This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Might have a virus, unsure

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a virus a few days ago and I thought I got rid of it, but I've been having some problems recently. While browsing in firefox, randomly a "skype.com" tab will open and then suddenly many more of the same exact tabs will continue to open, until my pc crashes. Thanks for the help! Here are my OTL logs:
OTL:

OTL logfile created on: 5/19/2011 9:15:09 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 260.35 Gb Free Space | 43.68% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Logitech\LWS\LU\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\LWS\LU\LULnchr.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (NetFlixDownloadManager) – C:\Program Files\Luttmann\vmcNetFlix\NetFlixDownloadManager.exe ()
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (Soluto) – C:\Windows\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (speedfan) – C:\Windows\system32\speedfan.sys (Almico Software)
DRV - (LVUVC) Logitech HD Webcam C310(UVC) – C:\Windows\System32\drivers\LVUVC.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (P17) – C:\Windows\System32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (giveio) – C:\Windows\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F4 DC 1F B7 FF 09 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.5.23s
FF - prefs.js..extensions.enabledItems: {3061A488-48A8-4F6F-9743-F89A57192F45}:1.9.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..network.proxy.autoconfig_url: "/*********************************************************** ** TJHSST Proxy Auto-Configuration Script ** ** For use with TJHSST school databases ** ** Use is restricted to TJHSST students and faculty ONLY. ** ** All other use is prohibited. ** ** Originally contributed by William Yang. ** ** Autogenerated version by Brandon Vargo. ** ************************************************************/ function FindProxyForURL(url, host) { if ( dnsDomainIs(host, \".abc-clio.com\") || dnsDomainIs(host, \"www.accessscience.com\") || dnsDomainIs(host, \".eb.com\") || dnsDomainIs(host, \"library.cqpress.com\") || dnsDomainIs(host, \".earthscape.org\") || dnsDomainIs(host, \"search.ebscohost.com\") || dnsDomainIs(host, \"ehrafworldcultures.yale.edu\") || dnsDomainIs(host, \"infotrac.galegroup.com\") || dnsDomainIs(host, \".grolier.com\") || dnsDomainIs(host, \"jchemed.chem.wisc.edu\") || dnsDomainIs(host, \"www.jstor.org\") || dnsDomainIs(host, \"web.lexis-nexis.com\") || dnsDomainIs(host, \"www.noodletools.com\") || dnsDomainIs(host, \"dictionary.oed.com\") || dnsDomainIs(host, \"poll.orspub.com\") || dnsDomainIs(host, \"proquestk12.com\") || dnsDomainIs(host, \"www.sciencedirect.com\") || dnsDomainIs(host, \"hwwilsonweb.com\") || dnsDomainIs(host, \".nature.com\") || dnsDomainIs(host, \"portal.bigchalk.com\") || dnsDomainIs(host, \".umi.com\") || dnsDomainIs(host, \".culturegrams.com\") || dnsDomainIs(host, \".acs.org\") || dnsDomainIs(host, \".opticsinfobase.org\") || dnsDomainIs(host, \"www.worldbookonline.com\") || dnsDomainIs(host, \".tumblebooks.com\") || dnsDomainIs(host, \".marshallcavendishdigital.com\") ) return \"PROXY local.border.tjhsst.edu:8080\"; else return \"DIRECT\"; }"
FF - prefs.js..network.proxy.backup.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 09:20:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 09:20:08 | 000,000,000 | —D | M]

[2010/11/13 17:03:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions
[2011/05/13 21:05:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions
[2011/03/25 07:11:24 | 000,000,000 | —D | M] (SkipScreen) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions\SkipScreen@SkipScreen
[2011/03/20 22:23:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/10 22:17:09 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/11/16 08:38:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) –
[2011/04/16 21:20:55 | 000,000,000 | —D | M] (XULRunner) – C:\USERS\RASHAD\APPDATA\LOCAL\{3061A488-48A8-4F6F-9743-F89A57192F45}
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011/05/08 09:20:06 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/11/16 08:38:48 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/08 09:20:07 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [P17RunE] C:\Windows\System32\P17RunE.dll (Creative Technology Ltd.)
O4 - HKCU..\Run: [F.lux] C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2007/01/09 20:32:15 | 000,000,206 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare) - E:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2010/01/26 17:22:17 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe – [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance)
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\configure\command - "" = D:\setup.exe – [2006/10/27 07:30:48 | 000,463,152 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\install\command - "" = D:\setup.exe – [2006/10/27 07:30:48 | 000,463,152 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{965fd789-f7ef-11df-8f90-001fd09a9959}\Shell - "" = AutoRun
O33 - MountPoints2\{965fd789-f7ef-11df-8f90-001fd09a9959}\Shell\AutoRun\command - "" = E:\autorun.exe – [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/05/18 19:36:02 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Program Files\SpeedFan
[2011/05/11 06:59:03 | 000,284,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2011/05/11 06:59:02 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2011/05/11 06:59:01 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/11 06:59:00 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/05/03 22:17:04 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Malwarebytes
[2011/05/03 22:16:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/03 22:16:56 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/03 22:16:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/01 17:12:17 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\Program Files\Elaborate Bytes
[2011/04/27 07:51:03 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2011/04/27 07:51:02 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2011/04/27 07:51:01 | 000,146,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2011/04/27 07:51:01 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2011/04/27 07:50:58 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/27 07:50:57 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/04/22 01:51:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/04/20 16:39:36 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2011/04/20 16:35:34 | 000,000,000 | —D | C] – C:\ProgramData\vmcNetFlix_Data
[2011/04/20 16:33:32 | 000,000,000 | —D | C] – C:\Program Files\Luttmann
[2011/04/20 16:31:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/04/20 16:31:12 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight

========== Files - Modified Within 30 Days ==========

[2011/05/19 21:13:25 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 21:13:25 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 21:11:16 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/19 21:11:16 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/19 21:06:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/19 21:06:08 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 20:19:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001UA.job
[2011/05/19 20:19:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001Core.job
[2011/05/14 15:01:44 | 000,000,969 | —- | M] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:44 | 000,000,045 | —- | M] () – C:\Windows\System32\initdebug.nfo
[2011/05/08 09:20:34 | 000,002,002 | —- | M] () – C:\Users\Rashad\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/03 22:16:59 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:05:30 | 000,011,800 | -HS- | M] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:04:26 | 000,011,808 | -HS- | M] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 19:22:08 | 000,000,120 | —- | M] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/05/03 19:22:08 | 000,000,000 | —- | M] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/05/03 00:16:32 | 000,001,055 | —- | M] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/22 10:32:09 | 000,409,784 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/20 16:27:15 | 000,000,362 | RHS- | M] () – C:\ProgramData\ntuser.pol

========== Files Created - No Company Name ==========

[2011/05/14 15:01:44 | 000,000,969 | —- | C] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:42 | 000,000,045 | —- | C] () – C:\Windows\System32\initdebug.nfo
[2011/05/03 22:16:59 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:02:21 | 000,011,808 | -HS- | C] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:02:21 | 000,011,800 | -HS- | C] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 00:08:53 | 000,001,055 | —- | C] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/20 16:27:15 | 000,000,362 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/04/16 21:20:56 | 000,000,120 | —- | C] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/04/16 21:20:56 | 000,000,000 | —- | C] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/04/15 22:15:47 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/02/09 20:56:30 | 000,000,410 | —- | C] () – C:\Windows\brwmark.ini
[2011/02/09 20:56:30 | 000,000,052 | —- | C] () – C:\Windows\BRPP2KA.INI
[2011/01/24 23:23:29 | 000,000,098 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/11/13 19:36:10 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/11/13 17:02:54 | 000,166,912 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2010/11/13 17:02:54 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/11/10 03:45:32 | 000,102,744 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2010/11/10 03:31:42 | 000,026,286 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2010/05/07 19:46:36 | 000,014,168 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2010/05/07 19:43:30 | 000,025,824 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/16 07:50:54 | 000,003,930 | —- | C] () – C:\Windows\System32\ludap17.ini
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,409,784 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/11/13 07:07:24 | 000,002,177 | —- | C] () – C:\Windows\P17EP.ini
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2007/12/04 06:20:30 | 000,001,489 | —- | C] () – C:\Windows\P17EP51.ini
[2007/06/07 06:25:42 | 000,001,578 | —- | C] () – C:\Windows\P17EPLS.ini
[2005/03/08 07:17:00 | 000,000,054 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2011/01/18 16:37:47 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\.Tribler
[2011/04/15 22:15:41 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\GetRightToGo
[2010/11/13 17:08:11 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Leadertech
[2011/01/27 16:40:55 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\LolClient
[2011/01/26 20:54:15 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Soluto
[2011/05/19 21:15:50 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2011/04/20 16:39:36 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2010/11/13 22:00:31 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\VOWSoft
[2011/03/13 08:42:21 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/05/19 21:06:08 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 21:06:13 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 19:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/13 17:02:09 | 000,000,221 | -HS- | M] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-19 02:38:19

< End of report >

Extra:

OTL Extras logfile created on: 5/19/2011 9:15:09 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 260.35 Gb Free Space | 43.68% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{17424F35-8B77-4ADF-BC63-BF9B81418539}" = Apple Application Support
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3A9D04F7-80CA-4755-97EC-6025B515A6B8}" = League of Legends
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7ADB1002-9FAC-4EF0-8EC0-57A0D7CB5355}" = Aurora
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{AE1E2901-7405-4568-B8D8-87958E63C7D0}" = Soluto
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C79743A0-BE17-4A80-9A1B-FAF9E8E31C41}" = Vista Media Center vmcNetFlix Add-In x86
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8843212-F0FC-4C3B-BFF3-D51829CB4F19}" = iTunes
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AudioCS" = Creative Audio Control Panel
"AVCWare iPod to iPod/Computer/iTunes Transfer" = AVCWare iPod to iPod/Computer/iTunes Transfer
"AviSynth" = AviSynth 2.5
"CCleaner" = CCleaner
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"Cucusoft iPod Video Converter_is1" = Cucusoft iPod Video Converter 8.08
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EphPod" = EphPod
"Free iPod Video Converter_is1" = Free iPod Video Converter 1.34
"ImgBurn" = ImgBurn
"Jack Claw_is1" = Jack Claw
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"SpeedFan" = SpeedFan (remove only)
"StarCraft II" = StarCraft II
"Steam App 11200" = Shadowgrounds: Survivor
"Steam App 240" = Counter-Strike: Source
"Steam App 2500" = Shadowgrounds
"Steam App 2505" = Shadowgrounds Editor
"Steam App 3480" = Peggle Deluxe
"Steam App 35700" = Trine
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 42910" = Magicka
"Steam App 440" = Team Fortress 2
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Tribler" = Tribler (remove only)
"uTorrent" = µTorrent
"Videora iPod Converter" = Videora iPod Converter 6
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.5
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Flux" = F.lux
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi,

Please do the following:


Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-21 12:28:31 —————————– 12:28:31.351 OS Version: Windows 6.1.7600 12:28:31.351 Number of processors: 2 586 0x170A 12:28:31.352 ComputerName: RASHAD-PC UserName: Rashad 12:28:40.690 Initialize success 12:28:47.184 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-5 12:28:47.186 Disk 0 Vendor: WDC_WD6400AAKS-75A7B0 01.03B01 Size: 610479MB BusType: 3 12:28:49.191 Disk 0 MBR read successfully 12:28:49.193 Disk 0 MBR scan 12:28:49.195 Disk 0 Windows 7 default MBR code 12:28:51.197 Disk 0 scanning sectors +1250258944 12:28:51.231 Disk 0 scanning C:\Windows\system32\drivers 12:28:55.798 Service scanning 12:28:56.651 Disk 0 trace - called modules: 12:28:56.664 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys afd.sys 12:28:56.667 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86154030] 12:28:56.670 3 CLASSPNP.SYS[8bd9e59e] -> nt!IofCallDriver -> [0x8539f620] 12:28:56.673 5 ACPI.sys[8b8963b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP5T0L0-5[0x86081908] 12:28:56.676 Scan finished successfully 12:32:38.969 Disk 0 MBR has been saved successfully to "C:\Users\Rashad\Desktop\MBR.dat" 12:32:38.974 The log file has been saved successfully to "C:\Users\Rashad\Desktop\aswMBR.txt"
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
ComboFix 11-05-19.02 - Rashad 05/21/2011 14:06:24.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3326.2041 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Rashad\AppData\Local\{3061A488-48A8-4F6F-9743-F89A57192F45} c:\users\Rashad\AppData\Local\{3061A488-48A8-4F6F-9743-F89A57192F45}\chrome.manifest c:\users\Rashad\AppData\Local\{3061A488-48A8-4F6F-9743-F89A57192F45}\chrome\content\_cfg.js c:\users\Rashad\AppData\Local\{3061A488-48A8-4F6F-9743-F89A57192F45}\chrome\content\overlay.xul c:\users\Rashad\AppData\Local\{3061A488-48A8-4F6F-9743-F89A57192F45}\install.rdf . . ((((((((((((((((((((((((( Files Created from 2011-04-21 to 2011-05-21 ))))))))))))))))))))))))))))))) . . 2011-05-21 18:12 . 2011-05-21 18:12 ——– d—–w- c:\users\Mcx1-RASHAD-PC\AppData\Local\temp 2011-05-21 18:12 . 2011-05-21 18:12 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-21 18:04 . 2011-05-21 18:04 ——– d—–w- C:\32788R22FWJFW 2011-05-18 23:36 . 2011-04-09 05:56 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-05-14 19:01 . 2011-05-19 01:52 ——– d—–w- c:\program files\SpeedFan 2011-05-11 10:59 . 2011-03-25 03:06 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 10:59 . 2011-03-25 03:06 284160 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 10:59 . 2011-03-25 03:06 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 10:59 . 2011-03-25 03:06 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 10:59 . 2011-03-25 03:06 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 10:59 . 2011-03-25 03:06 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 10:59 . 2011-03-25 03:06 5888 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-11 10:59 . 2011-04-09 06:13 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-05-11 10:59 . 2011-04-09 06:13 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-08 13:20 . 2011-05-08 13:20 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll 2011-05-08 13:20 . 2011-05-08 13:20 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll 2011-05-08 13:20 . 2011-05-08 13:20 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll 2011-05-08 13:20 . 2011-05-08 13:20 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll 2011-05-08 13:20 . 2011-05-08 13:20 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll 2011-05-08 13:20 . 2011-05-08 13:20 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll 2011-05-08 13:20 . 2011-05-08 13:20 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll 2011-05-08 13:20 . 2011-05-08 13:20 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll 2011-05-04 02:17 . 2011-05-04 02:17 ——– d—–w- c:\users\Rashad\AppData\Roaming\Malwarebytes 2011-05-04 02:16 . 2011-05-04 02:16 ——– d—–w- c:\programdata\Malwarebytes 2011-05-04 02:16 . 2010-12-20 22:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-04 02:16 . 2011-05-04 02:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-05-04 02:16 . 2010-12-20 22:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-05-03 09:27 . 2011-04-11 07:04 7071056 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4EE8B930-99BD-4324-9963-10508B36B3DE}\mpengine.dll 2011-05-01 20:55 . 2011-05-11 00:50 ——– d—–w- c:\program files\StarCraft II 2011-05-01 20:55 . 2011-05-04 02:21 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment 2011-05-01 20:55 . 2011-05-01 21:13 ——– d—–w- c:\programdata\Blizzard Entertainment 2011-05-01 20:32 . 2011-05-01 20:32 ——– d—–w- c:\program files\Elaborate Bytes 2011-04-27 11:51 . 2011-02-18 05:33 31232 —-a-w- c:\windows\system32\prevhost.exe 2011-04-27 11:51 . 2011-03-11 05:44 143744 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-04-27 11:51 . 2011-03-11 05:44 1210240 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-04-27 11:51 . 2011-03-11 05:44 117120 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-04-27 11:51 . 2011-03-11 05:39 1686016 —-a-w- c:\windows\system32\esent.dll 2011-04-27 11:51 . 2011-03-11 05:44 146304 —-a-w- c:\windows\system32\drivers\storport.sys 2011-04-27 11:51 . 2011-03-11 05:43 332160 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-04-27 11:51 . 2011-03-11 05:43 80256 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-04-27 11:51 . 2011-03-11 05:43 22400 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-04-27 11:51 . 2011-03-11 05:37 74240 —-a-w- c:\windows\system32\fsutil.exe 2011-04-27 11:50 . 2011-03-12 11:31 442880 —-a-w- c:\windows\system32\XpsPrint.dll 2011-04-27 11:50 . 2011-02-26 05:33 2614784 —-a-w- c:\windows\explorer.exe 2011-04-22 05:51 . 2011-04-22 05:51 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2 2011-04-22 05:47 . 2011-04-22 05:47 ——– d—–w- c:\users\Default\AppData\Local\Microsoft Help . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-03 23:22 . 2011-04-17 01:20 0 —-a-w- c:\users\Rashad\AppData\Local\Jlonul.bin 2011-04-20 20:24 . 2011-04-20 20:24 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2011-04-20 20:24 . 2011-04-20 20:24 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-04-20 20:24 . 2011-04-20 20:24 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-04-20 20:24 . 2011-04-20 20:24 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-03-11 05:40 . 2011-04-14 22:04 1164288 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-11 05:40 . 2011-04-14 22:04 1137664 —-a-w- c:\windows\system32\mfc42.dll 2011-03-08 05:38 . 2011-04-14 22:04 740864 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-07 02:08 . 2011-03-07 02:08 93552 —-a-w- c:\windows\system32\ElbyCDIO.dll 2011-03-07 00:52 . 2011-03-07 00:52 134512 —-a-w- c:\windows\system32\ElbyVCD.dll 2011-03-03 05:29 . 2011-04-14 22:04 132608 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-03-03 05:27 . 2011-04-14 22:04 28672 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-03-03 03:31 . 2011-04-14 22:04 2331136 —-a-w- c:\windows\system32\win32k.sys 2011-02-24 05:32 . 2011-04-14 22:04 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-02-24 05:32 . 2011-04-14 22:04 981504 —-a-w- c:\windows\system32\wininet.dll 2011-02-24 05:30 . 2011-04-14 22:04 44544 —-a-w- c:\windows\system32\licmgr10.dll 2011-02-24 04:23 . 2011-04-14 22:04 386048 —-a-w- c:\windows\system32\html.iec 2011-02-24 03:50 . 2011-04-14 22:04 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-02-23 05:06 . 2011-04-14 22:04 311296 —-a-w- c:\windows\system32\drivers\srv.sys 2011-02-23 05:05 . 2011-04-14 22:04 309760 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-02-23 05:05 . 2011-04-14 22:04 113664 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-02-23 05:05 . 2011-04-14 22:04 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-23 05:05 . 2011-04-14 22:04 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-23 05:05 . 2011-04-14 22:04 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-23 05:05 . 2011-04-14 22:04 69632 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-05-08 13:20 . 2011-05-08 13:20 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "F.lux"="c:\users\Rashad\Local Settings\Apps\F.lux\flux.exe" [2009-08-29 966656] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "P17RunE"="P17RunE.dll" [2008-03-28 14848] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-11-13 79360] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832] R3 NetFlixDownloadManager;VMC NetFlix Download Manager;c:\program files\Luttmann\vmcNetFlix\NetFlixDownloadManager.exe [2009-04-16 26624] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-14 1343400] S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys [2011-01-21 51144] S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [2011-01-21 308768] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] . . — Other Services/Drivers In Memory — . *NewlyCreated* - ASWMBR *Deregistered* - aswMBR . Contents of the 'Scheduled Tasks' folder . 2011-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001Core.job - c:\users\Rashad\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-03 01:09] . 2011-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001UA.job - c:\users\Rashad\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-03 01:09] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.ftp - local.border.tjhsst.edu FF - prefs.js: network.proxy.ftp_port - 8080 FF - prefs.js: network.proxy.gopher - local.border.tjhsst.edu FF - prefs.js: network.proxy.gopher_port - 8080 FF - prefs.js: network.proxy.http - local.border.tjhsst.edu FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.socks - local.border.tjhsst.edu FF - prefs.js: network.proxy.socks_port - 8080 FF - prefs.js: network.proxy.ssl - local.border.tjhsst.edu FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 0 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-05-21 14:14:42 ComboFix-quarantined-files.txt 2011-05-21 18:14 . Pre-Run: 279,867,691,008 bytes free Post-Run: 279,863,799,808 bytes free . - - End Of File - - 9CD038025847112F183F90A4E04CD578
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6646 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 5/22/2011 9:53:20 PM mbam-log-2011-05-22 (21-53-20).txt Scan type: Quick scan Objects scanned: 159537 Time elapsed: 2 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\23dbfa3d-3e3053e9 multiple threats C:\Users\Rashad\Downloads\videora-ipod-600-setup.exe Win32/OpenCandy application
Hi,

Please navigate to and delete this file, it's adware:

C:\Users\Rashad\Downloads\videora-ipod-600-setup.exe Win32/OpenCandy application

now do the following:


Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 22 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please post a fresh OTL log and advise how the computer is running now and if there are any outstanding issues.
So far everything seems to be running smoothly, I will let you know if problems arise. Thanks a bunch!

OTL logfile created on: 5/23/2011 5:57:51 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 259.13 Gb Free Space | 43.47% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (NetFlixDownloadManager) – C:\Program Files\Luttmann\vmcNetFlix\NetFlixDownloadManager.exe ()
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (Soluto) – C:\Windows\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (speedfan) – C:\Windows\system32\speedfan.sys (Almico Software)
DRV - (LVUVC) Logitech HD Webcam C310(UVC) – C:\Windows\System32\drivers\LVUVC.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (P17) – C:\Windows\System32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (giveio) – C:\Windows\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F4 DC 1F B7 FF 09 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.5.23s
FF - prefs.js..extensions.enabledItems: {3061A488-48A8-4F6F-9743-F89A57192F45}:1.9.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..network.proxy.autoconfig_url: "/*********************************************************** ** TJHSST Proxy Auto-Configuration Script ** ** For use with TJHSST school databases ** ** Use is restricted to TJHSST students and faculty ONLY. ** ** All other use is prohibited. ** ** Originally contributed by William Yang. ** ** Autogenerated version by Brandon Vargo. ** ************************************************************/ function FindProxyForURL(url, host) { if ( dnsDomainIs(host, \".abc-clio.com\") || dnsDomainIs(host, \"www.accessscience.com\") || dnsDomainIs(host, \".eb.com\") || dnsDomainIs(host, \"library.cqpress.com\") || dnsDomainIs(host, \".earthscape.org\") || dnsDomainIs(host, \"search.ebscohost.com\") || dnsDomainIs(host, \"ehrafworldcultures.yale.edu\") || dnsDomainIs(host, \"infotrac.galegroup.com\") || dnsDomainIs(host, \".grolier.com\") || dnsDomainIs(host, \"jchemed.chem.wisc.edu\") || dnsDomainIs(host, \"www.jstor.org\") || dnsDomainIs(host, \"web.lexis-nexis.com\") || dnsDomainIs(host, \"www.noodletools.com\") || dnsDomainIs(host, \"dictionary.oed.com\") || dnsDomainIs(host, \"poll.orspub.com\") || dnsDomainIs(host, \"proquestk12.com\") || dnsDomainIs(host, \"www.sciencedirect.com\") || dnsDomainIs(host, \"hwwilsonweb.com\") || dnsDomainIs(host, \".nature.com\") || dnsDomainIs(host, \"portal.bigchalk.com\") || dnsDomainIs(host, \".umi.com\") || dnsDomainIs(host, \".culturegrams.com\") || dnsDomainIs(host, \".acs.org\") || dnsDomainIs(host, \".opticsinfobase.org\") || dnsDomainIs(host, \"www.worldbookonline.com\") || dnsDomainIs(host, \".tumblebooks.com\") || dnsDomainIs(host, \".marshallcavendishdigital.com\") ) return \"PROXY local.border.tjhsst.edu:8080\"; else return \"DIRECT\"; }"
FF - prefs.js..network.proxy.backup.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 09:20:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/23 17:54:52 | 000,000,000 | —D | M]

[2010/11/13 17:03:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions
[2011/05/13 21:05:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions
[2011/03/25 07:11:24 | 000,000,000 | —D | M] (SkipScreen) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions\SkipScreen@SkipScreen
[2011/05/23 17:52:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/10 22:17:09 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/11/16 08:38:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/05/23 17:52:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011/05/08 09:20:06 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/08 09:20:07 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/05/21 14:12:19 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [P17RunE] C:\Windows\System32\P17RunE.dll (Creative Technology Ltd.)
O4 - HKCU..\Run: [F.lux] C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2007/01/09 20:32:15 | 000,000,206 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare) - E:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2010/01/26 17:22:17 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/05/23 17:54:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/05/23 17:54:32 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/05/23 17:53:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/23 17:52:55 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/05/23 17:52:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/05/23 17:52:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/05/22 21:55:54 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/05/22 21:49:02 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/21 14:14:44 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/21 14:14:43 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/05/21 14:05:02 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/05/21 14:05:02 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/05/21 14:05:02 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/05/21 14:04:57 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/05/21 14:04:51 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/21 14:04:38 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/05/21 14:04:35 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/05/18 19:36:02 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Program Files\SpeedFan
[2011/05/11 06:59:03 | 000,284,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2011/05/11 06:59:02 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2011/05/11 06:59:01 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/11 06:59:00 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/05/03 22:17:04 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Malwarebytes
[2011/05/03 22:16:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/03 22:16:56 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/03 22:16:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/01 17:12:17 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\Program Files\Elaborate Bytes
[2011/04/27 07:51:03 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2011/04/27 07:51:02 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2011/04/27 07:51:01 | 000,146,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2011/04/27 07:51:01 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2011/04/27 07:50:58 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/27 07:50:57 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe

========== Files - Modified Within 30 Days ==========

[2011/05/23 17:54:52 | 000,001,989 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/05/23 17:19:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001UA.job
[2011/05/22 21:56:04 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/22 21:56:04 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/22 21:53:53 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/22 21:53:53 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/22 21:49:02 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/22 21:48:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/22 21:48:30 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/22 20:19:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001Core.job
[2011/05/21 14:12:19 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/05/21 13:25:52 | 004,352,567 | R— | M] () – C:\Users\Rashad\Desktop\ComboFix.exe
[2011/05/21 12:32:38 | 000,000,512 | —- | M] () – C:\Users\Rashad\Desktop\MBR.dat
[2011/05/14 15:01:44 | 000,000,969 | —- | M] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:44 | 000,000,045 | —- | M] () – C:\Windows\System32\initdebug.nfo
[2011/05/08 09:20:34 | 000,002,002 | —- | M] () – C:\Users\Rashad\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/03 22:16:59 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:05:30 | 000,011,800 | -HS- | M] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:04:26 | 000,011,808 | -HS- | M] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 19:22:08 | 000,000,120 | —- | M] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/05/03 19:22:08 | 000,000,000 | —- | M] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/05/03 00:16:32 | 000,001,055 | —- | M] () – C:\Users\Public\Desktop\StarCraft II.lnk

========== Files Created - No Company Name ==========

[2011/05/23 17:54:52 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/05/23 17:54:52 | 000,001,989 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/05/21 14:05:02 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/21 14:05:02 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/21 14:05:02 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/05/21 14:05:02 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/21 14:05:02 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/05/21 13:25:52 | 004,352,567 | R— | C] () – C:\Users\Rashad\Desktop\ComboFix.exe
[2011/05/21 12:32:38 | 000,000,512 | —- | C] () – C:\Users\Rashad\Desktop\MBR.dat
[2011/05/14 15:01:44 | 000,000,969 | —- | C] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:42 | 000,000,045 | —- | C] () – C:\Windows\System32\initdebug.nfo
[2011/05/03 22:16:59 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:02:21 | 000,011,808 | -HS- | C] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:02:21 | 000,011,800 | -HS- | C] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 00:08:53 | 000,001,055 | —- | C] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/20 16:27:15 | 000,000,362 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/04/16 21:20:56 | 000,000,120 | —- | C] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/04/16 21:20:56 | 000,000,000 | —- | C] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/04/15 22:15:47 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/02/09 20:56:30 | 000,000,410 | —- | C] () – C:\Windows\brwmark.ini
[2011/02/09 20:56:30 | 000,000,052 | —- | C] () – C:\Windows\BRPP2KA.INI
[2011/01/24 23:23:29 | 000,000,098 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/11/13 19:36:10 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/11/13 17:02:54 | 000,166,912 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2010/11/13 17:02:54 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/11/10 03:45:32 | 000,102,744 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2010/11/10 03:31:42 | 000,026,286 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2010/05/07 19:46:36 | 000,014,168 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2010/05/07 19:43:30 | 000,025,824 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/16 07:50:54 | 000,003,930 | —- | C] () – C:\Windows\System32\ludap17.ini
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,409,784 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/11/13 07:07:24 | 000,002,177 | —- | C] () – C:\Windows\P17EP.ini
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2007/12/04 06:20:30 | 000,001,489 | —- | C] () – C:\Windows\P17EP51.ini
[2007/06/07 06:25:42 | 000,001,578 | —- | C] () – C:\Windows\P17EPLS.ini
[2005/03/08 07:17:00 | 000,000,054 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2011/01/18 16:37:47 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\.Tribler
[2011/04/15 22:15:41 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\GetRightToGo
[2010/11/13 17:08:11 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Leadertech
[2011/01/27 16:40:55 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\LolClient
[2011/01/26 20:54:15 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Soluto
[2011/05/23 17:59:20 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2011/04/20 16:39:36 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2010/11/13 22:00:31 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\VOWSoft
[2011/03/13 08:42:21 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2011/05/21 14:14:42 | 000,011,766 | —- | M] () – C:\ComboFix.txt
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/05/22 21:48:30 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/22 21:48:36 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 19:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/13 17:02:09 | 000,000,221 | -HS- | M] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/21 13:25:52 | 004,352,567 | R— | M] () – C:\Users\Rashad\Desktop\ComboFix.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-19 02:38:19

< End of report >
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/05/03 22:05:30 | 000,011,800 | -HS- | M] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
    [2011/05/03 22:04:26 | 000,011,808 | -HS- | M] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
    [2011/05/03 19:22:08 | 000,000,120 | —- | M] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
    [2011/05/03 19:22:08 | 000,000,000 | —- | M] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log
All processes killed
========== OTL ==========
C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605 moved successfully.
C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605 moved successfully.
C:\Users\Rashad\AppData\Local\Psoqutihol.dat moved successfully.
C:\Users\Rashad\AppData\Local\Jlonul.bin moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Rashad\Downloads\cmd.bat deleted successfully.
C:\Users\Rashad\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 56502 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Mcx1-RASHAD-PC
->Flash cache emptied: 56502 bytes

User: Public

User: Rashad
->Flash cache emptied: 242831 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Mcx1-RASHAD-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Rashad
->Temp folder emptied: 4492591 bytes
->Temporary Internet Files folder emptied: 2906166 bytes
->Java cache emptied: 1 bytes
->FireFox cache emptied: 122866707 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 851648 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 125.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05232011_213922

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Is there any possibility this could be a hardware problem? I had some cpu overheating issues in the past, but I thought I cleared that up.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI