This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer hangs and freezes

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!

Recently, when I started my PC

1) My windows firewall icon shows "turn off", and it reverts back to normal after 30 seconds or so after i have started up my computer (i have already set the settings to "on" on the windows firewall page)
2) My screen freezes sometimes, i'm not too sure if its hardware issue or virus
3) even my mozilla browser freezes and hangs (this happens quite frequently now)
4) I am using a wireless USB adaptor to connect to the internet, it has been working fine all the while, but recently, it doesn't connect automatically to the internet and i have to manually right click on the icon and select "repair" every single time to connect to the Internet.
5) I have the "windows update icon" located at my taskbar and even though i try to install the updates, the icon is always there when i turn on my PC

Did a Norton scan and all are fine.

Have downloaded OTL and attached are the findings… appreciate your kind advise!

Thanks

OTL.TXT
OTL logfile created on: 4/11/2011 8:38:16 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 151.00 Mb Available Physical Memory | 30.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 24.07 Gb Free Space | 61.63% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 23.75 Gb Free Space | 63.74% Space Free | Partition Type: NTFS

Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\user\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\user\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110410.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110410.002\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110408.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110225.002\BHDrvx86.sys (Symantec Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (SMCWGU(SMC)) SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) – C:\WINDOWS\system32\drivers\SMCWGU.sys (SMC Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC52) Intel® – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://sg.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/01/08 13:34:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 10:43:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 10:43:32 | 000,000,000 | —D | M]

[2010/06/23 19:14:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions
[2010/12/12 08:39:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/30 23:22:13 | 000,002,567 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\searchplugins\askcom.xml
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/24 21:04:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/19 16:51:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/01/08 13:34:21 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPLGN
[2010/12/19 16:50:56 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/12/19 16:50:55 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WINDVDPatch] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SMCWUSB-G 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/30 14:18:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ctmp3 - C:\WINDOWS\system32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/30 23:19:43 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\AskToolbar
[2011/03/30 23:18:09 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2011/03/30 23:17:38 | 000,000,000 | —D | C] – C:\Program Files\DsNET Corp
[2011/03/30 07:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\SelfMV
[2011/03/30 07:43:45 | 000,000,000 | —D | C] – C:\Program Files\MyFree Codec
[2011/03/28 18:01:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Samsung
[2011/03/28 18:00:01 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\WINDOWS\System32\dgderapi.dll
[2011/03/28 18:00:01 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\DIFxAPI.dll
[2011/03/28 18:00:01 | 000,020,032 | —- | C] (Devguru Co., Ltd) – C:\WINDOWS\System32\drivers\dgderdrv.sys
[2011/03/28 17:34:04 | 000,163,840 | —- | C] (CANON INC.) – C:\WINDOWS\BJPSUNST.EXE
[2011/03/28 17:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CD-LabelPrint
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\WINDOWS\StartHtmico
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200 Manual
[2011/03/28 17:29:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200
[2011/03/28 17:29:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/03/28 15:26:35 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2011/03/28 15:17:20 | 000,140,288 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM78.DLL
[2011/03/28 15:17:15 | 000,090,112 | R— | C] (CANON INC.) – C:\WINDOWS\System32\CNMCP78.exe
[2011/03/25 00:52:28 | 000,000,000 | —D | C] – C:\Temp
[2011/03/23 20:32:32 | 000,000,000 | —D | C] – C:\WINDOWS\System32\System32
[2011/03/22 23:04:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Samsung
[2011/03/22 23:03:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\samsung
[2011/03/22 01:26:13 | 000,136,680 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdm.sys
[2011/03/22 01:26:13 | 000,012,776 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdfl.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcmnt.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcm.sys
[2011/03/22 01:26:11 | 000,121,192 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadbus.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwhnt.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwh.sys
[2011/03/22 01:23:21 | 004,659,712 | —- | C] (Dmitry Streblechenko) – C:\WINDOWS\System32\Redemption.dll
[2011/03/22 01:21:57 | 000,000,000 | —D | C] – C:\Program Files\MarkAny
[2011/03/22 01:18:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Program Files\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/03/22 01:16:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2011/03/22 01:16:09 | 000,016,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/03/22 01:14:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\umdf
[2011/03/22 01:09:33 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Downloaded Installations
[2007/02/20 13:16:14 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/11 20:26:39 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/11 20:26:36 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.CDF
[2011/04/11 20:26:36 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.BAK
[2011/04/11 20:26:26 | 000,081,191 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/11 20:26:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/11 20:25:56 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2011/04/11 07:34:53 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/11 07:34:53 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/04/11 07:34:53 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/04/11 07:34:53 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/11 07:34:53 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/09 14:01:09 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/04/07 21:46:04 | 001,562,228 | —- | M] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/04/05 07:57:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/05 07:49:14 | 000,025,088 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 23:19:20 | 000,000,839 | —- | M] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/29 22:15:00 | 000,170,722 | —- | M] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:18 | 000,001,612 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/25 00:51:22 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/22 23:03:29 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/03/22 01:16:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/22 01:16:20 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | M] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/07 21:46:04 | 001,562,228 | —- | C] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/03/30 23:19:20 | 000,000,839 | —- | C] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/30 23:18:19 | 000,000,232 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/03/29 22:15:00 | 000,170,722 | —- | C] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:17 | 000,001,612 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/28 15:17:20 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2011/03/25 00:51:22 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/23 07:43:36 | 000,240,160 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/22 01:16:20 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | C] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[2011/01/29 17:00:24 | 000,030,568 | —- | C] () – C:\WINDOWS\MusiccityDownload.exe
[2011/01/29 17:00:22 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2011/01/29 17:00:22 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/29 17:00:22 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/29 17:00:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/01 03:13:12 | 008,596,886 | —- | C] () – C:\Documents and Settings\user\Application Data\Black Eyed Peas - The Time (Dirty Bit).zip
[2010/11/14 18:23:30 | 007,198,459 | —- | C] () – C:\Documents and Settings\user\Application Data\Kesha - We R Who We R.zip
[2010/10/21 19:16:51 | 000,001,940 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/21 07:41:34 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/03 00:51:48 | 000,016,384 | —- | C] () – C:\Documents and Settings\user\Application Data\tc7.exe
[2010/09/04 00:54:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/23 19:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/05/19 19:18:06 | 000,016,384 | —- | C] () – C:\Documents and Settings\user\Application Data\nn8.exe
[2009/10/06 15:16:00 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/16 09:26:11 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/04 20:02:08 | 000,025,088 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/09 19:25:59 | 000,000,398 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2008/06/07 15:04:14 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/06/07 15:04:14 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/06/07 15:04:07 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/07 15:04:05 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/06/07 15:04:03 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/06/07 15:03:46 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/06/07 15:03:46 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2008/06/07 15:03:41 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/04/25 20:22:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:17:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2007/02/20 13:17:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2007/02/20 13:16:44 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2007/02/20 13:16:44 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/02/20 13:16:35 | 000,164,044 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2007/02/20 13:16:35 | 000,113,373 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2007/02/20 13:16:35 | 000,113,273 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2007/02/20 13:16:33 | 000,179,669 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2007/02/20 13:16:33 | 000,044,055 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2007/02/20 13:16:22 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2007/02/20 13:16:22 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2007/02/20 13:16:20 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2007/02/20 13:16:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2007/02/20 12:35:52 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/03/20 23:36:32 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/30 22:09:29 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/30 22:08:17 | 000,134,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/30 14:43:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/30 14:38:37 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/11/30 14:38:37 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/30 14:38:36 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/30 14:21:25 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/11/30 14:15:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2004/08/04 20:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 20:00:00 | 000,432,686 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 20:00:00 | 000,067,516 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 20:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 20:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 20:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/03/14 12:24:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ZyDelReg.exe
[1999/01/23 02:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2011/03/28 17:29:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/06/27 10:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/12/23 11:09:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLive
[2011/03/28 17:56:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2010/11/08 21:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Thomson Reuters
[2010/07/03 19:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/02/20 21:02:15 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ICAClient
[2008/11/09 19:26:04 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\NJStar
[2011/03/28 17:55:55 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Samsung
[2006/10/20 20:27:46 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sports Interactive
[2006/09/17 17:18:52 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Teleca
[2010/11/04 19:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Tific
[2011/04/05 00:48:57 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\uTorrent
[2011/04/09 14:01:09 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/11/30 14:18:49 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/11/30 14:12:58 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/12/18 15:29:25 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/11/30 14:18:49 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/04/11 20:25:56 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2005/11/30 14:18:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/11/30 14:18:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 20:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/04/11 20:25:55 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2005/11/30 14:27:04 | 000,000,090 | —- | M] () – C:\setup.log
[2009/07/30 20:04:54 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/08/14 07:12:25 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/08/14 07:26:47 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/08/14 20:05:58 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/08/14 21:40:59 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/08/14 22:28:32 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/08/16 09:26:37 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/08/16 10:06:08 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/08/16 18:07:34 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/08/17 22:16:39 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/08/18 13:07:12 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/08/18 14:13:20 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/08/19 07:16:38 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/08/20 13:56:16 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/09/03 21:00:07 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/07/14 07:43:03 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/07/14 20:46:22 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/07/29 07:42:37 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/07/30 00:33:31 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/07/30 07:40:29 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/07/30 20:04:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/08/14 07:12:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/08/14 07:26:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/08/14 20:05:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/08/14 21:40:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/08/14 22:28:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/08/16 09:26:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/08/16 10:06:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/08/16 18:07:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/08/17 22:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/08/18 13:07:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/08/18 14:13:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/08/19 07:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/08/20 13:56:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/09/03 21:00:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/07/14 07:43:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/07/14 20:46:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/07/29 07:42:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/07/30 00:33:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/07/30 07:40:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/11/30 14:18:14 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 13:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2005/08/26 13:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/11/30 22:07:31 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/11/30 22:07:31 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/11/30 22:07:31 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/11/30 14:18:56 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2007/02/20 13:17:53 | 000,000,180 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Free AOL & Unlimited Internet.url

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/30 14:23:35 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/11/30 14:23:34 | 000,000,079 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/12/21 20:03:51 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\user\Desktop\erunt-setup.exe
[2008/05/11 20:41:46 | 002,963,912 | —- | M] (Macrovision Corporation) – C:\Documents and Settings\user\Desktop\ijjiAutoInstaller.exe
[2008/11/09 19:25:17 | 006,212,784 | —- | M] (NJStar Software Corp.) – C:\Documents and Settings\user\Desktop\njcom273sw8618.exe
[2010/12/18 12:29:37 | 000,296,448 | —- | M] () – C:\Documents and Settings\user\Desktop\uj7y5il6.exe
[2008/12/28 21:18:59 | 001,234,120 | —- | M] () – C:\Documents and Settings\user\Desktop\wrar380.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-10 23:34:07

< End of report >
from the extras.txt

OTL Extras logfile created on: 4/11/2011 8:38:16 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 151.00 Mb Available Physical Memory | 30.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 24.07 Gb Free Space | 61.63% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 23.75 Gb Free Space | 63.74% Space Free | Partition Type: NTFS

Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Funshion Online\Funshion\FunshionService.exe" = C:\Program Files\Funshion Online\Funshion\FunshionService.exe:*:Disabled:FunshionService
"C:\Program Files\Funshion Online\Funshion\FunshionUpgrade.exe" = C:\Program Files\Funshion Online\Funshion\FunshionUpgrade.exe:*:Disabled:FunshionUpgrade
"C:\Program Files\PPLive\PPTV\PPLive.exe" = C:\Program Files\PPLive\PPTV\PPLive.exe:*:Disabled:PPLive
"C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe" = C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe:*:Disabled:PPLive
"C:\Program Files\PPLive\PPTV\PPLiveU.exe" = C:\Program Files\PPLive\PPTV\PPLiveU.exe:*:Disabled:PPLiveU
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player – (Musiccity Co.Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{2DED5EA5-7C5E-4477-83F6-3BDCBE320FF0}" = Citrix Presentation Server Client - Web Only
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B124151-B6A0-492C-8838-0854B800535D}" = Creative MuVo NX-TX
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6C117F31-28A8-4477-BE91-64AC0A2204AD}" = Microsoft IntelliPoint 6.01
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{802C87BF-3A1E-45B0-8C12-9527A5C572B3}" = SMCWUSB-G 802.11g Wireless USB 2.0 Adapter
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9115E7DB-3B29-445A-802D-11E0AA945B7F}" = Sound Blaster Live!
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D75915D3-6CFF-445F-A346-18ED6EF2F618}" = Microsoft IntelliType Pro 6.01
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"aTube Catcher" = aTube Catcher
"CAL" = Canon Camera Access Library
"CameraUserGuide-PSSD1300IS_IXUS105" = Canon PowerShot SD1300 IS_IXUS 105 Camera User Guide
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon Setup Utility 2.0" = Canon Setup Utility 2.0
"CANONBJ_Deinstall_CNMCP78.DLL" = Canon iP4200
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{802C87BF-3A1E-45B0-8C12-9527A5C572B3}" = SMCWUSB-G 802.11g Wireless USB 2.0 Adapter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MovieUploaderForYouTube" = Canon Utilities Movie Uploader for YouTube
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"MuVo Driver" = MuVo Driver
"MyCamera" = Canon Utilities MyCamera
"NAV" = Norton AntiVirus
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NJStar Communicator" = NJStar Communicator
"NVIDIA Drivers" = NVIDIA Drivers
"Personal Printing Guide" = Canon Personal Printing Guide
"PhotoStitch" = Canon Utilities PhotoStitch
"Software Guide" = Canon DIGITAL CAMERA Solution Disk Software Guide
"SysInfo" = Creative System Information
"uTorrent" = µTorrent
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/4/2011 11:13:40 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application smcwguti.exe, version 2.3.0.2, faulting module
smcwguti.exe, version 2.3.0.2, fault address 0x0000a7f1.

Error - 3/14/2011 12:07:22 PM | Computer Name = USER-FD953F9ADA | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/22/2011 11:08:17 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.0.37, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9be.

Error - 3/25/2011 2:35:52 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.0.37, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9b5.

Error - 3/27/2011 12:17:20 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.0.37, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001ba4e.

Error - 3/27/2011 10:48:23 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.0.37, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9b5.

Error - 3/28/2011 1:24:56 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application smcwguti.exe, version 2.3.0.2, faulting module
smcwguti.exe, version 2.3.0.2, fault address 0x0000a7f1.

Error - 3/28/2011 5:27:39 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.0.37, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9be.

Error - 4/9/2011 1:55:52 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.0.37, faulting module
efacli.dll, version 2.1.2.11, fault address 0x00009d66.

Error - 4/9/2011 1:55:56 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.4095, faulting
module xul.dll, version 1.9.2.4095, fault address 0x0070a669.

[ System Events ]
Error - 4/11/2011 8:49:31 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:31 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:32 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:32 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:32 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:32 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:33 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:33 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:33 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 4/11/2011 8:49:33 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2


< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, speedz76

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

Let's check for rootkits.

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


—————————————————————————————————
Thank you Conspire I followed your instructions and ran GMER. THe scan took about 3 hours plus and after the scan is completed, i click "save" and this is the file. The file size seems a bit small (is it correct?) and i'm attaching it here. In case this is not the correct file, can you advise how to retrieve back the scan results (if possible and needed) Many thanks

Attachments:

Hi, yes it's the correct file. Thank you.

Please uninstall the following Programs using the Add/Remove Programs utility if they exist.
Ask Toolbar

Detailed steps below :-
On the Windows XP taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Add or Remove Programs.

===================================================

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan


click on Browse, and upload the following file for analysis:
C:\WINDOWS\MusiccityDownload.exe
C:\Documents and Settings\user\Application Data\tc7.exe
C:\Documents and Settings\user\Application Data\nn8.exe
C:\Documents and Settings\user\Desktop\uj7y5il6.exe


Then click Submit. Allow the file to be scanned, and then please copy and paste the results link(for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

===================================================

On your next reply please post :
File scanner report


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
thanks conspire


this is for musiccitydownload.exe
File name: MusiccityDownload.exe
Submission date: 2011-04-13 12:21:29 (UTC)
Current status: queued (#32) queued (#32) analysing finished


Result: 0/ 42 (0.0%)
VT Community

not reviewed
Safety score: -

Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.13.01 2011.04.13 -
AntiVir 7.11.6.93 2011.04.13 -
Antiy-AVL 2.0.3.7 2011.04.13 -
Avast 4.8.1351.0 2011.04.12 -
Avast5 5.0.677.0 2011.04.12 -
AVG 10.0.0.1190 2011.04.13 -
BitDefender 7.2 2011.04.13 -
CAT-QuickHeal 11.00 2011.04.13 -
ClamAV 0.97.0.0 2011.04.13 -
Commtouch 5.2.11.5 2011.04.13 -
Comodo 8325 2011.04.13 -
DrWeb 5.0.2.03300 2011.04.13 -
Emsisoft 5.1.0.5 2011.04.13 -
eSafe 7.0.17.0 2011.04.13 -
eTrust-Vet 36.1.8269 2011.04.13 -
F-Prot 4.6.2.117 2011.04.13 -
F-Secure 9.0.16440.0 2011.04.13 -
Fortinet 4.2.257.0 2011.04.13 -
GData 22 2011.04.13 -
Ikarus T3.1.1.103.0 2011.04.13 -
Jiangmin 13.0.900 2011.04.13 -
K7AntiVirus 9.96.4360 2011.04.11 -
Kaspersky 7.0.0.125 2011.04.13 -
McAfee 5.400.0.1158 2011.04.13 -
McAfee-GW-Edition 2010.1C 2011.04.12 -
Microsoft 1.6702 2011.04.11 -
NOD32 6038 2011.04.13 -
Norman 6.07.07 2011.04.12 -
Panda 10.0.3.5 2011.04.12 -
PCTools 7.0.3.5 2011.04.13 -
Prevx 3.0 2011.04.13 -
Rising 23.53.02.03 2011.04.13 -
Sophos 4.64.0 2011.04.13 -
SUPERAntiSpyware 4.40.0.1006 2011.04.12 -
Symantec 20101.3.2.89 2011.04.13 -
TheHacker 6.7.0.1.173 2011.04.13 -
TrendMicro 9.200.0.1012 2011.04.13 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.13 -
VBA32 3.12.14.3 2011.04.13 -
VIPRE 9004 2011.04.13 -
ViRobot 2011.4.13.4408 2011.04.13 -
VirusBuster 13.6.301.0 2011.04.12 -
Additional informationShow all
MD5 : 35783ff1ccab7cfbfe799ef8d6476c0d
SHA1 : ad563aa5d439a32e085d657759d7d734b95d0d06
SHA256: 7f5e34f7f1376ef8e9137d3c2ddba192e2b9ca18e6e85298dbe99d5efe1658af

for
C:\Documents and Settings\user\Application Data\tc7.exe
File name: tc7.exe
Submission date: 2011-04-13 12:27:34 (UTC)
Current status: queued queued analysing finished


Result: 3/ 42 (7.1%)
VT Community

not reviewed
Safety score: -

Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.13.01 2011.04.13 -
AntiVir 7.11.6.93 2011.04.13 -
Antiy-AVL 2.0.3.7 2011.04.13 -
Avast 4.8.1351.0 2011.04.12 -
Avast5 5.0.677.0 2011.04.12 -
AVG 10.0.0.1190 2011.04.13 -
BitDefender 7.2 2011.04.13 -
CAT-QuickHeal 11.00 2011.04.13 -
ClamAV 0.97.0.0 2011.04.13 -
Commtouch 5.2.11.5 2011.04.13 -
Comodo 8325 2011.04.13 -
DrWeb 5.0.2.03300 2011.04.13 Trojan.Siggen1.63828
Emsisoft 5.1.0.5 2011.04.13 -
eSafe 7.0.17.0 2011.04.13 -
eTrust-Vet 36.1.8269 2011.04.13 -
F-Prot 4.6.2.117 2011.04.13 -
F-Secure 9.0.16440.0 2011.04.13 -
Fortinet 4.2.257.0 2011.04.13 -
GData 22 2011.04.13 -
Ikarus T3.1.1.103.0 2011.04.13 -
Jiangmin 13.0.900 2011.04.13 -
K7AntiVirus 9.96.4360 2011.04.11 -
Kaspersky 7.0.0.125 2011.04.13 -
McAfee 5.400.0.1158 2011.04.13 -
McAfee-GW-Edition 2010.1C 2011.04.12 -
Microsoft 1.6702 2011.04.11 -
NOD32 6038 2011.04.13 -
Norman 6.07.07 2011.04.12 -
Panda 10.0.3.5 2011.04.12 -
PCTools 7.0.3.5 2011.04.13 -
Prevx 3.0 2011.04.13 Medium Risk Malware
Rising 23.53.02.03 2011.04.13 -
Sophos 4.64.0 2011.04.13 -
SUPERAntiSpyware 4.40.0.1006 2011.04.12 -
Symantec 20101.3.2.89 2011.04.13 WS.Reputation.1
TheHacker 6.7.0.1.173 2011.04.13 -
TrendMicro 9.200.0.1012 2011.04.13 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.13 -
VBA32 3.12.14.3 2011.04.13 -
VIPRE 9004 2011.04.13 -
ViRobot 2011.4.13.4408 2011.04.13 -
VirusBuster 13.6.302.1 2011.04.13 -
Additional informationShow all
MD5 : 731634912edc79c13d02536ddcf8e236
SHA1 : 67d02e636776bad4bcc99ebdaeea386ddd6161d5
SHA256: 89b224c889587964b657d631d0be32cff484f65aab2ccf20d902e22449732883


for
C:\Documents and Settings\user\Application Data\nn8.exe
File name: nn8.exe
Submission date: 2011-04-13 12:31:16 (UTC)
Current status: queued queued analysing finished


Result: 2/ 42 (4.8%)
VT Community

not reviewed
Safety score: -

Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.13.01 2011.04.13 -
AntiVir 7.11.6.93 2011.04.13 -
Antiy-AVL 2.0.3.7 2011.04.13 -
Avast 4.8.1351.0 2011.04.12 -
Avast5 5.0.677.0 2011.04.12 -
AVG 10.0.0.1190 2011.04.13 -
BitDefender 7.2 2011.04.13 -
CAT-QuickHeal 11.00 2011.04.13 -
ClamAV 0.97.0.0 2011.04.13 -
Commtouch 5.2.11.5 2011.04.13 -
Comodo 8325 2011.04.13 -
DrWeb 5.0.2.03300 2011.04.13 Trojan.PWS.Siggen.17041
Emsisoft 5.1.0.5 2011.04.13 -
eSafe 7.0.17.0 2011.04.13 -
eTrust-Vet 36.1.8269 2011.04.13 -
F-Prot 4.6.2.117 2011.04.13 -
F-Secure 9.0.16440.0 2011.04.13 -
Fortinet 4.2.257.0 2011.04.13 -
GData 22 2011.04.13 -
Ikarus T3.1.1.103.0 2011.04.13 -
Jiangmin 13.0.900 2011.04.13 -
K7AntiVirus 9.96.4360 2011.04.11 -
Kaspersky 7.0.0.125 2011.04.13 -
McAfee 5.400.0.1158 2011.04.13 -
McAfee-GW-Edition 2010.1C 2011.04.12 -
Microsoft 1.6702 2011.04.11 -
NOD32 6038 2011.04.13 -
Norman 6.07.07 2011.04.12 -
Panda 10.0.3.5 2011.04.12 -
PCTools 7.0.3.5 2011.04.13 -
Prevx 3.0 2011.04.13 Medium Risk Malware
Rising 23.53.02.03 2011.04.13 -
Sophos 4.64.0 2011.04.13 -
SUPERAntiSpyware 4.40.0.1006 2011.04.12 -
Symantec 20101.3.2.89 2011.04.13 -
TheHacker 6.7.0.1.173 2011.04.13 -
TrendMicro 9.200.0.1012 2011.04.13 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.13 -
VBA32 3.12.14.3 2011.04.13 -
VIPRE 9004 2011.04.13 -
ViRobot 2011.4.13.4408 2011.04.13 -
VirusBuster 13.6.302.1 2011.04.13 -
Additional informationShow all
MD5 : f147cdd1e629e6680ff8b6acad619fbf
SHA1 : 761f559199d5b779f3fe601747cb5e73f0abb59f
SHA256: 6efacb9d456f765f665acaa30c176a807417805cf34e52eed6f76f2f98eaa5e4


for
C:\Documents and Settings\user\Desktop\uj7y5il6.exe
File name: uj7y5il6.exe
Submission date: 2011-04-13 12:40:02 (UTC)
Current status: queued queued analysing finished


Result: 1/ 41 (2.4%)
VT Community

goodware
Safety score: 99.6%

Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.13.01 2011.04.13 -
AntiVir 7.11.6.93 2011.04.13 -
Antiy-AVL 2.0.3.7 2011.04.13 -
Avast 4.8.1351.0 2011.04.12 -
Avast5 5.0.677.0 2011.04.12 -
AVG 10.0.0.1190 2011.04.13 -
BitDefender 7.2 2011.04.13 -
CAT-QuickHeal 11.00 2011.04.13 -
ClamAV 0.97.0.0 2011.04.13 -
Commtouch 5.2.11.5 2011.04.13 -
Comodo 8325 2011.04.13 -
DrWeb 5.0.2.03300 2011.04.13 -
eSafe 7.0.17.0 2011.04.13 -
eTrust-Vet 36.1.8269 2011.04.13 -
F-Prot 4.6.2.117 2011.04.13 -
F-Secure 9.0.16440.0 2011.04.13 -
Fortinet 4.2.257.0 2011.04.13 -
GData 22 2011.04.13 -
Ikarus T3.1.1.103.0 2011.04.13 -
Jiangmin 13.0.900 2011.04.13 -
K7AntiVirus 9.96.4360 2011.04.11 -
Kaspersky 7.0.0.125 2011.04.13 -
McAfee 5.400.0.1158 2011.04.13 -
McAfee-GW-Edition 2010.1C 2011.04.12 -
Microsoft 1.6702 2011.04.11 -
NOD32 6038 2011.04.13 -
Norman 6.07.07 2011.04.12 -
Panda 10.0.3.5 2011.04.12 -
PCTools 7.0.3.5 2011.04.13 -
Prevx 3.0 2011.04.13 -
Rising 23.53.02.03 2011.04.13 Suspicious
Sophos 4.64.0 2011.04.13 -
SUPERAntiSpyware 4.40.0.1006 2011.04.12 -
Symantec 20101.3.2.89 2011.04.13 -
TheHacker 6.7.0.1.173 2011.04.13 -
TrendMicro 9.200.0.1012 2011.04.13 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.13 -
VBA32 3.12.14.3 2011.04.13 -
VIPRE 9004 2011.04.13 -
ViRobot 2011.4.13.4408 2011.04.13 -
VirusBuster 13.6.302.1 2011.04.13 -
Additional informationShow all
MD5 : df7501a91a7c99cc3f0269080748ee61
SHA1 : 453b6bed84bcc63f52d00b76ab6572f039c69b1f
SHA256: f2ffef9c4aee46839f249583d7469885e1bd34e49da8ddd31c7548b0d55ae85c

btw, the last file uj7y5il6.exe is actually GMER which i downloaded months before and i just placed it into the recycle bin before restoring it to the desktop to scan

thank you!

btw, the last file uj7y5il6.exe is actually GMER which i downloaded months before and i just placed it into the recycle bin before restoring it to the desktop to scan

Thought so lol

Do you happen to recognise any of the files above other than GMER?

===================================================

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

Please get a new OTL scan log. Please set OTL up this way for the scan.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
===================================================

On your next reply please post :
MBAM log
Fresh OTL log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

Thought so lol

Do you happen to recognise any of the files above other than GMER?



Hi Conspire, no, I do not even know where, when and how the other files downloaded onto my desktop.

I followed your instructions and ran Malwarebytes with the most updated database, but funny thing it reads no error, thus i did not have a chance to click "show selected" and "remove selected" according to the steps you have given.

The MBAM log and fresh OTL log as attached
MBAM log
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6351

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

4/13/2011 11:47:45 PM
mbam-log-2011-04-13 (23-47-45).txt

Scan type: Quick scan
Objects scanned: 159283
Time elapsed: 9 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OTL.txt
OTL logfile created on: 4/14/2011 12:21:29 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 114.00 Mb Available Physical Memory | 22.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 24.04 Gb Free Space | 61.56% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 23.75 Gb Free Space | 63.74% Space Free | Partition Type: NTFS

Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\user\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\user\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110413.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110413.002\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110412.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110225.002\BHDrvx86.sys (Symantec Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (SMCWGU(SMC)) SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) – C:\WINDOWS\system32\drivers\SMCWGU.sys (SMC Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC52) Intel® – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://sg.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/01/08 13:34:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 10:43:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 10:43:32 | 000,000,000 | —D | M]

[2010/06/23 19:14:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions
[2010/12/12 08:39:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/30 23:22:13 | 000,002,567 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\searchplugins\askcom.xml
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/24 21:04:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/19 16:51:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/01/08 13:34:21 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPLGN
[2010/12/19 16:50:56 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/12/19 16:50:55 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WINDVDPatch] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SMCWUSB-G 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/30 14:18:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/30 23:17:38 | 000,000,000 | —D | C] – C:\Program Files\DsNET Corp
[2011/03/30 07:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\SelfMV
[2011/03/30 07:43:45 | 000,000,000 | —D | C] – C:\Program Files\MyFree Codec
[2011/03/28 18:01:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Samsung
[2011/03/28 18:00:01 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\WINDOWS\System32\dgderapi.dll
[2011/03/28 18:00:01 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\DIFxAPI.dll
[2011/03/28 18:00:01 | 000,020,032 | —- | C] (Devguru Co., Ltd) – C:\WINDOWS\System32\drivers\dgderdrv.sys
[2011/03/28 17:34:04 | 000,163,840 | —- | C] (CANON INC.) – C:\WINDOWS\BJPSUNST.EXE
[2011/03/28 17:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CD-LabelPrint
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\WINDOWS\StartHtmico
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200 Manual
[2011/03/28 17:29:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200
[2011/03/28 17:29:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/03/28 15:26:35 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2011/03/28 15:17:20 | 000,140,288 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM78.DLL
[2011/03/28 15:17:15 | 000,090,112 | R— | C] (CANON INC.) – C:\WINDOWS\System32\CNMCP78.exe
[2011/03/25 00:52:28 | 000,000,000 | —D | C] – C:\Temp
[2011/03/23 20:32:32 | 000,000,000 | —D | C] – C:\WINDOWS\System32\System32
[2011/03/22 23:04:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Samsung
[2011/03/22 23:03:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\samsung
[2011/03/22 01:26:13 | 000,136,680 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdm.sys
[2011/03/22 01:26:13 | 000,012,776 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdfl.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcmnt.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcm.sys
[2011/03/22 01:26:11 | 000,121,192 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadbus.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwhnt.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwh.sys
[2011/03/22 01:23:21 | 004,659,712 | —- | C] (Dmitry Streblechenko) – C:\WINDOWS\System32\Redemption.dll
[2011/03/22 01:21:57 | 000,000,000 | —D | C] – C:\Program Files\MarkAny
[2011/03/22 01:18:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Program Files\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/03/22 01:16:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2011/03/22 01:16:09 | 000,016,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/03/22 01:14:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\umdf
[2011/03/22 01:09:33 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Downloaded Installations
[2007/02/20 13:16:14 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/13 23:01:49 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/13 23:01:01 | 000,081,191 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/13 23:00:57 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.CDF
[2011/04/13 23:00:57 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.BAK
[2011/04/13 23:00:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/13 23:00:27 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2011/04/13 21:42:54 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/13 21:42:54 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/13 21:42:54 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/13 21:42:54 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/13 21:42:54 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/04/13 21:42:54 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/04/13 21:42:54 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/13 21:42:54 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/13 00:03:22 | 000,301,568 | —- | M] () – C:\Documents and Settings\user\Desktop\0gr89kho.exe
[2011/04/07 21:46:04 | 001,562,228 | —- | M] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/04/05 07:57:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/05 07:49:14 | 000,025,088 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 23:19:20 | 000,000,839 | —- | M] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/29 22:15:00 | 000,170,722 | —- | M] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:18 | 000,001,612 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/25 00:51:22 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/22 23:03:29 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/03/22 01:16:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/22 01:16:20 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | M] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/13 00:03:09 | 000,301,568 | —- | C] () – C:\Documents and Settings\user\Desktop\0gr89kho.exe
[2011/04/07 21:46:04 | 001,562,228 | —- | C] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/03/30 23:19:20 | 000,000,839 | —- | C] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/29 22:15:00 | 000,170,722 | —- | C] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:17 | 000,001,612 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/28 15:17:20 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2011/03/25 00:51:22 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/23 07:43:36 | 000,240,160 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/22 01:16:20 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | C] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[2011/01/29 17:00:24 | 000,030,568 | —- | C] () – C:\WINDOWS\MusiccityDownload.exe
[2011/01/29 17:00:22 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2011/01/29 17:00:22 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/29 17:00:22 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/29 17:00:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/01 03:13:12 | 008,596,886 | —- | C] () – C:\Documents and Settings\user\Application Data\Black Eyed Peas - The Time (Dirty Bit).zip
[2010/11/14 18:23:30 | 007,198,459 | —- | C] () – C:\Documents and Settings\user\Application Data\Kesha - We R Who We R.zip
[2010/10/21 19:16:51 | 000,001,940 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/21 07:41:34 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/03 00:51:48 | 000,016,384 | —- | C] () – C:\Documents and Settings\user\Application Data\tc7.exe
[2010/09/04 00:54:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/23 19:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/05/19 19:18:06 | 000,016,384 | —- | C] () – C:\Documents and Settings\user\Application Data\nn8.exe
[2009/10/06 15:16:00 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/16 09:26:11 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/04 20:02:08 | 000,025,088 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/09 19:25:59 | 000,000,398 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2008/06/07 15:04:14 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/06/07 15:04:14 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/06/07 15:04:07 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/07 15:04:05 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/06/07 15:04:03 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/06/07 15:03:46 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/06/07 15:03:46 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2008/06/07 15:03:41 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/04/25 20:22:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:17:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2007/02/20 13:17:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2007/02/20 13:16:44 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2007/02/20 13:16:44 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/02/20 13:16:35 | 000,164,044 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2007/02/20 13:16:35 | 000,113,373 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2007/02/20 13:16:35 | 000,113,273 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2007/02/20 13:16:33 | 000,179,669 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2007/02/20 13:16:33 | 000,044,055 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2007/02/20 13:16:22 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2007/02/20 13:16:22 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2007/02/20 13:16:20 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2007/02/20 13:16:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2007/02/20 12:35:52 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/03/20 23:36:32 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/30 22:09:29 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/30 22:08:17 | 000,134,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/30 14:43:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/30 14:38:37 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/11/30 14:38:37 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/30 14:38:36 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/30 14:21:25 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/11/30 14:15:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2004/08/04 20:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 20:00:00 | 000,432,686 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 20:00:00 | 000,067,516 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 20:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 20:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 20:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/03/14 12:24:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ZyDelReg.exe
[1999/01/23 02:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

< End of report >
Hi,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Ask.com"
    FF - prefs.js..browser.search.order.1: "Ask.com"
    FF - prefs.js..browser.search.selectedEngine: "Ask.com"
    
    :Files
    C:\Documents and Settings\user\Application Data\tc7.exe
    C:\Documents and Settings\user\Application Data\nn8.exe
    C:\Documents and Settings\user\Desktop\uj7y5il6.exe
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script and( don't check the boxes beside LOP Check or Purity this time )
===================================================

On your next reply please post :
OTL fix log
Fresh OTL log
Feedback on system behaviour


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi A quick question before i run the OTL for "RUN FIX" Should the settings for the OTL is the same as before? "# Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted. # When the window appears, underneath Output at the top change it to Minimal Output # UNCheck the boxes beside LOP Check and Purity Check."
conspire,

manged to run the steps as required and these are the results

for OTL FIX log

All processes killed
========== OTL ==========
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
========== FILES ==========
C:\Documents and Settings\user\Application Data\tc7.exe moved successfully.
C:\Documents and Settings\user\Application Data\nn8.exe moved successfully.
C:\Documents and Settings\user\Desktop\uj7y5il6.exe moved successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Alvin

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: Mag
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

User: user
->Flash cache emptied: 80494 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Alvin

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: Mag
->Temp folder emptied: 18669 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: user
->Temp folder emptied: 169316575 bytes
->Temporary Internet Files folder emptied: 101431602 bytes
->Java cache emptied: 205983 bytes
->FireFox cache emptied: 46457668 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2950144 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1811520 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 702497 bytes

Total Files Cleaned = 308.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.22.3 log created on 04142011_203521

Files\Folders moved on Reboot…
C:\WINDOWS\temp\Perflib_Perfdata_5cc.dat moved successfully.

Registry entries deleted on Reboot…


for the refreshed OTL scan log

OTL logfile created on: 4/14/2011 9:04:15 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 71.00 Mb Available Physical Memory | 14.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 24.46 Gb Free Space | 62.62% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 23.75 Gb Free Space | 63.75% Space Free | Partition Type: NTFS

Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\user\My Documents\Downloads\OTL(3).exe (OldTimer Tools)
PRC - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\user\My Documents\Downloads\OTL(3).exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110413.035\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110413.035\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110412.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110225.002\BHDrvx86.sys (Symantec Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (SMCWGU(SMC)) SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) – C:\WINDOWS\system32\drivers\SMCWGU.sys (SMC Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC52) Intel® – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://sg.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/01/08 13:34:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 10:43:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 10:43:32 | 000,000,000 | —D | M]

[2010/06/23 19:14:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions
[2010/12/12 08:39:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/30 23:22:13 | 000,002,567 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\searchplugins\askcom.xml
[2011/04/11 07:21:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/24 21:04:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/19 16:51:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/01/08 13:34:21 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPLGN
[2010/12/19 16:50:56 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/12/19 16:50:55 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WINDVDPatch] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SMCWUSB-G 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/30 14:18:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/14 20:35:21 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/30 23:17:38 | 000,000,000 | —D | C] – C:\Program Files\DsNET Corp
[2011/03/30 07:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\SelfMV
[2011/03/30 07:43:45 | 000,000,000 | —D | C] – C:\Program Files\MyFree Codec
[2011/03/28 18:01:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Samsung
[2011/03/28 18:00:01 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\WINDOWS\System32\dgderapi.dll
[2011/03/28 18:00:01 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\DIFxAPI.dll
[2011/03/28 18:00:01 | 000,020,032 | —- | C] (Devguru Co., Ltd) – C:\WINDOWS\System32\drivers\dgderdrv.sys
[2011/03/28 17:34:04 | 000,163,840 | —- | C] (CANON INC.) – C:\WINDOWS\BJPSUNST.EXE
[2011/03/28 17:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CD-LabelPrint
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\WINDOWS\StartHtmico
[2011/03/28 17:30:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200 Manual
[2011/03/28 17:29:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon iP4200
[2011/03/28 17:29:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/03/28 15:26:35 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2011/03/28 15:17:20 | 000,140,288 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM78.DLL
[2011/03/28 15:17:15 | 000,090,112 | R— | C] (CANON INC.) – C:\WINDOWS\System32\CNMCP78.exe
[2011/03/25 00:52:28 | 000,000,000 | —D | C] – C:\Temp
[2011/03/23 20:32:32 | 000,000,000 | —D | C] – C:\WINDOWS\System32\System32
[2011/03/22 23:04:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Samsung
[2011/03/22 23:03:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\samsung
[2011/03/22 01:26:13 | 000,136,680 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdm.sys
[2011/03/22 01:26:13 | 000,012,776 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadmdfl.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcmnt.sys
[2011/03/22 01:26:13 | 000,010,472 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadcm.sys
[2011/03/22 01:26:11 | 000,121,192 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadbus.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwhnt.sys
[2011/03/22 01:26:11 | 000,010,344 | —- | C] (MCCI Corporation) – C:\WINDOWS\System32\drivers\ssadwh.sys
[2011/03/22 01:23:21 | 004,659,712 | —- | C] (Dmitry Streblechenko) – C:\WINDOWS\System32\Redemption.dll
[2011/03/22 01:21:57 | 000,000,000 | —D | C] – C:\Program Files\MarkAny
[2011/03/22 01:18:54 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Program Files\Samsung
[2011/03/22 01:18:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/03/22 01:16:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2011/03/22 01:16:09 | 000,016,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/03/22 01:14:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\umdf
[2011/03/22 01:09:33 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Downloaded Installations
[2007/02/20 13:16:14 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/04/14 21:00:40 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.CDF
[2011/04/14 21:00:40 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.BAK
[2011/04/14 21:00:27 | 000,081,191 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/14 21:00:26 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/14 20:59:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/14 20:59:46 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2011/04/14 20:59:03 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/14 20:59:03 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/14 20:59:03 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/14 20:59:03 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2011/04/14 20:59:03 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/04/14 20:59:03 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/04/14 20:59:03 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/14 20:59:03 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2011/04/13 00:03:22 | 000,301,568 | —- | M] () – C:\Documents and Settings\user\Desktop\0gr89kho.exe
[2011/04/07 21:46:04 | 001,562,228 | —- | M] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/04/05 07:57:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/05 07:49:14 | 000,025,088 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 23:19:20 | 000,000,839 | —- | M] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/29 22:15:00 | 000,170,722 | —- | M] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:18 | 000,001,612 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/25 00:51:22 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/22 23:03:29 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/03/22 01:16:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/22 01:16:20 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | M] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf

========== Files Created - No Company Name ==========

[2011/04/13 00:03:09 | 000,301,568 | —- | C] () – C:\Documents and Settings\user\Desktop\0gr89kho.exe
[2011/04/07 21:46:04 | 001,562,228 | —- | C] () – C:\Documents and Settings\user\My Documents\BkTimah-Nature-Reserve.pdf
[2011/03/30 23:19:20 | 000,000,839 | —- | C] () – C:\Documents and Settings\All Users\Desktop\aTube Catcher.lnk
[2011/03/29 22:15:00 | 000,170,722 | —- | C] () – C:\Documents and Settings\user\Desktop\parking fine.pdf
[2011/03/28 18:03:39 | 000,001,594 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Samsung Kies.lnk
[2011/03/28 18:01:17 | 000,001,612 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011/03/28 15:17:20 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2011/03/25 00:51:22 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2011/03/23 07:43:36 | 000,240,160 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/22 01:16:20 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2011/03/21 21:15:39 | 000,006,190 | —- | C] () – C:\Documents and Settings\user\Desktop\parking apr11.pdf
[2011/01/29 17:00:24 | 000,030,568 | —- | C] () – C:\WINDOWS\MusiccityDownload.exe
[2011/01/29 17:00:22 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2011/01/29 17:00:22 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/29 17:00:22 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/29 17:00:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/01 03:13:12 | 008,596,886 | —- | C] () – C:\Documents and Settings\user\Application Data\Black Eyed Peas - The Time (Dirty Bit).zip
[2010/11/14 18:23:30 | 007,198,459 | —- | C] () – C:\Documents and Settings\user\Application Data\Kesha - We R Who We R.zip
[2010/10/21 19:16:51 | 000,001,940 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/21 07:41:34 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/04 00:54:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/23 19:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/10/06 15:16:00 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/16 09:26:11 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/04 20:02:08 | 000,025,088 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/09 19:25:59 | 000,000,398 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2008/06/07 15:04:14 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/06/07 15:04:14 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/06/07 15:04:07 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/07 15:04:05 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/06/07 15:04:03 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/06/07 15:03:46 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/06/07 15:03:46 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2008/06/07 15:03:41 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/04/25 20:22:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:17:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2007/02/20 13:17:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2007/02/20 13:16:44 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2007/02/20 13:16:44 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/02/20 13:16:35 | 000,164,044 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2007/02/20 13:16:35 | 000,113,373 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2007/02/20 13:16:35 | 000,113,273 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2007/02/20 13:16:33 | 000,179,669 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2007/02/20 13:16:33 | 000,044,055 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2007/02/20 13:16:22 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2007/02/20 13:16:22 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2007/02/20 13:16:20 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2007/02/20 13:16:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2007/02/20 12:35:52 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/03/20 23:36:32 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/30 22:09:29 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/30 22:08:17 | 000,134,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/30 14:43:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/30 14:38:37 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/11/30 14:38:37 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/30 14:38:36 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/30 14:21:25 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/11/30 14:15:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2004/08/04 20:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 20:00:00 | 000,432,686 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 20:00:00 | 000,067,516 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 20:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 20:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 20:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/03/14 12:24:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ZyDelReg.exe
[1999/01/23 02:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

< End of report >

applications (like MS office) and mozilla definetly loads up much faster than before! - thank you!
however, my startup connection to the internet using my wireless USB adaptor still does not connect automatically, im not sure if thats hardware or virus/malware/software problem
hmm.. i don't.. would there be a way to check it? 1) does the scan reveal anything on the internet connection? 2) Also, is my "computer slow and hanging" issue solved? may i ask the cause of that? 3) I am currently on Norton and i have an auto update on the virus, why do i still have all these virus/malware. In one of the scans using malwarebytes earlier.. there are some files labelled as "trojan", "medium risk malware", is my Norton effective at all? thanks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI