Searchqu search engine is stressing me out!
12 min read
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
Download and run OTL
- Download OTL to your desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Under Custom Scan paste this in
netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- You may need two posts to fit them both in.
Run aswMBR
Download aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
Click to load external image (Posted Image)
On completion of the scan click save log, save it to your desktop and post in your next reply
Click to load external image (Posted Image)
Logs to include with next post:
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
OTL logfile created on: 5/24/2011 5:24:58 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\7017\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.86 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 57.52% Memory free
7.73 Gb Paging File | 5.87 Gb Available in Paging File | 75.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 179.00 Gb Total Space | 127.96 Gb Free Space | 71.49% Space Free | Partition Type: NTFS
Drive D: | 266.66 Gb Total Space | 175.79 Gb Free Space | 65.92% Space Free | Partition Type: NTFS
Computer Name: 7017-PC | User Name: 7017 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\7017\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (SEC)
PRC - C:\Program Files\BitDefender\BitDefender 2010\Antispam32\bdimguiaux.exe (BitDefender S.R.L.)
PRC - C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Windows\SysWOW64\Rezip.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\7017\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas64-v2_75\midas32.dll (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (LIVESRV) – C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender S.R.L.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe (BitDefender S.R.L.)
SRV:64bit: - (scan) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (S.C. BitDefender S.R.L)
SRV:64bit: - (Arrakis3) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender S.R.L. http://www.bitdefender.com)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (npggsvc) – C:\windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Rezip) – C:\Windows\SysWOW64\Rezip.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (rtl819xpn64) Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-) – C:\Windows\SysNative\drivers\rtl819xp.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BdfNdisf) – C:\Windows\SysNative\drivers\BdfNdisf6.sys (BitDefender LLC)
DRV:64bit: - (bdfwfpf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys (BitDefender LLC)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (BDFM) – C:\Windows\SysNative\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (BDVEDISK) – C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys (BitDefender)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (qcusbser) – C:\Windows\SysNative\drivers\qcusbser.sys (QUALCOMM Incorporated)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SABI) – C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MRV6X64U) Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x) – C:\Windows\SysNative\drivers\MRVW24C.sys (Marvell Semiconductor, Inc)
DRV:64bit: - (nmwcdx64) – C:\Windows\SysNative\drivers\nmwcdx64.sys (Nokia)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (rtport) – C:\Windows\SysWOW64\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\ [2011/05/14 19:11:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/04/05 02:45:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/04/05 02:45:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/23 17:13:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/23 17:13:07 | 000,000,000 | —D | M]
[2011/04/04 16:00:29 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Extensions
[2011/05/22 18:43:28 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Firefox\Profiles\x1oqovdw.Default User\extensions
[2011/05/23 18:53:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/09 14:45:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/05 02:45:51 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2011/04/05 02:45:51 | 000,000,000 | —D | M] (DivX HiQ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2011/04/04 15:59:59 | 000,000,000 | —D | M] ("Savevid.com Easy Video Downloader") – C:\PROGRAM FILES (X86)\SAVEVID\[removed]
[2011/04/04 16:00:29 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/05/14 19:11:21 | 000,000,000 | —D | M] ("BitDefender Antiphishing Toolbar") – C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2010\BDAPHFFEXT
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/05/20 21:15:32 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - File not found
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - File not found
O3:64bit: - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEToolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper 32] C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEShow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\7017\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\x64\datamngr.dll) - File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\x64\IEBHO.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\datamngr.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\IEBHO.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/05/24 17:21:47 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
[2011/05/24 17:08:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{89A7BFE4-A14A-42FA-A331-D5DA636EA36D}
[2011/05/24 17:07:38 | 000,000,000 | R–D | C] – C:\Users\7017\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2011/05/23 14:35:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{3F2B9A46-AF2C-4C9A-87EB-6834D0721D4E}
[2011/05/22 18:15:03 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\SUPERAntiSpyware.com
[2011/05/22 18:15:03 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/05/22 18:14:48 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/05/22 18:14:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/05/22 18:14:43 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/05/22 18:08:20 | 000,000,000 | —D | C] – C:\Program Files\chromium
[2011/05/22 18:07:53 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{D260EB27-6276-44DE-AC34-610227AC1C5F}
[2011/05/22 02:51:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{486D2C27-0F74-45FE-989F-4A8EB74676C1}
[2011/05/22 00:42:38 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\ImgBurn
[2011/05/22 00:05:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/21 20:12:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\LSoft Technologies
[2011/05/21 20:12:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ ISO Burner
[2011/05/21 19:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ImgBurn
[2011/05/21 19:48:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
[2011/05/21 16:06:46 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\Chromium
[2011/05/21 12:50:10 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{5FF2282E-3409-46F0-BB4E-62AA63E9886F}
[2011/05/20 22:39:51 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{3D03E705-F684-4C90-B5AA-B6143EF57473}
[2011/05/20 21:27:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/20 21:03:30 | 000,212,480 | —- | C] (SteelWerX) – C:\windows\SWXCACLS.exe
[2011/05/20 20:55:27 | 000,161,792 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2011/05/20 20:55:27 | 000,136,704 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2011/05/20 20:55:27 | 000,031,232 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2011/05/20 20:55:13 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/05/20 20:54:40 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/20 12:25:11 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2011/05/20 10:40:13 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/20 10:39:25 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{2DCD58F9-0D1F-4E2A-8F03-853967EE18E2}
[2011/05/19 22:38:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/05/19 03:01:58 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{EE701A32-6DDB-4418-820A-D21147B9BD98}
[2011/05/18 15:01:32 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{4A88A292-B0AF-415B-8126-E40A90A29FD9}
[2011/05/18 00:47:00 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{BB798A60-A1A3-4C54-850E-2BF454A5B46D}
[2011/05/17 12:47:06 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{C667E0B7-5EFF-459D-989E-20F11BE33216}
[2011/05/16 09:27:19 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{CDDFFA87-455E-45DF-959A-FA2D52A4644F}
[2011/05/15 16:38:44 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{527922EF-983C-4EC2-AD33-BBD5EA879941}
[2011/05/14 19:35:13 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{FB65AD8A-5769-439D-87DB-E9327FF6FBFC}
[2011/05/13 14:01:37 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{7B6BCBC7-41E1-47AC-9704-41D584702DBB}
[2011/05/12 16:39:52 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{1A8BFA72-3B69-49F2-A58B-6515850F1216}
[2011/05/11 17:31:52 | 005,562,240 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/05/11 17:31:49 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/05/11 17:31:49 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/05/11 17:24:38 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{E8A8062D-7DD7-4DC0-B889-1F1ED9256F30}
[2011/05/10 13:54:56 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{F3F1A6C1-2B28-4632-B228-81AF9828FC0F}
[2011/05/09 14:41:50 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{6486F907-F7E5-43A7-B5DC-58AB4FC011E8}
[2011/05/08 18:57:04 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{13F704A5-077A-43E8-974C-10D9E3D8C08E}
[2011/05/06 15:26:55 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{A983C20A-39FD-4345-8A88-CF1F9DCF5ADC}
[2011/05/06 01:05:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Marvell
[2011/05/06 01:05:17 | 000,000,000 | —D | C] – C:\LAN_Win7_11.22.3.3
[2011/05/06 01:01:57 | 000,000,000 | —D | C] – C:\Users\7017\x64
[2011/05/06 01:01:56 | 000,000,000 | —D | C] – C:\Users\7017\Lang
[2011/05/06 01:01:55 | 000,000,000 | —D | C] – C:\Users\7017\IIPS
[2011/05/06 00:41:08 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{5357BB7A-3ED7-4A6E-AE78-1F41C8B4CCA1}
[2011/05/06 00:23:20 | 000,000,000 | —D | C] – C:\HDMI_Win7_1.0.0.55
[2011/05/06 00:19:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\REALTEK Wireless LAN Software
[2011/05/06 00:19:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cisco
[2011/05/05 20:59:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
[2011/05/05 20:59:23 | 000,626,688 | —- | C] (On2.com) – C:\windows\SysWow64\vp7vfw.dll
[2011/05/05 20:59:22 | 001,184,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wvc1dmod.dll
[2011/05/05 20:58:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Games
[2011/05/05 12:40:42 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{17EEA0A0-73AF-41D1-BFAA-81562E8DF59C}
[2011/05/04 18:02:02 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{21AC932A-C1F6-45EB-9688-FDDFF4352620}
[2011/05/04 06:01:49 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{B226A868-FE83-4BAB-B32C-04FC434EDB60}
[2011/05/04 04:32:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2011/05/04 04:32:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\ConduitEngine
[2011/05/04 04:32:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrentBar
[2011/05/04 03:42:39 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\Publish Providers
[2011/05/04 03:35:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2011/05/04 03:34:56 | 000,000,000 | —D | C] – C:\ProgramData\Sony
[2011/05/04 03:34:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2011/05/04 03:06:04 | 000,000,000 | —D | C] – C:\Users\7017\Desktop\Sony Vegas Pro 10.0c [x64]-[Win]-[CyberPiraten]
[2011/05/04 02:23:34 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\Sony
[2011/05/04 02:19:25 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\Sony
[2011/05/03 18:01:23 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{B6DD644C-F7D3-4D65-BA50-E24165B5806F}
[2011/05/02 15:50:31 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{AB285F6A-B87B-4F2A-8416-245BF2A815D6}
[2011/05/02 03:50:06 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{67828FB3-6EEE-40D2-8012-BD808CE9D38F}
[2011/05/01 15:49:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{EF641177-0898-4F62-99D7-DEAD516481EC}
[2011/04/30 18:01:44 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{2A192EFE-2BE5-4E2C-A619-1AA39CB7BDE4}
[2011/04/29 14:57:00 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{D824852D-750B-4370-BB39-C6FA3E5EB687}
[2011/04/28 13:51:23 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{23C1ECAF-388A-43F9-8309-2B7D9A59F864}
[2011/04/27 12:51:15 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{14FD5380-A7CE-4D29-AA7E-7CF69243AFAC}
[2011/04/26 18:13:14 | 002,871,808 | —- | C] (Microsoft Corporation) – C:\windows\explorer.exe
[2011/04/26 18:13:14 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\explorer.exe
[2011/04/26 18:13:09 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\esent.dll
[2011/04/26 18:13:09 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\esent.dll
[2011/04/26 18:13:09 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\storport.sys
[2011/04/26 18:13:09 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\windows\SysNative\drivers\amdsata.sys
[2011/04/26 18:13:09 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\fsutil.exe
[2011/04/26 18:13:09 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\windows\SysNative\drivers\amdxata.sys
[2011/04/26 18:13:08 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\fsutil.exe
[2011/04/26 18:12:55 | 001,465,344 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XpsPrint.dll
[2011/04/26 18:12:55 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XpsPrint.dll
[2011/04/26 18:12:54 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\prevhost.exe
[2011/04/26 18:12:53 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\prevhost.exe
[2011/04/26 16:18:07 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{BE568D98-CA82-4B99-8E5D-E4DCFE15F5C4}
[2011/04/25 16:11:31 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/04/25 16:10:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/04/25 16:10:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/04/25 16:00:04 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{F7B6F411-5158-4A2C-918B-C2D275BEEF3A}
[2011/04/25 01:18:14 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{94842CDC-93E7-4B92-B731-6BA73E2F820E}
========== Files - Modified Within 30 Days ==========
[2011/05/24 17:21:47 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
[2011/05/24 17:11:38 | 000,014,144 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/24 17:11:38 | 000,014,144 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/24 17:05:17 | 000,000,064 | —- | M] () – C:\windows\SysWow64\rp_stats.dat
[2011/05/24 17:05:17 | 000,000,044 | —- | M] () – C:\windows\SysWow64\rp_rules.dat
[2011/05/24 17:02:12 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/05/24 17:02:09 | 4148,744,192 | -HS- | M] () – C:\hiberfil.sys
[2011/05/23 22:32:06 | 000,000,052 | —- | M] () – C:\windows\SysNative\ashttpstats.csv
[2011/05/22 18:14:47 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/22 00:05:33 | 000,001,869 | —- | M] () – C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/21 23:55:08 | 000,739,790 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/05/21 23:55:08 | 000,637,228 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/05/21 23:55:08 | 000,114,638 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/05/21 20:12:51 | 000,834,544 | —- | M] () – C:\windows\SysNative\drivers\sptd.sys
[2011/05/21 01:24:10 | 000,001,967 | —- | M] () – C:\Users\7017\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/21 01:24:10 | 000,001,943 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/20 21:15:32 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/05/20 12:38:03 | 000,000,872 | —- | M] () – C:\windows\SysNative\drivers\kgpcpy.cfg
[2011/05/20 10:40:13 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/16 01:50:26 | 000,000,786 | —- | M] () – C:\Users\7017\Desktop\Flyff.lnk
[2011/05/06 01:01:57 | 000,018,855 | —- | M] () – C:\Users\7017\Setup.if2
[2011/05/06 01:01:57 | 000,002,302 | —- | M] () – C:\Users\7017\Setup2.if2
[2011/05/06 00:14:18 | 000,626,792 | —- | M] (Realtek Semiconductor Corporation ) – C:\windows\SysNative\drivers\rtl819xp.sys
[2011/05/05 21:01:24 | 000,001,057 | —- | M] () – C:\Users\7017\AppData\Roaming\vso_ts_preview.xml
[2011/05/05 21:00:11 | 000,001,583 | —- | M] () – C:\Users\7017\Desktop\ConvertXtoDvd.exe - Shortcut.lnk
[2011/05/05 20:58:22 | 000,002,230 | —- | M] () – C:\Users\7017\Desktop\Ranch Rush 2 .lnk
[2011/05/04 03:42:04 | 000,002,812 | —- | M] () – C:\Users\7017\Documents\Register Vegas Pro.htm
[2011/05/04 03:05:32 | 214,248,820 | —- | M] () – C:\Users\7017\Desktop\Sony_Vegas_Pro_10.0c_FULL.rar
[2011/05/04 00:43:39 | 000,793,322 | —- | M] () – C:\Users\7017\Documents\waltermyresume.png
[2011/05/04 00:41:15 | 007,900,919 | —- | M] () – C:\Users\7017\Documents\MarcNEW RES.psd
[2011/05/02 20:23:30 | 000,126,824 | -H– | M] () – C:\windows\SysWow64\mlfcache.dat
[2011/04/27 17:03:43 | 013,414,907 | —- | M] () – C:\Users\7017\Desktop\rani-en
========== Files Created - No Company Name ==========
[2011/05/22 18:14:47 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/22 00:05:33 | 000,001,881 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/22 00:05:33 | 000,001,869 | —- | C] () – C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/21 20:12:50 | 000,834,544 | —- | C] () – C:\windows\SysNative\drivers\sptd.sys
[2011/05/20 20:55:27 | 000,256,512 | —- | C] () – C:\windows\PEV.exe
[2011/05/20 20:55:27 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2011/05/20 20:55:27 | 000,089,088 | —- | C] () – C:\windows\MBR.exe
[2011/05/20 20:55:27 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2011/05/20 20:55:27 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2011/05/20 12:37:18 | 000,000,872 | —- | C] () – C:\windows\SysNative\drivers\kgpcpy.cfg
[2011/05/19 22:38:42 | 000,001,967 | —- | C] () – C:\Users\7017\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 22:38:42 | 000,001,943 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/16 01:50:26 | 000,000,786 | —- | C] () – C:\Users\7017\Desktop\Flyff.lnk
[2011/05/16 01:39:31 | 901,039,426 | —- | C] () – C:\Users\7017\Desktop\FlyffUsaSetup_v15.exe
[2011/05/05 21:00:11 | 000,001,583 | —- | C] () – C:\Users\7017\Desktop\ConvertXtoDvd.exe - Shortcut.lnk
[2011/05/05 20:58:22 | 000,002,230 | —- | C] () – C:\Users\7017\Desktop\Ranch Rush 2 .lnk
[2011/05/04 03:42:04 | 000,002,812 | —- | C] () – C:\Users\7017\Documents\Register Vegas Pro.htm
[2011/05/04 03:05:31 | 214,248,820 | —- | C] () – C:\Users\7017\Desktop\Sony_Vegas_Pro_10.0c_FULL.rar
[2011/05/04 00:43:23 | 000,793,322 | —- | C] () – C:\Users\7017\Documents\waltermyresume.png
[2011/05/04 00:39:36 | 007,900,919 | —- | C] () – C:\Users\7017\Documents\MarcNEW RES.psd
[2011/05/02 20:23:30 | 000,126,824 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/04/27 17:03:42 | 013,414,907 | —- | C] () – C:\Users\7017\Desktop\rani-en
[2011/04/26 16:15:53 | 000,000,064 | —- | C] () – C:\windows\SysWow64\rp_stats.dat
[2011/04/26 16:15:53 | 000,000,044 | —- | C] () – C:\windows\SysWow64\rp_rules.dat
[2011/03/27 23:54:18 | 000,010,876 | -HS- | C] () – C:\Users\7017\AppData\Local\g24068o1rgj522p0x643n2m3xc20eqyr1e
[2011/03/27 23:54:18 | 000,010,876 | -HS- | C] () – C:\ProgramData\g24068o1rgj522p0x643n2m3xc20eqyr1e
[2011/03/08 15:21:06 | 000,001,057 | —- | C] () – C:\Users\7017\AppData\Roaming\vso_ts_preview.xml
[2011/03/08 15:20:18 | 000,007,859 | —- | C] () – C:\Users\7017\AppData\Roaming\pcouffin.cat
[2011/03/08 15:20:18 | 000,001,167 | —- | C] () – C:\Users\7017\AppData\Roaming\pcouffin.inf
[2010/12/29 23:37:09 | 000,000,025 | —- | C] () – C:\Users\7017\AppData\Roaming\bdfvconp.ini
[2010/12/26 01:51:46 | 000,000,008 | —- | C] () – C:\Users\7017\AppData\Local\84756-11986-27475-00TC1-94865
[2010/12/26 01:02:37 | 000,748,704 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2010/12/25 19:32:15 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2010/09/02 00:06:24 | 000,307,200 | —- | C] () – C:\windows\SetDisplayResolution.exe
[2010/09/01 23:12:46 | 000,001,960 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 23:11:10 | 000,311,296 | —- | C] () – C:\windows\SysWow64\Rezip.exe
[2010/01/13 22:41:00 | 000,309,248 | —- | C] () – C:\windows\SysWow64\sqlite36_engine.dll
[2010/01/13 22:38:00 | 000,023,552 | —- | C] () – C:\windows\SysWow64\DirectCOM.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | —- | C] () – C:\windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | —- | C] () – C:\windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | —- | C] () – C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | —- | C] () – C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2006/10/08 20:33:54 | 000,000,000 | —- | C] () – C:\windows\R-series.ini
========== LOP Check ==========
[2010/12/26 01:04:18 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\BitDefender
[2011/03/10 12:47:50 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\freshgames
[2011/03/25 00:18:53 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\funkitron
[2010/12/25 15:18:25 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\GetRightToGo
[2011/05/22 00:46:44 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\ImgBurn
[2011/02/17 19:07:04 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\NetMeter
[2011/03/08 00:11:05 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Oberon Media
[2011/04/05 02:31:42 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\OpenOffice.org
[2010/12/25 14:32:04 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Outertech
[2011/05/04 03:42:39 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Publish Providers
[2011/02/16 01:28:24 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Ringtone Maker
[2011/03/25 00:15:40 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\SoftGrid Client
[2011/05/04 03:42:33 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Sony
[2011/01/12 13:49:54 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\TP
[2011/05/22 00:33:05 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\uTorrent
[2011/05/05 21:01:24 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Vso
[2011/03/11 13:33:15 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Windows Live Writer
[2011/02/16 01:34:45 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Xilisoft
[2011/05/03 17:58:32 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/05/24 17:02:08 | 000,024,585 | —- | M] () – C:\aaw7boot.log
[2011/05/13 20:49:09 | 000,021,825 | —- | M] () – C:\bdlog.txt
[2011/05/20 21:17:30 | 000,027,751 | —- | M] () – C:\ComboFix.txt
[2011/05/24 17:02:09 | 4148,744,192 | -HS- | M] () – C:\hiberfil.sys
[2011/05/24 17:02:09 | 4148,744,192 | -HS- | M] () – C:\pagefile.sys
[2010/09/01 23:08:10 | 000,002,162 | —- | M] () – C:\RHDSetup.log
[2010/12/25 22:20:55 | 000,000,166 | —- | M] () – C:\Setup.log
[2011/05/21 16:33:10 | 000,068,494 | —- | M] () – C:\TDSSKiller.2.5.1.0_21.05.2011_16.32.21_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
[2006/11/09 18:31:56 | 000,016,018 | —- | M] () – C:\Windows\Samsung.png
< %systemroot%\*.scr >
[2009/11/16 03:27:16 | 019,480,587 | —- | M] () – C:\Windows\Crystal Delight.scr
[2008/02/20 17:50:28 | 000,903,680 | —- | M] (Jan Kolarik & Ondrej Vaverka) – C:\Windows\R-series.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/01/07 20:31:41 | 000,001,670 | -HS- | M] () – C:\Users\7017\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/25 22:25:39 | 000,000,221 | -HS- | M] () – C:\Users\7017\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/04/13 21:56:20 | 901,039,426 | —- | M] () – C:\Users\7017\Desktop\FlyffUsaSetup_v15.exe
[2011/05/24 17:21:47 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:8CE646EE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8530A643
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:5320A31B
< End of report >
Extras.txt says:
OTL Extras logfile created on: 5/24/2011 5:24:58 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\7017\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.86 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 57.52% Memory free
7.73 Gb Paging File | 5.87 Gb Available in Paging File | 75.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 179.00 Gb Total Space | 127.96 Gb Free Space | 71.49% Space Free | Partition Type: NTFS
Drive D: | 266.66 Gb Total Space | 175.79 Gb Free Space | 65.92% Space Free | Partition Type: NTFS
Computer Name: 7017-PC | User Name: 7017 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{028FF35A-9CFD-4653-9E5B-9667BD72D6AF}" = BitDefender Total Security 2010
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{16DDB3D1-5C27-4599-9C63-E583287191CC}" = iTunes
"{1A8BA6CE-822D-4888-89E2-ACBF4308F271}" = Intel® PROSet/Wireless WiFi Software
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intel® Turbo Boost Technology Monitor
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{563F041C-DFDB-437B-A1E8-E141E0906076}" = Microsoft IntelliPoint 8.0
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9CF4A37B-A8C4-44D7-8C53-13B9D9594BB3}" = Paint.NET v3.5.8
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{C616FD4F-11F5-11E0-A38F-0013D3D69929}" = Vegas Pro 10.0 (64-bit)
"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.00 beta 3 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F796312-289C-40CA-856C-9FBCF5E83342}" = REALTEK Wireless LAN Software
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 4
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Blu-ray Disc Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3EED7541-55F8-4DC6-B9CD-28762D71310E}" = Samsung R-Series
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A331D24-A9E8-484F-835E-1BA7B139689C}" = EasyBatteryManager
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74A579FB-EB06-497D-B194-01590D6FE51A}" = BatteryLifeExtender
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110109903}" = Flip Words
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110160733}" = Slingo
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110245793}" = Insaniquarium Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110521483}" = Gem Shop
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111768557}" = Bonbon Quest
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113128447}" = Daycare Nightmare
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981405}" = SaveVid Plug-in
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}" = ChargeableUSB
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92B6797-9C07-4E25-AD96-29087D3A2AC2}" = TouchCopy 09
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B1924580-0C5D-11E0-B655-0013D3D69929}" = MSVCRT Redists
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1434266-0486-4469-B338-A60082CC04E1}" = Atheros Client Installation Program
"{D1725D54-279A-40C5-A70D-23C1785DB920}_is1" = AoA Audio Extractor Platinum
"{D1F6FBBB-B204-459A-9BF8-D06FFAB96CCC}_is1" = Game Pack
"{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}" = Samsung Update Plus
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.10.348
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Samsung Support Center
"{F9557866-B4C8-4CE5-8508-0E386BDC20B2}" = Easy Network Manager
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ares" = Ares 2.1.7
"conduitEngine" = Conduit Engine
"DivX Setup.divx.com" = DivX Setup
"GetDiz 4.5" = GetDiz 4.5
"ImgBurn" = ImgBurn
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Blu-ray Disc Suite
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Marvell Miniport Driver" = Marvell Miniport Driver
"Mozilla Firefox (3.5.19)" = Mozilla Firefox (3.5.19)
"Ranch Rush 2 Collectors Edition 1.00" = Ranch Rush 2 Collectors Edition 1.00
"SaveVid Plug-in" = SaveVid Plug-in
"Searchqu 405 MediaBar" = Windows Savevid Toolbar
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"WinLiveSuite" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
P2P - I see you have P2P software, (uTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.
Should you decide to keep it, please don’t use it until we have finished up here.
===================================================
• Hold down the Windows key and press R to open a run box
• type the following text into the run box
appwiz.cpl
• This will open your Programs And Features• A list of installed programs will populate
• Remove the following program:
Searchqu 406 MediaBar
===================================================Run OTL
- Double click on the icon to run it.
- Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL [2011/04/04 16:00:29 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\x64\datamngr.dll) - File not found O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\x64\IEBHO.dll) - File not found O20 - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\datamngr.dll) - File not found O20 - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\IEBHO.dll) - File not found :Reg :Files ipconfig /flushdns /c :Commands [purity] [CreateRestorePoint] [ResetHosts] [EmptyFlash] [emptytemp] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Download Malwarebytes-Anti-Malware
Click here
- double-click mbam-setup.exe and follow the prompts to install the program.
- at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
- if an update is found, it will download and install the latest version.
- once the program has loaded, select Perform quick scan, then click Scan.
- when the scan is complete, click OK, then Show Results to view the results.
- be sure that everything is checked, and click Remove Selected.
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
===================================================
Also, I notice you have run ComboFix which is not recommended without expert.guidance.
Please send the log from when you ran it. ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc
===================================================
Logs to include with next post:
OTL fix log
New OTL log
Mbam.txt
Combofix.txt
Thanks
Satchfan
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6696
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
27/05/2011 5:21:22 PM
mbam-log-2011-05-27 (17-21-22).txt
Scan type: Quick scan
Objects scanned: 160427
Time elapsed: 4 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
First OTL Log:
OTL logfile created on: 5/24/2011 5:24:58 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\7017\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.86 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 57.52% Memory free
7.73 Gb Paging File | 5.87 Gb Available in Paging File | 75.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 179.00 Gb Total Space | 127.96 Gb Free Space | 71.49% Space Free | Partition Type: NTFS
Drive D: | 266.66 Gb Total Space | 175.79 Gb Free Space | 65.92% Space Free | Partition Type: NTFS
Computer Name: 7017-PC | User Name: 7017 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\7017\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (SEC)
PRC - C:\Program Files\BitDefender\BitDefender 2010\Antispam32\bdimguiaux.exe (BitDefender S.R.L.)
PRC - C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Windows\SysWOW64\Rezip.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\7017\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas64-v2_75\midas32.dll (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (LIVESRV) – C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender S.R.L.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe (BitDefender S.R.L.)
SRV:64bit: - (scan) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (S.C. BitDefender S.R.L)
SRV:64bit: - (Arrakis3) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender S.R.L. http://www.bitdefender.com)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (npggsvc) – C:\windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Rezip) – C:\Windows\SysWOW64\Rezip.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (rtl819xpn64) Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-) – C:\Windows\SysNative\drivers\rtl819xp.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BdfNdisf) – C:\Windows\SysNative\drivers\BdfNdisf6.sys (BitDefender LLC)
DRV:64bit: - (bdfwfpf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys (BitDefender LLC)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (BDFM) – C:\Windows\SysNative\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (BDVEDISK) – C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys (BitDefender)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (qcusbser) – C:\Windows\SysNative\drivers\qcusbser.sys (QUALCOMM Incorporated)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SABI) – C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MRV6X64U) Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x) – C:\Windows\SysNative\drivers\MRVW24C.sys (Marvell Semiconductor, Inc)
DRV:64bit: - (nmwcdx64) – C:\Windows\SysNative\drivers\nmwcdx64.sys (Nokia)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (rtport) – C:\Windows\SysWOW64\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\ [2011/05/14 19:11:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/04/05 02:45:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/04/05 02:45:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/23 17:13:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/23 17:13:07 | 000,000,000 | —D | M]
[2011/04/04 16:00:29 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Extensions
[2011/05/22 18:43:28 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Firefox\Profiles\x1oqovdw.Default User\extensions
[2011/05/23 18:53:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/09 14:45:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/05 02:45:51 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2011/04/05 02:45:51 | 000,000,000 | —D | M] (DivX HiQ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2011/04/04 15:59:59 | 000,000,000 | —D | M] ("Savevid.com Easy Video Downloader") – C:\PROGRAM FILES (X86)\SAVEVID\[removed]
[2011/04/04 16:00:29 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/05/14 19:11:21 | 000,000,000 | —D | M] ("BitDefender Antiphishing Toolbar") – C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2010\BDAPHFFEXT
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/05/20 21:15:32 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - File not found
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - File not found
O3:64bit: - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEToolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper 32] C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEShow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\7017\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\x64\datamngr.dll) - File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\x64\IEBHO.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\datamngr.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\WI5C88~1\Datamngr\IEBHO.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/05/24 17:21:47 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
[2011/05/24 17:08:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{89A7BFE4-A14A-42FA-A331-D5DA636EA36D}
[2011/05/24 17:07:38 | 000,000,000 | R–D | C] – C:\Users\7017\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2011/05/23 14:35:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{3F2B9A46-AF2C-4C9A-87EB-6834D0721D4E}
[2011/05/22 18:15:03 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\SUPERAntiSpyware.com
[2011/05/22 18:15:03 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/05/22 18:14:48 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/05/22 18:14:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/05/22 18:14:43 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/05/22 18:08:20 | 000,000,000 | —D | C] – C:\Program Files\chromium
[2011/05/22 18:07:53 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{D260EB27-6276-44DE-AC34-610227AC1C5F}
[2011/05/22 02:51:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{486D2C27-0F74-45FE-989F-4A8EB74676C1}
[2011/05/22 00:42:38 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\ImgBurn
[2011/05/22 00:05:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/21 20:12:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\LSoft Technologies
[2011/05/21 20:12:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ ISO Burner
[2011/05/21 19:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ImgBurn
[2011/05/21 19:48:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
[2011/05/21 16:06:46 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\Chromium
[2011/05/21 12:50:10 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{5FF2282E-3409-46F0-BB4E-62AA63E9886F}
[2011/05/20 22:39:51 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{3D03E705-F684-4C90-B5AA-B6143EF57473}
[2011/05/20 21:27:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/20 21:03:30 | 000,212,480 | —- | C] (SteelWerX) – C:\windows\SWXCACLS.exe
[2011/05/20 20:55:27 | 000,161,792 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2011/05/20 20:55:27 | 000,136,704 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2011/05/20 20:55:27 | 000,031,232 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2011/05/20 20:55:13 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/05/20 20:54:40 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/20 12:25:11 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2011/05/20 10:40:13 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/20 10:39:25 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{2DCD58F9-0D1F-4E2A-8F03-853967EE18E2}
[2011/05/19 22:38:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/05/19 03:01:58 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{EE701A32-6DDB-4418-820A-D21147B9BD98}
[2011/05/18 15:01:32 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{4A88A292-B0AF-415B-8126-E40A90A29FD9}
[2011/05/18 00:47:00 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{BB798A60-A1A3-4C54-850E-2BF454A5B46D}
[2011/05/17 12:47:06 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{C667E0B7-5EFF-459D-989E-20F11BE33216}
[2011/05/16 09:27:19 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{CDDFFA87-455E-45DF-959A-FA2D52A4644F}
[2011/05/15 16:38:44 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{527922EF-983C-4EC2-AD33-BBD5EA879941}
[2011/05/14 19:35:13 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{FB65AD8A-5769-439D-87DB-E9327FF6FBFC}
[2011/05/13 14:01:37 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{7B6BCBC7-41E1-47AC-9704-41D584702DBB}
[2011/05/12 16:39:52 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{1A8BFA72-3B69-49F2-A58B-6515850F1216}
[2011/05/11 17:31:52 | 005,562,240 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/05/11 17:31:49 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/05/11 17:31:49 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/05/11 17:24:38 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{E8A8062D-7DD7-4DC0-B889-1F1ED9256F30}
[2011/05/10 13:54:56 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{F3F1A6C1-2B28-4632-B228-81AF9828FC0F}
[2011/05/09 14:41:50 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{6486F907-F7E5-43A7-B5DC-58AB4FC011E8}
[2011/05/08 18:57:04 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{13F704A5-077A-43E8-974C-10D9E3D8C08E}
[2011/05/06 15:26:55 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{A983C20A-39FD-4345-8A88-CF1F9DCF5ADC}
[2011/05/06 01:05:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Marvell
[2011/05/06 01:05:17 | 000,000,000 | —D | C] – C:\LAN_Win7_11.22.3.3
[2011/05/06 01:01:57 | 000,000,000 | —D | C] – C:\Users\7017\x64
[2011/05/06 01:01:56 | 000,000,000 | —D | C] – C:\Users\7017\Lang
[2011/05/06 01:01:55 | 000,000,000 | —D | C] – C:\Users\7017\IIPS
[2011/05/06 00:41:08 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{5357BB7A-3ED7-4A6E-AE78-1F41C8B4CCA1}
[2011/05/06 00:23:20 | 000,000,000 | —D | C] – C:\HDMI_Win7_1.0.0.55
[2011/05/06 00:19:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\REALTEK Wireless LAN Software
[2011/05/06 00:19:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cisco
[2011/05/05 20:59:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
[2011/05/05 20:59:23 | 000,626,688 | —- | C] (On2.com) – C:\windows\SysWow64\vp7vfw.dll
[2011/05/05 20:59:22 | 001,184,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wvc1dmod.dll
[2011/05/05 20:58:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Games
[2011/05/05 12:40:42 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{17EEA0A0-73AF-41D1-BFAA-81562E8DF59C}
[2011/05/04 18:02:02 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{21AC932A-C1F6-45EB-9688-FDDFF4352620}
[2011/05/04 06:01:49 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{B226A868-FE83-4BAB-B32C-04FC434EDB60}
[2011/05/04 04:32:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2011/05/04 04:32:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\ConduitEngine
[2011/05/04 04:32:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrentBar
[2011/05/04 03:42:39 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\Publish Providers
[2011/05/04 03:35:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2011/05/04 03:34:56 | 000,000,000 | —D | C] – C:\ProgramData\Sony
[2011/05/04 03:34:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2011/05/04 03:06:04 | 000,000,000 | —D | C] – C:\Users\7017\Desktop\Sony Vegas Pro 10.0c [x64]-[Win]-[CyberPiraten]
[2011/05/04 02:23:34 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\Sony
[2011/05/04 02:19:25 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\Sony
[2011/05/03 18:01:23 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{B6DD644C-F7D3-4D65-BA50-E24165B5806F}
[2011/05/02 15:50:31 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{AB285F6A-B87B-4F2A-8416-245BF2A815D6}
[2011/05/02 03:50:06 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{67828FB3-6EEE-40D2-8012-BD808CE9D38F}
[2011/05/01 15:49:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{EF641177-0898-4F62-99D7-DEAD516481EC}
[2011/04/30 18:01:44 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{2A192EFE-2BE5-4E2C-A619-1AA39CB7BDE4}
[2011/04/29 14:57:00 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{D824852D-750B-4370-BB39-C6FA3E5EB687}
[2011/04/28 13:51:23 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{23C1ECAF-388A-43F9-8309-2B7D9A59F864}
[2011/04/27 12:51:15 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{14FD5380-A7CE-4D29-AA7E-7CF69243AFAC}
[2011/04/26 18:13:14 | 002,871,808 | —- | C] (Microsoft Corporation) – C:\windows\explorer.exe
[2011/04/26 18:13:14 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\explorer.exe
[2011/04/26 18:13:09 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\esent.dll
[2011/04/26 18:13:09 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\esent.dll
[2011/04/26 18:13:09 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\storport.sys
[2011/04/26 18:13:09 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\windows\SysNative\drivers\amdsata.sys
[2011/04/26 18:13:09 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\fsutil.exe
[2011/04/26 18:13:09 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\windows\SysNative\drivers\amdxata.sys
[2011/04/26 18:13:08 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\fsutil.exe
[2011/04/26 18:12:55 | 001,465,344 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\XpsPrint.dll
[2011/04/26 18:12:55 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\XpsPrint.dll
[2011/04/26 18:12:54 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\prevhost.exe
[2011/04/26 18:12:53 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\prevhost.exe
[2011/04/26 16:18:07 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{BE568D98-CA82-4B99-8E5D-E4DCFE15F5C4}
[2011/04/25 16:11:31 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/04/25 16:10:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/04/25 16:10:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/04/25 16:00:04 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{F7B6F411-5158-4A2C-918B-C2D275BEEF3A}
[2011/04/25 01:18:14 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{94842CDC-93E7-4B92-B731-6BA73E2F820E}
========== Files - Modified Within 30 Days ==========
[2011/05/24 17:21:47 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
[2011/05/24 17:11:38 | 000,014,144 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/24 17:11:38 | 000,014,144 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/24 17:05:17 | 000,000,064 | —- | M] () – C:\windows\SysWow64\rp_stats.dat
[2011/05/24 17:05:17 | 000,000,044 | —- | M] () – C:\windows\SysWow64\rp_rules.dat
[2011/05/24 17:02:12 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/05/24 17:02:09 | 4148,744,192 | -HS- | M] () – C:\hiberfil.sys
[2011/05/23 22:32:06 | 000,000,052 | —- | M] () – C:\windows\SysNative\ashttpstats.csv
[2011/05/22 18:14:47 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/22 00:05:33 | 000,001,869 | —- | M] () – C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/21 23:55:08 | 000,739,790 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/05/21 23:55:08 | 000,637,228 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/05/21 23:55:08 | 000,114,638 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/05/21 20:12:51 | 000,834,544 | —- | M] () – C:\windows\SysNative\drivers\sptd.sys
[2011/05/21 01:24:10 | 000,001,967 | —- | M] () – C:\Users\7017\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/21 01:24:10 | 000,001,943 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/20 21:15:32 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/05/20 12:38:03 | 000,000,872 | —- | M] () – C:\windows\SysNative\drivers\kgpcpy.cfg
[2011/05/20 10:40:13 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/16 01:50:26 | 000,000,786 | —- | M] () – C:\Users\7017\Desktop\Flyff.lnk
[2011/05/06 01:01:57 | 000,018,855 | —- | M] () – C:\Users\7017\Setup.if2
[2011/05/06 01:01:57 | 000,002,302 | —- | M] () – C:\Users\7017\Setup2.if2
[2011/05/06 00:14:18 | 000,626,792 | —- | M] (Realtek Semiconductor Corporation ) – C:\windows\SysNative\drivers\rtl819xp.sys
[2011/05/05 21:01:24 | 000,001,057 | —- | M] () – C:\Users\7017\AppData\Roaming\vso_ts_preview.xml
[2011/05/05 21:00:11 | 000,001,583 | —- | M] () – C:\Users\7017\Desktop\ConvertXtoDvd.exe - Shortcut.lnk
[2011/05/05 20:58:22 | 000,002,230 | —- | M] () – C:\Users\7017\Desktop\Ranch Rush 2 .lnk
[2011/05/04 03:42:04 | 000,002,812 | —- | M] () – C:\Users\7017\Documents\Register Vegas Pro.htm
[2011/05/04 03:05:32 | 214,248,820 | —- | M] () – C:\Users\7017\Desktop\Sony_Vegas_Pro_10.0c_FULL.rar
[2011/05/04 00:43:39 | 000,793,322 | —- | M] () – C:\Users\7017\Documents\waltermyresume.png
[2011/05/04 00:41:15 | 007,900,919 | —- | M] () – C:\Users\7017\Documents\MarcNEW RES.psd
[2011/05/02 20:23:30 | 000,126,824 | -H– | M] () – C:\windows\SysWow64\mlfcache.dat
[2011/04/27 17:03:43 | 013,414,907 | —- | M] () – C:\Users\7017\Desktop\rani-en
========== Files Created - No Company Name ==========
[2011/05/22 18:14:47 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/22 00:05:33 | 000,001,881 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/22 00:05:33 | 000,001,869 | —- | C] () – C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/21 20:12:50 | 000,834,544 | —- | C] () – C:\windows\SysNative\drivers\sptd.sys
[2011/05/20 20:55:27 | 000,256,512 | —- | C] () – C:\windows\PEV.exe
[2011/05/20 20:55:27 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2011/05/20 20:55:27 | 000,089,088 | —- | C] () – C:\windows\MBR.exe
[2011/05/20 20:55:27 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2011/05/20 20:55:27 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2011/05/20 12:37:18 | 000,000,872 | —- | C] () – C:\windows\SysNative\drivers\kgpcpy.cfg
[2011/05/19 22:38:42 | 000,001,967 | —- | C] () – C:\Users\7017\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 22:38:42 | 000,001,943 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/16 01:50:26 | 000,000,786 | —- | C] () – C:\Users\7017\Desktop\Flyff.lnk
[2011/05/16 01:39:31 | 901,039,426 | —- | C] () – C:\Users\7017\Desktop\FlyffUsaSetup_v15.exe
[2011/05/05 21:00:11 | 000,001,583 | —- | C] () – C:\Users\7017\Desktop\ConvertXtoDvd.exe - Shortcut.lnk
[2011/05/05 20:58:22 | 000,002,230 | —- | C] () – C:\Users\7017\Desktop\Ranch Rush 2 .lnk
[2011/05/04 03:42:04 | 000,002,812 | —- | C] () – C:\Users\7017\Documents\Register Vegas Pro.htm
[2011/05/04 03:05:31 | 214,248,820 | —- | C] () – C:\Users\7017\Desktop\Sony_Vegas_Pro_10.0c_FULL.rar
[2011/05/04 00:43:23 | 000,793,322 | —- | C] () – C:\Users\7017\Documents\waltermyresume.png
[2011/05/04 00:39:36 | 007,900,919 | —- | C] () – C:\Users\7017\Documents\MarcNEW RES.psd
[2011/05/02 20:23:30 | 000,126,824 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/04/27 17:03:42 | 013,414,907 | —- | C] () – C:\Users\7017\Desktop\rani-en
[2011/04/26 16:15:53 | 000,000,064 | —- | C] () – C:\windows\SysWow64\rp_stats.dat
[2011/04/26 16:15:53 | 000,000,044 | —- | C] () – C:\windows\SysWow64\rp_rules.dat
[2011/03/27 23:54:18 | 000,010,876 | -HS- | C] () – C:\Users\7017\AppData\Local\g24068o1rgj522p0x643n2m3xc20eqyr1e
[2011/03/27 23:54:18 | 000,010,876 | -HS- | C] () – C:\ProgramData\g24068o1rgj522p0x643n2m3xc20eqyr1e
[2011/03/08 15:21:06 | 000,001,057 | —- | C] () – C:\Users\7017\AppData\Roaming\vso_ts_preview.xml
[2011/03/08 15:20:18 | 000,007,859 | —- | C] () – C:\Users\7017\AppData\Roaming\pcouffin.cat
[2011/03/08 15:20:18 | 000,001,167 | —- | C] () – C:\Users\7017\AppData\Roaming\pcouffin.inf
[2010/12/29 23:37:09 | 000,000,025 | —- | C] () – C:\Users\7017\AppData\Roaming\bdfvconp.ini
[2010/12/26 01:51:46 | 000,000,008 | —- | C] () – C:\Users\7017\AppData\Local\84756-11986-27475-00TC1-94865
[2010/12/26 01:02:37 | 000,748,704 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2010/12/25 19:32:15 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2010/09/02 00:06:24 | 000,307,200 | —- | C] () – C:\windows\SetDisplayResolution.exe
[2010/09/01 23:12:46 | 000,001,960 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 23:11:10 | 000,311,296 | —- | C] () – C:\windows\SysWow64\Rezip.exe
[2010/01/13 22:41:00 | 000,309,248 | —- | C] () – C:\windows\SysWow64\sqlite36_engine.dll
[2010/01/13 22:38:00 | 000,023,552 | —- | C] () – C:\windows\SysWow64\DirectCOM.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | —- | C] () – C:\windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | —- | C] () – C:\windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | —- | C] () – C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | —- | C] () – C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2006/10/08 20:33:54 | 000,000,000 | —- | C] () – C:\windows\R-series.ini
========== LOP Check ==========
[2010/12/26 01:04:18 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\BitDefender
[2011/03/10 12:47:50 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\freshgames
[2011/03/25 00:18:53 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\funkitron
[2010/12/25 15:18:25 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\GetRightToGo
[2011/05/22 00:46:44 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\ImgBurn
[2011/02/17 19:07:04 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\NetMeter
[2011/03/08 00:11:05 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Oberon Media
[2011/04/05 02:31:42 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\OpenOffice.org
[2010/12/25 14:32:04 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Outertech
[2011/05/04 03:42:39 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Publish Providers
[2011/02/16 01:28:24 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Ringtone Maker
[2011/03/25 00:15:40 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\SoftGrid Client
[2011/05/04 03:42:33 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Sony
[2011/01/12 13:49:54 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\TP
[2011/05/22 00:33:05 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\uTorrent
[2011/05/05 21:01:24 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Vso
[2011/03/11 13:33:15 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Windows Live Writer
[2011/02/16 01:34:45 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Xilisoft
[2011/05/03 17:58:32 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/05/24 17:02:08 | 000,024,585 | —- | M] () – C:\aaw7boot.log
[2011/05/13 20:49:09 | 000,021,825 | —- | M] () – C:\bdlog.txt
[2011/05/20 21:17:30 | 000,027,751 | —- | M] () – C:\ComboFix.txt
[2011/05/24 17:02:09 | 4148,744,192 | -HS- | M] () – C:\hiberfil.sys
[2011/05/24 17:02:09 | 4148,744,192 | -HS- | M] () – C:\pagefile.sys
[2010/09/01 23:08:10 | 000,002,162 | —- | M] () – C:\RHDSetup.log
[2010/12/25 22:20:55 | 000,000,166 | —- | M] () – C:\Setup.log
[2011/05/21 16:33:10 | 000,068,494 | —- | M] () – C:\TDSSKiller.2.5.1.0_21.05.2011_16.32.21_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
[2006/11/09 18:31:56 | 000,016,018 | —- | M] () – C:\Windows\Samsung.png
< %systemroot%\*.scr >
[2009/11/16 03:27:16 | 019,480,587 | —- | M] () – C:\Windows\Crystal Delight.scr
[2008/02/20 17:50:28 | 000,903,680 | —- | M] (Jan Kolarik & Ondrej Vaverka) – C:\Windows\R-series.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/01/07 20:31:41 | 000,001,670 | -HS- | M] () – C:\Users\7017\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/25 22:25:39 | 000,000,221 | -HS- | M] () – C:\Users\7017\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/04/13 21:56:20 | 901,039,426 | —- | M] () – C:\Users\7017\Desktop\FlyffUsaSetup_v15.exe
[2011/05/24 17:21:47 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:8CE646EE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8530A643
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:5320A31B
< End of report >
Second OTL Log:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\PROGRAM FILES (X86)\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION\content folder moved successfully.
C:\PROGRAM FILES (X86)\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION\components folder moved successfully.
C:\PROGRAM FILES (X86)\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION folder moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI5C88~1\Datamngr\x64\datamngr.dll deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI5C88~1\Datamngr\x64\IEBHO.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI5C88~1\Datamngr\datamngr.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI5C88~1\Datamngr\IEBHO.dll deleted successfully.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\7017\Desktop\cmd.bat deleted successfully.
C:\Users\7017\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYFLASH]
User: 7017
->Flash cache emptied: 128273 bytes
User: All Users
User: Default
User: Default User
User: Public
Total Flash Files Cleaned = 0.00 mb
[EMPTYTEMP]
User: 7017
->Temp folder emptied: 157023524 bytes
->Temporary Internet Files folder emptied: 47575405 bytes
->Java cache emptied: 349073 bytes
->FireFox cache emptied: 92701548 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 111096 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67496 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 666 bytes
RecycleBin emptied: 65358853 bytes
Total Files Cleaned = 346.00 mb
OTL by OldTimer - Version 3.2.23.0 log created on 05272011_170341
Files\Folders moved on Reboot…
C:\Users\7017\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
ComboFix Quarantined Files Log:
2011-05-21 01:16:34 . 2011-05-21 01:16:34 890 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-GetDiz 4.5.reg.dat
2011-05-21 01:16:25 . 2011-05-21 01:16:25 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SynTPEnh.reg.dat
2011-05-21 01:16:25 . 2011-05-21 01:16:25 171 —-a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}.reg.dat
2011-05-21 01:16:24 . 2011-05-21 01:16:24 142 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-10.reg.dat
2011-05-21 01:16:24 . 2011-05-21 01:16:24 92 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-Locked.reg.dat
2011-05-21 01:16:18 . 2011-05-21 01:16:18 534 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-MCODS.reg.dat
2011-05-21 01:16:18 . 2011-05-21 01:16:18 546 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-mcmscsvc.reg.dat
2011-05-21 01:16:08 . 2011-05-21 01:16:08 104 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-Locked.reg.dat
2011-05-21 01:13:57 . 2011-05-21 01:13:57 31,340 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-05-21 00:55:13 . 2011-05-21 01:04:02 102 —-a-w- C:\Qoobox\Quarantine\catchme.log
2011-04-04 20:00:16 . 2010-12-09 15:17:40 5,529 —-a-w- C:\Qoobox\Quarantine\C\Users\7017\AppData\Roaming\Mozilla\Firefox\Profiles\i119sv5t.default\searchplugins\SearchquWebSearch.xml.vir
2011-03-08 19:20:18 . 2011-04-18 00:48:00 99,384 —-a-w- C:\Qoobox\Quarantine\C\Users\7017\AppData\Roaming\inst.exe.vir
2011-03-08 19:20:18 . 2011-04-18 00:48:00 82,816 —-a-w- C:\Qoobox\Quarantine\C\Users\7017\AppData\Roaming\pcouffin.sys.vir
2011-03-08 19:19:41 . 2011-03-08 19:19:41 2 —-a-w- C:\Qoobox\Quarantine\C\1833.exe.vir
2011-03-08 19:19:30 . 2011-03-08 19:19:30 2 —-a-w- C:\Qoobox\Quarantine\C\54212.exe.vir
2010-12-26 02:10:34 . 2010-01-16 12:18:08 131,368 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\FullRemove.exe.vir
2010-04-09 18:09:18 . 2011-05-06 05:01:57 952,856 —-a-w- C:\Qoobox\Quarantine\C\Users\7017\Setup.exe.vir
2008-12-30 20:31:22 . 2011-05-06 05:01:55 25 —-a-w- C:\Qoobox\Quarantine\C\Users\7017\AUTORUN.INF.vir
2006-11-02 12:21:54 . 2011-05-06 05:01:55 319,456 —-a-w- C:\Qoobox\Quarantine\C\Users\7017\DIFxAPI.dll.vir
Please Note: When I looked for the Searchqu 406 MediaBar, it did not appear, even after I revealed hidden files. This could be because I deleted the source files from my computer before I came on to WTT to get assistance. Please let me know if this matters, thanks
So does this mean I'm good to go??
No. merely acknowledging the receipt of your reply.So does this mean I'm good to go??
=========================================
I would like you to explain what problems currently remain
Thanks
Satchfan
I’d like to point out a couple of things that you may be unaware of.
===================================================
Stopzilla
This has been classified as scraping the edge of rogue antimalware. Some things that have been said about it:
• It's difficult to completely remove
• It slows your computer down
• The awards they list on their site are fake
I suggest you remove it from your “Programs” folder
===================================================
The Ask toolbar
The ASK toolbar comes bundled with many third-party applications, is considered as Spyware and comes with vulnerabilities.
See the following links and decide yourself whether or not you want to keep it.:
http://secunia.com/advisories/product/15810/
http://www.benedelman.org/spyware/ask-toolbars/
===================================================
Run OTL • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
• Post the OTL.txt log it produces in your next reply.
Please post back with the log
Thanks
Satchfan
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\7017\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.86 Gb Total Physical Memory | 1.85 Gb Available Physical Memory | 47.96% Memory free
7.73 Gb Paging File | 5.57 Gb Available in Paging File | 72.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 179.00 Gb Total Space | 125.37 Gb Free Space | 70.04% Space Free | Partition Type: NTFS
Drive D: | 266.66 Gb Total Space | 175.71 Gb Free Space | 65.89% Space Free | Partition Type: NTFS
Computer Name: 7017-PC | User Name: 7017 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\7017\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\chromium\chrome-win32\chrome.exe (The Chromium Authors)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\BingApp.exe (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (SEC)
PRC - C:\Program Files\BitDefender\BitDefender 2010\Antispam32\bdimguiaux.exe (BitDefender S.R.L.)
PRC - C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Windows\SysWOW64\Rezip.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\7017\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas64-v2_75\midas32.dll (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (LIVESRV) – C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender S.R.L.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe (BitDefender S.R.L.)
SRV:64bit: - (scan) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (S.C. BitDefender S.R.L)
SRV:64bit: - (Arrakis3) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender S.R.L. http://www.bitdefender.com)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (npggsvc) – C:\windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Rezip) – C:\Windows\SysWOW64\Rezip.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (rtl819xpn64) Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-) – C:\Windows\SysNative\drivers\rtl819xp.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BdfNdisf) – C:\Windows\SysNative\drivers\BdfNdisf6.sys (BitDefender LLC)
DRV:64bit: - (bdfwfpf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys (BitDefender LLC)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (BDFM) – C:\Windows\SysNative\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (BDVEDISK) – C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys (BitDefender)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (qcusbser) – C:\Windows\SysNative\drivers\qcusbser.sys (QUALCOMM Incorporated)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SABI) – C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MRV6X64U) Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x) – C:\Windows\SysNative\drivers\MRVW24C.sys (Marvell Semiconductor, Inc)
DRV:64bit: - (nmwcdx64) – C:\Windows\SysNative\drivers\nmwcdx64.sys (Nokia)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (rtport) – C:\Windows\SysWOW64\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\ [2011/05/14 19:11:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/04/05 02:45:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/04/05 02:45:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/27 18:23:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/27 18:23:59 | 000,000,000 | —D | M]
[2011/04/04 16:00:29 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Extensions
[2011/05/22 18:43:28 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Firefox\Profiles\x1oqovdw.Default User\extensions
[2011/05/27 17:45:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/09 14:45:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/27 18:23:36 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/27 18:23:40 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/05/27 17:04:27 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - File not found
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - File not found
O3:64bit: - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEToolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper 32] C:\Program Files\BitDefender\BitDefender 2010\Antispam32\IEShow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - Startup: C:\Users\7017\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/05/28 17:43:14 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{9AA45BC0-9C21-47D0-9504-3E9F57218904}
[2011/05/28 17:41:35 | 000,000,000 | R–D | C] – C:\Users\7017\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2011/05/27 17:12:41 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{06935DC7-184E-477C-A1D3-47604810A141}
[2011/05/27 17:03:41 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/27 11:53:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{8D66E562-E37A-4A93-BBB7-CE7B27B54A83}
[2011/05/26 16:50:06 | 000,000,000 | —D | C] – C:\Users\7017\Desktop\redsn0w_win_0.9.6rc16
[2011/05/26 15:35:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{C184143E-5ED5-4B2D-BFE3-E4C2CEB7C867}
[2011/05/25 21:35:30 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{BDA91B1D-B54F-4345-AC57-3108530D4D68}
[2011/05/24 17:34:19 | 000,589,632 | —- | C] (AVAST Software) – C:\Users\7017\Desktop\aswMBR.exe
[2011/05/24 17:21:47 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
[2011/05/24 17:08:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{89A7BFE4-A14A-42FA-A331-D5DA636EA36D}
[2011/05/23 14:35:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{3F2B9A46-AF2C-4C9A-87EB-6834D0721D4E}
[2011/05/22 18:15:03 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/05/22 18:08:20 | 000,000,000 | —D | C] – C:\Program Files\chromium
[2011/05/22 18:07:53 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{D260EB27-6276-44DE-AC34-610227AC1C5F}
[2011/05/22 02:51:33 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{486D2C27-0F74-45FE-989F-4A8EB74676C1}
[2011/05/22 00:42:38 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\ImgBurn
[2011/05/22 00:05:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/21 20:12:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\LSoft Technologies
[2011/05/21 20:12:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ ISO Burner
[2011/05/21 19:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ImgBurn
[2011/05/21 16:06:46 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\Chromium
[2011/05/21 12:50:10 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{5FF2282E-3409-46F0-BB4E-62AA63E9886F}
[2011/05/20 22:39:51 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{3D03E705-F684-4C90-B5AA-B6143EF57473}
[2011/05/20 21:27:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/20 21:03:30 | 000,212,480 | —- | C] (SteelWerX) – C:\windows\SWXCACLS.exe
[2011/05/20 20:55:27 | 000,161,792 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2011/05/20 20:55:27 | 000,136,704 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2011/05/20 20:55:27 | 000,031,232 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2011/05/20 20:55:13 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/05/20 20:54:40 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/20 12:25:11 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2011/05/20 10:39:25 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{2DCD58F9-0D1F-4E2A-8F03-853967EE18E2}
[2011/05/19 03:01:58 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{EE701A32-6DDB-4418-820A-D21147B9BD98}
[2011/05/18 15:01:32 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{4A88A292-B0AF-415B-8126-E40A90A29FD9}
[2011/05/18 00:47:00 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{BB798A60-A1A3-4C54-850E-2BF454A5B46D}
[2011/05/17 12:47:06 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{C667E0B7-5EFF-459D-989E-20F11BE33216}
[2011/05/16 09:27:19 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{CDDFFA87-455E-45DF-959A-FA2D52A4644F}
[2011/05/15 16:38:44 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{527922EF-983C-4EC2-AD33-BBD5EA879941}
[2011/05/14 19:35:13 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{FB65AD8A-5769-439D-87DB-E9327FF6FBFC}
[2011/05/13 14:01:37 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{7B6BCBC7-41E1-47AC-9704-41D584702DBB}
[2011/05/12 16:39:52 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{1A8BFA72-3B69-49F2-A58B-6515850F1216}
[2011/05/11 17:24:38 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{E8A8062D-7DD7-4DC0-B889-1F1ED9256F30}
[2011/05/10 13:54:56 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{F3F1A6C1-2B28-4632-B228-81AF9828FC0F}
[2011/05/09 14:41:50 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{6486F907-F7E5-43A7-B5DC-58AB4FC011E8}
[2011/05/08 18:57:04 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{13F704A5-077A-43E8-974C-10D9E3D8C08E}
[2011/05/06 15:26:55 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{A983C20A-39FD-4345-8A88-CF1F9DCF5ADC}
[2011/05/06 01:05:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Marvell
[2011/05/06 01:05:17 | 000,000,000 | —D | C] – C:\LAN_Win7_11.22.3.3
[2011/05/06 01:01:57 | 000,000,000 | —D | C] – C:\Users\7017\x64
[2011/05/06 01:01:56 | 000,000,000 | —D | C] – C:\Users\7017\Lang
[2011/05/06 01:01:55 | 000,000,000 | —D | C] – C:\Users\7017\IIPS
[2011/05/06 00:41:08 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{5357BB7A-3ED7-4A6E-AE78-1F41C8B4CCA1}
[2011/05/06 00:23:20 | 000,000,000 | —D | C] – C:\HDMI_Win7_1.0.0.55
[2011/05/06 00:19:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\REALTEK Wireless LAN Software
[2011/05/06 00:19:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cisco
[2011/05/05 20:59:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
[2011/05/05 20:59:23 | 000,626,688 | —- | C] (On2.com) – C:\windows\SysWow64\vp7vfw.dll
[2011/05/05 20:58:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Games
[2011/05/05 12:40:42 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{17EEA0A0-73AF-41D1-BFAA-81562E8DF59C}
[2011/05/04 18:02:02 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{21AC932A-C1F6-45EB-9688-FDDFF4352620}
[2011/05/04 06:01:49 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{B226A868-FE83-4BAB-B32C-04FC434EDB60}
[2011/05/04 04:32:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2011/05/04 04:32:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\ConduitEngine
[2011/05/04 04:32:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrentBar
[2011/05/04 03:42:39 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\Publish Providers
[2011/05/04 03:35:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2011/05/04 03:34:56 | 000,000,000 | —D | C] – C:\ProgramData\Sony
[2011/05/04 03:34:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2011/05/04 03:06:04 | 000,000,000 | —D | C] – C:\Users\7017\Desktop\Sony Vegas Pro 10.0c [x64]-[Win]-[CyberPiraten]
[2011/05/04 02:23:34 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\Sony
[2011/05/04 02:19:25 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Roaming\Sony
[2011/05/03 18:01:23 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{B6DD644C-F7D3-4D65-BA50-E24165B5806F}
[2011/05/02 15:50:31 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{AB285F6A-B87B-4F2A-8416-245BF2A815D6}
[2011/05/02 03:50:06 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{67828FB3-6EEE-40D2-8012-BD808CE9D38F}
[2011/05/01 15:49:40 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{EF641177-0898-4F62-99D7-DEAD516481EC}
[2011/04/30 18:01:44 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{2A192EFE-2BE5-4E2C-A619-1AA39CB7BDE4}
[2011/04/29 14:57:00 | 000,000,000 | —D | C] – C:\Users\7017\AppData\Local\{D824852D-750B-4370-BB39-C6FA3E5EB687}
========== Files - Modified Within 30 Days ==========
[2011/05/28 17:48:55 | 000,014,144 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/28 17:48:55 | 000,014,144 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/28 17:41:57 | 000,000,408 | —- | M] () – C:\windows\tasks\Ad-Aware Update (Weekly).job
[2011/05/28 17:41:03 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/05/28 17:41:00 | 4148,744,192 | -HS- | M] () – C:\hiberfil.sys
[2011/05/27 23:00:56 | 000,000,052 | —- | M] () – C:\windows\SysNative\ashttpstats.csv
[2011/05/27 22:20:48 | 000,002,056 | —- | M] () – C:\Users\7017\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/27 17:06:24 | 000,000,064 | —- | M] () – C:\windows\SysWow64\rp_stats.dat
[2011/05/27 17:06:24 | 000,000,044 | —- | M] () – C:\windows\SysWow64\rp_rules.dat
[2011/05/27 17:04:27 | 000,000,098 | —- | M] () – C:\windows\SysNative\drivers\etc\Hosts
[2011/05/24 17:36:25 | 000,000,512 | —- | M] () – C:\Users\7017\Desktop\MBR.dat
[2011/05/24 17:34:19 | 000,589,632 | —- | M] (AVAST Software) – C:\Users\7017\Desktop\aswMBR.exe
[2011/05/24 17:21:47 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\7017\Desktop\OTL.exe
[2011/05/22 00:05:33 | 000,001,869 | —- | M] () – C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/21 23:55:08 | 000,739,790 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/05/21 23:55:08 | 000,637,228 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/05/21 23:55:08 | 000,114,638 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/05/21 20:12:51 | 000,834,544 | —- | M] () – C:\windows\SysNative\drivers\sptd.sys
[2011/05/21 01:24:10 | 000,001,943 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/20 12:38:03 | 000,000,872 | —- | M] () – C:\windows\SysNative\drivers\kgpcpy.cfg
[2011/05/16 01:50:26 | 000,000,786 | —- | M] () – C:\Users\7017\Desktop\Flyff.lnk
[2011/05/06 01:01:57 | 000,018,855 | —- | M] () – C:\Users\7017\Setup.if2
[2011/05/06 01:01:57 | 000,002,302 | —- | M] () – C:\Users\7017\Setup2.if2
[2011/05/05 21:01:24 | 000,001,057 | —- | M] () – C:\Users\7017\AppData\Roaming\vso_ts_preview.xml
[2011/05/05 21:00:11 | 000,001,583 | —- | M] () – C:\Users\7017\Desktop\ConvertXtoDvd.exe - Shortcut.lnk
[2011/05/05 20:58:22 | 000,002,230 | —- | M] () – C:\Users\7017\Desktop\Ranch Rush 2 .lnk
[2011/05/04 03:42:04 | 000,002,812 | —- | M] () – C:\Users\7017\Documents\Register Vegas Pro.htm
[2011/05/04 03:05:32 | 214,248,820 | —- | M] () – C:\Users\7017\Desktop\Sony_Vegas_Pro_10.0c_FULL.rar
[2011/05/04 00:43:39 | 000,793,322 | —- | M] () – C:\Users\7017\Documents\waltermyresume.png
[2011/05/04 00:41:15 | 007,900,919 | —- | M] () – C:\Users\7017\Documents\MarcNEW RES.psd
[2011/05/02 20:23:30 | 000,126,824 | -H– | M] () – C:\windows\SysWow64\mlfcache.dat
========== Files Created - No Company Name ==========
[2011/05/28 17:41:57 | 000,000,408 | —- | C] () – C:\windows\tasks\Ad-Aware Update (Weekly).job
[2011/05/27 18:24:01 | 000,001,154 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/24 17:36:25 | 000,000,512 | —- | C] () – C:\Users\7017\Desktop\MBR.dat
[2011/05/22 00:05:33 | 000,001,881 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/22 00:05:33 | 000,001,869 | —- | C] () – C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/21 20:12:50 | 000,834,544 | —- | C] () – C:\windows\SysNative\drivers\sptd.sys
[2011/05/20 20:55:27 | 000,256,512 | —- | C] () – C:\windows\PEV.exe
[2011/05/20 20:55:27 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2011/05/20 20:55:27 | 000,089,088 | —- | C] () – C:\windows\MBR.exe
[2011/05/20 20:55:27 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2011/05/20 20:55:27 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2011/05/20 12:37:18 | 000,000,872 | —- | C] () – C:\windows\SysNative\drivers\kgpcpy.cfg
[2011/05/19 22:38:42 | 000,002,056 | —- | C] () – C:\Users\7017\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 22:38:42 | 000,001,943 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/16 01:50:26 | 000,000,786 | —- | C] () – C:\Users\7017\Desktop\Flyff.lnk
[2011/05/16 01:39:31 | 901,039,426 | —- | C] () – C:\Users\7017\Desktop\FlyffUsaSetup_v15.exe
[2011/05/05 21:00:11 | 000,001,583 | —- | C] () – C:\Users\7017\Desktop\ConvertXtoDvd.exe - Shortcut.lnk
[2011/05/05 20:58:22 | 000,002,230 | —- | C] () – C:\Users\7017\Desktop\Ranch Rush 2 .lnk
[2011/05/04 03:42:04 | 000,002,812 | —- | C] () – C:\Users\7017\Documents\Register Vegas Pro.htm
[2011/05/04 03:05:31 | 214,248,820 | —- | C] () – C:\Users\7017\Desktop\Sony_Vegas_Pro_10.0c_FULL.rar
[2011/05/04 00:43:23 | 000,793,322 | —- | C] () – C:\Users\7017\Documents\waltermyresume.png
[2011/05/04 00:39:36 | 007,900,919 | —- | C] () – C:\Users\7017\Documents\MarcNEW RES.psd
[2011/05/02 20:23:30 | 000,126,824 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/04/26 16:15:53 | 000,000,064 | —- | C] () – C:\windows\SysWow64\rp_stats.dat
[2011/04/26 16:15:53 | 000,000,044 | —- | C] () – C:\windows\SysWow64\rp_rules.dat
[2011/03/27 23:54:18 | 000,010,876 | -HS- | C] () – C:\Users\7017\AppData\Local\g24068o1rgj522p0x643n2m3xc20eqyr1e
[2011/03/27 23:54:18 | 000,010,876 | -HS- | C] () – C:\ProgramData\g24068o1rgj522p0x643n2m3xc20eqyr1e
[2011/03/08 15:21:06 | 000,001,057 | —- | C] () – C:\Users\7017\AppData\Roaming\vso_ts_preview.xml
[2011/03/08 15:20:18 | 000,007,859 | —- | C] () – C:\Users\7017\AppData\Roaming\pcouffin.cat
[2011/03/08 15:20:18 | 000,001,167 | —- | C] () – C:\Users\7017\AppData\Roaming\pcouffin.inf
[2010/12/29 23:37:09 | 000,000,025 | —- | C] () – C:\Users\7017\AppData\Roaming\bdfvconp.ini
[2010/12/26 01:51:46 | 000,000,008 | —- | C] () – C:\Users\7017\AppData\Local\84756-11986-27475-00TC1-94865
[2010/12/26 01:02:37 | 000,748,704 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2010/12/25 19:32:15 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2010/09/02 00:06:24 | 000,307,200 | —- | C] () – C:\windows\SetDisplayResolution.exe
[2010/09/01 23:12:46 | 000,001,960 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 23:11:10 | 000,311,296 | —- | C] () – C:\windows\SysWow64\Rezip.exe
[2010/01/13 22:41:00 | 000,309,248 | —- | C] () – C:\windows\SysWow64\sqlite36_engine.dll
[2010/01/13 22:38:00 | 000,023,552 | —- | C] () – C:\windows\SysWow64\DirectCOM.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | —- | C] () – C:\windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | —- | C] () – C:\windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | —- | C] () – C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | —- | C] () – C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2006/10/08 20:33:54 | 000,000,000 | —- | C] () – C:\windows\R-series.ini
========== LOP Check ==========
[2010/12/26 01:04:18 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\BitDefender
[2011/03/10 12:47:50 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\freshgames
[2011/03/25 00:18:53 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\funkitron
[2010/12/25 15:18:25 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\GetRightToGo
[2011/05/22 00:46:44 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\ImgBurn
[2011/02/17 19:07:04 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\NetMeter
[2011/03/08 00:11:05 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Oberon Media
[2011/04/05 02:31:42 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\OpenOffice.org
[2010/12/25 14:32:04 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Outertech
[2011/05/04 03:42:39 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Publish Providers
[2011/02/16 01:28:24 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Ringtone Maker
[2011/03/25 00:15:40 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\SoftGrid Client
[2011/05/04 03:42:33 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Sony
[2011/01/12 13:49:54 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\TP
[2011/05/26 16:39:56 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\uTorrent
[2011/05/05 21:01:24 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Vso
[2011/03/11 13:33:15 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Windows Live Writer
[2011/02/16 01:34:45 | 000,000,000 | —D | M] – C:\Users\7017\AppData\Roaming\Xilisoft
[2011/05/28 17:41:57 | 000,000,408 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/05/03 17:58:32 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:8CE646EE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8530A643
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:5320A31B
< End of report >
Please Note: For some reason when I hit the scan, LOP Check and Purity Check automatically checked
Run OTL
- Double click on the icon to run it.
- Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL FF - prefs.js..extensions.enabledItems: [removed]:1.0 [2011/04/04 16:00:29 | 000,000,000 | —D | M] (No name found) – C:\Users\7017\AppData\Roaming\Mozilla\Extensions O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O8:64bit: - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm () O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm () O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found @Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:8CE646EE @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8530A643 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:5320A31B :Reg :Files :Commands [purity] [emptytemp] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Can you also tell me how things are running now and any current problems
Satchfan
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI