It has been running a lot sluggish and ridiculously loud for a computer only a couple of months old.
I have MBAMed it and it is now nice and quiet and programs are booting faster but the internet still feels like it is 256k. It is only slow on this PC and this PC has the shorted lead to BoB so should technically be the fastest of the lot to boot.
No other computers are actively using the internet either.
MBAM Log.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6531
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
8/05/2011 9:53:08 PM
mbam-log-2011-05-08 (21-53-08).txt
Scan type: Quick scan
Objects scanned: 158157
Time elapsed: 3 minute(s), 16 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
c:\Users\margarita\AppData\Roaming\taskhost.exe (Trojan.Dropper) -> 3404 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Task Manager (Trojan.Dropper) -> Value: Windows Task Manager -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Internet (Backdoor.Bot) -> Value: Internet -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\margarita\AppData\Roaming\taskhost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\margarita\AppData\Local\Temp\c2XKB8M.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
OTL Log
OTL logfile created on: 8/05/2011 10:02:47 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Margarita\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 54.80 Gb Free Space | 23.53% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 195.64 Gb Free Space | 21.00% Space Free | Partition Type: NTFS
Drive E: | 298.08 Gb Total Space | 182.08 Gb Free Space | 61.08% Space Free | Partition Type: NTFS
Drive H: | 931.51 Gb Total Space | 918.84 Gb Free Space | 98.64% Space Free | Partition Type: NTFS
Computer Name: MARGARITA-PC | User Name: Margarita | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found
PRC - C:\Users\Margarita\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\17.5.0.127\InstStub.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files\TRENDnet\TEW-649UB\WlanCU.exe ()
PRC - C:\Program Files\TRENDnet\TEW-649UB\WlanWpsSvc.exe ()
PRC - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\Margarita\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (WlanWpsSvc) – C:\Program Files\TRENDnet\TEW-649UB\WlanWpsSvc.exe ()
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
SRV - (BCUService) – C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Adobe Version Cue CS3) – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
========== Driver Services (SafeList) ==========
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8192su) – C:\Windows\SysNative\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (KMWDFILTER) – C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20091209.020\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20091209.020\ENG64.SYS (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 44 05 7D C6 41 0B CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\IPSFFPlgn\
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\coFFPlgn\
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/16 22:50:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/08 12:06:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/08 21:58:53 | 000,000,000 | —D | M]
[2010/11/23 16:34:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Margarita\AppData\Roaming\Mozilla\Extensions
[2010/11/25 07:23:16 | 000,000,000 | —D | M] (No name found) – C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\8rvzc43k.default\extensions
[2011/04/10 13:41:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/11/30 00:14:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/28 20:46:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/16 22:50:24 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/11/28 20:46:50 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [\\IIMAGINATION\EPSON Stylus CX3900] File not found
O4 - HKCU..\Run: [EPSON Stylus CX3900 Series] File not found
O4 - Startup: C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/22 15:53:23 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/05/08 21:59:24 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{6FE5CE3A-E491-460F-8A9C-708E978524B2}
[2011/05/08 21:43:21 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Malwarebytes
[2011/05/08 21:43:18 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/08 21:43:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/08 21:43:18 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/08 21:43:15 | 000,024,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/05/08 21:43:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/05/07 12:59:38 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BFA1104A-7441-4201-9FA2-04D66C8F845D}
[2011/05/06 16:29:28 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{71F69727-7853-43F9-BB3D-97A6E60232D6}
[2011/05/06 04:29:16 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8A203111-011D-4C87-B7BE-AE8D8A29B8EA}
[2011/05/05 16:29:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BCD7E099-19B4-4E62-B7D4-E52BFC8EBF15}
[2011/05/04 12:15:39 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A5B796B9-2BD6-43D3-B03B-AEDE50278DDD}
[2011/05/04 00:15:27 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{65A51963-CA12-4BBE-BBE5-69C2D0223A6E}
[2011/05/03 12:15:15 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{C29530FB-B512-4BF9-8F00-436E60BE4173}
[2011/05/03 00:15:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8F719CB6-48B1-49CB-9FC5-4A9C4E24965C}
[2011/05/02 12:14:51 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{364D1DFB-EA25-4A33-A8D2-EF0808795B78}
[2011/05/02 00:14:39 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8DA79990-A3AC-498B-9FF8-56D987C5D073}
[2011/05/01 12:14:28 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{1B767BB1-F3CD-4056-AC36-BE2B976DDC28}
[2011/05/01 00:14:16 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{E8BAA70E-0EAB-4D93-A96A-026067959ABF}
[2011/04/30 12:14:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{3895A538-0540-41FD-B3BE-422573FE6DD0}
[2011/04/30 02:48:09 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\AustarAnywhereDesktopApplication.7C28940E702BD503DC2BDA2FC8B8270C7F1C0180.1
[2011/04/30 02:48:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AUSTAR AnyWhere
[2011/04/30 02:48:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\AUSTAR AnyWhere
[2011/04/29 22:15:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{64303F0D-E385-496D-93B3-04A5514C55CC}
[2011/04/29 10:14:45 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A58F3595-2CEE-479E-B718-771B1312E718}
[2011/04/28 21:15:22 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{B454C046-CDA7-477D-B322-D92AF4CA00A2}
[2011/04/28 09:15:10 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{B3F2DC18-1B1E-4DDD-9279-4C92D88BB294}
[2011/04/27 18:06:11 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A72CACE7-31A4-45AB-AF6E-6DEB217EC03C}
[2011/04/27 06:05:59 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{FA7A7C37-FF92-44B4-AFD5-3A0A77F237AC}
[2011/04/26 18:05:47 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{405E0F50-0EB3-4EBA-98A8-C8085B849E82}
[2011/04/26 06:05:09 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BE67BC8B-5742-4B7F-A93D-AC09027328D9}
[2011/04/25 19:48:59 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{F25D3DC9-1BBB-46BA-B9AD-DBF61D554E4C}
[2011/04/25 19:32:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8C7CC14C-273A-4C81-BDDA-769ED1A37B84}
[2011/04/24 03:30:41 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{E5341BBB-CEE5-4F76-A43F-9B66C14563FA}
[2011/04/23 15:30:28 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5C19C153-8F39-4E31-9908-19B8768308DE}
[2011/04/23 00:55:17 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{783B973E-B530-4041-8253-3C19D82DD0EC}
[2011/04/22 12:55:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{31DA25FD-CDBC-4E43-9217-778EB480B936}
[2011/04/22 00:37:55 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{DBE137FF-F3E3-4DDC-89E2-55CAFD756D6C}
[2011/04/21 12:37:32 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5EA94598-685D-4B89-9844-32C99CC4270A}
[2011/04/21 00:37:17 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{0B47EFB2-FA39-4C1B-AE59-86F80CEF7C35}
[2011/04/20 12:37:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{208DBD8B-A923-4DBC-A467-756052DF545E}
[2011/04/20 00:36:52 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{78AFC37E-DF8F-4D7B-8530-FA143B06BFEF}
[2011/04/19 12:36:40 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{79E1B54D-171D-47C0-808C-1F53F0D394E4}
[2011/04/18 21:34:54 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A8C51C05-E5A3-4AF5-ABC7-766AD5D2950D}
[2011/04/18 09:34:42 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{360D2A28-B834-4AE8-86E5-DCC293C3A28D}
[2011/04/17 21:34:30 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{86DF9362-8309-4DF2-AE32-150E65E1ABA7}
[2011/04/17 09:34:06 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{42BB1C3C-F9FE-4A13-92EF-50A773B9659D}
[2011/04/16 22:57:55 | 000,719,872 | —- | C] (Abysmal Software) – C:\Windows\SysWow64\devil.dll
[2011/04/16 22:57:55 | 000,369,152 | —- | C] (The Public) – C:\Windows\SysWow64\avisynth.dll
[2011/04/16 22:57:55 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2011/04/16 22:57:55 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2011/04/16 22:57:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\AviSynth 2.5
[2011/04/16 22:54:19 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) – C:\Windows\SysWow64\nbDX.dll
[2011/04/16 22:54:19 | 000,186,880 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLOgg.ax
[2011/04/16 22:54:19 | 000,163,328 | RHS- | C] (Gabest) – C:\Windows\SysWow64\flvDX.dll
[2011/04/16 22:54:19 | 000,161,792 | RHS- | C] (Gabest) – C:\Windows\SysWow64\RealMediaDX.ax
[2011/04/16 22:54:19 | 000,092,672 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLVorbisDec.ax
[2011/04/16 22:54:19 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSSplitter.ax
[2011/04/16 22:54:19 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSDecoder.ax
[2011/04/16 22:54:19 | 000,067,584 | RHS- | C] (RadLight, LLC) – C:\Windows\SysWow64\RLTheoraDec.ax
[2011/04/16 22:54:19 | 000,031,232 | RHS- | C] (Hans Mayerl) – C:\Windows\SysWow64\msfDX.dll
[2011/04/16 22:54:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
[2011/04/16 22:54:18 | 000,179,200 | RHS- | C] (Gabest) – C:\Windows\SysWow64\DiracSplitter.ax
[2011/04/16 22:54:18 | 000,169,472 | RHS- | C] (Gabest) – C:\Windows\SysWow64\MatroskaDX.ax
[2011/04/16 22:54:18 | 000,123,904 | RHS- | C] (CoreCodec) – C:\Windows\SysWow64\AVCDX.ax
[2011/04/16 22:50:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/04/16 22:50:22 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/04/16 22:50:19 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/04/16 22:50:19 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/04/16 22:50:18 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/04/16 22:50:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011/04/16 22:49:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/04/16 22:49:55 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/04/16 22:49:53 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Real
[2011/04/16 22:39:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\eRightSoft
[2011/04/16 22:20:34 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AllToAVI
[2011/04/16 22:20:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AllToAVI
[2011/04/16 22:20:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\AllToAVI
[2011/04/16 22:08:51 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\vlc
[2011/04/16 22:06:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/04/16 22:06:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2011/04/16 21:33:54 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{ACD2B533-D7D6-484F-B7EC-984C39AF3A08}
[2011/04/16 09:33:30 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{005E1703-0C6A-4D88-865B-64CC754A75C6}
[2011/04/15 21:33:18 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{2A7AF92C-8AA6-4833-AD34-4B5180CA2EC4}
[2011/04/15 10:43:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{AEF7D097-C1A8-4822-9F30-A4996D8C5312}
[2011/04/14 22:31:57 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{E95B8857-F5D6-4125-A412-45283CA65721}
[2011/04/14 10:24:37 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{947A3672-4383-49A2-8774-0A31FCA709C4}
[2011/04/13 22:24:12 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{40654857-D858-4728-B87D-7496D39E704F}
[2011/04/13 10:24:00 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{9BB02A69-DDA2-4192-A5F9-EED45875216D}
[2011/04/12 22:23:36 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{F6AE10A9-B1DB-4744-B8C1-679EAFA6180E}
[2011/04/12 10:23:24 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{B5D45EE3-0CC0-43A0-841E-7A489B89F553}
[2011/04/11 22:22:59 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BEB581F5-1BD5-4DD2-A309-3C9D4289F860}
[2011/04/11 10:22:47 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5514C86F-C415-4EE9-9C1A-3AEA0C1F2B62}
[2011/04/10 22:22:22 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{69B0628C-B01F-45DA-8CCB-3AEB47EE7903}
[2011/04/10 10:21:55 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{896A230A-1836-40FD-8D86-E327B5B569CA}
[2011/04/09 21:21:58 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{CB6483E0-B1DF-446C-8B5E-B069E2E5E283}
[2011/04/09 09:21:46 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5B3B902D-9D96-4852-B803-BB4E01E2F6E1}
========== Files - Modified Within 30 Days ==========
[2011/05/08 22:04:04 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/08 22:00:36 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/08 22:00:36 | 000,628,024 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/08 22:00:36 | 000,110,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/08 21:58:54 | 000,002,019 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/05/08 21:55:58 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/08 21:55:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/08 21:55:32 | 3082,018,816 | -HS- | M] () – C:\hiberfil.sys
[2011/05/08 21:54:38 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/08 21:54:38 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/08 21:43:18 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/08 04:04:45 | 000,002,344 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/05/07 04:12:26 | 000,015,956 | —- | M] () – C:\Users\Margarita\Documents\disbor.odt
[2011/05/06 06:54:34 | 000,013,991 | —- | M] () – C:\Users\Margarita\Documents\Ass2 research (2).odt
[2011/05/06 04:37:10 | 000,015,134 | —- | M] () – C:\Users\Margarita\Documents\Ass2 research.odt
[2011/04/30 02:48:02 | 000,000,941 | —- | M] () – C:\Users\Public\Desktop\AUSTAR AnyWhere.lnk
[2011/04/28 17:21:34 | 000,056,348 | —- | M] () – C:\Users\Margarita\Documents\Research Plan (40%).pdf
[2011/04/24 02:01:16 | 000,418,148 | —- | M] () – C:\Users\Margarita\Documents\Present Tags.pdf
[2011/04/19 03:18:05 | 000,014,700 | —- | M] () – C:\Users\Margarita\Documents\mis.jpg
[2011/04/17 10:49:12 | 000,014,493 | —- | M] () – C:\Users\Margarita\Documents\Payment Receipt - PayPal.pdf
[2011/04/16 22:50:33 | 000,001,952 | —- | M] () – C:\Users\Public\Desktop\Free Movies & Games.lnk
[2011/04/16 22:50:33 | 000,001,268 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/04/16 22:50:22 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/04/16 22:50:19 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/04/16 22:50:19 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/04/16 22:50:18 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/04/16 22:50:17 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/04/16 22:50:17 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/04/16 22:20:34 | 000,001,021 | —- | M] () – C:\Users\Margarita\Desktop\AllToAVI.lnk
[2011/04/16 22:06:39 | 000,001,070 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/13 10:52:06 | 000,031,168 | —- | M] () – C:\Users\Margarita\Documents\Change Deductions.pdf
[2011/04/11 21:13:38 | 000,163,692 | —- | M] () – C:\Users\Margarita\Documents\kobyfull.jpg
[2011/04/11 14:45:51 | 000,072,801 | —- | M] () – C:\Users\Margarita\Documents\koby.jpg
[2011/04/11 14:00:50 | 000,073,831 | —- | M] () – C:\Users\Margarita\Documents\koby4.jpg
[2011/04/10 21:56:28 | 000,140,634 | —- | M] () – C:\Users\Margarita\Documents\koby3.jpg
[2011/04/10 21:41:33 | 000,075,971 | —- | M] () – C:\Users\Margarita\Documents\kobysamp.jpg
[2011/04/10 18:39:27 | 000,093,191 | —- | M] () – C:\Users\Margarita\Documents\koby1.jpg
[2011/04/10 18:37:08 | 000,046,227 | —- | M] () – C:\Users\Margarita\Documents\koby2.jpg
[2011/04/10 18:36:59 | 000,366,030 | —- | M] () – C:\Users\Margarita\Documents\koby2.pdf
[2011/04/10 18:25:47 | 000,298,025 | —- | M] () – C:\Users\Margarita\Documents\koby1.pdf
========== Files Created - No Company Name ==========
[2011/05/08 21:43:18 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/06 15:47:18 | 000,013,991 | —- | C] () – C:\Users\Margarita\Documents\Ass2 research (2).odt
[2011/05/03 17:27:23 | 000,015,134 | —- | C] () – C:\Users\Margarita\Documents\Ass2 research.odt
[2011/04/30 02:48:02 | 000,000,941 | —- | C] () – C:\Users\Public\Desktop\AUSTAR AnyWhere.lnk
[2011/04/28 17:21:34 | 000,056,348 | —- | C] () – C:\Users\Margarita\Documents\Research Plan (40%).pdf
[2011/04/24 02:01:09 | 000,418,148 | —- | C] () – C:\Users\Margarita\Documents\Present Tags.pdf
[2011/04/19 03:18:05 | 000,014,700 | —- | C] () – C:\Users\Margarita\Documents\mis.jpg
[2011/04/17 10:49:12 | 000,014,493 | —- | C] () – C:\Users\Margarita\Documents\Payment Receipt - PayPal.pdf
[2011/04/16 22:57:55 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2011/04/16 22:54:19 | 000,107,520 | RHS- | C] () – C:\Windows\SysWow64\RLMPCDec.ax
[2011/04/16 22:54:19 | 000,070,656 | RHS- | C] () – C:\Windows\SysWow64\RLAPEDec.ax
[2011/04/16 22:54:19 | 000,051,712 | RHS- | C] () – C:\Windows\SysWow64\RLSpeexDec.ax
[2011/04/16 22:54:18 | 000,227,328 | RHS- | C] () – C:\Windows\SysWow64\ac3DX.ax
[2011/04/16 22:54:18 | 000,175,104 | RHS- | C] () – C:\Windows\SysWow64\CoreAAC.ax
[2011/04/16 22:54:18 | 000,120,832 | RHS- | C] () – C:\Windows\SysWow64\MPCDx.ax
[2011/04/16 22:54:18 | 000,097,280 | RHS- | C] () – C:\Windows\SysWow64\FLACDX.ax
[2011/04/16 22:54:18 | 000,081,920 | RHS- | C] () – C:\Windows\SysWow64\aac_parser.ax
[2011/04/16 22:50:33 | 000,001,952 | —- | C] () – C:\Users\Public\Desktop\Free Movies & Games.lnk
[2011/04/16 22:50:33 | 000,001,268 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/04/16 22:20:34 | 000,001,021 | —- | C] () – C:\Users\Margarita\Desktop\AllToAVI.lnk
[2011/04/16 22:06:39 | 000,001,070 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/13 10:52:06 | 000,031,168 | —- | C] () – C:\Users\Margarita\Documents\Change Deductions.pdf
[2011/04/11 21:13:38 | 000,163,692 | —- | C] () – C:\Users\Margarita\Documents\kobyfull.jpg
[2011/04/11 14:45:51 | 000,072,801 | —- | C] () – C:\Users\Margarita\Documents\koby.jpg
[2011/04/11 14:00:50 | 000,073,831 | —- | C] () – C:\Users\Margarita\Documents\koby4.jpg
[2011/04/10 21:56:28 | 000,140,634 | —- | C] () – C:\Users\Margarita\Documents\koby3.jpg
[2011/04/10 21:41:33 | 000,075,971 | —- | C] () – C:\Users\Margarita\Documents\kobysamp.jpg
[2011/04/10 18:39:27 | 000,093,191 | —- | C] () – C:\Users\Margarita\Documents\koby1.jpg
[2011/04/10 18:37:06 | 000,046,227 | —- | C] () – C:\Users\Margarita\Documents\koby2.jpg
[2011/04/10 18:36:51 | 000,366,030 | —- | C] () – C:\Users\Margarita\Documents\koby2.pdf
[2011/04/10 18:25:39 | 000,298,025 | —- | C] () – C:\Users\Margarita\Documents\koby1.pdf
[2010/12/09 16:52:13 | 002,463,976 | —- | C] () – C:\Windows\SysWow64\NPSWF32.dll
[2010/11/23 15:40:00 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2010/11/23 15:40:00 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010/11/23 15:39:57 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010/11/23 15:39:57 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010/11/23 15:37:35 | 000,042,730 | —- | C] () – C:\Windows\Ascd_log.ini
[2010/11/23 15:30:18 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/11/23 15:30:11 | 000,030,774 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/08/25 18:34:30 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/08/25 18:34:30 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/04/21 10:14:52 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/04/21 09:22:50 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/04/21 09:22:50 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/14 15:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 12:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 10:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 07:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/04/02 22:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2009/02/25 21:38:27 | 000,188,416 | —- | C] () – C:\Windows\SysWow64\HFCdtASP.dll
[2006/03/18 23:16:04 | 000,540,178 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2005/08/18 19:34:09 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\HFCNTS.dll
========== LOP Check ==========
[2011/04/30 02:48:09 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\AustarAnywhereDesktopApplication.7C28940E702BD503DC2BDA2FC8B8270C7F1C0180.1
[2011/04/08 20:26:24 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\DVDVideoSoft
[2011/02/17 13:41:04 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\HandBrake
[2010/11/30 05:16:38 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\OpenOffice.org
[2011/01/18 08:54:47 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\Windows Live Writer
[2009/07/14 15:08:49 | 000,012,960 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/14 11:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/24 10:19:27 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/05/08 21:55:32 | 3082,018,816 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 07:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/05/08 21:55:36 | 4109,361,152 | -HS- | M] () – C:\pagefile.sys
[2010/11/23 15:26:42 | 000,171,136 | RHS- | M] () – C:\w7ldr
[2010/12/01 00:20:45 | 000,000,013 | —- | M] () – C:\Winvdrvr.dll
< %systemroot%\Fonts\*.com >
[2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/23 15:55:27 | 000,000,221 | -HS- | M] () – C:\Users\Margarita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
Thanks
ETA: Just a couple of things I remembered going through the log (thanks to the enormous lot of file not founds???)
1: It will not print to the network printer from anything but OpenOffice. This has been extremely frustrating. I have reinstalled the drivers a dozen times.
2: I do have ReaderX - the Acrobat 8 is part of AMC3.
3: Google Chrome sometimes registers the click but wont actually load the page. It does the swirly thing and then kinda does that "look, I loaded the page" hop, but it hasn't done squat.
A reboot of my system and router has improved interweb speeds. Hopefully permanently. I do plan on moving a lot of the stuff on C onto one of the other drives but will leave the drive intact until I am sure it is clear.
I am usually a lot better than this and this is embarrassing, but I needed some conversion programs in a hurry and while normally I would have checked the reviews and bought something decent, I let my guard down and installed a couple of questionable ones just trying to get the job done. I also usually have proper programs running rather than what comes with windows but this machine is new and I am a first class procrastinator! (Might explain why I was downloading dodgy software moments from deadline! HA!)
ETA: Again.. Remembering more stuff.
E: is my old system drive. XP on there skitzed over something and the whole system crashed epically and wouldn't speak to me. I got my tech guy to fix it (he is three hours away so I don't call on him for anything but epic fails) and he got it up and running again. I didn't plug it in straight away, it was raining here (think QLD Australia floods, although it didn't flood here. It just rained a whole lot.) and moisture got into the power supply and I didn't know so when I did plug it in, it blew up quite spectacularly. Anyway, I salvaged the drive out, put it in here to get all my work off of it. Anything that might pop up on it would possibly be dormant as the OS was hacked off of that drive.
I am meant to be cleaning it off and formatting it…. there is that procrastination again!