This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected ?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I'm not sure if infected or not, My son has been using my laptop and it is running very slow and i keep getting active x message pop up warnings. Also some programs will not launch.

Please could you check my OTL logs ?

Many Thanks in advance

OTL logfile created on: 07/05/2011 15:51:09 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Lee Edgar\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

893.00 Mb Total Physical Memory | 140.00 Mb Available Physical Memory | 16.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 46.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.42 Gb Total Space | 31.01 Gb Free Space | 48.13% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.91 Gb Free Space | 59.13% Space Free | Partition Type: NTFS

Computer Name: SUZANNE-EDGAR | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Lee Edgar\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Lee Edgar\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (KService) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (DLADResM) – C:\Windows\System32\DLA\DLADResM.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=6070524
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/08 19:17:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/21 22:56:55 | 000,000,000 | —D | M]

[2010/07/27 16:05:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Lee Edgar\AppData\Roaming\Mozilla\Extensions
[2011/04/22 10:39:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Lee Edgar\AppData\Roaming\Mozilla\Firefox\Profiles\of0l06te.default\extensions
[2010/07/30 08:42:26 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Lee Edgar\AppData\Roaming\Mozilla\Firefox\Profiles\of0l06te.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/22 10:39:25 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/09/16 21:18:56 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/07/11 10:18:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 13:07:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/04 21:51:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/21 23:10:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/02/09 23:31:51 | 000,000,000 | —D | M] (Mozilla Firefox distributed by RealNetworks) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/11/07 14:15:53 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/11/07 14:15:53 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/11/07 14:15:53 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/11/07 14:15:53 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (no name) - {EEE6C35C-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [4oD] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [EPSON Stylus SX400 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [EPSON Stylus SX400 Series (Copy 1)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab (EPUImageControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (AVGRSSTX.DLL) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Toco Toucan.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Toco Toucan.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/07 15:01:40 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Lee Edgar\Desktop\OTL.exe
[2011/05/07 14:56:57 | 000,000,000 | —D | C] – C:\Users\Lee Edgar\AppData\Local\VirtualStore
[2011/05/02 15:46:49 | 000,000,000 | —D | C] – C:\Program Files\CONEXANT
[2011/05/02 11:29:57 | 000,000,000 | —D | C] – C:\Program Files\TweetDeck
[2011/05/02 09:43:41 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/05/02 09:43:39 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/05/01 12:26:29 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/21 23:10:05 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/21 23:10:05 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/21 23:10:05 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/13 16:34:56 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/13 16:34:56 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/13 16:34:56 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/13 16:34:55 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/13 16:34:55 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/13 16:34:55 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/13 16:34:55 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/13 16:34:54 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/13 16:34:54 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/13 16:34:54 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/13 16:34:54 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/13 16:34:53 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/13 16:34:53 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/13 16:34:53 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/13 16:34:48 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/13 16:34:48 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/13 16:34:48 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/13 16:34:42 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/04/13 16:34:41 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/04/13 16:34:34 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/04/13 16:34:31 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/04/13 16:34:25 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/13 16:34:23 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/13 16:34:02 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/04/13 16:33:52 | 002,041,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/04/13 10:38:44 | 000,371,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys

========== Files - Modified Within 30 Days ==========

[2011/05/07 15:38:06 | 000,003,680 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/07 15:38:06 | 000,003,680 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/07 15:37:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/07 15:37:31 | 935,415,808 | -HS- | M] () – C:\hiberfil.sys
[2011/05/07 15:01:54 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Lee Edgar\Desktop\OTL.exe
[2011/05/07 13:54:38 | 000,000,434 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{69063AAD-1E17-44C8-A26C-6B13DEEF953D}.job
[2011/05/02 11:31:04 | 000,140,544 | -H– | M] () – C:\Windows\System32\mlfcache.dat
[2011/05/02 11:30:00 | 000,000,764 | —- | M] () – C:\Users\Public\Desktop\TweetDeck.lnk
[2011/05/02 11:22:37 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/05/02 09:26:46 | 000,002,485 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2011/05/01 12:10:57 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/01 12:10:57 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/21 23:06:03 | 000,001,866 | —- | M] () – C:\ProgramData\QuickSet.xml
[2011/04/21 22:56:57 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/04/21 22:39:47 | 000,005,120 | —- | M] () – C:\Users\Lee Edgar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/13 16:58:02 | 000,321,176 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/13 14:47:50 | 000,000,034 | —- | M] () – C:\Users\Lee Edgar\jagex_runescape_preferences.dat
[2011/04/13 14:47:41 | 000,000,129 | —- | M] () – C:\Users\Lee Edgar\jagex_runescape_preferences2.dat
[2011/04/13 10:47:43 | 000,000,680 | —- | M] () – C:\Users\Lee Edgar\AppData\Local\d3d9caps.dat
[2011/04/13 10:38:43 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt

========== Files Created - No Company Name ==========

[2011/05/02 11:31:04 | 000,140,544 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2011/05/02 11:30:01 | 000,000,776 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweetDeck.lnk
[2011/05/02 11:30:00 | 000,000,764 | —- | C] () – C:\Users\Public\Desktop\TweetDeck.lnk
[2011/04/21 23:06:01 | 000,001,866 | —- | C] () – C:\ProgramData\QuickSet.xml
[2011/04/13 11:02:11 | 000,000,129 | —- | C] () – C:\Users\Lee Edgar\jagex_runescape_preferences2.dat
[2011/04/13 11:01:26 | 000,000,034 | —- | C] () – C:\Users\Lee Edgar\jagex_runescape_preferences.dat
[2011/04/09 17:59:49 | 935,415,808 | -HS- | C] () – C:\hiberfil.sys
[2011/01/04 22:05:09 | 000,000,680 | —- | C] () – C:\Users\Lee Edgar\AppData\Local\d3d9caps.dat
[2010/11/07 18:38:38 | 000,000,134 | —- | C] () – C:\Users\Lee Edgar\AppData\Roaming\wklnhst.dat
[2010/10/20 20:28:32 | 000,000,036 | —- | C] () – C:\Windows\webica.ini
[2010/07/21 17:37:58 | 000,005,120 | —- | C] () – C:\Users\Lee Edgar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/03 15:37:00 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/10/03 15:05:37 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2009/09/17 08:44:26 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/17 08:44:25 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/31 15:00:22 | 000,021,504 | —- | C] () – C:\Windows\System32\WBCustomizer.dll
[2009/08/31 15:00:21 | 000,185,344 | —- | C] () – C:\Windows\System32\MemWarp.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2008/09/28 19:28:11 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2007/06/28 21:15:39 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2007/06/28 21:15:36 | 000,000,120 | —- | C] () – C:\Windows\wininit.ini
[2007/06/17 15:50:05 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2007/06/17 15:48:40 | 000,003,941 | —- | C] () – C:\Windows\mozver.dat
[2007/05/24 23:57:06 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2007/05/24 23:57:06 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/05/24 23:57:06 | 000,138,101 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2007/05/24 23:57:04 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/05/24 23:56:54 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/05/24 16:20:00 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2007/05/24 16:19:57 | 000,024,064 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2006/11/07 20:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 13:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:44:53 | 000,321,176 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 11:33:01 | 000,609,196 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,108,672 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll

========== LOP Check ==========

[2010/11/07 18:39:11 | 000,000,000 | —D | M] – C:\Users\Lee Edgar\AppData\Roaming\Template
[2010/10/13 18:25:21 | 000,000,000 | —D | M] – C:\Users\Lee Edgar\AppData\Roaming\TuxPaint
[2011/05/07 15:26:59 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/05/07 13:54:38 | 000,000,434 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{69063AAD-1E17-44C8-A26C-6B13DEEF953D}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 22:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/05/24 23:57:15 | 000,004,164 | RH– | M] () – C:\dell.sdr
[2011/05/07 15:37:31 | 935,415,808 | -HS- | M] () – C:\hiberfil.sys
[2011/04/13 10:57:55 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2010/03/09 12:24:04 | 000,022,729 | —- | M] () – C:\newfile.enc
[2010/03/09 12:24:04 | 000,022,729 | —- | M] () – C:\newkey
[2011/05/07 15:37:28 | 1251,291,136 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 13:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/19 19:25:35 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/19 08:34:28 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/23 15:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/09/28 19:17:55 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/19 21:46:24 | 000,000,221 | -HS- | M] () – C:\Users\Lee Edgar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/07 15:01:54 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Lee Edgar\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-07 14:20:31

< >

< >

========== Files - Unicode (All) ==========
[2010/05/18 19:51:13 | 000,480,056 | —- | M] ()(C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav) – C:\Windows\System32\A ι ∂ α и_18_05_2010@19_46_57.wav
[2010/05/18 19:51:13 | 000,480,056 | —- | C] ()(C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav) – C:\Windows\System32\A ι ∂ α и_18_05_2010@19_46_57.wav

< End of report >



OTL Extras logfile created on: 07/05/2011 15:51:09 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Lee Edgar\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

893.00 Mb Total Physical Memory | 140.00 Mb Available Physical Memory | 16.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 46.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.42 Gb Total Space | 31.01 Gb Free Space | 48.13% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.91 Gb Free Space | 59.13% Space Free | Partition Type: NTFS

Computer Name: SUZANNE-EDGAR | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CEC7F32-EBCE-4D01-8BB3-D1111D6280D0}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1CAF7102-7C9A-489F-8375-A548AE9EB2A5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1FEA25B5-533A-4235-BA18-FAF68CD2E488}" = lport=2869 | protocol=6 | dir=in | app=system |
"{35CDD9F9-DED0-4898-9A21-0301881E65EC}" = rport=139 | protocol=6 | dir=out | app=system |
"{381408B2-91A4-4556-BBA0-EFBD2669DC0B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{395F8995-ADE7-44CD-9125-0D9C8A846502}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{39C37574-A6D4-40CD-8568-104BB6EA1379}" = lport=138 | protocol=17 | dir=in | app=system |
"{5B5614AB-50C6-4F0E-A770-3DE883AC9E81}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5B94BEC0-CAC6-4B75-BD0B-C765C26AF4F0}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5C21F8F8-8E6D-464E-9AD0-B389BE8898FB}" = lport=445 | protocol=6 | dir=in | app=system |
"{5C2E2510-949F-4EFA-BC73-1F0A40141D2F}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{60F2B068-AA9E-4E04-9679-87AB88BFA3B0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{64C621D4-F764-4540-B19C-71D665C38A0D}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{661373D9-B107-4980-A301-ADE014351790}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6EAC2E73-A1E1-4749-990F-92F335A9AD61}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6FE08152-BBC8-4F7F-A476-A78F2A027136}" = rport=445 | protocol=6 | dir=out | app=system |
"{704F52BE-B327-4456-918B-EC8584E6B6B7}" = rport=137 | protocol=17 | dir=out | app=system |
"{7E10D80B-4013-427C-B634-D242A5CAF73C}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7FD9F75E-892F-4C0B-A1BC-FE0F574D9108}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8FF30FCA-95E1-45B8-B9E0-ECAE32AB5712}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{93517D8C-8D2F-4BDB-8CE0-0E1ED3AB97B7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{99DD5269-8A20-499E-8C23-15E629CD8740}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2195B1E-EAFC-450B-8AFF-7DD930AC7FE6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A46452A9-CDDD-4780-B454-2CA9978899C3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AD1DFDF7-825A-42AC-8D21-F66C6CC7EB7C}" = lport=139 | protocol=6 | dir=in | app=system |
"{B2DAFA18-68E1-4931-8D7C-EFECA38D13F2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B45E1401-61CB-4E63-86C6-13EA91A784F2}" = rport=138 | protocol=17 | dir=out | app=system |
"{B9664908-B8EE-4625-A764-74F05C63C7FE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BEC4EEEE-7398-461C-851E-CC43CFB42797}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{C7AA3E2A-F1A8-46D3-9580-58156307261B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CE983294-3D00-4DFF-932C-F825A073D288}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DCF80BD7-83B9-40EB-A2FD-6EBB570AAB52}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{DDBD2FD7-8DA6-43AE-B36E-88A2891067A6}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F1BEB2FC-7531-4662-A504-79D6304D80C0}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{F350E1B6-E6E7-4975-A620-2D9EBECCB09C}" = rport=2869 | protocol=6 | dir=out | app=system |
"{F83D309E-3AFC-4023-8E8D-952DB5FD4EC7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{FD0A8250-E077-4C26-9B71-E49FA6BEED39}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0486A471-FEED-4C1D-A511-BFA77A90F3AA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{087090FB-21C1-4202-B732-C49591E9352C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{08F23A1A-B35C-45B1-88A4-0422CA2DE868}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{0C33163C-D5C4-44E0-AAB8-73AA594BBEDE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0C961FF4-5012-4E41-9290-CF470AC96EA2}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{15EA101C-3289-4883-A3BB-0831D634E32E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1B9A8740-8B67-42E7-BCCF-069E9948CBCF}" = protocol=6 | dir=in | app=c:\users\suzanne edgar\appdata\local\microsoft\windows\temporary internet files\content.ie5\xyormhi0\sweetimsetup[1].exe |
"{1C783C81-A4C8-4681-BD45-1F40B9E45A74}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{28A892F0-3914-4ECD-B339-9C0D5059F953}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{2B1054A0-F788-4D95-99BC-BF624A52C0A7}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{335DB195-5414-454D-9EA6-6628CD6CB480}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{34E80AE1-2AF5-4830-96CC-6B06B5414DC8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{364D8A72-7948-418C-9631-38B3BF6453F8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{39E95F03-C293-4985-8B69-0A47E2A8FE93}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3B996620-714E-4801-99FA-5F016DF12B8D}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{3F9B3520-EA2A-4E9B-9C6A-BCE87429E4EB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{408E484E-A3B0-4891-ACEC-65D295C8E914}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{422C6CFA-3BF2-43E5-8CD5-FECA60A8EB25}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{45180228-1170-4062-8D5C-924F74ADFD0D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{474EC78E-C555-4D10-A37F-80E0F9EA47A3}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{488C5E63-8238-4D9D-B55B-7B233146EF99}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4CC8B53D-3B25-414A-9DE7-57FF3695B034}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4D77EC7A-A60D-4DFC-91F0-A497C8971E75}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4F0EB7D7-2D34-4A16-824C-F7EFA9C544D8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{515F109B-B99F-4131-84F0-F135DD72DC66}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{52CE107D-80BE-4350-9D9A-F9D05D1FCD6D}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
"{53C63702-0A63-4206-87CF-12FFC047B7D4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5ABAFAC9-9BB1-4E84-BBD3-93C46B819B0E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5CA3F644-2CB9-4167-8D01-5F1B472625E3}" = protocol=6 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{5FB987FC-86EB-4080-A7D8-776253AAB3C0}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{64F471A5-43C0-4067-B589-61617BF10FDD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6542839E-1908-46D1-AB4C-E497CE2ED9E7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{69BF4DA4-2648-48AB-8044-A626B9B3597A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6D9FEE52-99AA-4373-A65A-4EBCB72E8D47}" = protocol=6 | dir=out | app=system |
"{7648EC2A-7E98-485A-8175-C19D1600C103}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{77124739-777B-4085-858C-AA4C29D63F56}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{79326378-EA77-43D0-BEFF-753581ACF28F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7B9B10C7-5CA3-4B2F-B832-6D3F94005990}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7D946C29-DD33-4AED-B4EA-232EB34F0B96}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{86193D0B-5586-41AC-A71E-E05FBF17C816}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8745055A-9571-4946-8B2D-D9188029C83B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8DF1A4C8-8D90-4F6C-873D-56C30A6FEFDA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93A20081-4183-48CD-A3BD-825DB79FDC14}" = protocol=17 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{94E84928-CB28-49FC-9B73-D88B4F4D3278}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{993C3FD7-AC02-4819-948B-9F58DD40967B}" = protocol=17 | dir=in | app=c:\users\suzanne edgar\appdata\local\microsoft\windows\temporary internet files\content.ie5\xyormhi0\sweetimsetup[1].exe |
"{9D62AA45-0A96-4886-A61D-B1B57B1E162C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9E7C0467-7D62-4D5B-810F-F70DC568BC83}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A18B270C-5916-45F4-93FF-2AC504B7B088}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B2A70AEE-243B-4CAA-BB37-1910BC1F763F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BA6E22D3-0D3B-45E9-9332-20E4B1DE5BC3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C028E8FB-87EA-4E2F-81B7-B7D8FABC7785}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C0603F51-936C-4EB1-A930-515D75DFBFA1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C3850AE2-772F-4531-891C-F4F1D41147AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C6C4ED6B-FF00-4624-83FD-1BDEFC10AD3F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CB83EFD8-D7EB-436E-B57C-93F27F1708E1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CCB5D79F-89C6-4C8D-A8BC-6CB7ED00BCF2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D1B8CB5F-347E-4F97-997E-A64B6BC8634D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D7B30104-40B1-4F7E-A2A4-FAFB82859738}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D8B5DDB6-8D61-4603-B7B8-12186D4A7C04}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{DC51A5A1-C428-419A-AE39-4B2D28D91C3B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DD535DFB-F048-4E07-9458-F130C7E82BA1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{DD61564F-B03A-467F-8004-F97F791F3316}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E3789212-BB51-4F39-8903-F44272407FC2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E67A5C44-0E6B-466A-9A2A-8AC6FF0EF332}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{EDCD23EC-8670-4C2A-A6D5-CDB8AB5A32DE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F743F2D6-4C1D-46E5-9721-41FB256BE5D0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F9F0EEB0-BC26-46CC-99FF-DECB63E81A55}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{FBFF0677-BD1B-47C8-826F-2EB402897624}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FEA1D251-C196-456F-A82B-541E9FD9C8A9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{2F0B0AA5-5C66-4664-8222-5E6B8D883918}C:\program files\common files\roxio shared\9.0\sharedcom\roxwatchtray9.exe" = protocol=6 | dir=in | app=c:\program files\common files\roxio shared\9.0\sharedcom\roxwatchtray9.exe |
"TCP Query User{2F1CF23B-AA61-40F4-B8EC-8DA040065192}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"TCP Query User{72DF1613-FC52-4039-84EC-717F4CACA9A3}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{9EE9AEC2-038F-4EBA-BDA0-9BA2F4D87024}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"TCP Query User{C398276D-AE8F-4701-958C-4E391C76390F}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"TCP Query User{C6A2A852-E4D2-4930-81F2-C39B4FE7F10F}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{5D79DAC9-B48B-4CB8-9294-F21076D306D5}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"UDP Query User{7178343A-2053-4DEC-826A-C28DB2838500}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"UDP Query User{7BE3EAD9-062C-4C30-84B2-A13DC827AA9C}C:\program files\common files\roxio shared\9.0\sharedcom\roxwatchtray9.exe" = protocol=17 | dir=in | app=c:\program files\common files\roxio shared\9.0\sharedcom\roxwatchtray9.exe |
"UDP Query User{88C7A2F2-8C63-45CC-BD72-8740131DCB4A}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{9F369EC2-A2CC-491F-8AA1-2EDA847D7FA1}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{A1263A7C-540B-4611-BE2F-B288E71ED337}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{196B7B22-A476-4906-B4D5-C587103A2A5A}" = SweetIM for Messenger 3.0
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 24
"{281ECE39-F043-492B-8337-F2E546B5604A}" = PowerDVD
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E5386F5-C0F6-4532-A54A-374865AEAB71}" = Cisco PEAP Module
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{64088381-C625-41E7-B3FA-A5EE3268E264}_is1" = PCX Viewer
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76F9CF97-FC4B-4E20-B363-D127C888448F}" = Cisco LEAP Module
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7ADE3A47-B425-45E9-8FF6-11BE2B775645}" = Corel Snapfire Plus
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B7443F5-E141-42A0-AB61-ED2331AAD606}" = 4oD
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93A1B09E-BAFA-4628-A5B6-921CB026955A}" = Corel Paint Shop Pro Photo XI
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}" = Citrix Presentation Server Client
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BF53252E-4AB2-4C7F-A0FD-6100755745E3}" = Cisco EAP-FAST Module
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E713653C-8312-4BC6-AFC9-ADE1F2F04AB9}" = ATI PCI Express (3GIO) Filter Driver
"{EAB9C426-6626-7B76-64F3-569FDCA9852D}" = ATI Catalyst Control Center Ex
"{EAEFE1C0-EB56-8963-9EC5-A0EB5FBA358D}" = TweetDeck
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"4oD" = 4oD
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast" = avast! Free Antivirus
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"EPSON Stylus SX400 Series" = EPSON Stylus SX400 Series Printer Uninstall
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"RealPlayer 6.0" = RealPlayer
"SopCast" = SopCast 3.2.9
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Tux Paint_is1" = Tux Paint 0.9.21
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"VLC media player" = VLC media player 1.1.2
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 22/04/2011 04:46:55 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 22/04/2011 04:47:07 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 22/04/2011 04:47:20 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 22/04/2011 05:45:28 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 22/04/2011 05:45:39 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 22/04/2011 05:45:50 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 22/04/2011 11:49:49 | Computer Name = SUZANNE-EDGAR | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.19048 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 10c0 Start Time: 01cc01040b6e38bc Termination Time: 0

Error - 01/05/2011 07:10:13 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 01/05/2011 07:10:25 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

Error - 01/05/2011 07:10:40 | Computer Name = SUZANNE-EDGAR | Source = MsiInstaller | ID = 1024
Description =

[ Broadcom Wireless LAN Events ]
Error - 16/04/2009 14:37:27 | Computer Name = SUZANNE-EDGAR | Source = WLAN-Tray | ID = 0
Description = 19:37:27, Thu, Apr 16, 09 Error - Unable to gain access to user store


[ System Events ]
Error - 07/05/2011 10:26:09 | Computer Name = SUZANNE-EDGAR | Source = DCOM | ID = 10010
Description =

Error - 07/05/2011 10:26:34 | Computer Name = SUZANNE-EDGAR | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 07/05/2011 10:37:32 | Computer Name = SUZANNE-EDGAR | Source = R300 | ID = 43015
Description = I2c return failed

Error - 07/05/2011 10:37:32 | Computer Name = SUZANNE-EDGAR | Source = R300 | ID = 43015
Description = I2c return failed

Error - 07/05/2011 10:39:23 | Computer Name = SUZANNE-EDGAR | Source = Service Control Manager | ID = 7000
Description =

Error - 07/05/2011 10:39:23 | Computer Name = SUZANNE-EDGAR | Source = Service Control Manager | ID = 7000
Description =

Error - 07/05/2011 10:46:29 | Computer Name = SUZANNE-EDGAR | Source = Service Control Manager | ID = 7000
Description =

Error - 07/05/2011 10:46:29 | Computer Name = SUZANNE-EDGAR | Source = Service Control Manager | ID = 7000
Description =

Error - 07/05/2011 10:48:11 | Computer Name = SUZANNE-EDGAR | Source = Service Control Manager | ID = 7000
Description =

Error - 07/05/2011 10:48:11 | Computer Name = SUZANNE-EDGAR | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Hi ,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Not really seeing anything.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
[2010/07/11 10:18:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 13:07:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/04 21:51:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
O2 - BHO: (no name) - {EEE6C35C-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.6.0_20)
O20 - AppInit_DLLs: (AVGRSSTX.DLL) - File not found
[2010/05/18 19:51:13 | 000,480,056 | —- | M] ()(C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav) – C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav
[2010/05/18 19:51:13 | 000,480,056 | —- | C] ()(C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav) – C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
Hi Tomk Thanks for your time Here is the log All processes killed ========== PROCESSES ========== ========== OTL ========== Prefs.js: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7B13EC3E-999A-4B70-B9CB-2617B8323822} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7B13EC3E-999A-4B70-B9CB-2617B8323822}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:AVGRSSTX.DLL deleted successfully. File C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav not found. File C:\Windows\System32\A ? ? a ?_18_05_2010@19_46_57.wav not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Lee Edgar ->Temp folder emptied: 211253748 bytes ->Temporary Internet Files folder emptied: 49663228 bytes ->Java cache emptied: 45917 bytes ->FireFox cache emptied: 100265499 bytes ->Flash cache emptied: 18584 bytes User: Public User: SUZANNE EDGAR ->Temp folder emptied: 461938470 bytes ->Temporary Internet Files folder emptied: 446978560 bytes ->Java cache emptied: 136485331 bytes ->FireFox cache emptied: 49897890 bytes ->Google Chrome cache emptied: 6562163 bytes ->Flash cache emptied: 51772 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 210566931 bytes RecycleBin emptied: 2622 bytes Total Files Cleaned = 1,596.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05092011_202822 Files\Folders moved on Reboot… File\Folder C:\Users\SUZANNE EDGAR\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\XV3P3SVM\MB_1001to5000_last9;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat= 1;items=11;sz=180x150;ord=1258816148925;tile=2;um=4;us=12;eb_trk=132339;pr=22;xp= 33;np=22[2].htm not found! File\Folder C:\Users\SUZANNE EDGAR\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\O3EI1YSD\5000_last9;seg=GL_AllSucBuy_Mar05;seg=GL_AllRegisteredUsers;tcat=1;items=11 ;sz=160x600;ord=1258816148925;dcopt=ist;tile=1;um=4;us=12;eb_trk=135666;pr=22;xp= 33;np=22[1].htm not found! C:\Windows\temp\_avast_\unp81718127.tmp moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot…
edgardavids,

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Nothing found on the ESET scan ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=08fd9129e4a67c46811525b29d84feff # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-05-10 08:15:44 # local_time=2011-05-10 09:15:44 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=770 16774141 100 100 2365255 241334163 0 0 # compatibility_mode=5892 16776573 100 100 275006 142585781 0 0 # compatibility_mode=8192 67108863 100 0 335 335 0 0 # scanned=145620 # found=0 # cleaned=0 # scan_time=5534
edgardavids,

I don't think you are infected with malware. However, you are kicking some controller errors. I suggest that you post over in the Windows Forum and see if the Tech Team can help you get things straightened out. When you post there, it would be good if you included a link back to this thread so they can see what you have posted here.

Let's cleanup after ourselves first.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Be sure to re-activate any security that you disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI