This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

antimalware doctor virus

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Everyone, I need some help. I was just on the net and realised I have somehow got antimalware doctor installed on my laptop. everytime I turn on my laptop it runs antimalware doctor, but I didn't install this, it's driving me crazy. I've scaned with malwarebytes antimalware and tried unistalling the program but it just keeps running. please help :pullhair: :pullhair:
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
===================================================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

In your next post, please include the following:
  • OTL log
  • MBRCheck log
  • GMER log
thanks for such a quick reply and assisting me through this.
ok here is the OTL log
OTL.txt first

OTL logfile created on: 6/04/2011 3:04:49 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Alessandra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.95 Gb Total Space | 169.71 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 3.67 Gb Free Space | 36.72% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 261.59 Gb Free Space | 87.76% Space Free | Partition Type: NTFS

Computer Name: ALESSANDRA-PC | User Name: Alessandra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Alessandra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe ()
PRC - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - C:\Program Files\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Windows\System32\drivers\ACFXAU32.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Alessandra\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll ()
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (mi-raysat_3dsmax2011_32) – C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (FAService) – C:\Program Files\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (Adobe Version Cue CS4) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (XAudioService) – C:\Windows\System32\drivers\ACFXAU32.exe (Conexant Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKsla30762e3) – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D62022C1-AF51-403B-8475-31D9F31255C0}\MpKsla30762e3.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (FACAP) – C:\Windows\System32\drivers\facap.sys (Sensible Vision )
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (k57nd60x) Broadcom NetLink ™ – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\ACFXAU32.sys (Conexant Systems, Inc.)
DRV - (acfva) – C:\Windows\System32\drivers\ACFVA32.sys (Conexant Systems Inc.)
DRV - (dgcfltr) – C:\Windows\System32\drivers\ACFDCP32.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\ACFSDK32.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.shareware.pro/?lang=en

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/02/14 16:39:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/03/15 21:15:50 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/05/19 13:07:12 | 000,000,089 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - C:\Program Files\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] C:\Program Files\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [k70ccreloc.exe] C:\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\k70ccreloc.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: latrobe.edu.au ([owa] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\FastAccess: DllName - C:\Program Files\Sensible Vision\Fast Access\FALogNot.dll - C:\Program Files\Sensible Vision\Fast Access\FALogNot.dll ()
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Alessandra\Pictures\2010 painting studies\IMG_0105.JPG
O24 - Desktop BackupWallPaper: C:\Users\Alessandra\Pictures\2010 painting studies\IMG_0105.JPG
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/18 15:18:07 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2006/09/19 07:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/02/02 21:37:32 | 000,000,000 | RH-D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/17 12:56:50 | 000,000,036 | RH– | M] () - F:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/06 14:58:58 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Alessandra\Desktop\OTL.exe
[2011/04/06 00:13:22 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Local\Adobe
[2011/04/05 23:04:00 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547
[2011/03/24 16:16:39 | 000,000,000 | —D | C] – C:\Users\Alessandra\Documents\jobs
[2011/03/24 07:43:31 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/24 07:43:31 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/21 11:11:51 | 000,000,000 | —D | C] – C:\Users\Alessandra\Documents\edx
[2011/03/15 21:15:04 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2011/03/15 21:15:04 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/03/15 21:14:49 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Roaming\HpUpdate
[2011/03/15 21:14:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2011/03/15 21:12:41 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2011/03/15 21:12:24 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/03/15 21:11:32 | 000,000,000 | —D | C] – C:\Users\Alessandra\AppData\Local\HP
[2011/03/15 21:10:08 | 000,213,864 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpinkcoi8711.dll
[2011/03/15 21:10:07 | 000,267,112 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpinksts8711LM.dll
[2011/03/15 21:09:40 | 001,792,872 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\HPScanMiniDrv_DJ2050_510g.dll
[2011/03/15 20:43:29 | 000,000,000 | —D | C] – C:\Users\Alessandra\Documents\fonts
[2011/03/13 19:36:26 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/13 19:36:25 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/13 19:36:25 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/13 19:36:25 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2009/08/05 13:17:21 | 008,653,312 | —- | C] (Dell, Inc. ) – C:\Users\Alessandra\AppData\Roaming\DataSafeDotNet.exe

========== Files - Modified Within 30 Days ==========

[2011/04/06 14:59:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Alessandra\Desktop\OTL.exe
[2011/04/06 14:54:12 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/06 14:54:12 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/06 14:47:38 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 14:47:38 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 14:47:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/06 14:47:25 | 3215,835,136 | -HS- | M] () – C:\hiberfil.sys
[2011/04/06 11:24:30 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/06 00:12:08 | 000,006,836 | —- | M] () – C:\Users\Alessandra\AppData\Local\d3d9caps.dat
[2011/04/05 19:43:50 | 000,072,884 | —- | M] () – C:\Users\Alessandra\Documents\312b rent.JPG
[2011/04/03 19:57:27 | 001,728,076 | —- | M] () – C:\Users\Alessandra\Documents\dress 1 (2).tif
[2011/04/03 19:56:43 | 001,723,810 | —- | M] () – C:\Users\Alessandra\Documents\dress 9.tif
[2011/04/03 19:56:05 | 002,059,870 | —- | M] () – C:\Users\Alessandra\Documents\dress 8.tif
[2011/04/03 19:55:26 | 001,087,634 | —- | M] () – C:\Users\Alessandra\Documents\dress 5.tif
[2011/04/03 19:55:07 | 001,719,628 | —- | M] () – C:\Users\Alessandra\Documents\dress 2.tif
[2011/04/03 19:54:36 | 002,634,500 | —- | M] () – C:\Users\Alessandra\Documents\dress3.tif
[2011/04/03 19:54:08 | 001,601,856 | —- | M] () – C:\Users\Alessandra\Documents\dress4.tif
[2011/04/03 19:53:30 | 002,736,800 | —- | M] () – C:\Users\Alessandra\Documents\dress 1.tif
[2011/04/03 19:50:00 | 001,288,118 | —- | M] () – C:\Users\Alessandra\Documents\dress 6.tif
[2011/04/03 19:49:49 | 002,170,666 | —- | M] () – C:\Users\Alessandra\Documents\dress 7.tif
[2011/04/02 21:38:19 | 000,053,248 | —- | M] () – C:\Users\Alessandra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/29 22:57:07 | 022,937,556 | —- | M] () – C:\Users\Alessandra\Documents\DEAIM.tif
[2011/03/27 15:26:31 | 000,139,628 | —- | M] () – C:\Users\Alessandra\Desktop\pre selection kit interior design.pdf
[2011/03/24 15:30:33 | 008,416,770 | —- | M] () – C:\Users\Alessandra\Documents\Scan.tif
[2011/03/20 17:22:40 | 000,889,973 | —- | M] () – C:\Users\Alessandra\Documents\turtle-care-guide-2010.pdf
[2011/03/16 11:25:56 | 029,688,790 | —- | M] () – C:\Users\Alessandra\Documents\hue.tif
[2011/03/16 10:18:38 | 000,000,672 | —- | M] () – C:\Windows\tasks\hpwebreg_CN11O3925G05D1.job
[2011/03/16 10:18:32 | 002,316,904 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/03/15 21:14:09 | 000,002,101 | —- | M] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series.lnk
[2011/03/15 21:14:09 | 000,001,054 | —- | M] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series Scan.lnk
[2011/03/14 21:41:30 | 000,834,247 | —- | M] () – C:\Users\Alessandra\Desktop\75 tram.pdf
[2011/03/14 21:40:32 | 000,799,861 | —- | M] () – C:\Users\Alessandra\Desktop\70 tram.pdf
[2011/03/14 21:14:44 | 000,070,110 | —- | M] () – C:\Users\Alessandra\Desktop\F1C-timetable.pdf

========== Files Created - No Company Name ==========

[2011/04/05 19:43:48 | 000,072,884 | —- | C] () – C:\Users\Alessandra\Documents\312b rent.JPG
[2011/04/03 19:52:55 | 001,728,076 | —- | C] () – C:\Users\Alessandra\Documents\dress 1 (2).tif
[2011/04/03 19:45:56 | 001,723,810 | —- | C] () – C:\Users\Alessandra\Documents\dress 9.tif
[2011/04/03 19:45:23 | 002,059,870 | —- | C] () – C:\Users\Alessandra\Documents\dress 8.tif
[2011/04/03 19:39:12 | 002,170,666 | —- | C] () – C:\Users\Alessandra\Documents\dress 7.tif
[2011/04/03 19:38:26 | 001,288,118 | —- | C] () – C:\Users\Alessandra\Documents\dress 6.tif
[2011/04/03 19:36:34 | 001,087,634 | —- | C] () – C:\Users\Alessandra\Documents\dress 5.tif
[2011/04/03 19:33:06 | 001,601,856 | —- | C] () – C:\Users\Alessandra\Documents\dress4.tif
[2011/04/03 19:31:49 | 002,634,500 | —- | C] () – C:\Users\Alessandra\Documents\dress3.tif
[2011/04/03 19:23:47 | 001,719,628 | —- | C] () – C:\Users\Alessandra\Documents\dress 2.tif
[2011/04/03 19:22:05 | 002,736,800 | —- | C] () – C:\Users\Alessandra\Documents\dress 1.tif
[2011/03/29 22:57:05 | 022,937,556 | —- | C] () – C:\Users\Alessandra\Documents\DEAIM.tif
[2011/03/27 15:26:31 | 000,139,628 | —- | C] () – C:\Users\Alessandra\Desktop\pre selection kit interior design.pdf
[2011/03/24 15:28:17 | 008,416,770 | —- | C] () – C:\Users\Alessandra\Documents\Scan.tif
[2011/03/20 17:22:36 | 000,889,973 | —- | C] () – C:\Users\Alessandra\Documents\turtle-care-guide-2010.pdf
[2011/03/16 11:25:53 | 029,688,790 | —- | C] () – C:\Users\Alessandra\Documents\hue.tif
[2011/03/15 21:16:35 | 000,000,672 | —- | C] () – C:\Windows\tasks\hpwebreg_CN11O3925G05D1.job
[2011/03/15 21:15:52 | 000,001,203 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Default Manager.lnk
[2011/03/15 21:14:09 | 000,002,101 | —- | C] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series.lnk
[2011/03/15 21:14:09 | 000,001,054 | —- | C] () – C:\Users\Public\Desktop\HP Deskjet 2050 J510 series Scan.lnk
[2011/03/14 21:41:30 | 000,834,247 | —- | C] () – C:\Users\Alessandra\Desktop\75 tram.pdf
[2011/03/14 21:40:32 | 000,799,861 | —- | C] () – C:\Users\Alessandra\Desktop\70 tram.pdf
[2011/03/14 21:14:44 | 000,070,110 | —- | C] () – C:\Users\Alessandra\Desktop\F1C-timetable.pdf
[2010/09/10 13:09:49 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2010/09/08 23:40:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/08 23:40:16 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/08 23:40:13 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/08 23:40:13 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/08 23:40:13 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/08/01 19:13:09 | 000,000,000 | —- | C] () – C:\Windows\OpPrintServer.INI
[2010/05/14 19:15:35 | 000,053,248 | —- | C] () – C:\Windows\System32\pxhpinst.exe
[2010/02/11 18:11:29 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/02/11 17:59:19 | 000,000,000 | —- | C] () – C:\Windows\EEventManager.INI
[2009/11/08 08:49:21 | 000,006,836 | —- | C] () – C:\Users\Alessandra\AppData\Local\d3d9caps.dat
[2009/10/05 15:59:52 | 000,111,932 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2009/10/05 15:59:52 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2009/10/05 15:59:51 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2009/10/05 15:59:51 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2009/10/05 15:59:51 | 000,026,154 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2009/10/05 15:59:51 | 000,024,903 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2009/10/05 15:59:51 | 000,021,390 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2009/10/05 15:59:51 | 000,020,148 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2009/10/05 15:59:51 | 000,011,811 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2009/10/05 15:59:51 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2009/10/05 15:59:51 | 000,001,146 | —- | C] () – C:\Windows\System32\EPPICPresetData_DU.dat
[2009/10/05 15:59:51 | 000,001,139 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2009/10/05 15:59:51 | 000,001,139 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2009/10/05 15:59:51 | 000,001,136 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2009/10/05 15:59:51 | 000,001,129 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2009/10/05 15:59:51 | 000,001,129 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2009/10/05 15:59:51 | 000,001,120 | —- | C] () – C:\Windows\System32\EPPICPresetData_IT.dat
[2009/10/05 15:59:51 | 000,001,107 | —- | C] () – C:\Windows\System32\EPPICPresetData_GE.dat
[2009/10/05 15:59:51 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2009/08/20 18:33:54 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/20 18:33:53 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/04/17 17:22:45 | 000,053,248 | —- | C] () – C:\Users\Alessandra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/03 00:44:10 | 000,000,422 | —- | C] () – C:\Users\Alessandra\AppData\Roaming\wklnhst.dat
[2009/03/12 18:36:54 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2009/03/12 18:36:54 | 000,174,819 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/03/12 18:36:54 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2009/03/12 18:36:54 | 000,090,112 | —- | C] () – C:\Windows\System32\atibrtmon.exe
[2009/03/12 18:32:34 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/12 10:44:39 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/03/12 03:22:02 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/03/12 03:11:57 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/03/12 03:02:26 | 000,000,628 | —- | C] () – C:\Windows\System32\PCI_VEN_1102&DEV_FF05&SUBSYS_00001102.ini
[2009/03/12 03:02:25 | 000,101,376 | —- | C] () – C:\Windows\System32\APOMngr.dll
[2009/03/12 03:02:25 | 000,066,560 | —- | C] () – C:\Windows\System32\CmdRtr.dll
[2008/09/05 19:16:36 | 000,233,216 | —- | C] () – C:\Windows\System32\FACrashRpt.dll
[2008/09/05 19:16:36 | 000,059,136 | —- | C] () – C:\Windows\System32\FAib.dll
[2008/09/05 19:16:20 | 000,087,296 | —- | C] () – C:\Windows\System32\FAIEExtension.dll
[2007/04/16 05:24:16 | 000,023,752 | —- | C] () – C:\Windows\System32\providers.bin
[2006/11/02 22:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 22:47:37 | 002,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 22:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 20:33:01 | 000,609,196 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 20:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 20:33:01 | 000,108,672 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 20:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 20:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 18:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 18:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 17:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 17:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/14 15:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2011/04/05 23:04:03 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547
[2010/05/18 18:57:02 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Autodesk
[2011/02/13 13:27:57 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/01/12 12:17:20 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\DriverCure
[2009/10/05 16:21:56 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Epson
[2010/05/17 19:32:53 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Publish Providers
[2010/05/20 16:04:44 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Sony
[2009/04/03 00:44:12 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Template
[2010/01/12 12:58:25 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\Uniblue
[2010/05/19 12:56:43 | 000,000,000 | —D | M] – C:\Users\Alessandra\AppData\Roaming\uTorrent
[2011/04/06 11:24:30 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/19 07:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 16:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/02/18 12:34:17 | 000,015,887 | —- | M] () – C:\ComboFix.txt
[2006/09/19 07:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/03/12 18:37:06 | 000,005,286 | RH– | M] () – C:\dell.sdr
[2011/04/06 14:47:25 | 3215,835,136 | -HS- | M] () – C:\hiberfil.sys
[2010/05/01 12:46:19 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2010/05/17 18:21:48 | 000,000,778 | -H– | M] () – C:\os117275.bin
[2011/04/06 14:47:17 | 3529,646,080 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 22:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 22:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 22:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/03 18:34:51 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/19 07:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 22:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2008/12/05 00:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 12:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 13:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 13:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 13:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 20:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 20:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/04 19:17:14 | 000,000,350 | -HS- | M] () – C:\Users\Alessandra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/02/17 15:53:14 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Alessandra\Desktop\ATF_Cleaner.exe
[2011/04/06 14:59:13 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Alessandra\Desktop\OTL.exe
[2009/09/30 15:34:32 | 070,124,864 | —- | M] (CANON INC.) – C:\Users\Alessandra\Desktop\rc150upd_7l.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >
[2010/02/11 17:22:20 | 004,493,736 | —- | M] (Microsoft Corporation) – C:\Users\Alessandra\mssefullinstall-x86fre-en-us-vista-win7.exe
[2010/05/13 14:57:58 | 160,991,560 | —- | M] (Sony Creative Software Inc.) – C:\Users\Alessandra\soundforgepro10.0b.exe

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/04/02 18:19:02 | 000,000,402 | -HS- | M] () – C:\Users\Alessandra\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2010/02/11 18:11:29 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-06 00:47:53

< End of report >
heres the Extras.Txt

OTL Extras logfile created on: 6/04/2011 3:04:49 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Alessandra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.95 Gb Total Space | 169.71 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 3.67 Gb Free Space | 36.72% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 261.59 Gb Free Space | 87.76% Space Free | Partition Type: NTFS

Computer Name: ALESSANDRA-PC | User Name: Alessandra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05E27E21-9D91-41AD-AA4F-8C2B2F3BC31F}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{067F42AA-5B04-457B-B964-F3FB969F5AAA}" = lport=49163 | protocol=6 | dir=in | name=akamai netsession interface |
"{0B03C591-C862-4095-AB80-0C36D3516C5A}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{25FB90EB-2BC5-4DC0-9387-9BE2A96ED2BF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2654928A-E883-4EFD-8194-0F34B366C2BA}" = lport=49198 | protocol=6 | dir=in | name=akamai netsession interface |
"{3D248692-D131-4395-8F50-6F1DCA4542D7}" = rport=137 | protocol=17 | dir=out | app=system |
"{3DF92612-FE11-4EFF-8350-DDC5D7276176}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{45CB6F17-8E17-4E6D-B0E1-A34322E99108}" = rport=139 | protocol=6 | dir=out | app=system |
"{5EF2244D-75FF-4E20-9719-4A1F50286CDD}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{5FE857E0-381D-41B4-A288-A4B391EF0E8E}" = lport=139 | protocol=6 | dir=in | app=system |
"{67168335-91BC-4914-903D-E159D3635EF2}" = lport=137 | protocol=17 | dir=in | app=system |
"{888B6766-BDF1-43CD-82E0-E894F9CE8B3F}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8BE0ED30-C40B-4153-A79C-6F1D52F7157F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{8CA6D6F6-9393-4B53-995F-65620669D8BE}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{973D966A-CF12-4769-9252-5A78FF1DB530}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9CBD7804-BFA1-4B8F-B11E-21A88388C435}" = lport=138 | protocol=17 | dir=in | app=system |
"{9F9C957B-0E87-4084-B65A-35F2F2A82698}" = rport=138 | protocol=17 | dir=out | app=system |
"{AA3A0420-D495-42E1-B5D4-B82464087617}" = rport=445 | protocol=6 | dir=out | app=system |
"{AFC1CCF9-3AED-48C5-BC25-ACA9DE3161FE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B64BCA7E-7DDE-467A-9D74-6E74CFBC3646}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{BEA4DB54-0A42-4377-B5BB-F0A28F0E3F3A}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{C357B7BD-7782-47D9-9B67-1B3837FE5657}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{C3FAEFF6-AA07-4119-8F88-80AA1CBFC1E2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D12F0E34-3639-41A5-9DA8-F43810B026A0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E863FFDD-50ED-4DC7-B8DD-4F72555A2061}" = lport=445 | protocol=6 | dir=in | app=system |
"{F5A29660-E2F6-4DE1-9D41-DDF123001812}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{127B85FB-F5B4-4D3F-AD5F-00B3C90504D4}" = protocol=6 | dir=in | app=c:\program files\autodesk\backburner\server.exe |
"{159C6D7C-4DB4-4829-934F-2339E013F96E}" = protocol=17 | dir=in | app=c:\program files\autodesk\backburner\server.exe |
"{1FEF353E-95A5-457C-AA1E-9D79681135C9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{24671BC9-472D-4222-9DFC-FAB79D9833C8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{25E572F5-D155-4E3C-A762-39F2CF16B672}" = protocol=6 | dir=in | app=c:\program files\autodesk\backburner\monitor.exe |
"{2A221A9C-8AF2-407A-A92A-DAADB74C4430}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe |
"{32679510-3452-4F6B-9ECB-B086CA3266DE}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_32.exe |
"{442972E9-68FA-4A69-B4A6-B50EE7A63F2C}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{564DDFA0-1AB7-4AE9-9AE1-0BB1CE42A8C9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{5CB1B409-C854-4B7C-962D-64205C33BC32}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5CD4B409-98EA-4F90-B70C-4F1F5C858EB8}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 2050 j510 series\bin\usbsetup.exe |
"{6553AD57-711E-4733-8417-E37EBCDE90D2}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max 2011\3dsmax.exe |
"{66C59677-ACBB-432C-ADF4-E51AEB727912}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7E88B6DD-8B95-4F88-AE8C-9E8EA680AAB0}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{7F185F66-B8F7-4CC1-A7DC-240C33D19507}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max 2011\3dsmax.exe |
"{A9A369B2-1DFF-41DF-89C1-DE08B0A887BF}" = protocol=6 | dir=in | app=c:\program files\autodesk\backburner\manager.exe |
"{BA63ADE8-CE75-45DC-9407-77598A7CEF10}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C89B091B-CBE6-4685-A13D-C9D28170E77D}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe |
"{CDB21B32-5434-48CB-B169-0E1106665B70}" = protocol=17 | dir=in | app=c:\program files\autodesk\backburner\monitor.exe |
"{DD65D1C2-4744-4875-868C-637F46B7A021}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_32.exe |
"{DF24A755-2CAC-4035-B55E-25B1B884AA73}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{E4397844-538E-4CE2-9C40-E3CC853DFEC2}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 2050 j510 series\bin\usbsetup.exe |
"{F277FA28-0050-4416-A0ED-6BD7228855DC}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F46FF51C-FC97-42B6-9112-876CD50EB4A6}" = protocol=17 | dir=in | app=c:\program files\autodesk\backburner\manager.exe |
"TCP Query User{197A1EA9-2717-47F8-AC6F-9662BD17B863}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{E5218293-327C-494C-AA2B-55E2238B4F17}C:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"UDP Query User{5B069493-7D2E-4615-A97A-1DA6683597B5}C:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"UDP Query User{F26797D8-9C59-4B86-A21F-D3B853267F83}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.1.0.4402
"{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0709B06B-82BC-6073-0E43-DE107DF1389C}" = Catalyst Control Center Localization Spanish
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{11D03BF4-A66F-325E-7762-4F64586C673F}" = Catalyst Control Center Graphics Full New
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}" = RemoteCapture 2.7.5
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15EB6A85-A28D-2ED8-C344-DEBC592F2E12}" = Catalyst Control Center Localization German
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1882D3BE-8B8F-4EA3-9414-EB06CD5B9CD8}" = Modem Diagnostics Tool
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{20207CCE-A8FA-44A7-AA3D-1E43EB307B27}" = Sony Sound Forge Audio Studio 9.0
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{2236B741-6631-49AE-B76E-3E14CA01CC87}" = RemoteCapture Task
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C3CD30-2DF4-FEFA-3F4E-D6C1C3257FCE}" = ccc-core-static
"{29498512-A137-4478-8691-922829F108DC}" = HP Deskjet 2050 J510 series Product Improvement Study
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2D1C2321-8FDB-49B8-A66B-4008DC0B6B5D}" = File Viewer Utility 1.3.2
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{32C2CBBB-4540-E526-206D-B7BC7932D82F}" = CCC Help Danish
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2008.1
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{425819E1-D68E-8CE1-85D5-CDBA64E82DDE}" = CCC Help Japanese
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{4392E2AF-1643-29DA-E873-C94D547467D7}" = Catalyst Control Center Localization Swedish
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{44FDDB51-0E97-DD4A-9FB2-8D394DBEE47F}" = CCC Help Dutch
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{48C86A94-A6C0-D2D0-1649-ECB00D2DF4DE}" = Catalyst Control Center Localization Norwegian
"{48CC1AD8-2013-82B3-284F-E0253195664F}" = Catalyst Control Center Localization French
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{496C34BF-9DE5-9628-48CC-052DD6A8453E}" = Catalyst Control Center Core Implementation
"{4A4D109A-D9C4-E460-4F9A-0252F581D600}" = CCC Help Swedish
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4CA09BF7-1CFC-44B8-80EA-7B4D15D12DC5}" = Catalyst Control Center - Branding
"{4F9EF11C-A91A-42D0-BDAC-BB9695237075}" = Canon Camera TWAIN Driver
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57847CB0-95DA-D785-B170-1F00FC79B860}" = Catalyst Control Center Localization Chinese Traditional
"{5A72A2C4-9D4A-0718-DA28-95B73C2270DA}" = Catalyst Control Center Localization Danish
"{60D7B7D1-16A5-4168-9F46-AE956B0C5046}" = FastAccess
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6406E3EA-9777-45B7-A0C0-89741E629352}" = Composite 2011
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{67574624-BF0F-0409-AF6D-19FBD86FF7F7}" = Autodesk 3ds Max 2011 32-bit
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{682FED0E-738E-0048-F448-B3EE427978CC}" = Catalyst Control Center Localization Japanese
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6B00208E-2844-7480-5F50-6515A5907F0B}" = CCC Help Norwegian
"{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}" = EDocs
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{76E12A66-1AEC-3816-E75A-330998F2D40C}" = CCC Help Korean
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{79FBDD2E-DD2B-141A-DCF0-B8C125B5A008}" = Catalyst Control Center Graphics Previews Vista
"{7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}" = HP Deskjet 2050 J510 series Help
"{7C63DFEB-6176-C3F1-AA83-F997E32B44EA}" = Catalyst Control Center Localization Portuguese
"{7C8B5E63-821A-4DFB-BDFA-19854D88EC5C}" = 3dsmax ancillary install
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84557D91-D8C7-D7A4-1393-3AB3A16106C7}" = CCC Help Chinese Traditional
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9266D931-C05C-86F5-B74A-B1A382249916}" = Catalyst Control Center Localization Italian
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{94333A1C-DC4A-E70F-FA92-16AB6F2443D6}" = Catalyst Control Center Graphics Full Existing
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{974BBAF1-048D-4230-2254-62FEA00B18E9}" = Skins
"{975951E7-14D0-49AF-A630-89680D12D7F6}" = Autodesk Material Library 2011 Medium Image library
"{998D91BE-65FE-8B9D-5C6E-1D52401EAAA1}" = CCC Help English
"{99F80251-DAE8-0409-BD08-DCBBEF56B8CB}" = Autodesk 3ds Max 2011 32-bit Components
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{9AB377EE-454D-374C-C309-D2DFA9AB535B}" = CCC Help Italian
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A14F7508-B784-40B8-B11A-E0E2EEB7229F}" = Adobe Premiere Pro 1.5 Tryout
"{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}" = Camera Window
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A4874CD2-6942-E7A7-3690-277B9CB56DF5}" = Catalyst Control Center Graphics Light
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B578DD15-CB17-CBB8-611E-D1AE7D5568AC}" = Catalyst Control Center Graphics Previews Common
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BC5C42B3-CE50-8D5E-A495-6C48C0FF6336}" = CCC Help Portuguese
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BEFFB92B-8238-E6B7-E9D4-494BA407E593}" = Catalyst Control Center Localization Korean
"{BFC19AEE-8C4D-65BF-3BAE-729D1252E86C}" = Catalyst Control Center InstallProxy
"{C177F7FD-C061-003B-47F6-41483424517B}" = Catalyst Control Center Localization Chinese Standard
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
"{D3171626-2269-7CF9-82AC-7BFC534A0E6A}" = ccc-utility
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D86C72D4-57DB-D59E-1FE3-9ED8819B28C4}" = Catalyst Control Center Localization Russian
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DAD207CE-44D2-0C73-198B-8DD3B4F27426}" = CCC Help Spanish
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DEDB47A3-C988-4A43-A645-E2CEA571E680}" = Epson Easy Photo Print 2
"{E1ED3247-902C-9B94-31AB-81572A6D77AA}" = Catalyst Control Center Localization Dutch
"{E374F278-E64E-D574-332F-AE9241580749}" = CCC Help Chinese Standard
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E60E58A1-6093-3DFC-C382-3702EFB40F0E}" = CCC Help French
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E654D1E3-B18B-4953-BFBC-F16227323E05}" = HP Deskjet 2050 J510 series Basic Device Software
"{E87A027B-8051-4323-1B8D-34CB90A9EEBE}" = CCC Help German
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EAD1C99F-6325-E477-C94C-58B2DB656959}" = Catalyst Control Center Localization Finnish
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EED50C97-C79E-4149-BD82-7C5A22437708}" = Adobe Setup
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = PhotoStitch
"{F688B66F-AC95-809B-0056-154AF871D5EF}" = CCC Help Finnish
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FAF0DAD8-1EA7-4FEF-80E5-8D8D6EBD5A23}" = RAW Image Task
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FC41BB0E-F005-F0B8-9040-18E935D752E7}" = CCC Help Russian
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FCED9B62-34FF-4C15-8A23-F65221F7874D}" = ITECIR Driver
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe_a68eec966ce913ddaa63251dc82ed31" = Adobe Flash CS4 Professional
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Age of Mythology 1.0" = Age of Mythology
"Akamai" = Akamai NetSession Interface
"Autodesk FBX Plug-in 2011.1 - 3ds Max 2011" = Autodesk FBX Plug-in 2011.1 - 3ds Max 2011
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 7_is1" = AVS Video Converter 7
"Canon RAW Codec" = Canon RAW Codec
"CNXT_MODEM_USB_ACF" = Conexant USB D400 V.92 Modem
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Creative OA001" = Integrated Webcam Driver (1.03.02.0919)
"Dell Video Chat" = Dell Video Chat (remove only)
"Dell Webcam Central" = Dell Webcam Central
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Scanner" = EPSON Scan
"EPSON Stylus Photo PX700W_PX800FW_TX700W_TX800FW User’s Guide" = EPSON Stylus Photo PX700W_PX800FW_TX700W_TX800FW Manual
"EPSON TX700W Series" = EPSON TX700W Series Printer Uninstall
"GoToAssist" = GoToAssist 8.0.0.514
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photo Creations" = HP Photo Creations
"InstallShield_{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}" = Canon Utilities RemoteCapture 2.7
"InstallShield_{2236B741-6631-49AE-B76E-3E14CA01CC87}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{2D1C2321-8FDB-49B8-A66B-4008DC0B6B5D}" = Canon Utilities File Viewer Utility 1.3
"InstallShield_{4F9EF11C-A91A-42D0-BDAC-BB9695237075}" = Canon EOS Kiss REBEL 300D TWAIN Driver
"InstallShield_{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}" = Canon Camera Window for ZoomBrowser EX
"InstallShield_{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{FAF0DAD8-1EA7-4FEF-80E5-8D8D6EBD5A23}" = Canon RAW Image Task for ZoomBrowser EX
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.3.0 (Full)
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"Sony Vocal Eraser_is1" = Sony Vocal Eraser
"uTorrent" = µTorrent
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Antimalware Doctor" = Antimalware Doctor

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21/03/2011 5:55:09 PM | Computer Name = Alessandra-PC | Source = EventSystem | ID = 4621
Description =

Error - 22/03/2011 5:24:32 PM | Computer Name = Alessandra-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/03/2011 5:32:47 PM | Computer Name = Alessandra-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 22/03/2011 7:34:05 PM | Computer Name = Alessandra-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 22/03/2011 7:34:05 PM | Computer Name = Alessandra-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7220319

Error - 22/03/2011 7:34:05 PM | Computer Name = Alessandra-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7220319

Error - 23/03/2011 5:33:50 PM | Computer Name = Alessandra-PC | Source = WinMgmt | ID = 10
Description =

Error - 24/03/2011 4:37:22 AM | Computer Name = Alessandra-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 24/03/2011 4:37:23 AM | Computer Name = Alessandra-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7594597

Error - 24/03/2011 4:37:23 AM | Computer Name = Alessandra-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7594597

[ System Events ]
Error - 5/04/2011 10:12:26 AM | Computer Name = Alessandra-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 5/04/2011 10:34:01 AM | Computer Name = Alessandra-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 5/04/2011 10:36:23 AM | Computer Name = Alessandra-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022FB197D38 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/04/2011 8:44:48 PM | Computer Name = Alessandra-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 5/04/2011 8:46:32 PM | Computer Name = Alessandra-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022FB197D38 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/04/2011 8:49:13 PM | Computer Name = Alessandra-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 5/04/2011 8:58:56 PM | Computer Name = Alessandra-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022FB197D38 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/04/2011 9:17:24 PM | Computer Name = Alessandra-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022FB197D38 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/04/2011 12:48:21 AM | Computer Name = Alessandra-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/04/2011 12:50:46 AM | Computer Name = Alessandra-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022FB197D38 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).


< End of report >
ok here's the MBR cheak MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 2 (build 6002), 32-bit Base Board Manufacturer: Dell Inc. BIOS Manufacturer: Dell Inc. System Manufacturer: Dell Inc. System Product Name: Studio 1537 Logical Drives Mask: 0x0000003c Kernel Drivers (total 165): 0x8243F000 \SystemRoot\system32\ntkrnlpa.exe 0x8240C000 \SystemRoot\system32\hal.dll 0x80401000 \SystemRoot\system32\kdcom.dll 0x80408000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x80478000 \SystemRoot\system32\PSHED.dll 0x80489000 \SystemRoot\system32\BOOTVID.dll 0x80491000 \SystemRoot\system32\CLFS.SYS 0x804D2000 \SystemRoot\system32\CI.dll 0x8060D000 \SystemRoot\system32\drivers\Wdf01000.sys 0x80689000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x80696000 \SystemRoot\system32\drivers\acpi.sys 0x806DC000 \SystemRoot\system32\drivers\WMILIB.SYS 0x806E5000 \SystemRoot\system32\drivers\msisadrv.sys 0x806ED000 \SystemRoot\system32\drivers\pci.sys 0x80714000 \SystemRoot\System32\drivers\partmgr.sys 0x80723000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x80726000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x80730000 \SystemRoot\system32\drivers\volmgr.sys 0x8073F000 \SystemRoot\System32\drivers\volmgrx.sys 0x80789000 \SystemRoot\System32\drivers\mountmgr.sys 0x80799000 \SystemRoot\system32\drivers\atapi.sys 0x807A1000 \SystemRoot\system32\drivers\ataport.SYS 0x807BF000 \SystemRoot\system32\drivers\msahci.sys 0x807C9000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x805B2000 \SystemRoot\system32\drivers\fltmgr.sys 0x807D7000 \SystemRoot\system32\drivers\fileinfo.sys 0x807E7000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x82A0D000 \SystemRoot\System32\Drivers\ksecdd.sys 0x82A7E000 \SystemRoot\system32\drivers\ndis.sys 0x82B89000 \SystemRoot\system32\drivers\msrpc.sys 0x82BB4000 \SystemRoot\system32\drivers\NETIO.SYS 0x8A406000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8A516000 \SystemRoot\system32\drivers\volsnap.sys 0x8A54F000 \SystemRoot\System32\Drivers\spldr.sys 0x8A557000 \SystemRoot\System32\Drivers\mup.sys 0x8A566000 \SystemRoot\System32\drivers\ecache.sys 0x8A58D000 \SystemRoot\system32\drivers\disk.sys 0x8A59E000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x8A5BF000 \SystemRoot\system32\drivers\crcdisk.sys 0x8A5EA000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8A5F5000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x8E208000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x8E804000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8E8A4000 \SystemRoot\System32\drivers\watchdog.sys 0x8E8B0000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8E93D000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8E948000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8E986000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8EA0A000 \SystemRoot\system32\DRIVERS\NETw5v32.sys 0x8ED92000 \SystemRoot\system32\DRIVERS\k57nd60x.sys 0x8EDC7000 \SystemRoot\system32\DRIVERS\ohci1394.sys 0x8EDD7000 \SystemRoot\system32\DRIVERS\1394BUS.SYS 0x8EDE5000 \SystemRoot\system32\DRIVERS\sdbus.sys 0x8E995000 \SystemRoot\system32\DRIVERS\rimmptsk.sys 0x8E9A6000 \SystemRoot\system32\DRIVERS\rimsptsk.sys 0x8E79F000 \SystemRoot\system32\DRIVERS\rixdptsk.sys 0x8F008000 \SystemRoot\system32\DRIVERS\itecir.sys 0x8F060000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x8F073000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8F07E000 \SystemRoot\system32\DRIVERS\Apfiltr.sys 0x8F0AB000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8F0B6000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8F0CE000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x8F0D4000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8F0E3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x8F0EC000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x8F0F0000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8F11F000 \SystemRoot\system32\DRIVERS\storport.sys 0x8F160000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8F16B000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8F182000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8F18D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8F1B0000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8F1BF000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8F1D3000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8F1E8000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8F1F8000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8E9BA000 \SystemRoot\system32\DRIVERS\ks.sys 0x8E9E4000 \SystemRoot\system32\DRIVERS\circlass.sys 0x8EA00000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8E9F2000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8F800000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8F835000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8F846000 \SystemRoot\system32\drivers\HdAudio.sys 0x8F885000 \SystemRoot\system32\drivers\portcls.sys 0x8F8B2000 \SystemRoot\system32\drivers\drmk.sys 0x8F8D7000 \SystemRoot\system32\DRIVERS\stwrt.sys 0x8F93B000 \SystemRoot\system32\DRIVERS\hidir.sys 0x8F946000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x8F956000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x8F95D000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x8F966000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x8F96E000 \SystemRoot\system32\DRIVERS\MpFilter.sys 0x8F991000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8F99A000 \SystemRoot\System32\Drivers\Null.SYS 0x8F9A1000 \SystemRoot\System32\Drivers\Beep.SYS 0x8F9A8000 \SystemRoot\System32\drivers\vga.sys 0x8F9B4000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8F9D5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8F9DD000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8F9E5000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8F9F0000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8E7F1000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x8FA04000 \SystemRoot\System32\drivers\tcpip.sys 0x8FAEE000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8FB09000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8FB1F000 \SystemRoot\system32\DRIVERS\smb.sys 0x8FB33000 \SystemRoot\system32\drivers\afd.sys 0x8FB7B000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8FBAD000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8FBC3000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8FBD1000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8FC0C000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8FC48000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8FC52000 \SystemRoot\System32\Drivers\dfsc.sys 0x8FC69000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x8FC80000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8FC82000 \SystemRoot\system32\DRIVERS\OA001Vid.sys 0x8FCC6000 \SystemRoot\system32\DRIVERS\OA001Ufd.sys 0x8FCEA000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0x8FCFF000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8FD08000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8FD15000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x8FD20000 \SystemRoot\System32\Drivers\dump_msahci.sys 0x9C250000 \SystemRoot\System32\win32k.sys 0x8FD2A000 \SystemRoot\System32\drivers\Dxapi.sys 0x8FD34000 \SystemRoot\system32\DRIVERS\monitor.sys 0x9C470000 \SystemRoot\System32\TSDDD.dll 0x9C490000 \SystemRoot\System32\cdd.dll 0x9C4A0000 \SystemRoot\System32\ATMFD.DLL 0x8FD43000 \SystemRoot\system32\drivers\luafv.sys 0xA0E0A000 \SystemRoot\system32\drivers\spsys.sys 0xA0EBA000 \SystemRoot\system32\DRIVERS\lltdio.sys 0xA0ECA000 \SystemRoot\system32\DRIVERS\nwifi.sys 0xA0EF4000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA0EFE000 \SystemRoot\system32\DRIVERS\rspndr.sys 0xA0F11000 \SystemRoot\system32\drivers\HTTP.sys 0xA0F7E000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xA0F9B000 \SystemRoot\system32\DRIVERS\bowser.sys 0xA0FB4000 \SystemRoot\System32\drivers\mpsdrv.sys 0xA0FC9000 \SystemRoot\system32\drivers\mrxdav.sys 0x8FD5E000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x8FD7D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x8FDB6000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x8FDCE000 \SystemRoot\System32\DRIVERS\srv2.sys 0xA1608000 \SystemRoot\System32\DRIVERS\srv.sys 0xA166E000 \SystemRoot\system32\DRIVERS\ACFSDK32.sys 0xA1672000 \SystemRoot\system32\drivers\peauth.sys 0xA1750000 \SystemRoot\System32\Drivers\fastfat.SYS 0xA1778000 \SystemRoot\System32\Drivers\secdrv.SYS 0xA1782000 \SystemRoot\System32\drivers\tcpipreg.sys 0xA178E000 \SystemRoot\system32\DRIVERS\ACFXAU32.sys 0xA1796000 \SystemRoot\System32\Drivers\BTHUSB.sys 0xA3E0A000 \SystemRoot\System32\Drivers\bthport.sys 0xA3E8A000 \SystemRoot\system32\DRIVERS\rfcomm.sys 0xA3EB3000 \SystemRoot\system32\DRIVERS\BthEnum.sys 0xA3EBD000 \SystemRoot\system32\DRIVERS\bthpan.sys 0xA3ED7000 \SystemRoot\system32\drivers\btwavdt.sys 0xA3F48000 \SystemRoot\system32\drivers\btwaudio.sys 0xA3FC8000 \SystemRoot\system32\DRIVERS\btwl2cap.sys 0xA3FD2000 \SystemRoot\system32\DRIVERS\btwrchid.sys 0xA3FD5000 \SystemRoot\system32\DRIVERS\MpNWMon.sys 0xA3FDE000 \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D62022C1-AF51-403B-8475-31D9F31255C0}\MpKsla30762e3.sys 0xA3FE4000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x773C0000 \Windows\System32\ntdll.dll Processes (total 84): 0 System Idle Process 4 System 420 C:\Windows\System32\smss.exe 552 csrss.exe 612 C:\Windows\System32\wininit.exe 624 csrss.exe 656 C:\Windows\System32\services.exe 668 C:\Windows\System32\lsass.exe 676 C:\Windows\System32\lsm.exe 756 C:\Windows\System32\winlogon.exe 868 C:\Windows\System32\svchost.exe 928 C:\Windows\System32\svchost.exe 980 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe 1076 C:\Windows\System32\Ati2evxx.exe 1116 C:\Windows\System32\svchost.exe 1140 C:\Windows\System32\svchost.exe 1168 C:\Windows\System32\svchost.exe 1200 C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe 1344 C:\Windows\System32\audiodg.exe 1432 C:\Windows\System32\svchost.exe 1456 C:\Windows\System32\SLsvc.exe 1484 C:\Windows\System32\svchost.exe 1596 C:\Windows\System32\Ati2evxx.exe 1760 C:\Windows\System32\svchost.exe 1936 C:\Windows\System32\spoolsv.exe 1964 C:\Windows\System32\svchost.exe 436 C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe 520 C:\Windows\System32\svchost.exe 516 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 544 C:\Program Files\Bonjour\mDNSResponder.exe 604 C:\Windows\System32\svchost.exe 856 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 800 C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe 1016 C:\Windows\System32\CTSVCCDA.EXE 1468 C:\Program Files\Sensible Vision\Fast Access\FAService.exe 1972 C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe 2084 C:\Windows\System32\svchost.exe 2148 C:\Program Files\Microsoft\BingBar\SeaPort.EXE 2200 C:\Windows\System32\svchost.exe 2256 C:\Windows\System32\svchost.exe 2280 C:\Windows\System32\SearchIndexer.exe 2356 C:\Windows\System32\drivers\ACFXAU32.exe 2944 C:\Windows\System32\dwm.exe 2980 C:\Windows\explorer.exe 3084 C:\Windows\System32\taskeng.exe 3288 C:\Windows\System32\taskeng.exe 3540 C:\Program Files\DellTPad\Apoint.exe 3556 C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe 3576 C:\Program Files\Sensible Vision\Fast Access\FATrayMon.exe 3640 C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe 3652 C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe 3660 C:\Program Files\Dell\MediaDirect\PCMService.exe 3668 C:\Program Files\Dell Support Center\bin\sprtcmd.exe 3676 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe 3692 C:\Program Files\IDT\WDM\sttray.exe 3700 C:\Program Files\Sensible Vision\Fast Access\FATrayAlert.exe 3708 C:\Program Files\Epson Software\Event Manager\EEventManager.exe 3732 C:\Program Files\Java\jre6\bin\jusched.exe 3772 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 3788 C:\Program Files\Microsoft Security Essentials\msseces.exe 1012 C:\Program Files\DellTPad\ApMsgFwd.exe 1568 C:\Program Files\DellTPad\hidfind.exe 2880 C:\Program Files\DellTPad\ApntEx.exe 3116 C:\Program Files\iTunes\iTunesHelper.exe 3280 C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe 3252 C:\Program Files\HP\HP Software Update\hpwuschd2.exe 3324 C:\Program Files\Windows Sidebar\sidebar.exe 3340 C:\Windows\ehome\ehtray.exe 2852 C:\Program Files\Dell\QuickSet\quickset.exe 3412 C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE 1296 C:\Windows\ehome\ehmsas.exe 3032 WmiPrvSE.exe 3388 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 2580 C:\Program Files\iPod\bin\iPodService.exe 4544 C:\Windows\System32\svchost.exe 4588 C:\Program Files\Dell Support Center\bin\sprtsvc.exe 4696 C:\Windows\System32\svchost.exe 5500 C:\Windows\System32\wuauclt.exe 5708 C:\Program Files\Windows Media Player\wmpnscfg.exe 5748 C:\Program Files\Windows Media Player\wmpnetwk.exe 5192 C:\Windows\System32\SearchProtocolHost.exe 5648 C:\Windows\System32\SearchFilterHost.exe 3596 C:\Windows\System32\SearchProtocolHost.exe 4568 C:\Users\Alessandra\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000002`88e00000 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`08e00000 (NTFS) \\.\F: –> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS) PhysicalDrive0 Model Number: WDCWD3200BEVT-75ZCT2, Rev: 11.01A11 PhysicalDrive1 Model Number: WD3200BEV External, Rev: 1.75 Size Device Name MBR Status ——————————————– 298 GB \\.\PhysicalDrive0 Windows Vista MBR code detected SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979 298 GB \\.\PhysicalDrive1 RE: Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
Hi alessandra23,

No problem :)

Please do the following:

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your  Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: 
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
and here is the Gmer

GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-06 16:24:25
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200BEVT-75ZCT2 rev.11.01A11
Running: gmer.exe; Driver: C:\Users\ALESSA~1\AppData\Local\Temp\uwdyakod.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8E209000, 0x20BE32, 0xE8000020]

—- Devices - GMER 1.0.15 —-

Device \Driver\BTHUSB \Device\00000081 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000083 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BthPort\Parameters\Keys\00225f4c70d4
Reg HKLM\SYSTEM\ControlSet002\Services\BthPort\Parameters\Keys\00225f4c70d4 (not active ControlSet)

—- EOF - GMER 1.0.15 —-
here's othe Combofix ComboFix 11-04-05.02 - Alessandra 06/04/2011 16:51:55.2.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3066.1341 [GMT 10:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66} SP: Microsoft Security Essentials *Disabled/Updated* {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547 c:\users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\enemies-names.txt c:\users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\k70ccreloc.exe c:\users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\local.ini c:\users\Alessandra\AppData\Roaming\Adobe\plugs c:\users\Alessandra\AppData\Roaming\Adobe\shed F:\Autorun.inf . . ((((((((((((((((((((((((( Files Created from 2011-03-06 to 2011-04-06 ))))))))))))))))))))))))))))))) . . 2011-04-06 06:58 . 2011-04-06 06:58 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-04-06 05:31 . 2011-04-06 05:31 100480 —-a-w- C:\uwdyakod.sys 2011-04-05 14:13 . 2011-04-06 04:58 ——– d—–w- c:\users\Alessandra\AppData\Local\Adobe 2011-04-01 08:32 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D62022C1-AF51-403B-8475-31D9F31255C0}\mpengine.dll 2011-03-23 21:43 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-23 21:43 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll 2011-03-23 21:43 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll 2011-03-15 11:15 . 2011-03-15 11:16 ——– d—–w- c:\programdata\HP Photo Creations 2011-03-15 11:15 . 2011-03-15 11:15 ——– d—–w- c:\program files\HP Photo Creations 2011-03-15 11:14 . 2011-03-15 11:14 ——– d—–w- c:\users\Alessandra\AppData\Roaming\HpUpdate 2011-03-15 11:12 . 2011-03-15 11:12 ——– d—–w- c:\programdata\HP 2011-03-15 11:12 . 2011-03-15 11:14 ——– d—–w- c:\program files\HP 2011-03-15 11:11 . 2011-03-15 11:29 ——– d—–w- c:\users\Alessandra\AppData\Local\HP 2011-03-15 11:10 . 2010-11-16 23:48 213864 —-a-w- c:\windows\system32\hpinkcoi8711.dll 2011-03-15 11:10 . 2010-11-16 23:48 267112 —-a-w- c:\windows\system32\hpinksts8711LM.dll 2011-03-15 11:09 . 2010-11-16 23:48 1792872 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ2050_510g.dll 2011-03-13 09:36 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-03-13 09:36 . 2010-12-29 18:28 322560 —-a-w- c:\windows\system32\sbe.dll 2011-03-13 09:36 . 2010-12-29 18:28 153088 —-a-w- c:\windows\system32\sbeio.dll 2011-03-13 09:36 . 2010-12-29 18:26 177664 —-a-w- c:\windows\system32\mpg2splt.ax 2011-03-13 09:36 . 2010-12-17 15:45 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-03-13 09:36 . 2010-12-17 13:54 677888 —-a-w- c:\windows\system32\mstsc.exe . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-15 04:05 . 2010-02-21 23:42 6792528 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-01-20 16:37 . 2011-02-12 00:45 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-01-20 16:08 . 2011-02-12 00:45 478720 —-a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08 . 2011-02-12 00:45 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08 . 2011-02-12 00:45 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08 . 2011-02-12 00:45 1029120 —-a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:08 . 2011-02-12 00:45 189952 —-a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:07 . 2011-02-12 00:45 37376 —-a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07 . 2011-02-12 00:45 258048 —-a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07 . 2011-02-12 00:45 586240 —-a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06 . 2011-02-12 00:45 2873344 —-a-w- c:\windows\system32\mf.dll 2011-01-20 16:06 . 2011-02-12 00:45 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04 . 2011-02-12 00:45 209920 —-a-w- c:\windows\system32\mfplat.dll 2011-01-20 16:04 . 2011-02-12 00:45 98816 —-a-w- c:\windows\system32\mfps.dll 2011-01-20 14:28 . 2011-02-12 00:45 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27 . 2011-02-12 00:45 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26 . 2011-02-12 00:45 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25 . 2011-02-12 00:45 847360 —-a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24 . 2011-02-12 00:45 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15 . 2011-02-12 00:45 979456 —-a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14 . 2011-02-12 00:45 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14 . 2011-02-12 00:45 302592 —-a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:14 . 2011-02-12 00:45 261632 —-a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:12 . 2011-02-12 00:45 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11 . 2011-02-12 00:45 486400 —-a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47 . 2011-02-12 00:45 683008 —-a-w- c:\windows\system32\d2d1.dll 2011-01-08 08:47 . 2011-02-12 00:44 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-01-08 06:28 . 2011-02-12 00:44 292352 —-a-w- c:\windows\system32\atmfd.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-07-17 196608] "VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440] "FATrayAlert"="c:\program files\Sensible Vision\Fast Access\FATrayMon.exe" [2008-09-05 95488] "Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635] "Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-08-15 611712] "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-14 1094224] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-10-25 932288] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] . c:\users\Alessandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-3-12 50688] QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-9 1616976] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess] 2008-09-05 09:16 140544 —-a-w- c:\program files\Sensible Vision\Fast Access\FALogNot.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2009-03-11 17:27 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R1 MpKsla30762e3;MpKsla30762e3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D62022C1-AF51-403B-8475-31D9F31255C0}\MpKsla30762e3.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 acfva;acfva;c:\windows\system32\DRIVERS\ACFVA32.sys [2007-11-13 86656] R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-14 284016] R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 dgcfltr;DGC Filter Driver;c:\windows\system32\DRIVERS\ACFDCP32.sys [2007-11-13 28928] R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [2008-08-02 230912] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2008-12-22 81920] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504] S2 FAService;FAService;c:\program files\Sensible Vision\Fast Access\FAService.exe [2008-09-05 2340096] S2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-03-09 86016] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-06-16 29736] S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2008-07-28 54784] S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-05-29 203264] S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-07-04 3663360] S3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\DRIVERS\OA001Ufd.sys [2008-10-27 144672] S3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\DRIVERS\OA001Vid.sys [2008-10-27 277440] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder . 2011-03-16 c:\windows\Tasks\hpwebreg_CN11O3925G05D1.job - c:\program files\HP\HP Deskjet 2050 J510 series\Bin\hpwebreg.exe [2010-11-16 10:16] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com.au/ mStart Page = hxxp://search.shareware.pro/?lang=en uInternet Settings,ProxyOverride = *.local IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm Trusted Zone: latrobe.edu.au\owa . - - - - ORPHANS REMOVED - - - - . HKCU-Run-AdobeBridge - (no file) HKCU-Run-k70ccreloc.exe - c:\users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\k70ccreloc.exe HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe HKLM-Run-FAStartup - (no file) . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(3372) c:\windows\system32\btncopy.dll . ———————— Other Running Processes ———————— . c:\program files\Microsoft Security Essentials\MsMpEng.exe c:\windows\system32\Ati2evxx.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe c:\windows\system32\Ati2evxx.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe c:\windows\system32\CTsvcCDA.exe c:\program files\Microsoft\BingBar\SeaPort.EXE c:\windows\system32\DRIVERS\ACFXAU32.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2011-04-06 17:08:06 - machine was rebooted ComboFix-quarantined-files.txt 2011-04-06 07:07 ComboFix2.txt 2010-02-18 02:34 . Pre-Run: 182,535,274,496 bytes free Post-Run: 182,670,299,136 bytes free . - - End Of File - - 11BC050CC849F128515E2A7A91D53460
How is your computer running now?


I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
hi the version ESET I downloaded from the link provided didn't have the details tab, it had something else so I just saved that. here's the log C:\Qoobox\Quarantine\C\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\enemies-names.txt.vir Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Qoobox\Quarantine\C\Users\Alessandra\AppData\Roaming\636208FD9E2A5AA0845378E6ABC8D547\local.ini.vir Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Users\Alessandra\Documents\media.player.codec.pack.v3.9.6.setup.exe Win32/Adware.Toolbar.Dealio application I hope I did that right. My lapto is running ok its a bit slow but other than that it's ok. the antimalware doctor has stoped popping up.
Hi,

Thanks for the log. Everything looks good. We need to get rid of one more bad file, but besides that your computer appears to be clean, so your machine's sluggishness is probably due to something else. We still need to clean up the tools we used after this, so please stay with the thread.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Users\Alessandra\Documents\media.player.codec.pack.v3.9.6.setup.exe
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste
here are the results

ComboFix 11-04-05.02 - Alessandra 09/04/2011 9:41.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3066.1751 [GMT 10:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Alessandra\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66}
SP: Microsoft Security Essentials *Disabled/Updated* {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Alessandra\Documents\media.player.codec.pack.v3.9.6.setup.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Alessandra\Documents\media.player.codec.pack.v3.9.6.setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-08 to 2011-04-08 )))))))))))))))))))))))))))))))
.
.
2011-04-08 23:48 . 2011-04-08 23:49 ——– d—–w- c:\users\Alessandra\AppData\Local\temp
2011-04-08 23:48 . 2011-04-08 23:48 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-04-08 23:48 . 2011-04-08 23:48 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-08 23:26 . 2011-04-08 23:26 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{36DC7D8C-D3BC-4618-B60B-0517A029650C}\MpKsl9df32847.sys
2011-04-08 07:36 . 2011-04-08 07:36 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{36DC7D8C-D3BC-4618-B60B-0517A029650C}\MpKsla20fcbba.sys
2011-04-08 07:36 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{36DC7D8C-D3BC-4618-B60B-0517A029650C}\mpengine.dll
2011-04-07 07:04 . 2011-04-07 07:04 ——– d—–w- c:\program files\ESET
2011-04-06 05:31 . 2011-04-06 05:31 100480 —-a-w- C:\uwdyakod.sys
2011-04-05 14:13 . 2011-04-06 04:58 ——– d—–w- c:\users\Alessandra\AppData\Local\Adobe
2011-03-23 21:43 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 21:43 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-23 21:43 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-15 11:15 . 2011-03-15 11:16 ——– d—–w- c:\programdata\HP Photo Creations
2011-03-15 11:15 . 2011-03-15 11:15 ——– d—–w- c:\program files\HP Photo Creations
2011-03-15 11:14 . 2011-03-15 11:14 ——– d—–w- c:\users\Alessandra\AppData\Roaming\HpUpdate
2011-03-15 11:12 . 2011-03-15 11:12 ——– d—–w- c:\programdata\HP
2011-03-15 11:12 . 2011-03-15 11:14 ——– d—–w- c:\program files\HP
2011-03-15 11:11 . 2011-03-15 11:29 ——– d—–w- c:\users\Alessandra\AppData\Local\HP
2011-03-15 11:10 . 2010-11-16 23:48 213864 —-a-w- c:\windows\system32\hpinkcoi8711.dll
2011-03-15 11:10 . 2010-11-16 23:48 267112 —-a-w- c:\windows\system32\hpinksts8711LM.dll
2011-03-15 11:09 . 2010-11-16 23:48 1792872 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ2050_510g.dll
2011-03-13 09:36 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-03-13 09:36 . 2010-12-29 18:28 322560 —-a-w- c:\windows\system32\sbe.dll
2011-03-13 09:36 . 2010-12-29 18:28 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-03-13 09:36 . 2010-12-29 18:26 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-13 09:36 . 2010-12-17 15:45 2067968 —-a-w- c:\windows\system32\mstscax.dll
2011-03-13 09:36 . 2010-12-17 13:54 677888 —-a-w- c:\windows\system32\mstsc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-15 04:05 . 2010-02-21 23:42 6792528 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-01-20 16:37 . 2011-02-12 00:45 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-12 00:45 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-12 00:45 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-12 00:45 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-12 00:45 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:08 . 2011-02-12 00:45 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:07 . 2011-02-12 00:45 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-12 00:45 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-12 00:45 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-12 00:45 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-12 00:45 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-12 00:45 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-12 00:45 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-12 00:45 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-12 00:45 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-12 00:45 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-12 00:45 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-12 00:45 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-12 00:45 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-12 00:45 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-12 00:45 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14 . 2011-02-12 00:45 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12 . 2011-02-12 00:45 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-12 00:45 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-12 00:45 683008 —-a-w- c:\windows\system32\d2d1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-07-17 196608]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"FATrayAlert"="c:\program files\Sensible Vision\Fast Access\FATrayMon.exe" [2008-09-05 95488]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-08-15 611712]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-14 1094224]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-10-25 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"FAStartup"="" [BU]
.
c:\users\Alessandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-3-12 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-9 1616976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2008-09-05 09:16 140544 —-a-w- c:\program files\Sensible Vision\Fast Access\FALogNot.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-03-11 17:27 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R1 MpKsla30762e3;MpKsla30762e3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D62022C1-AF51-403B-8475-31D9F31255C0}\MpKsla30762e3.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-03-09 86016]
R3 acfva;acfva;c:\windows\system32\DRIVERS\ACFVA32.sys [2007-11-13 86656]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-14 284016]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 dgcfltr;DGC Filter Driver;c:\windows\system32\DRIVERS\ACFDCP32.sys [2007-11-13 28928]
R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [2008-08-02 230912]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 MpKsl9df32847;MpKsl9df32847;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{36DC7D8C-D3BC-4618-B60B-0517A029650C}\MpKsl9df32847.sys [2011-04-08 28752]
S1 MpKsla20fcbba;MpKsla20fcbba;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{36DC7D8C-D3BC-4618-B60B-0517A029650C}\MpKsla20fcbba.sys [2011-04-08 28752]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2008-12-22 81920]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 FAService;FAService;c:\program files\Sensible Vision\Fast Access\FAService.exe [2008-09-05 2340096]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-06-16 29736]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2008-07-28 54784]
S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-05-29 203264]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-07-04 3663360]
S3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\DRIVERS\OA001Ufd.sys [2008-10-27 144672]
S3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\DRIVERS\OA001Vid.sys [2008-10-27 277440]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL9DF32847
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-16 c:\windows\Tasks\hpwebreg_CN11O3925G05D1.job
- c:\program files\HP\HP Deskjet 2050 J510 series\Bin\hpwebreg.exe [2010-11-16 10:16]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
mStart Page = hxxp://search.shareware.pro/?lang=en
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: latrobe.edu.au\owa
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-09 09:49
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\users\ALESSA~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-09 09:50:56
ComboFix-quarantined-files.txt 2011-04-08 23:50
ComboFix2.txt 2011-04-06 07:08
ComboFix3.txt 2010-02-18 02:34
.
Pre-Run: 182,487,711,744 bytes free
Post-Run: 182,493,519,872 bytes free
.
- - End Of File - - A41B23C5E92A6FD54368C1E4FB7722A1

my laptop seems to be back to normal speed now
Great! Time for cleanup.


Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

Please delete GMER and MBRCheck from your desktop.

===================================================

Your Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 24.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u24-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • Click Start > Run
  • Type Inetcpl.cpl and click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected and Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update   regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Do you have any further questions?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI