This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Seriously Degraded Performance

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, so as annoying as it is to have to post again, but … :pullhair:

It has been running a lot sluggish and ridiculously loud for a computer only a couple of months old.

I have MBAMed it and it is now nice and quiet and programs are booting faster but the internet still feels like it is 256k. It is only slow on this PC and this PC has the shorted lead to BoB so should technically be the fastest of the lot to boot.
No other computers are actively using the internet either.

MBAM Log.


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6531

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

8/05/2011 9:53:08 PM
mbam-log-2011-05-08 (21-53-08).txt

Scan type: Quick scan
Objects scanned: 158157
Time elapsed: 3 minute(s), 16 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
c:\Users\margarita\AppData\Roaming\taskhost.exe (Trojan.Dropper) -> 3404 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Task Manager (Trojan.Dropper) -> Value: Windows Task Manager -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Internet (Backdoor.Bot) -> Value: Internet -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\margarita\AppData\Roaming\taskhost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\margarita\AppData\Local\Temp\c2XKB8M.exe (Trojan.Dropper) -> Quarantined and deleted successfully.



OTL Log

OTL logfile created on: 8/05/2011 10:02:47 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Margarita\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 54.80 Gb Free Space | 23.53% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 195.64 Gb Free Space | 21.00% Space Free | Partition Type: NTFS
Drive E: | 298.08 Gb Total Space | 182.08 Gb Free Space | 61.08% Space Free | Partition Type: NTFS
Drive H: | 931.51 Gb Total Space | 918.84 Gb Free Space | 98.64% Space Free | Partition Type: NTFS

Computer Name: MARGARITA-PC | User Name: Margarita | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Margarita\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\17.5.0.127\InstStub.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files\TRENDnet\TEW-649UB\WlanCU.exe ()
PRC - C:\Program Files\TRENDnet\TEW-649UB\WlanWpsSvc.exe ()
PRC - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Margarita\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (WlanWpsSvc) – C:\Program Files\TRENDnet\TEW-649UB\WlanWpsSvc.exe ()
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
SRV - (BCUService) – C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Adobe Version Cue CS3) – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8192su) – C:\Windows\SysNative\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (KMWDFILTER) – C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20091209.020\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20091209.020\ENG64.SYS (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 44 05 7D C6 41 0B CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\IPSFFPlgn\
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\coFFPlgn\
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/16 22:50:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/08 12:06:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/08 21:58:53 | 000,000,000 | —D | M]

[2010/11/23 16:34:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Margarita\AppData\Roaming\Mozilla\Extensions
[2010/11/25 07:23:16 | 000,000,000 | —D | M] (No name found) – C:\Users\Margarita\AppData\Roaming\Mozilla\Firefox\Profiles\8rvzc43k.default\extensions
[2011/04/10 13:41:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/11/30 00:14:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/28 20:46:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/16 22:50:24 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/11/28 20:46:50 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [\\IIMAGINATION\EPSON Stylus CX3900] File not found
O4 - HKCU..\Run: [EPSON Stylus CX3900 Series] File not found
O4 - Startup: C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/22 15:53:23 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/08 21:59:24 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{6FE5CE3A-E491-460F-8A9C-708E978524B2}
[2011/05/08 21:43:21 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Malwarebytes
[2011/05/08 21:43:18 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/08 21:43:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/08 21:43:18 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/08 21:43:15 | 000,024,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/05/08 21:43:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/05/07 12:59:38 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BFA1104A-7441-4201-9FA2-04D66C8F845D}
[2011/05/06 16:29:28 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{71F69727-7853-43F9-BB3D-97A6E60232D6}
[2011/05/06 04:29:16 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8A203111-011D-4C87-B7BE-AE8D8A29B8EA}
[2011/05/05 16:29:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BCD7E099-19B4-4E62-B7D4-E52BFC8EBF15}
[2011/05/04 12:15:39 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A5B796B9-2BD6-43D3-B03B-AEDE50278DDD}
[2011/05/04 00:15:27 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{65A51963-CA12-4BBE-BBE5-69C2D0223A6E}
[2011/05/03 12:15:15 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{C29530FB-B512-4BF9-8F00-436E60BE4173}
[2011/05/03 00:15:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8F719CB6-48B1-49CB-9FC5-4A9C4E24965C}
[2011/05/02 12:14:51 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{364D1DFB-EA25-4A33-A8D2-EF0808795B78}
[2011/05/02 00:14:39 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8DA79990-A3AC-498B-9FF8-56D987C5D073}
[2011/05/01 12:14:28 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{1B767BB1-F3CD-4056-AC36-BE2B976DDC28}
[2011/05/01 00:14:16 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{E8BAA70E-0EAB-4D93-A96A-026067959ABF}
[2011/04/30 12:14:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{3895A538-0540-41FD-B3BE-422573FE6DD0}
[2011/04/30 02:48:09 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\AustarAnywhereDesktopApplication.7C28940E702BD503DC2BDA2FC8B8270C7F1C0180.1
[2011/04/30 02:48:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AUSTAR AnyWhere
[2011/04/30 02:48:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\AUSTAR AnyWhere
[2011/04/29 22:15:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{64303F0D-E385-496D-93B3-04A5514C55CC}
[2011/04/29 10:14:45 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A58F3595-2CEE-479E-B718-771B1312E718}
[2011/04/28 21:15:22 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{B454C046-CDA7-477D-B322-D92AF4CA00A2}
[2011/04/28 09:15:10 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{B3F2DC18-1B1E-4DDD-9279-4C92D88BB294}
[2011/04/27 18:06:11 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A72CACE7-31A4-45AB-AF6E-6DEB217EC03C}
[2011/04/27 06:05:59 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{FA7A7C37-FF92-44B4-AFD5-3A0A77F237AC}
[2011/04/26 18:05:47 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{405E0F50-0EB3-4EBA-98A8-C8085B849E82}
[2011/04/26 06:05:09 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BE67BC8B-5742-4B7F-A93D-AC09027328D9}
[2011/04/25 19:48:59 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{F25D3DC9-1BBB-46BA-B9AD-DBF61D554E4C}
[2011/04/25 19:32:03 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{8C7CC14C-273A-4C81-BDDA-769ED1A37B84}
[2011/04/24 03:30:41 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{E5341BBB-CEE5-4F76-A43F-9B66C14563FA}
[2011/04/23 15:30:28 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5C19C153-8F39-4E31-9908-19B8768308DE}
[2011/04/23 00:55:17 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{783B973E-B530-4041-8253-3C19D82DD0EC}
[2011/04/22 12:55:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{31DA25FD-CDBC-4E43-9217-778EB480B936}
[2011/04/22 00:37:55 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{DBE137FF-F3E3-4DDC-89E2-55CAFD756D6C}
[2011/04/21 12:37:32 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5EA94598-685D-4B89-9844-32C99CC4270A}
[2011/04/21 00:37:17 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{0B47EFB2-FA39-4C1B-AE59-86F80CEF7C35}
[2011/04/20 12:37:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{208DBD8B-A923-4DBC-A467-756052DF545E}
[2011/04/20 00:36:52 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{78AFC37E-DF8F-4D7B-8530-FA143B06BFEF}
[2011/04/19 12:36:40 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{79E1B54D-171D-47C0-808C-1F53F0D394E4}
[2011/04/18 21:34:54 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{A8C51C05-E5A3-4AF5-ABC7-766AD5D2950D}
[2011/04/18 09:34:42 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{360D2A28-B834-4AE8-86E5-DCC293C3A28D}
[2011/04/17 21:34:30 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{86DF9362-8309-4DF2-AE32-150E65E1ABA7}
[2011/04/17 09:34:06 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{42BB1C3C-F9FE-4A13-92EF-50A773B9659D}
[2011/04/16 22:57:55 | 000,719,872 | —- | C] (Abysmal Software) – C:\Windows\SysWow64\devil.dll
[2011/04/16 22:57:55 | 000,369,152 | —- | C] (The Public) – C:\Windows\SysWow64\avisynth.dll
[2011/04/16 22:57:55 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2011/04/16 22:57:55 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2011/04/16 22:57:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\AviSynth 2.5
[2011/04/16 22:54:19 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) – C:\Windows\SysWow64\nbDX.dll
[2011/04/16 22:54:19 | 000,186,880 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLOgg.ax
[2011/04/16 22:54:19 | 000,163,328 | RHS- | C] (Gabest) – C:\Windows\SysWow64\flvDX.dll
[2011/04/16 22:54:19 | 000,161,792 | RHS- | C] (Gabest) – C:\Windows\SysWow64\RealMediaDX.ax
[2011/04/16 22:54:19 | 000,092,672 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLVorbisDec.ax
[2011/04/16 22:54:19 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSSplitter.ax
[2011/04/16 22:54:19 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSDecoder.ax
[2011/04/16 22:54:19 | 000,067,584 | RHS- | C] (RadLight, LLC) – C:\Windows\SysWow64\RLTheoraDec.ax
[2011/04/16 22:54:19 | 000,031,232 | RHS- | C] (Hans Mayerl) – C:\Windows\SysWow64\msfDX.dll
[2011/04/16 22:54:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
[2011/04/16 22:54:18 | 000,179,200 | RHS- | C] (Gabest) – C:\Windows\SysWow64\DiracSplitter.ax
[2011/04/16 22:54:18 | 000,169,472 | RHS- | C] (Gabest) – C:\Windows\SysWow64\MatroskaDX.ax
[2011/04/16 22:54:18 | 000,123,904 | RHS- | C] (CoreCodec) – C:\Windows\SysWow64\AVCDX.ax
[2011/04/16 22:50:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/04/16 22:50:22 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/04/16 22:50:19 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/04/16 22:50:19 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/04/16 22:50:18 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/04/16 22:50:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011/04/16 22:49:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/04/16 22:49:55 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/04/16 22:49:53 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Real
[2011/04/16 22:39:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\eRightSoft
[2011/04/16 22:20:34 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AllToAVI
[2011/04/16 22:20:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AllToAVI
[2011/04/16 22:20:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\AllToAVI
[2011/04/16 22:08:51 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Roaming\vlc
[2011/04/16 22:06:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/04/16 22:06:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2011/04/16 21:33:54 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{ACD2B533-D7D6-484F-B7EC-984C39AF3A08}
[2011/04/16 09:33:30 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{005E1703-0C6A-4D88-865B-64CC754A75C6}
[2011/04/15 21:33:18 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{2A7AF92C-8AA6-4833-AD34-4B5180CA2EC4}
[2011/04/15 10:43:04 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{AEF7D097-C1A8-4822-9F30-A4996D8C5312}
[2011/04/14 22:31:57 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{E95B8857-F5D6-4125-A412-45283CA65721}
[2011/04/14 10:24:37 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{947A3672-4383-49A2-8774-0A31FCA709C4}
[2011/04/13 22:24:12 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{40654857-D858-4728-B87D-7496D39E704F}
[2011/04/13 10:24:00 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{9BB02A69-DDA2-4192-A5F9-EED45875216D}
[2011/04/12 22:23:36 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{F6AE10A9-B1DB-4744-B8C1-679EAFA6180E}
[2011/04/12 10:23:24 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{B5D45EE3-0CC0-43A0-841E-7A489B89F553}
[2011/04/11 22:22:59 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{BEB581F5-1BD5-4DD2-A309-3C9D4289F860}
[2011/04/11 10:22:47 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5514C86F-C415-4EE9-9C1A-3AEA0C1F2B62}
[2011/04/10 22:22:22 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{69B0628C-B01F-45DA-8CCB-3AEB47EE7903}
[2011/04/10 10:21:55 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{896A230A-1836-40FD-8D86-E327B5B569CA}
[2011/04/09 21:21:58 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{CB6483E0-B1DF-446C-8B5E-B069E2E5E283}
[2011/04/09 09:21:46 | 000,000,000 | —D | C] – C:\Users\Margarita\AppData\Local\{5B3B902D-9D96-4852-B803-BB4E01E2F6E1}

========== Files - Modified Within 30 Days ==========

[2011/05/08 22:04:04 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/08 22:00:36 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/08 22:00:36 | 000,628,024 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/08 22:00:36 | 000,110,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/08 21:58:54 | 000,002,019 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/05/08 21:55:58 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/08 21:55:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/08 21:55:32 | 3082,018,816 | -HS- | M] () – C:\hiberfil.sys
[2011/05/08 21:54:38 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/08 21:54:38 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/08 21:43:18 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/08 04:04:45 | 000,002,344 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/05/07 04:12:26 | 000,015,956 | —- | M] () – C:\Users\Margarita\Documents\disbor.odt
[2011/05/06 06:54:34 | 000,013,991 | —- | M] () – C:\Users\Margarita\Documents\Ass2 research (2).odt
[2011/05/06 04:37:10 | 000,015,134 | —- | M] () – C:\Users\Margarita\Documents\Ass2 research.odt
[2011/04/30 02:48:02 | 000,000,941 | —- | M] () – C:\Users\Public\Desktop\AUSTAR AnyWhere.lnk
[2011/04/28 17:21:34 | 000,056,348 | —- | M] () – C:\Users\Margarita\Documents\Research Plan (40%).pdf
[2011/04/24 02:01:16 | 000,418,148 | —- | M] () – C:\Users\Margarita\Documents\Present Tags.pdf
[2011/04/19 03:18:05 | 000,014,700 | —- | M] () – C:\Users\Margarita\Documents\mis.jpg
[2011/04/17 10:49:12 | 000,014,493 | —- | M] () – C:\Users\Margarita\Documents\Payment Receipt - PayPal.pdf
[2011/04/16 22:50:33 | 000,001,952 | —- | M] () – C:\Users\Public\Desktop\Free Movies & Games.lnk
[2011/04/16 22:50:33 | 000,001,268 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/04/16 22:50:22 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/04/16 22:50:19 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/04/16 22:50:19 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/04/16 22:50:18 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/04/16 22:50:17 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/04/16 22:50:17 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/04/16 22:20:34 | 000,001,021 | —- | M] () – C:\Users\Margarita\Desktop\AllToAVI.lnk
[2011/04/16 22:06:39 | 000,001,070 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/13 10:52:06 | 000,031,168 | —- | M] () – C:\Users\Margarita\Documents\Change Deductions.pdf
[2011/04/11 21:13:38 | 000,163,692 | —- | M] () – C:\Users\Margarita\Documents\kobyfull.jpg
[2011/04/11 14:45:51 | 000,072,801 | —- | M] () – C:\Users\Margarita\Documents\koby.jpg
[2011/04/11 14:00:50 | 000,073,831 | —- | M] () – C:\Users\Margarita\Documents\koby4.jpg
[2011/04/10 21:56:28 | 000,140,634 | —- | M] () – C:\Users\Margarita\Documents\koby3.jpg
[2011/04/10 21:41:33 | 000,075,971 | —- | M] () – C:\Users\Margarita\Documents\kobysamp.jpg
[2011/04/10 18:39:27 | 000,093,191 | —- | M] () – C:\Users\Margarita\Documents\koby1.jpg
[2011/04/10 18:37:08 | 000,046,227 | —- | M] () – C:\Users\Margarita\Documents\koby2.jpg
[2011/04/10 18:36:59 | 000,366,030 | —- | M] () – C:\Users\Margarita\Documents\koby2.pdf
[2011/04/10 18:25:47 | 000,298,025 | —- | M] () – C:\Users\Margarita\Documents\koby1.pdf

========== Files Created - No Company Name ==========

[2011/05/08 21:43:18 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/06 15:47:18 | 000,013,991 | —- | C] () – C:\Users\Margarita\Documents\Ass2 research (2).odt
[2011/05/03 17:27:23 | 000,015,134 | —- | C] () – C:\Users\Margarita\Documents\Ass2 research.odt
[2011/04/30 02:48:02 | 000,000,941 | —- | C] () – C:\Users\Public\Desktop\AUSTAR AnyWhere.lnk
[2011/04/28 17:21:34 | 000,056,348 | —- | C] () – C:\Users\Margarita\Documents\Research Plan (40%).pdf
[2011/04/24 02:01:09 | 000,418,148 | —- | C] () – C:\Users\Margarita\Documents\Present Tags.pdf
[2011/04/19 03:18:05 | 000,014,700 | —- | C] () – C:\Users\Margarita\Documents\mis.jpg
[2011/04/17 10:49:12 | 000,014,493 | —- | C] () – C:\Users\Margarita\Documents\Payment Receipt - PayPal.pdf
[2011/04/16 22:57:55 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2011/04/16 22:54:19 | 000,107,520 | RHS- | C] () – C:\Windows\SysWow64\RLMPCDec.ax
[2011/04/16 22:54:19 | 000,070,656 | RHS- | C] () – C:\Windows\SysWow64\RLAPEDec.ax
[2011/04/16 22:54:19 | 000,051,712 | RHS- | C] () – C:\Windows\SysWow64\RLSpeexDec.ax
[2011/04/16 22:54:18 | 000,227,328 | RHS- | C] () – C:\Windows\SysWow64\ac3DX.ax
[2011/04/16 22:54:18 | 000,175,104 | RHS- | C] () – C:\Windows\SysWow64\CoreAAC.ax
[2011/04/16 22:54:18 | 000,120,832 | RHS- | C] () – C:\Windows\SysWow64\MPCDx.ax
[2011/04/16 22:54:18 | 000,097,280 | RHS- | C] () – C:\Windows\SysWow64\FLACDX.ax
[2011/04/16 22:54:18 | 000,081,920 | RHS- | C] () – C:\Windows\SysWow64\aac_parser.ax
[2011/04/16 22:50:33 | 000,001,952 | —- | C] () – C:\Users\Public\Desktop\Free Movies & Games.lnk
[2011/04/16 22:50:33 | 000,001,268 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/04/16 22:20:34 | 000,001,021 | —- | C] () – C:\Users\Margarita\Desktop\AllToAVI.lnk
[2011/04/16 22:06:39 | 000,001,070 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/13 10:52:06 | 000,031,168 | —- | C] () – C:\Users\Margarita\Documents\Change Deductions.pdf
[2011/04/11 21:13:38 | 000,163,692 | —- | C] () – C:\Users\Margarita\Documents\kobyfull.jpg
[2011/04/11 14:45:51 | 000,072,801 | —- | C] () – C:\Users\Margarita\Documents\koby.jpg
[2011/04/11 14:00:50 | 000,073,831 | —- | C] () – C:\Users\Margarita\Documents\koby4.jpg
[2011/04/10 21:56:28 | 000,140,634 | —- | C] () – C:\Users\Margarita\Documents\koby3.jpg
[2011/04/10 21:41:33 | 000,075,971 | —- | C] () – C:\Users\Margarita\Documents\kobysamp.jpg
[2011/04/10 18:39:27 | 000,093,191 | —- | C] () – C:\Users\Margarita\Documents\koby1.jpg
[2011/04/10 18:37:06 | 000,046,227 | —- | C] () – C:\Users\Margarita\Documents\koby2.jpg
[2011/04/10 18:36:51 | 000,366,030 | —- | C] () – C:\Users\Margarita\Documents\koby2.pdf
[2011/04/10 18:25:39 | 000,298,025 | —- | C] () – C:\Users\Margarita\Documents\koby1.pdf
[2010/12/09 16:52:13 | 002,463,976 | —- | C] () – C:\Windows\SysWow64\NPSWF32.dll
[2010/11/23 15:40:00 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2010/11/23 15:40:00 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010/11/23 15:39:57 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010/11/23 15:39:57 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010/11/23 15:37:35 | 000,042,730 | —- | C] () – C:\Windows\Ascd_log.ini
[2010/11/23 15:30:18 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/11/23 15:30:11 | 000,030,774 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/08/25 18:34:30 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/08/25 18:34:30 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/04/21 10:14:52 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/04/21 09:22:50 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/04/21 09:22:50 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/14 15:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 12:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 10:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 07:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/04/02 22:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2009/02/25 21:38:27 | 000,188,416 | —- | C] () – C:\Windows\SysWow64\HFCdtASP.dll
[2006/03/18 23:16:04 | 000,540,178 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2005/08/18 19:34:09 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\HFCNTS.dll

========== LOP Check ==========

[2011/04/30 02:48:09 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\AustarAnywhereDesktopApplication.7C28940E702BD503DC2BDA2FC8B8270C7F1C0180.1
[2011/04/08 20:26:24 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\DVDVideoSoft
[2011/02/17 13:41:04 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\HandBrake
[2010/11/30 05:16:38 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\OpenOffice.org
[2011/01/18 08:54:47 | 000,000,000 | —D | M] – C:\Users\Margarita\AppData\Roaming\Windows Live Writer
[2009/07/14 15:08:49 | 000,012,960 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/14 11:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/24 10:19:27 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/05/08 21:55:32 | 3082,018,816 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 07:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/05/08 21:55:36 | 4109,361,152 | -HS- | M] () – C:\pagefile.sys
[2010/11/23 15:26:42 | 000,171,136 | RHS- | M] () – C:\w7ldr
[2010/12/01 00:20:45 | 000,000,013 | —- | M] () – C:\Winvdrvr.dll

< %systemroot%\Fonts\*.com >
[2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/23 15:55:27 | 000,000,221 | -HS- | M] () – C:\Users\Margarita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


Thanks

ETA: Just a couple of things I remembered going through the log (thanks to the enormous lot of file not founds???)

1: It will not print to the network printer from anything but OpenOffice. This has been extremely frustrating. I have reinstalled the drivers a dozen times.
2: I do have ReaderX - the Acrobat 8 is part of AMC3.
3: Google Chrome sometimes registers the click but wont actually load the page. It does the swirly thing and then kinda does that "look, I loaded the page" hop, but it hasn't done squat.

A reboot of my system and router has improved interweb speeds. Hopefully permanently. I do plan on moving a lot of the stuff on C onto one of the other drives but will leave the drive intact until I am sure it is clear.

I am usually a lot better than this and this is embarrassing, but I needed some conversion programs in a hurry and while normally I would have checked the reviews and bought something decent, I let my guard down and installed a couple of questionable ones just trying to get the job done. I also usually have proper programs running rather than what comes with windows but this machine is new and I am a first class procrastinator! (Might explain why I was downloading dodgy software moments from deadline! HA!)

ETA: Again.. Remembering more stuff.

E: is my old system drive. XP on there skitzed over something and the whole system crashed epically and wouldn't speak to me. I got my tech guy to fix it (he is three hours away so I don't call on him for anything but epic fails) and he got it up and running again. I didn't plug it in straight away, it was raining here (think QLD Australia floods, although it didn't flood here. It just rained a whole lot.) and moisture got into the power supply and I didn't know so when I did plug it in, it blew up quite spectacularly. Anyway, I salvaged the drive out, put it in here to get all my work off of it. Anything that might pop up on it would possibly be dormant as the OS was hacked off of that drive.

I am meant to be cleaning it off and formatting it…. there is that procrastination again!
Hi Aylyese,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

That's alot of information. I'm not sure what all you're telling me, but let's much around a bit and see what we find.

First off:
Malwarebytes found that your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI