 000,546,304 | -H– | C] (TFTC) – C:\ProgramData\LGxJuggkBGegHQ.exe
    [2011/03/31 13:05:54 | 000,000,579 | -H– | M] () – C:\Users\Administrator\Desktop\Windows Repair.lnk
    [2011/03/31 13:05:50 | 000,000,328 | -H– | M] () – C:\ProgramData\45473544
    [2011/03/31 13:05:47 | 000,467,968 | -H– | M] () – C:\ProgramData\45473544.exe
    [2011/03/31 12:41:54 | 000,000,328 | -H– | M] () – C:\ProgramData\46522120
    [2011/03/31 12:13:06 | 000,000,344 | -H– | M] () – C:\ProgramData\45670152
    [2011/03/31 08:36:25 | 000,000,336 | -H– | M] () – C:\ProgramData\43835144
    [2011/03/31 00:40:58 | 000,000,336 | -H– | M] () – C:\ProgramData\48619272
    [2011/03/31 00:31:46 | 000,546,304 | -H– | M] (TFTC) – C:\ProgramData\LGxJuggkBGegHQ.exe
    [2011/01/31 23:08:54 | 000,000,000 | -H– | C] () – C:\Windows\nsreg.dat
    [2010/10/15 10:34:33 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\AVG10
    @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:97F0A1F8
    @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:77271429
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:868A72DA
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8C885EDD
    @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:DD3F5AF4
    @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A2947BEA
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

===================================================

"Adware Professional 5.0_is1" = Adware Professional v5.0

This is the Rogue program that has caused most, if not all of the problems.

Please do as I asked previously and remove it by uninstalling it.

Let me know if you have a problem

Satchfan
Hi here's the new log……………but I did do as you asked, first time, regarding the uninstall of Adware now when I go to the Control Panel and Programmes it is not there, it does not appear, so I don't know how to delete it again? All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully. C:\Program Files\Mozilla Firefox\extensions folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\avgsecuritytoolbar\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2DDE6B2-9684-4A55-86D4-E255E237B77C}\ deleted successfully. File {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\ not found. File move failed. E:\MATHSWATCH_Foundation_GCSE.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\ not found. File J:\LaunchU3.exe -a not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found. File K:\LaunchU3.exe -a not found. C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair folder moved successfully. C:\ProgramData\LGxJuggkBGegHQ.exe moved successfully. C:\Users\Administrator\Desktop\Windows Repair.lnk moved successfully. C:\ProgramData\45473544 moved successfully. C:\ProgramData\45473544.exe moved successfully. C:\ProgramData\46522120 moved successfully. C:\ProgramData\45670152 moved successfully. C:\ProgramData\43835144 moved successfully. C:\ProgramData\48619272 moved successfully. File C:\ProgramData\LGxJuggkBGegHQ.exe not found. C:\Windows\nsreg.dat moved successfully. C:\Users\Administrator\AppData\Roaming\AVG10\cfgall folder moved successfully. C:\Users\Administrator\AppData\Roaming\AVG10 folder moved successfully. ADS C:\ProgramData\TEMP:97F0A1F8 deleted successfully. ADS C:\ProgramData\TEMP:77271429 deleted successfully. ADS C:\ProgramData\TEMP:868A72DA deleted successfully. ADS C:\ProgramData\TEMP:8C885EDD deleted successfully. ADS C:\ProgramData\TEMP:DD3F5AF4 deleted successfully. ADS C:\ProgramData\TEMP:A2947BEA deleted successfully. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 2046479243 bytes ->Temporary Internet Files folder emptied: 387047454 bytes ->Java cache emptied: 12111346 bytes ->FireFox cache emptied: 62185311 bytes ->Google Chrome cache emptied: 90108053 bytes ->Apple Safari cache emptied: 150729728 bytes ->Flash cache emptied: 266226 bytes User: All Users User: Andrew ->Temp folder emptied: 1989462 bytes ->Temporary Internet Files folder emptied: 54776547 bytes ->Java cache emptied: 12119679 bytes ->Flash cache emptied: 3358 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Rebecca ->Temp folder emptied: 165958554 bytes ->Temporary Internet Files folder emptied: 1442611424 bytes ->Java cache emptied: 12165915 bytes ->FireFox cache emptied: 46517201 bytes ->Apple Safari cache emptied: 11865088 bytes ->Flash cache emptied: 151635 bytes User: Ruth ->Temp folder emptied: 411982704 bytes ->Temporary Internet Files folder emptied: 233696205 bytes ->Java cache emptied: 13931247 bytes ->FireFox cache emptied: 15512236 bytes ->Apple Safari cache emptied: 32615424 bytes ->Flash cache emptied: 82493 bytes %systemdrive% .tmp files removed: 16384 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 154084628 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 5,111.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04042011_153416 Files\Folders moved on Reboot… File move failed. E:\MATHSWATCH_Foundation_GCSE.exe scheduled to be moved on reboot. C:\Users\Administrator\AppData\Local\Temp\~DFE5F4.tmp moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VIOFREPI\index[9].htm moved successfully. File\Folder C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VIOFREPI\like[6].htm not found! C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6IDFTLTZ\iframe[2].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. File\Folder C:\Windows\temp\ZLT0752f.TMP not found! Registry entries deleted on Reboot…
Hi Andrew

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adware Professional 5.0_is1]
    [-HKEY_CURRENT_USER\Software\Adware Professional]
    
    :Files
    C:\ProgramData\Adware Professional
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • run OTL again, click on Extra Registry -> Use Safelist then click Run Scan
    Don't check the boxes beside LOP Check or Purity this time)
Post back with the OTL fix log and the 2 logfiles

===================================================

Try updating and running Malwarebytes again.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI