This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Slowing Down (Byte by Byte)

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello!

Hows it going guys. Thank you for taking time to help me out with my computer here.

During the past couple of days my computer seems to have been slowing down and using a lot of memory even when I'm not running any programs. I'm assuming that it caught some sort of bug from a third party site. I've also got a couple of blue screens and crashes for no apparent reason other than me starting up my computer and running 2 version of Google Chrome. If you could help me get my baby back to order, it would really save me a bundle.

Thanks again :)

HI JACK LOG:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:03:34 AM, on 3/31/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\AVG\AVG10\avgwdsvc.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Microsoft LifeCam\MSCamS32.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
D:\Program Files\QuickTime\QTTask.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
D:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
D:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
D:\Program Files\HBLite\bin\11.0.264.0\HBLiteSA.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Microsoft IntelliType Pro\itype.exe
D:\Program Files\AVG\AVG10\avgnsx.exe
D:\Program Files\Zune\ZuneBusEnum.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\AVG\AVG10\avgemcx.exe
D:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
D:\Program Files\AVG\AVG10\avgchsvx.exe
D:\Program Files\AVG\AVG10\avgtray.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
D:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
D:\Program Files\ooVoo\oovoo.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\NETGEAR GA311 Adapter\GA311.exe
D:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
D:\WINDOWS\ALCFDRTM.EXE
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe
D:\Documents and Settings\Aleksandr\Local Settings\Apps\2.0\X66DWTDW.1RE\3CN3NG33.19T\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe
D:\Program Files\OpenOffice.org 3\program\soffice.exe
D:\Program Files\OpenOffice.org 3\program\soffice.bin
D:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\903CB56BA52F42478957BE8314837A86\PamelaPCR.exe
D:\Program Files\Common Files\Java\Java Update\jucheck.exe
D:\Program Files\Microsoft LifeCam\LifeTray.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\taskmgr.exe
D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Aleksandr\My Documents\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.100:2
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - D:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
R3 - URLSearchHook: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: XfireXO - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - D:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - D:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [PinnacleDriverCheck] D:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "D:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "D:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "D:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HBLiteSA] "D:\Program Files\HBLite\bin\11.0.264.0\HBLiteSA.exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [itype] "D:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [LifeCam] "D:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [IWHE Agent] D:\WINDOWS\system32\28463\IWHE.exe
O4 - HKLM\..\Run: [Zune Launcher] "D:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [AVG_TRAY] D:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ooVoo.exe] D:\Program Files\ooVoo\oovoo.exe /minimized
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: Dropbox.lnk = D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe
O4 - Startup: OpenOffice.org 3.2.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: GA311 Smart Wizard Utility.lnk = D:\Program Files\NETGEAR GA311 Adapter\GA311.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - D:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - D:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - D:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - D:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - D:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe

–
End of file - 11653 bytes
Hello Aleks and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please do not install/uninstall any programs unless asked to.
Please do not run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again Aleks

Uninstall the following programs, if present:

HBLite

and

EITHER Avast
OR AVG 10


You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them all ineffective. Please remove one. What you choose to do after your computer problem is resolved is up to you but please follow these instructions until that time.

To remove them:• Click on Start, Settings, Control Panel
• Double-click Add or Remove Programs (it may take time for the list to appear, so be patient)
• Scroll down the list and look for any of the above entries:
• If they are present, click on the program name and then on Remove.

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

O4 - HKLM\..\Run: [HBLiteSA] "D:\Program Files\HBLite\bin\11.0.264.0\HBLiteSA.exe"

Close all windows except for HijackThis and click Fix checked.


Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Hello again,

I ran Hi Jack and OLT as asked for in the previous post. However when I tried to run GMer (the first time, my computer froze and the second time I got a blue screen). If you would like me to keep trying please let me know :)

Other wise I will break the OLT logs into 2 different posts. Thanks again

OLT LOG


OTL logfile created on: 3/31/2011 5:31:29 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\Aleksandr\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 189.91 Gb Total Space | 181.95 Gb Free Space | 95.81% Space Free | Partition Type: NTFS
Drive D: | 298.08 Gb Total Space | 7.78 Gb Free Space | 2.61% Space Free | Partition Type: NTFS

Computer Name: SASHA | User Name: Aleksandr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\Aleksandr\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
PRC - D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - D:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - D:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - D:\Documents and Settings\Aleksandr\Local Settings\Apps\2.0\X66DWTDW.1RE\3CN3NG33.19T\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe (Curse)
PRC - D:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
PRC - D:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - D:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - D:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\903CB56BA52F42478957BE8314837A86\PamelaPCR.exe (Scendix Software GmbH)
PRC - D:\WINDOWS\ALCFDRTM.EXE (Realtek Semiconductor Corp.)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - D:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe ()
PRC - D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - D:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - D:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - D:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - D:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Co.)
PRC - D:\Program Files\NETGEAR GA311 Adapter\GA311.exe ()


========== Modules (SafeList) ==========

MOD - D:\Documents and Settings\Aleksandr\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
MOD - D:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – D:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (WMZuneComm) – D:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – D:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – D:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – D:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (MSCamSvc) – D:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (McComponentHostService) – D:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (LVPrcSrv) – D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (Pml Driver HPZ12) – D:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (nSvcIp) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (ForcewareWebInterface) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – D:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – D:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – D:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – D:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – D:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – D:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – D:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (MSHUSBVideo) – D:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – D:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – D:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – D:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (LVPr2Mon) – D:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – D:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (nm) – D:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (WinUSB) – D:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (emAudio) – D:\WINDOWS\system32\drivers\emAudio.sys (Pinnacle Systems, Inc.)
DRV - (DCamUSBEMPIA) – D:\WINDOWS\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – D:\WINDOWS\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – D:\WINDOWS\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (nvata) – D:\WINDOWS\System32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) – D:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – D:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCLEPCI) – D:\WINDOWS\system32\drivers\Pclepci.sys (Pinnacle Systems GmbH)
DRV - (ASAPIW2K) – D:\WINDOWS\system32\drivers\asapiW2k.sys (VOB Computersysteme GmbH)
DRV - (Diag69xp) – D:\WINDOWS\system32\drivers\diag69xp.sys (Realtek Semiconductor Corporation)
DRV - (LANPkt) – D:\WINDOWS\system32\drivers\LANPkt.sys (Windows ® 2000 DDK provider)
DRV - (ADM8511) – D:\WINDOWS\system32\drivers\ADM8511.SYS (ADMtek Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.100:2

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "XfireXO Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledItems: [removed]:11.0.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001
FF - prefs.js..extensions.enabledItems: [removed]:20110101
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4d93b88c&v;=6.103.018.001&i;=26&tp;=ab&iy;=&ychte;=us&lng;=en-US&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions [2010/08/27 17:01:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/30 19:54:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/20 17:03:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 16:43:48 | 000,000,000 | —D | M]

[2010/08/27 17:03:15 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Extensions
[2010/08/27 17:03:15 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Extensions\[removed]
[2011/03/30 23:44:44 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\extensions
[2010/09/09 19:10:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/31 19:59:31 | 000,000,000 | —D | M] (XfireXO Toolbar) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2010/06/11 02:08:24 | 000,000,917 | —- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\searchplugins\conduit.xml
[2010/10/06 23:26:31 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/03/30 19:54:22 | 000,000,000 | —D | M] (avast! WebRep) – D:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) – D:\PROGRAM FILES\AVG\AVG10\FIREFOX4
File not found (No name found) – D:\PROGRAM FILES\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED
[2010/08/27 17:01:19 | 000,000,000 | —D | M] (Hotbar Component) – D:\PROGRAM FILES\HBLITE\BIN\11.0.264.0\FIREFOX\EXTENSIONS

O1 HOSTS File: ([2003/03/31 08:00:00 | 000,000,734 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] D:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IWHE Agent] File not found
O4 - HKLM..\Run: [LifeCam] D:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] D:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PinnacleDriverCheck] D:\WINDOWS\System32\\PSDrvCheck.exe ()
O4 - HKLM..\Run: [USB2Check] D:\WINDOWS\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [USBToolTip] D:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
O4 - HKLM..\Run: [Zune Launcher] D:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ooVoo.exe] D:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - Startup: D:\Documents and Settings\Aleksandr\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: D:\Documents and Settings\Aleksandr\Start Menu\Programs\Startup\Dropbox.lnk = D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe ()
O4 - Startup: D:\Documents and Settings\Aleksandr\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\GA311 Smart Wizard Utility.lnk = D:\Program Files\NETGEAR GA311 Adapter\GA311.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/31 19:52:50 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - D:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - D:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - D:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.FPS1 - D:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.MJPG - D:\WINDOWS\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.PIM1 - pclepim1.dll File not found
Drivers32: vidc.tscc - D:\WINDOWS\system32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.XFR1 - D:\WINDOWS\System32\xfcodec.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/30 23:49:20 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\TEMP
[2011/03/30 23:49:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Stellar Phoenix Photo Recovery
[2011/03/30 23:49:10 | 000,000,000 | —D | C] – D:\Program Files\Stellar Phoenix Photo Recovery
[2011/03/30 23:44:25 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\AVG Security Toolbar
[2011/03/30 19:54:50 | 000,301,528 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswSP.sys
[2011/03/30 19:54:50 | 000,019,544 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/03/30 19:54:50 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/03/30 19:54:49 | 000,371,544 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswSnx.sys
[2011/03/30 19:54:49 | 000,102,232 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswmon2.sys
[2011/03/30 19:54:49 | 000,096,344 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswmon.sys
[2011/03/30 19:54:49 | 000,049,240 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswTdi.sys
[2011/03/30 19:54:49 | 000,030,680 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aavmker4.sys
[2011/03/30 19:54:49 | 000,025,432 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswRdr.sys
[2011/03/30 19:54:21 | 000,190,016 | —- | C] (AVAST Software) – D:\WINDOWS\System32\aswBoot.exe
[2011/03/30 19:54:21 | 000,040,648 | —- | C] (AVAST Software) – D:\WINDOWS\avastSS.scr
[2011/03/30 19:54:13 | 000,000,000 | —D | C] – D:\Program Files\AVAST Software
[2011/03/30 19:54:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/29 21:06:16 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Desktop\4chan
[2011/03/29 20:41:14 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Application Data\AVG10
[2011/03/29 20:33:43 | 000,000,000 | -H-D | C] – D:\Documents and Settings\All Users\Application Data\Common Files
[2011/03/29 20:31:59 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/29 20:27:34 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/25 19:58:02 | 000,000,000 | —D | C] – D:\Documents and Settings\NetworkService\Application Data\Xfire
[2011/03/23 19:35:34 | 000,000,000 | -HSD | C] – D:\found.000
[2011/03/08 22:07:48 | 000,000,000 | —D | C] – D:\WINDOWS\XSxS
[2011/03/08 22:07:48 | 000,000,000 | —D | C] – D:\Program Files\Xenocode
[2011/03/07 00:36:31 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Skype
[2011/03/03 22:21:23 | 000,000,000 | —D | C] – D:\WINDOWS\System32\QuickTime
[2011/03/03 22:21:23 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Camtasia Studio 7
[2011/03/03 22:21:16 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\TechSmith
[2011/03/03 22:21:03 | 000,000,000 | —D | C] – D:\Program Files\Common Files\TechSmith Shared
[2011/03/03 22:20:58 | 000,000,000 | —D | C] – D:\Program Files\TechSmith
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[12 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/31 17:26:29 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2011/03/31 17:26:26 | 2683,883,520 | -HS- | M] () – D:\hiberfil.sys
[2011/03/31 00:26:24 | 000,025,600 | —- | M] () – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/31 00:09:00 | 000,000,994 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-152049171-839522115-1004UA.job
[2011/03/30 23:49:13 | 000,000,835 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Stellar Phoenix Photo Recovery.lnk
[2011/03/30 19:54:50 | 000,001,689 | —- | M] () – D:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/03/30 19:54:49 | 000,002,625 | —- | M] () – D:\WINDOWS\System32\CONFIG.NT
[2011/03/30 16:09:02 | 000,000,942 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-152049171-839522115-1004Core.job
[2011/03/29 22:36:33 | 000,332,966 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\wow.jpg
[2011/03/29 20:06:09 | 000,079,055 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\19502121.jpg
[2011/03/28 22:29:53 | 000,316,492 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 27.png
[2011/03/28 22:05:59 | 000,141,288 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 4.png
[2011/03/28 22:05:51 | 000,141,641 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 6.png
[2011/03/28 22:03:56 | 000,341,489 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 13.png
[2011/03/28 18:09:57 | 000,002,316 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Google Chrome.lnk
[2011/03/28 18:09:57 | 000,002,294 | —- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/03/28 17:31:04 | 000,013,646 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2011/03/25 19:58:02 | 000,000,284 | —- | M] () – D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/19 15:02:26 | 000,819,661 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Zuleika_Blood_Elf_Death_Knight_by_morganagod.jpg
[2011/03/19 14:53:44 | 000,000,664 | —- | M] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/03/16 15:38:01 | 000,001,374 | —- | M] () – D:\WINDOWS\imsins.BAK
[2011/03/13 20:52:39 | 000,501,382 | —- | M] () – D:\WINDOWS\System32\perfh009.dat
[2011/03/13 20:52:39 | 000,087,288 | —- | M] () – D:\WINDOWS\System32\perfc009.dat
[2011/03/08 20:21:47 | 038,068,268 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\City and Colour (Ukulele Sample) - Sasha Marchant.wav
[2011/03/08 19:54:58 | 038,314,028 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\testsong1.wav
[2011/03/03 22:21:23 | 000,000,893 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Camtasia Studio 7.lnk
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[12 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/30 23:49:13 | 000,000,835 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Stellar Phoenix Photo Recovery.lnk
[2011/03/30 19:54:50 | 000,001,689 | —- | C] () – D:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/03/29 22:36:33 | 000,332,966 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\wow.jpg
[2011/03/29 20:06:16 | 000,079,055 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\19502121.jpg
[2011/03/28 22:29:44 | 000,316,492 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 27.png
[2011/03/28 22:05:52 | 000,141,288 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 4.png
[2011/03/28 22:05:44 | 000,141,641 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 6.png
[2011/03/28 22:03:47 | 000,341,489 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 13.png
[2011/03/19 15:02:29 | 000,819,661 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Zuleika_Blood_Elf_Death_Knight_by_morganagod.jpg
[2011/03/19 14:53:44 | 000,000,664 | —- | C] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/03/08 20:21:40 | 038,068,268 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\City and Colour (Ukulele Sample) - Sasha Marchant.wav
[2011/03/08 19:54:55 | 038,314,028 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\testsong1.wav
[2011/03/03 22:21:23 | 000,000,893 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Camtasia Studio 7.lnk
[2011/02/25 21:19:32 | 000,041,872 | —- | C] () – D:\WINDOWS\System32\xfcodec.dll
[2011/01/30 18:33:33 | 000,000,262 | —- | C] () – D:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/01/27 20:24:27 | 000,000,156 | —- | C] () – D:\WINDOWS\ae_mini.INI
[2011/01/27 20:23:00 | 000,000,128 | —- | C] () – D:\WINDOWS\smrpro.INI
[2010/11/13 11:03:58 | 000,025,600 | —- | C] () – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/02 10:59:47 | 000,000,132 | —- | C] () – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\fusioncache.dat
[2010/09/19 22:05:48 | 000,274,384 | —- | C] () – D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/12 19:58:12 | 000,088,397 | —- | C] () – D:\WINDOWS\hpoins06.dat
[2010/09/12 19:58:12 | 000,005,389 | —- | C] () – D:\WINDOWS\hpomdl06.dat
[2010/09/07 18:04:24 | 000,122,713 | —- | C] () – D:\WINDOWS\HPHins11.dat
[2010/09/07 18:04:24 | 000,013,767 | —- | C] () – D:\WINDOWS\hphmdl11.dat
[2010/09/07 18:04:20 | 000,077,824 | R— | C] () – D:\WINDOWS\System32\HPZIDS01.dll
[2010/08/05 15:59:19 | 000,153,088 | —- | C] () – D:\Program Files\UNWISE.EXE
[2010/07/31 19:55:16 | 000,194,248 | —- | C] () – D:\WINDOWS\System32\LTRFD13n.DLL
[2010/07/31 19:52:50 | 000,001,208 | —- | C] () – D:\WINDOWS\VFO.INI
[2010/07/31 19:52:49 | 000,196,096 | —- | C] () – D:\WINDOWS\System32\macd32.dll
[2010/07/31 19:52:49 | 000,138,752 | —- | C] () – D:\WINDOWS\System32\mase32.dll
[2010/07/31 19:52:49 | 000,136,192 | —- | C] () – D:\WINDOWS\System32\mamc32.dll
[2010/07/31 19:52:49 | 000,057,856 | —- | C] () – D:\WINDOWS\System32\masd32.dll
[2010/07/31 19:52:49 | 000,027,648 | —- | C] () – D:\WINDOWS\System32\ma32.dll
[2010/07/30 14:56:51 | 000,000,056 | -H– | C] () – D:\WINDOWS\System32\ezsidmv.dat
[2010/07/29 16:26:13 | 000,040,960 | R— | C] () – D:\WINDOWS\System32\psfind.dll
[2010/07/29 14:00:18 | 000,004,569 | —- | C] () – D:\WINDOWS\System32\secupd.dat
[2010/07/28 19:54:55 | 000,000,552 | —- | C] () – D:\WINDOWS\System32\d3d8caps.dat
[2010/07/25 21:26:54 | 000,000,000 | —- | C] () – D:\WINDOWS\nsreg.dat
[2010/07/25 19:30:09 | 000,002,048 | –S- | C] () – D:\WINDOWS\bootstat.dat
[2010/07/25 19:27:15 | 000,021,640 | —- | C] () – D:\WINDOWS\System32\emptyregdb.dat
[2010/07/25 15:23:29 | 000,004,161 | —- | C] () – D:\WINDOWS\ODBCINST.INI
[2010/07/25 15:22:12 | 000,169,096 | —- | C] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – D:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – D:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/27 16:12:22 | 001,604,482 | —- | C] () – D:\WINDOWS\System32\nvdata.bin
[2009/04/30 22:39:36 | 000,082,289 | —- | C] () – D:\WINDOWS\System32\lvcoinst.ini
[2005/07/29 14:38:24 | 003,375,104 | —- | C] () – D:\WINDOWS\System32\qt-mt331.dll
[2004/03/11 00:26:10 | 000,406,016 | —- | C] () – D:\WINDOWS\System32\PSDrvCheck.exe
[2003/03/31 08:00:00 | 013,107,200 | —- | C] () – D:\WINDOWS\System32\oembios.bin
[2003/03/31 08:00:00 | 000,673,088 | —- | C] () – D:\WINDOWS\System32\mlang.dat
[2003/03/31 08:00:00 | 000,501,382 | —- | C] () – D:\WINDOWS\System32\perfh009.dat
[2003/03/31 08:00:00 | 000,272,128 | —- | C] () – D:\WINDOWS\System32\perfi009.dat
[2003/03/31 08:00:00 | 000,218,003 | —- | C] () – D:\WINDOWS\System32\dssec.dat
[2003/03/31 08:00:00 | 000,087,288 | —- | C] () – D:\WINDOWS\System32\perfc009.dat
[2003/03/31 08:00:00 | 000,046,258 | —- | C] () – D:\WINDOWS\System32\mib.bin
[2003/03/31 08:00:00 | 000,028,626 | —- | C] () – D:\WINDOWS\System32\perfd009.dat
[2003/03/31 08:00:00 | 000,004,461 | —- | C] () – D:\WINDOWS\System32\oembios.dat
[2003/03/31 08:00:00 | 000,001,804 | —- | C] () – D:\WINDOWS\System32\dcache.bin
[2003/03/31 08:00:00 | 000,000,741 | —- | C] () – D:\WINDOWS\System32\noise.dat
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – D:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/10/17 23:08:40 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\.minecraft
[2010/08/04 21:39:29 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Acoustica
[2011/01/27 19:58:32 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Audacity
[2010/12/26 23:01:56 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\AudioTuner
[2011/03/29 20:41:15 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\AVG10
[2011/03/31 17:28:16 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Dropbox
[2010/08/24 15:44:57 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\FOG Downloader
[2010/08/27 17:01:19 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\HBLite
[2010/08/01 19:34:11 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Leadertech
[2010/10/28 21:03:43 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\LimeWire
[2010/10/05 22:56:36 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\ooVoo Details
[2010/10/06 23:28:32 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\OpenOffice.org
[2010/08/04 15:47:25 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Publish Providers
[2010/08/04 15:47:13 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Sony
[2010/08/04 21:43:04 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\SynthMaker
[2011/01/25 18:42:49 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\TS3Client
[2011/01/25 17:20:55 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\uTorrent
[2010/08/27 17:01:19 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
[2010/08/04 21:37:44 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Acoustica
[2011/03/30 19:54:13 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/31 17:21:03 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/29 20:33:43 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/28 21:33:38 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Driver Whiz
[2011/03/31 17:14:48 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\HBLiteSA
[2011/03/29 20:31:29 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\MFAData
[2010/08/04 17:50:57 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/08/04 17:51:10 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2010/10/16 18:26:20 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\PMB Files
[2010/07/31 19:54:12 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/08/04 23:42:36 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Sony
[2011/03/03 22:21:16 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TechSmith
[2011/03/30 23:49:20 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/25 22:02:25 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\{B7A015B7-4802-4678-8CEC-700380BA9AFD}

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/31 17:26:26 | 2683,883,520 | -HS- | M] () – D:\hiberfil.sys
[2011/03/31 17:26:25 | 2145,386,496 | -HS- | M] () – D:\pagefile.sys
[2010/09/28 17:36:17 | 000,006,599 | —- | M] () – D:\video.pass

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – D:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – D:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – D:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – D:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2005/05/11 23:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – D:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2010/07/25 19:28:50 | 000,000,067 | -HS- | M] () – D:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/05/05 08:48:54 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2006/03/22 21:08:20 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp463.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/23 10:04:21 | 000,040,648 | —- | M] (AVAST Software) – D:\WINDOWS\avastSS.scr
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2002/07/26 18:02:06 | 000,153,088 | —- | M] () – D:\Program Files\UNWISE.EXE

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/07/25 15:21:24 | 000,094,208 | —- | M] () – D:\WINDOWS\system32\config\default.sav
[2010/07/25 15:21:24 | 000,602,112 | —- | M] () – D:\WINDOWS\system32\config\software.sav
[2010/07/25 15:21:24 | 000,425,984 | —- | M] () – D:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/29 15:03:17 | 000,000,272 | -HS- | M] () – D:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/29 15:07:01 | 000,000,177 | -HS- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/25 19:32:50 | 000,000,079 | —- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/10/17 23:02:19 | 000,232,501 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Minecraft.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Files - Unicode (All) ==========
[2011/03/08 20:22:15 | 000,144,276 | —- | M] ()(D:\Documents and Settings\Aleksandr\Desktop\??? ? ???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\вид с балкона.JPG
[2011/03/08 20:22:10 | 000,144,276 | —- | C] ()(D:\Documents and Settings\Aleksandr\Desktop\??? ? ???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\вид с балкона.JPG
[2011/03/08 20:15:32 | 000,164,767 | —- | M] ()(D:\Documents and Settings\Aleksandr\Desktop\???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\Виталик.JPG
[2011/03/08 20:15:28 | 000,164,767 | —- | C] ()(D:\Documents and Settings\Aleksandr\Desktop\???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\Виталик.JPG
[2011/03/08 20:11:29 | 000,267,371 | —- | M] ()(D:\Documents and Settings\Aleksandr\Desktop\?????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\каска.JPG
[2011/03/08 20:11:23 | 000,267,371 | —- | C] ()(D:\Documents and Settings\Aleksandr\Desktop\?????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\каска.JPG

< End of report >
EXTRAS LOG


OTL Extras logfile created on: 3/31/2011 5:31:29 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\Aleksandr\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 189.91 Gb Total Space | 181.95 Gb Free Space | 95.81% Space Free | Partition Type: NTFS
Drive D: | 298.08 Gb Total Space | 7.78 Gb Free Space | 2.61% Space Free | Partition Type: NTFS

Computer Name: SASHA | User Name: Aleksandr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"57463:TCP" = 57463:TCP:*:Enabled:Pando Media Booster
"57463:UDP" = 57463:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"57463:TCP" = 57463:TCP:*:Enabled:Pando Media Booster
"57463:UDP" = 57463:UDP:*:Enabled:Pando Media Booster
"443:TCP" = 443:TCP:*:Enabled:ooVoo TCP port 443
"443:UDP" = 443:UDP:*:Enabled:ooVoo UDP port 443
"37674:TCP" = 37674:TCP:*:Enabled:ooVoo TCP port 37674
"37674:UDP" = 37674:UDP:*:Enabled:ooVoo UDP port 37674
"37675:UDP" = 37675:UDP:*:Enabled:ooVoo UDP port 37675
"37676:TCP" = 37676:TCP:*:Enabled:ooVoo TCP port 37676
"37676:UDP" = 37676:UDP:*:Enabled:ooVoo UDP port 37676
"37677:UDP" = 37677:UDP:*:Enabled:ooVoo UDP port 37677

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\Program Files\Pando Networks\Media Booster\PMB.exe" = D:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Documents and Settings\Aleksandr\My Documents\Downloads\StarCraft_2_NA_en-US.exe" = D:\Documents and Settings\Aleksandr\My Documents\Downloads\StarCraft_2_NA_en-US.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"D:\Program Files\StarCraft II\StarCraft II.exe" = D:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"D:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = D:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems, Inc.)
"D:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = D:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"D:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = D:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"D:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = D:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi – (Pinnacle Systems, Inc.)
"D:\Program Files\Xfire\Xfire.exe" = D:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe" = D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – ()
"D:\Program Files\Pando Networks\Media Booster\PMB.exe" = D:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\gPotato.com\Allods Online\bin\Launcher.exe" = C:\gPotato.com\Allods Online\bin\Launcher.exe:*:Enabled:Allods Online launcher.exe – (© 2008 - 2009 Astrum Nival, LLC)
"C:\gPotato.com\Allods Online\bin\AOgame.exe" = C:\gPotato.com\Allods Online\bin\AOgame.exe:*:Enabled:Allods Online AOgame.exe – (© 2008 - 2009 Astrum Nival, LLC)
"D:\Program Files\Runes of Magic\Client.exe" = D:\Program Files\Runes of Magic\Client.exe:*:Enabled:Runes of Magic – (Runewaker)
"D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"D:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"D:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = D:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"D:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = D:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"D:\Program Files\Microsoft LifeCam\LifeCam.exe" = D:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"D:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = D:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe – (Microsoft Corporation)
"D:\Program Files\Microsoft LifeCam\LifeExp.exe" = D:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"D:\Program Files\Microsoft LifeCam\LifeTray.exe" = D:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe – (Microsoft Corporation)
"D:\Program Files\ooVoo\ooVoo.exe" = D:\Program Files\ooVoo\ooVoo.exe:*:Enabled:ooVoo – (ooVoo LLC)
"D:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe" = D:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe:*:Enabled:lotroclient – (Turbine, Inc.)
"D:\Program Files\LimeWire\LimeWire.exe" = D:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"D:\Program Files\Muvizu\Binaries\Muvizu.exe" = D:\Program Files\Muvizu\Binaries\Muvizu.exe:*:Enabled:Muvizu – (DA Group Ltd)
"D:\Program Files\Logitech\Vid HD\Vid.exe" = D:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD – (Logitech Inc.)
"D:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe" = D:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"D:\Program Files\World of Warcraft\Launcher.exe" = D:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"D:\Program Files\Ventrilo\Ventrilo.exe" = D:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"D:\WINDOWS\system32\mmc.exe" = D:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"D:\Program Files\Acoustica Mixcraft 5\mixcraft5.exe" = D:\Program Files\Acoustica Mixcraft 5\mixcraft5.exe:*:Disabled:Mixcraft 5 – (Acoustica, Inc)
"D:\Program Files\AVG\AVG10\avgmfapx.exe" = D:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer
"D:\Documents and Settings\Aleksandr\Local Settings\Apps\2.0\X66DWTDW.1RE\3CN3NG33.19T\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe" = D:\Documents and Settings\Aleksandr\Local Settings\Apps\2.0\X66DWTDW.1RE\3CN3NG33.19T\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe:*:Enabled:Curse Client 4.0 – (Curse)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{11E94FDB-C895-45F1-B756-1C9B8C36C8F1}" = Microsoft IntelliType Pro 7.1
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.6.5
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6423DE-7959-4178-80E0-023C7EAA5347}" = NVIDIA ForceWare Network Access Manager
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{412B69AF-C352-4F6F-A318-B92B3CB9ACC6}" = Titan Quest
"{41CA14B6-3D43-4A24-9F7F-8A2A281D0A14}" = D1300
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{49140327-BEBF-43dd-B386-43311A065609}" = hph_ProductContext
"{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}" = Camtasia Studio 7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4CD67A02-DF59-43f7-8E8F-86DCF40543EF}" = 2570_Help
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{50E7BB78-02B4-469a-9D8B-B2F42835F90E}" = ProductContextNPI
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5D9C3FCE-A8BA-42F0-9019-769A1CF9A7A9}" = hph_software
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76BEC1D7-8A9F-472D-84C7-014BB155E4B2}" = HP Photosmart and Deskjet 7.0 Software
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C9AD221-994C-45B2-B46D-26F5735158CF}" = Sony Vegas Pro 8.0
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{893429F2-083B-4F82-92DC-DFDC45E8503C}" = hph_readme
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A2F166A0-F031-4E27-A057-C69733219434}_is1" = Runes of Magic
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}" = DiscAPI (Studio 10)
"{A8D91906-4032-4443-8C49-69F90E38F39D}" = 2570
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B5C5C17E-FEF6-4062-8151-A427AE8AF9D7}" = Titan Quest Immortal Throne
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B9B1AED3-40FB-47CC-B880-ED9A2C9FE658}" = D1300_Help
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BBBF3122-9A09-40B2-A065-CD684059FB19}" = hph_software_req
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DBD40476-78A4-4738-86B4-A5FB8807946D}" = NETGEAR GA311 Gigabit Adapter
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EE55FD52-0D47-4c5a-96EC-48F70FF30520}" = 2570Trb
"{EEECE229-49F6-4851-A73A-99B058221F8C}" = RAPID (Studio 10)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™ v03.02.03.8013
"Acoustica Effects Pack" = Acoustica Effects Pack
"Acoustica Mixcraft 5" = Acoustica Mixcraft 5
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AstrumNival Allods" = Allods Online 1700
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"Audio Tuner" = Audio Tuner (remove only)
"avast" = avast! Free Antivirus
"conduitEngine" = Conduit Engine
"Fraps" = Fraps
"Game Cam" = Game Cam 2.54.0.47
"HBLiteSA" = Hotbar
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347}" = NVIDIA ForceWare Network Access Manager
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{DBD40476-78A4-4738-86B4-A5FB8807946D}" = NETGEAR GA311 Smart Wizard Utility
"Logitech Vid" = Logitech Vid HD
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Muvizu" = Muvizu
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"StarCraft II" = StarCraft II
"Stellar Phoenix Photo Recovery_is1" = Stellar Phoenix Photo Recovery v3.5
"Super Mp3 Recorder Professional_is1" = Super Mp3 Recorder Professional v6.2
"SystemRequirementsLab" = System Requirements Lab
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Virtual DJ Home - Atomix Productions" = Virtual DJ Home - Atomix Productions
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"World of Warcraft" = World of Warcraft
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Xfire" = Xfire (remove only)
"XfireXO Toolbar" = XfireXO Toolbar
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/16/2010 3:50:11 PM | Computer Name = SASHA | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
hpqcxm08.dll, version 70.0.170.0, fault address 0x0000131c.

Error - 9/17/2010 10:00:58 PM | Computer Name = SASHA | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x00a236bb.

Error - 9/19/2010 5:18:47 PM | Computer Name = SASHA | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x00a20048.

Error - 9/19/2010 5:20:31 PM | Computer Name = SASHA | Source = Application Hang | ID = 1002
Description = Hanging application Skype.exe, version 4.2.0.169, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/19/2010 5:20:33 PM | Computer Name = SASHA | Source = Application Hang | ID = 1002
Description = Hanging application Skype.exe, version 4.2.0.169, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/23/2010 8:50:59 PM | Computer Name = SASHA | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x00a20360.

Error - 9/28/2010 4:48:23 PM | Computer Name = SASHA | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x00a0e1c0.

Error - 9/30/2010 8:19:13 PM | Computer Name = SASHA | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
xmlparse.dll, version 1.0.0.1, fault address 0x000018f3.

[ System Events ]
Error - 3/31/2011 5:11:46 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:11:48 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:11:52 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:11:55 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:12:00 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:12:05 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:12:10 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:12:17 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:12:38 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7000
Description = The Logitech LVPr2Mon Driver service failed to start due to the following
error: %%87

Error - 3/31/2011 5:12:38 PM | Computer Name = SASHA | Source = Service Control Manager | ID = 7023
Description = The Process Monitor service terminated with the following error: %%110


< End of report >
Hi Aleks

when I tried to run GMer (the first time, my computer froze and the second time I got a blue screen

Please run GMER again, but this time uncheck everything EXCEPT "Sections" and "C:\" .

If it still doesn’t work:

Scan With RKUnHooker• Please Download Rootkit Unhooker Save it to your desktop
• Double-click on RKUnhookerLE.exe to run it
• Click the Report tab, then click Scan
• Check (tick) Drivers, Stealth. Uncheck the rest. then Click OK
• Wait till the scanner has finished and then click File, Save Report
• Save the report somewhere where you can find it. Click Close
Copy the entire contents of the report and paste it in a reply here.

Note** you may get this warning:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


It is ok, just ignore it

Please run GMER again, but this time uncheck everything EXCEPT "Sections" and "C:\" .


My primary drive is D:\ , meaning that C is just a back up for whatever. Do you still want me to uncheck D during the scan?
GMER LOG


GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-31 20:25:32
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c Maxtor_6Y200P0 rev.YAR41BW0
Running: gmer.exe; Driver: D:\DOCUME~1\ALEKSA~1\LOCALS~1\Temp\uxtdypow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xA7ED09CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xA86A1A68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xA7EF0AF5]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xA7ED2EAC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xA7ED2F04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xA7ED301A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xA7EF04A9]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xA7ED2E02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xA7ED2F54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xA7ED2E56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xA7ED2FC8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xA7ED09EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xA7EF11BB]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xA7EF1471]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xA7ED329E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xA7EF1026]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xA7EF0E91]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xA86A1B18]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xA7ED07B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xA7ED0A12]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xA7ED3412]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xA7ED14AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xA7ED2EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xA7ED2F2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xA7ED3044]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xA7EF0805]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xA7ED2E2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xA7ED30D6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xA7ED2F94]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xA7ED2E84]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xA7ED31BA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xA7ED2FF2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xA86A1BB0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xA7EF0D0C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xA7ED1370]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xA7EF0B5E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xA86A9E26]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xA7EEFB1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xA7ED0A36]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xA7ED0A5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xA7ED0812]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xA7ED094E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xA7EF12C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xA7ED092A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xA7ED0972]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xA7ED0A7E]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xA86B68DE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\LANPkt \Device\RTLPKT_{6E664E3E-58E6-4795-A022-81A83742E42E} B85F8CD2

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\LANPkt \Device\RTLPKT B85D8CD2

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 …
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 …
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 …
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB …
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 …
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC …
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 …
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 …
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 …
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ D:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x05 0x73 0x21 0xDD …

—- EOF - GMER 1.0.15 —-
Hi Aleks

P2P - I see you have P2P software, (uTorrent, LimeWire), on your machine even though it is not installed. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.


Run AVG removal tool

There are still some remnants of AVG on your computer so please use download and run AVG Removal Tool from here


Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001
    FF - prefs.js..extensions.enabledItems: [removed]:11.0.0.0
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
    File not found (No name found) – D:\PROGRAM FILES\AVG\AVG10\FIREFOX4
    File not found (No name found) – D:\PROGRAM FILES\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O4 - HKLM..\Run: [IWHE Agent] File not found
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
    [2011/03/30 23:44:25 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\AVG Security Toolbar
    [2011/03/29 20:31:59 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\AVG10
    [2011/03/29 20:41:14 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Application Data\AVG10
    [2010/08/27 17:01:19 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\HBLite
    [2010/08/27 17:01:19 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
    [2011/03/31 17:14:48 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\HBLiteSA
    [2011/03/29 20:31:29 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\MFAData
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Satchfan
Thank you for the heads up about the P2P programs. I'm pretty sure that I managed to get rid of AVG all together now. However, I could not run OTL. I tried twice and received a memory dump blue screen on both occasions :/
Hi Aleks

Try running it in safe mode with Networking:

To Enter Safemode• Restart your computer
• As the computer starts to boot-up, Tap the F8 KEY - this will bring up a menu.
• Use the Up and Down Arrow Keys to scroll up to Safemode
• Then press Enter on your keyboard
I tried to run windows in safe mode. And apparently I CAN'T run it in safe mode. A ton of error messages came up and I had to restart the system. Tried it 3 times with no avail. I also tried to run OLG normally and it crashed my computer regardless. Yesterday my computer started using a lot of memory too with no apparent reason. I wasn't on the internet or running any programs and it was up at 50-80% usage. I found that to be a little strange.

A ton of error messages came up and I had to restart the system

what kind of error messages?

Can you explain exactly at what stage of starting the computer in safe mode this happened.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI