This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vista Recovery and slow running

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 01/06/2011 00:08:17 - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Stefan\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.60 Gb Available Physical Memory | 53.27% Memory free
6.22 Gb Paging File | 4.82 Gb Available in Paging File | 77.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 292.72 Gb Total Space | 10.47 Gb Free Space | 3.58% Space Free | Partition Type: NTFS
Drive D: | 982.13 Mb Total Space | 930.23 Mb Free Space | 94.72% Space Free | Partition Type: FAT
Drive I: | 702.31 Mb Total Space | 380.98 Mb Free Space | 54.25% Space Free | Partition Type: UDF

Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stefan\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - c:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)


========== Modules (SafeList) ==========

MOD - C:\Users\Stefan\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\guard32.dll ()
MOD - C:\Windows\System32\winsta.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CLTNetCnService) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (FETND6V) – C:\Windows\System32\drivers\fetnd6v.sys (VIA Technologies, Inc. )
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdguard.sys (COMODO)
DRV - (Inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (StarOpen) – C:\Windows\System32\drivers\StarOpen.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/28 11:54:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/05/11 13:53:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 10:56:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 10:56:47 | 000,000,000 | —D | M]

[2010/12/12 20:23:07 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Stefan\AppData\Roaming\Mozilla\Extensions
[2011/05/08 10:30:09 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\v7tgfu29.default\extensions
[2010/12/14 16:33:32 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\v7tgfu29.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/14 09:42:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/20 12:38:02 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/14 09:42:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2011/05/11 13:53:00 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/05/08 10:56:41 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/08 10:56:43 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/05/08 10:56:43 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/05/08 10:56:43 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/05/08 10:56:43 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/05/08 10:56:43 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (MSVPS System) - {ACD85107-9CF9-4C9E-B0B7-39940A0017C0} - File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BrowserChoice] C:\Windows\System32\browserchoice.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EPSON Stylus DX5000 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE (SEIKO EPSON CORPORATION)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O13 - gopher Prefix: missing
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} http://site.ebrary.com/lib/uclan/support/p…s/ebraryRdr.cab (Infotl Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/09/10 16:07:52 | 000,050,176 | —- | M] () - I:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2001/06/20 16:41:36 | 000,000,027 | —- | M] () - I:\autorun.inf – [ UDF ]
O33 - MountPoints2\{0b0b63bd-69dc-11dd-a385-001bb9500681}\Shell - "" = AutoRun
O33 - MountPoints2\{0b0b63bd-69dc-11dd-a385-001bb9500681}\Shell\AutoRun\command - "" = J:\Ladbrokes.exe
O33 - MountPoints2\{3ac40718-5e24-11dc-8894-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{3ac40718-5e24-11dc-8894-806e6f6e6963}\Shell\AutoRun\command - "" = I:\autorun.exe – [2001/09/10 16:07:52 | 000,050,176 | —- | M] ()
O33 - MountPoints2\{d961c781-5f19-11dc-8f37-001bb9500681}\Shell - "" = AutoRun
O33 - MountPoints2\{d961c781-5f19-11dc-8f37-001bb9500681}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\Ladbrokes.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.clmp3enc - C:\Program Files\CyberLink\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/31 23:12:19 | 000,000,000 | -H-D | C] – C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Vista Recovery
[2011/05/31 23:12:09 | 000,368,128 | -H– | C] (Microsoft Corporation) – C:\ProgramData\34594552.exe
[2011/05/31 23:05:31 | 000,470,016 | -H– | C] (Microsoft Corporation) – C:\ProgramData\uaaiHfWFhq.exe
[2011/05/30 01:55:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/05/23 22:33:51 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/23 22:21:00 | 000,000,000 | —D | C] – C:\Windows\en
[2011/05/23 22:18:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/05/23 22:14:40 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/05/23 22:14:19 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2011/05/23 22:14:19 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2011/05/23 22:13:59 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2011/05/23 22:10:21 | 000,000,000 | -H-D | C] – C:\Users\Stefan\AppData\Local\Windows Live
[2011/05/23 22:10:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/05/23 22:09:39 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2011/05/23 22:07:18 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/23 22:07:17 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/23 22:07:17 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/23 22:07:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/23 22:07:16 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/23 22:07:16 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/23 22:07:16 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/23 22:07:16 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/23 22:07:15 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/23 22:07:15 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/23 22:07:15 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/23 22:07:15 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/23 22:07:15 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/23 22:07:15 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/23 22:07:14 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/23 22:07:14 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/23 22:07:14 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/23 22:07:14 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/23 22:07:14 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/23 22:07:14 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/23 22:07:13 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/23 22:07:13 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/23 22:07:13 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/23 22:07:13 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/23 22:07:13 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/23 22:07:12 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/23 22:07:12 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/23 22:07:12 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/23 22:07:12 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/23 22:07:12 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/23 22:07:12 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/23 22:07:11 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/23 22:07:11 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/23 22:07:11 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/23 22:07:11 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/23 22:07:11 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/23 22:07:11 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/23 22:07:11 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/23 22:07:10 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/23 22:03:00 | 000,000,000 | -H-D | C] – C:\ProgramData\NVIDIA Corporation
[2011/05/16 18:58:24 | 000,000,000 | -H-D | C] – C:\Users\Stefan\AppData\Local\Unity
[2011/05/16 01:42:57 | 000,000,000 | -H-D | C] – C:\Users\Stefan\Documents\Daria
[2011/05/06 09:10:07 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/05/06 09:10:05 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/05/06 09:09:57 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/01 00:15:00 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6161EF72-2ED3-43BE-BB28-F84783DADBBF}.job
[2011/05/31 23:38:24 | 000,002,627 | —- | M] () – C:\Users\Stefan\Desktop\Microsoft Office Word 2007 (2).lnk
[2011/05/31 23:36:42 | 000,001,614 | —- | M] () – C:\Users\Stefan\Desktop\Calculator (2).lnk
[2011/05/31 23:36:33 | 000,000,941 | —- | M] () – C:\Users\Stefan\Desktop\Championship Manager 01-02.lnk
[2011/05/31 23:36:28 | 000,000,791 | —- | M] () – C:\Users\Stefan\Desktop\Launch Medieval II Total War.lnk
[2011/05/31 23:34:41 | 116,765,761 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/05/31 23:33:30 | 000,647,164 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/31 23:33:30 | 000,124,162 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/31 23:28:17 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/31 23:28:17 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/31 23:28:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/31 23:16:38 | 000,000,152 | -H– | M] () – C:\ProgramData\~34594552r
[2011/05/31 23:16:38 | 000,000,136 | -H– | M] () – C:\ProgramData\~34594552
[2011/05/31 23:16:09 | 000,000,600 | -H– | M] () – C:\Users\Stefan\Desktop\Windows Vista Recovery.lnk
[2011/05/31 23:12:13 | 000,000,336 | -H– | M] () – C:\ProgramData\34594552
[2011/05/31 23:12:09 | 000,368,128 | -H– | M] (Microsoft Corporation) – C:\ProgramData\34594552.exe
[2011/05/31 23:03:29 | 000,470,016 | -H– | M] (Microsoft Corporation) – C:\ProgramData\uaaiHfWFhq.exe
[2011/05/31 22:25:33 | 000,037,013 | -H– | M] () – C:\ProgramData\nvModes.dat
[2011/05/31 22:25:33 | 000,037,013 | -H– | M] () – C:\ProgramData\nvModes.001
[2011/05/31 22:25:29 | 000,000,444 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2011/05/31 00:33:02 | 000,000,418 | —- | M] () – C:\Windows\tasks\ParetoLogic Update Version2.job
[2011/05/29 16:02:02 | 000,235,520 | -H– | M] () – C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/23 22:33:51 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/23 22:29:57 | 000,270,632 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/05/23 22:07:30 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/05/23 22:07:30 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/05/23 22:07:18 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/23 22:07:17 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/23 22:07:17 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/23 22:07:16 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/23 22:07:16 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/23 22:07:16 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/23 22:07:16 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/23 22:07:16 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/23 22:07:15 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/23 22:07:15 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/23 22:07:15 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/23 22:07:15 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/23 22:07:15 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/23 22:07:15 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/23 22:07:14 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/23 22:07:14 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/23 22:07:14 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/23 22:07:14 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/23 22:07:14 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/23 22:07:14 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/23 22:07:14 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/23 22:07:13 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/23 22:07:13 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/23 22:07:13 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/23 22:07:13 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/23 22:07:13 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/23 22:07:12 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/23 22:07:12 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/23 22:07:12 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/23 22:07:12 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/23 22:07:12 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/23 22:07:12 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/23 22:07:11 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/23 22:07:11 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/23 22:07:11 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/23 22:07:11 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/23 22:07:11 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/23 22:07:11 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/23 22:07:11 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/23 22:07:10 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/16 01:34:34 | 000,011,184 | -HS- | M] () – C:\Users\Stefan\AppData\Local\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/16 01:34:34 | 000,011,184 | -HS- | M] () – C:\ProgramData\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/12 00:22:02 | 000,000,680 | -H– | M] () – C:\Users\Stefan\AppData\Local\d3d9caps.dat
[2011/05/10 15:42:01 | 000,354,377 | —- | M] () – C:\Windows\System32\drivers\AVG\iavichjg.avm
[2011/05/06 14:11:05 | 000,002,627 | -H– | M] () – C:\Users\Stefan\Desktop\Microsoft Office Word 2007.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/31 23:36:48 | 000,002,627 | —- | C] () – C:\Users\Stefan\Desktop\Microsoft Office Word 2007 (2).lnk
[2011/05/31 23:36:42 | 000,001,614 | —- | C] () – C:\Users\Stefan\Desktop\Calculator (2).lnk
[2011/05/31 23:36:33 | 000,000,941 | —- | C] () – C:\Users\Stefan\Desktop\Championship Manager 01-02.lnk
[2011/05/31 23:36:28 | 000,000,791 | —- | C] () – C:\Users\Stefan\Desktop\Launch Medieval II Total War.lnk
[2011/05/31 23:16:38 | 000,000,152 | -H– | C] () – C:\ProgramData\~34594552r
[2011/05/31 23:16:38 | 000,000,136 | -H– | C] () – C:\ProgramData\~34594552
[2011/05/31 23:16:09 | 000,000,600 | -H– | C] () – C:\Users\Stefan\Desktop\Windows Vista Recovery.lnk
[2011/05/31 23:12:13 | 000,000,336 | -H– | C] () – C:\ProgramData\34594552
[2011/05/23 22:20:05 | 000,001,163 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/05/23 22:19:01 | 000,001,232 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/05/23 22:17:34 | 000,001,042 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/05/23 22:16:54 | 000,002,030 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/05/23 22:07:14 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/16 01:10:24 | 000,011,184 | -HS- | C] () – C:\Users\Stefan\AppData\Local\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/16 01:10:24 | 000,011,184 | -HS- | C] () – C:\ProgramData\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/08 10:56:49 | 000,000,863 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2010/08/21 16:25:24 | 000,037,013 | -H– | C] () – C:\ProgramData\nvModes.001
[2010/08/21 16:25:13 | 000,037,013 | -H– | C] () – C:\ProgramData\nvModes.dat
[2009/10/21 21:35:14 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/10/21 21:35:13 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/05/20 17:26:32 | 000,000,680 | -H– | C] () – C:\Users\Stefan\AppData\Local\d3d9caps.dat
[2009/01/24 13:51:25 | 000,147,192 | —- | C] () – C:\Windows\System32\guard32.dll
[2008/09/03 17:40:40 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2008/08/07 22:11:55 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/25 19:56:42 | 000,000,000 | -H– | C] () – C:\ProgramData\LauncherAccess.dt
[2008/07/25 19:54:06 | 000,005,632 | —- | C] () – C:\Windows\System32\drivers\StarOpen.sys
[2008/07/14 09:08:13 | 000,107,520 | —- | C] () – C:\Windows\System32\UnCasino5.exe
[2008/04/19 16:08:36 | 000,000,059 | —- | C] () – C:\Windows\wininit.ini
[2008/03/28 09:52:35 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2008/03/28 09:52:32 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/03/28 09:52:31 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/03/28 09:52:31 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2007/09/28 21:41:02 | 000,235,520 | -H– | C] () – C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,270,632 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,647,164 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,124,162 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/10/27 08:26:56 | 000,069,632 | —- | C] () – C:\Windows\System32\vuins32.dll

========== LOP Check ==========

[2010/11/17 12:17:11 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\AVG10
[2009/09/15 17:45:01 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2008/07/14 10:36:24 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\CasinoOnNet
[2010/03/12 11:44:41 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/01/25 12:03:18 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\DAEMON Tools
[2009/01/25 12:10:02 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite
[2009/01/25 12:03:18 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\DAEMON Tools Pro
[2009/04/11 02:59:43 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\DriverCure
[2009/05/12 17:24:11 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\Samsung
[2010/09/29 21:27:28 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\Serif
[2009/07/29 23:33:16 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\The Creative Assembly
[2011/05/18 20:54:58 | 000,000,000 | -H-D | M] – C:\Users\Stefan\AppData\Roaming\uTorrent
[2011/05/31 22:25:29 | 000,000,444 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2011/05/31 00:33:02 | 000,000,418 | —- | M] () – C:\Windows\Tasks\ParetoLogic Update Version2.job
[2011/05/31 23:26:49 | 000,032,578 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/01 00:15:00 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{6161EF72-2ED3-43BE-BB28-F84783DADBBF}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/13 10:26:37 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/07/14 09:28:38 | 000,000,132 | —- | M] () – C:\ICSYSINF.log
[2008/07/01 20:06:10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/07/01 20:06:10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/05/31 23:28:02 | 3533,258,752 | -HS- | M] () – C:\pagefile.sys
[2007/12/23 21:50:26 | 000,000,156 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/22 08:43:37 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/05/29 10:45:44 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-31 21:39:05

========== Alternate Data Streams ==========

@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
OTL Extras logfile created on: 01/06/2011 00:08:17 - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Stefan\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.60 Gb Available Physical Memory | 53.27% Memory free
6.22 Gb Paging File | 4.82 Gb Available in Paging File | 77.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 292.72 Gb Total Space | 10.47 Gb Free Space | 3.58% Space Free | Partition Type: NTFS
Drive D: | 982.13 Mb Total Space | 930.23 Mb Free Space | 94.72% Space Free | Partition Type: FAT
Drive I: | 702.31 Mb Total Space | 380.98 Mb Free Space | 54.25% Space Free | Partition Type: UDF

Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile – "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{54AA830F-9A1A-48A6-8B21-BEC3E038A4DB}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{663FB377-AD15-48BA-B3E9-2C25D04BF8C5}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{66CEC6BE-1C82-435A-AC93-A91537574D76}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EAA0B169-8C88-4FDD-A3B9-5B3323427993}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{187E1485-32CC-40B0-8D27-80F898B99A20}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{1DBF2F8B-30EE-47ED-9B88-94987DA2D406}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{2AB5053F-BE0A-4DBC-9941-07C50596EB44}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{386765D1-11C0-4723-9726-7AEDFE43ECD3}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{455E17D6-4972-4D3D-8BE7-B8F791152EB9}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{5E7FBCF1-7EE0-4B08-B436-C9738106263C}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{6CC95B2B-6EEA-4749-9DE6-F17D398E97E6}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{778B0EE6-CF84-47DE-9B1F-68D9D6250330}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{90CBACAA-81E0-47F4-B23A-A03D7B25E4DC}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{A22B49C2-0AD9-4BBC-8584-1ADF1B832552}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{AB6F63C7-0A85-4D69-9696-4F845471B369}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{CB96446F-7752-4A0D-A8A5-22BE04DC5DF0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E57780AC-8A7B-4DBB-B668-4E5224A09944}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{EF642FF3-5EE0-45C9-8C4E-CECC7C346E4D}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"TCP Query User{296FD952-4513-45A9-A399-DFA63C29686D}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{655B2BC1-8A82-48BD-B620-615F866D5566}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{F097D9E8-1E24-436B-997A-01AED91B2A50}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{01F7F30B-B091-47C5-8BC0-F71D56A3F482}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{4349E120-3D95-4B28-9642-9864203188E6}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{8394B838-53B6-4138-B061-26CABDF9904C}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0323CB96-221A-4042-84A3-93EDE47099FC}" = AVG 2011
"{04E7A3BB-DB38-481C-A809-35FA60C78EDF}" = AVG 2011
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{09234F0D-5971-4701-94EE-89CB6926E273}" = Serif PhotoPlus SE
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{230E8DDC-FB78-4F9F-8461-22ED20DBC3BA}" = AVG 2011
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A276502A-8979-44FB-8090-90CF72F22ABC}" = AVG 2011
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A64FF1D4-9CBC-467C-8D11-C1AFAA0B8AFF}" = AVG 2011
"{A7894110-9C15-43EF-89E9-060363290188}" = Samsung PC Studio
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3AEF776-7FFF-4C50-A402-9119E3849EE0}" = AVG 2011
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BABA6734-23CF-42AC-9E4C-EA2C7C80AA4E}" = AVG 2011
"{BEA18030-8B42-1286-EF64-CDA6BD083888}" = BBC iPlayer Desktop
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG" = AVG 2011
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Championship Manager 01-02" = Championship Manager 01-02
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"COMODO Internet Security" = COMODO Internet Security
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IsoBuster_is1" = IsoBuster 1.7
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.8.5 Full
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 4.0.1 (x86 en-GB)" = Mozilla Firefox 4.0.1 (x86 en-GB)
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"VLC media player" = VLC media player 1.1.9
"VN_VUIns_Rhine_VIA" = VIA Rhine Family Fast Ethernet Adapter
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Applications" = BT Yahoo! Applications

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:27:45, on 01/06/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Stefan\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.thetechguys.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSVPS System - {ACD85107-9CF9-4C9E-B0B7-39940A0017C0} - C:\Windows\nsduo.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [EPSON Stylus DX5000 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\Windows\TEMP\E_SEDB7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [BrowserChoice] "C:\Windows\System32\browserchoice.exe" /run
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
O9 - Extra button: InterCasino £££ - {03588886-5C50-4645-BD5D-F105F84417DE} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: InterCasino £££ - {03588886-5C50-4645-BD5D-F105F84417DE} - (no file) (HKCU)
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - (no file) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/uclan/support/p…s/ebraryRdr.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

–
End of file - 6757 bytes
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 0:32:20 on 2011-06-01
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1574 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
"C:\Windows\system32\svchost.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\system32\svchost.exe"
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Stefan\Downloads\dds.scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bbc.co.uk/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: MSVPS System: {acd85107-9cf9-4c9e-b0b7-39940a0017c0} - c:\windows\nsduo.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [EPSON Stylus DX5000 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibve.exe /fu "c:\windows\temp\E_SEDB7.tmp" /EF "HKCU"
uRun: [BrowserChoice] "c:\windows\system32\browserchoice.exe" /run
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com/lib/uclan/support/plugins/ebraryRdr.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/WebfettiInitialSetup1.0.1.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-gb.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\windows\system32\guard32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\stefan\appdata\roaming\mozilla\firefox\profiles\v7tgfu29.default\
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\stefan\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-1-24 99344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-1-24 25104]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-5-27 21504]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 28624]
R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;c:\windows\system32\drivers\fetnd6v.sys [2009-5-15 43520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-05-31 22:12:09 368128 —ha-w- c:\programdata\34594552.exe
2011-05-31 22:05:31 470016 —ha-w- c:\programdata\uaaiHfWFhq.exe
2011-05-31 21:38:54 6962000 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{653ba584-489b-47f7-acec-653abc0adfb5}\mpengine.dll
2011-05-23 21:33:51 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-23 21:21:00 ——– d—–w- c:\windows\en
2011-05-23 21:18:35 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-23 21:14:19 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2011-05-23 21:14:19 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2011-05-23 21:13:59 453456 —-a-w- c:\windows\system32\d3dx10_42.dll
2011-05-23 21:13:20 94040 —-a-w- c:\program files\common files\windows live\.cache\3d5d0cbb1cc198e14\DSETUP.dll
2011-05-23 21:13:20 525656 —-a-w- c:\program files\common files\windows live\.cache\3d5d0cbb1cc198e14\DXSETUP.exe
2011-05-23 21:13:20 1691480 —-a-w- c:\program files\common files\windows live\.cache\3d5d0cbb1cc198e14\dsetup32.dll
2011-05-23 21:13:13 94040 —-a-w- c:\program files\common files\windows live\.cache\38f7b6cb1cc198e13\DSETUP.dll
2011-05-23 21:13:13 525656 —-a-w- c:\program files\common files\windows live\.cache\38f7b6cb1cc198e13\DXSETUP.exe
2011-05-23 21:13:13 1691480 —-a-w- c:\program files\common files\windows live\.cache\38f7b6cb1cc198e13\dsetup32.dll
2011-05-23 21:10:21 ——– d–h–w- c:\users\stefan\appdata\local\Windows Live
2011-05-23 21:10:19 ——– d—–w- c:\program files\common files\Windows Live
2011-05-23 21:09:39 754688 —-a-w- c:\windows\system32\webservices.dll
2011-05-23 21:03:00 ——– d–h–w- c:\programdata\NVIDIA Corporation
2011-05-16 17:58:24 ——– d–h–w- c:\users\stefan\appdata\local\Unity
2011-05-10 20:37:22 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-05-08 09:56:42 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-05-08 09:56:42 781272 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-05-08 09:56:42 465880 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-05-08 09:56:42 1874904 —-a-w- c:\program files\mozilla firefox\mozjs.dll
2011-05-08 09:56:42 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-05-08 09:56:41 1974616 —-a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-05-08 09:56:41 1892184 —-a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-05-08 09:56:41 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-05-06 08:10:07 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-05-06 08:10:05 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-05-06 08:09:57 876032 —-a-w- c:\windows\system32\XpsPrint.dll
.
==================== Find3M ====================
.
2011-04-14 20:28:18 134480 —-a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-04-04 23:59:56 297168 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2011-03-16 15:03:20 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42:03 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-03 15:40:07 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40:05 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40:05 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40:04 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 13:25:11 2041856 —-a-w- c:\windows\system32\win32k.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x854241F8]<<
_asm { MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX; PUSH 0x85424008; MOV EAX, 0x8a6594a0; CALL EAX; }
1 nt!IofCallDriver[0x8249711B] -> \Device\Harddisk0\DR0[0x85D1B968]
3 CLASSPNP[0x8ADC18B3] -> nt!IofCallDriver[0x8249711B] -> [0x8549C178]
5 acpi[0x8A77D6BC] -> nt!IofCallDriver[0x8249711B] -> \Device\Ide\IdeDeviceP0T0L0-0[0x85488B98]
\Driver\atapi[0x8549CD18] -> IRP_MJ_CREATE -> 0x854241F8
kernel: MBR read successfully
_asm { NOP ; XOR AX, AX; NOP ; MOV DS, AX; MOV ES, AX; NOP ; MOV SS, AX; MOV SP, 0x7c00; MOV SI, 0x7c00; NOP ; MOV DI, 0x600; NOP ; MOV CX, 0x80; NOP ; CLD ; REP MOVSD ; NOP ; JMP FAR 0x0:0x626; }
detected disk devices:
detected hooks:
\Driver\atapi -> 0x854241f8
user != kernel MBR !!!
Warning: possible MBR rootkit infection !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 0:35:31.77 ===============
. ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 µTorrent AutoUpdate AVG 2011 BBC iPlayer Desktop BT Yahoo! Applications Championship Manager 01-02 COMODO Internet Security D3DX10 DivX Codec DivX Converter DivX Player DivX Version Checker DivX Web Player EPSON Printer Software EPSON Scan Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) IsoBuster 1.7 Java Auto Updater Java™ 6 Update 24 Java™ 6 Update 7 Junk Mail filter update K-Lite Codec Pack 3.8.5 Full Macromedia Dreamweaver 8 Macromedia Extension Manager Medieval II Total War Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual J# .NET Redistributable Package 1.1 Mozilla Firefox 4.0.1 (x86 en-GB) MSVCRT MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Norton 360 NVIDIA Display Control Panel NVIDIA Drivers OGA Notifier 2.0.0048.0 Power2Go 5.0 PVSonyDll QuickTime RealPlayer Realtek High Definition Audio Driver Samsung PC Studio Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2466156) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft Office Excel 2007 (KB2464583) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Segoe UI Serif PhotoPlus SE Shockwave Unity Web Player Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VC80CRTRedist - 8.0.50727.762 VIA Rhine Family Fast Ethernet Adapter VLC media player 1.1.9 Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WinZip 12.1 . ==== Event Viewer Messages From Past Week ======== . 31/05/2011 09:11:43, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service. . ==== End Of File ===========================
Hi Guys Got a bogus recovery app popping up, Vista Recovery! Have slow running, lost icons and documents. Please help, thanks S
Followed instructions for another identical post and recovered my icons but not docs, downloads and music folders. They still appear in virus scans. ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yrsgtjkbutlqmc not found. File C:\Documents and Settings\All Users\Application Data\~19914532r not found. File C:\Documents and Settings\All Users\Application Data\~19914532 not found. File C:\Documents and Settings\All Users\Application Data\19914532 not found. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.23.0 log created on 06012011_004928
OTL logfile created on: 01/06/2011 00:54:42 - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Stefan\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.56 Gb Available Physical Memory | 52.05% Memory free
6.22 Gb Paging File | 4.85 Gb Available in Paging File | 77.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 292.72 Gb Total Space | 11.06 Gb Free Space | 3.78% Space Free | Partition Type: NTFS
Drive D: | 982.13 Mb Total Space | 930.23 Mb Free Space | 94.72% Space Free | Partition Type: FAT
Drive I: | 702.31 Mb Total Space | 380.98 Mb Free Space | 54.25% Space Free | Partition Type: UDF

Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stefan\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)


========== Modules (SafeList) ==========

MOD - C:\Users\Stefan\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\guard32.dll ()
MOD - C:\Windows\System32\winsta.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CLTNetCnService) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (FETND6V) – C:\Windows\System32\drivers\fetnd6v.sys (VIA Technologies, Inc. )
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdguard.sys (COMODO)
DRV - (Inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (StarOpen) – C:\Windows\System32\drivers\StarOpen.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/28 11:54:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/05/11 13:53:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 10:56:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 10:56:47 | 000,000,000 | —D | M]

[2010/12/12 20:23:07 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Stefan\AppData\Roaming\Mozilla\Extensions
[2011/05/08 10:30:09 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\v7tgfu29.default\extensions
[2010/12/14 16:33:32 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\v7tgfu29.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/14 09:42:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/20 12:38:02 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/14 09:42:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2011/05/11 13:53:00 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/05/08 10:56:41 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/08 10:56:43 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/05/08 10:56:43 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/05/08 10:56:43 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/05/08 10:56:43 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/05/08 10:56:43 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (MSVPS System) - {ACD85107-9CF9-4C9E-B0B7-39940A0017C0} - File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BrowserChoice] C:\Windows\System32\browserchoice.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EPSON Stylus DX5000 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE (SEIKO EPSON CORPORATION)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O13 - gopher Prefix: missing
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} http://site.ebrary.com/lib/uclan/support/p…s/ebraryRdr.cab (Infotl Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/09/10 16:07:52 | 000,050,176 | —- | M] () - I:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2001/06/20 16:41:36 | 000,000,027 | —- | M] () - I:\autorun.inf – [ UDF ]
O33 - MountPoints2\{0b0b63bd-69dc-11dd-a385-001bb9500681}\Shell - "" = AutoRun
O33 - MountPoints2\{0b0b63bd-69dc-11dd-a385-001bb9500681}\Shell\AutoRun\command - "" = J:\Ladbrokes.exe
O33 - MountPoints2\{3ac40718-5e24-11dc-8894-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{3ac40718-5e24-11dc-8894-806e6f6e6963}\Shell\AutoRun\command - "" = I:\autorun.exe – [2001/09/10 16:07:52 | 000,050,176 | —- | M] ()
O33 - MountPoints2\{d961c781-5f19-11dc-8f37-001bb9500681}\Shell - "" = AutoRun
O33 - MountPoints2\{d961c781-5f19-11dc-8f37-001bb9500681}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\Ladbrokes.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/01 00:49:28 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/31 23:12:19 | 000,000,000 | -H-D | C] – C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Vista Recovery
[2011/05/31 23:12:09 | 000,368,128 | -H– | C] (Microsoft Corporation) – C:\ProgramData\34594552.exe
[2011/05/31 23:05:31 | 000,470,016 | -H– | C] (Microsoft Corporation) – C:\ProgramData\uaaiHfWFhq.exe
[2011/05/30 01:55:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/05/23 22:33:51 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/23 22:21:00 | 000,000,000 | —D | C] – C:\Windows\en
[2011/05/23 22:18:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/05/23 22:14:40 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/05/23 22:14:19 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2011/05/23 22:14:19 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2011/05/23 22:13:59 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2011/05/23 22:10:21 | 000,000,000 | -H-D | C] – C:\Users\Stefan\AppData\Local\Windows Live
[2011/05/23 22:10:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/05/23 22:09:39 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2011/05/23 22:07:18 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/23 22:07:17 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/23 22:07:17 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/23 22:07:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/23 22:07:16 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/23 22:07:16 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/23 22:07:16 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/23 22:07:16 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/23 22:07:15 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/23 22:07:15 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/23 22:07:15 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/23 22:07:15 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/23 22:07:15 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/23 22:07:15 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/23 22:07:14 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/23 22:07:14 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/23 22:07:14 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/23 22:07:14 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/23 22:07:14 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/23 22:07:14 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/23 22:07:13 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/23 22:07:13 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/23 22:07:13 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/23 22:07:13 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/23 22:07:13 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/23 22:07:12 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/23 22:07:12 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/23 22:07:12 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/23 22:07:12 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/23 22:07:12 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/23 22:07:12 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/23 22:07:11 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/23 22:07:11 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/23 22:07:11 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/23 22:07:11 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/23 22:07:11 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/23 22:07:11 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/23 22:07:11 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/23 22:07:10 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/23 22:03:00 | 000,000,000 | -H-D | C] – C:\ProgramData\NVIDIA Corporation
[2011/05/16 18:58:24 | 000,000,000 | -H-D | C] – C:\Users\Stefan\AppData\Local\Unity
[2011/05/16 01:42:57 | 000,000,000 | -H-D | C] – C:\Users\Stefan\Documents\Daria
[2011/05/06 09:10:07 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/05/06 09:10:05 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/05/06 09:09:57 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/01 00:55:00 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6161EF72-2ED3-43BE-BB28-F84783DADBBF}.job
[2011/06/01 00:33:01 | 000,000,418 | —- | M] () – C:\Windows\tasks\ParetoLogic Update Version2.job
[2011/05/31 23:34:41 | 116,765,761 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/05/31 23:33:30 | 000,647,164 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/31 23:33:30 | 000,124,162 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/31 23:28:17 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/31 23:28:17 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/31 23:28:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/31 23:16:38 | 000,000,152 | -H– | M] () – C:\ProgramData\~34594552r
[2011/05/31 23:16:38 | 000,000,136 | -H– | M] () – C:\ProgramData\~34594552
[2011/05/31 23:12:13 | 000,000,336 | -H– | M] () – C:\ProgramData\34594552
[2011/05/31 23:12:09 | 000,368,128 | -H– | M] (Microsoft Corporation) – C:\ProgramData\34594552.exe
[2011/05/31 23:03:29 | 000,470,016 | -H– | M] (Microsoft Corporation) – C:\ProgramData\uaaiHfWFhq.exe
[2011/05/31 22:25:33 | 000,037,013 | -H– | M] () – C:\ProgramData\nvModes.dat
[2011/05/31 22:25:33 | 000,037,013 | -H– | M] () – C:\ProgramData\nvModes.001
[2011/05/31 22:25:29 | 000,000,444 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2011/05/30 01:55:40 | 000,000,864 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/05/29 16:02:02 | 000,235,520 | -H– | M] () – C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/23 22:33:51 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/23 22:31:15 | 000,000,948 | —- | M] () – C:\Users\Stefan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/23 22:29:57 | 000,270,632 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/05/23 22:07:30 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/05/23 22:07:30 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/05/23 22:07:18 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/23 22:07:17 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/23 22:07:17 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/23 22:07:16 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/23 22:07:16 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/23 22:07:16 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/23 22:07:16 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/23 22:07:16 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/23 22:07:15 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/23 22:07:15 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/23 22:07:15 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/23 22:07:15 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/23 22:07:15 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/23 22:07:15 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/23 22:07:14 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/23 22:07:14 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/23 22:07:14 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/23 22:07:14 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/23 22:07:14 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/23 22:07:14 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/23 22:07:14 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/23 22:07:13 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/23 22:07:13 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/23 22:07:13 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/23 22:07:13 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/23 22:07:13 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/23 22:07:12 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/23 22:07:12 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/23 22:07:12 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/23 22:07:12 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/23 22:07:12 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/23 22:07:12 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/23 22:07:11 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/23 22:07:11 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/23 22:07:11 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/23 22:07:11 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/23 22:07:11 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/23 22:07:11 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/23 22:07:11 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/23 22:07:10 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/16 01:34:34 | 000,011,184 | -HS- | M] () – C:\Users\Stefan\AppData\Local\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/16 01:34:34 | 000,011,184 | -HS- | M] () – C:\ProgramData\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/12 00:22:02 | 000,000,680 | -H– | M] () – C:\Users\Stefan\AppData\Local\d3d9caps.dat
[2011/05/11 13:53:01 | 000,000,835 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/05/10 15:42:01 | 000,354,377 | —- | M] () – C:\Windows\System32\drivers\AVG\iavichjg.avm
[2011/05/06 14:11:05 | 000,002,627 | —- | M] () – C:\Users\Stefan\Desktop\Microsoft Office Word 2007.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/01 00:48:30 | 000,002,033 | —- | C] () – C:\Users\Public\Desktop\Serif PhotoPlus SE.lnk
[2011/06/01 00:48:30 | 000,001,952 | —- | C] () – C:\Users\Public\Desktop\Macromedia Dreamweaver 8.lnk
[2011/06/01 00:48:30 | 000,001,897 | —- | C] () – C:\Users\Public\Desktop\Medieval II Total War.lnk
[2011/06/01 00:48:30 | 000,001,731 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/01 00:48:30 | 000,001,729 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/01 00:48:30 | 000,000,864 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/06/01 00:48:29 | 000,001,892 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/06/01 00:48:29 | 000,001,753 | —- | C] () – C:\Users\Stefan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/01 00:48:29 | 000,000,953 | —- | C] () – C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2011/06/01 00:48:29 | 000,000,948 | —- | C] () – C:\Users\Stefan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/01 00:48:29 | 000,000,943 | —- | C] () – C:\Users\Stefan\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/06/01 00:48:29 | 000,000,930 | —- | C] () – C:\Users\Stefan\Application Data\Microsoft\Internet Explorer\Quick Launch\IsoBuster.lnk
[2011/06/01 00:48:29 | 000,000,923 | —- | C] () – C:\Users\Public\Desktop\Championship Manager 01-02.lnk
[2011/06/01 00:48:29 | 000,000,877 | —- | C] () – C:\Users\Public\Desktop\Acrobat_com.lnk
[2011/06/01 00:48:29 | 000,000,867 | —- | C] () – C:\Users\Public\Desktop\BBC iPlayer Desktop.lnk
[2011/06/01 00:48:29 | 000,000,835 | —- | C] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/01 00:48:29 | 000,000,770 | —- | C] () – C:\Users\Public\Desktop\EPSON Scan.lnk
[2011/06/01 00:48:29 | 000,000,240 | —- | C] () – C:\Users\Stefan\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/31 23:16:38 | 000,000,152 | -H– | C] () – C:\ProgramData\~34594552r
[2011/05/31 23:16:38 | 000,000,136 | -H– | C] () – C:\ProgramData\~34594552
[2011/05/31 23:12:13 | 000,000,336 | -H– | C] () – C:\ProgramData\34594552
[2011/05/23 22:20:05 | 000,001,163 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/05/23 22:19:01 | 000,001,232 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/05/23 22:17:34 | 000,001,042 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/05/23 22:16:54 | 000,002,030 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/05/23 22:07:14 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/16 01:10:24 | 000,011,184 | -HS- | C] () – C:\Users\Stefan\AppData\Local\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/16 01:10:24 | 000,011,184 | -HS- | C] () – C:\ProgramData\2by3mj7mu7nel8ibc3duertfny4y7tan6rv8hwi10mcw61b
[2011/05/08 10:56:49 | 000,000,863 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2010/08/21 16:25:24 | 000,037,013 | -H– | C] () – C:\ProgramData\nvModes.001
[2010/08/21 16:25:13 | 000,037,013 | -H– | C] () – C:\ProgramData\nvModes.dat
[2009/10/21 21:35:14 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/10/21 21:35:13 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/05/20 17:26:32 | 000,000,680 | -H– | C] () – C:\Users\Stefan\AppData\Local\d3d9caps.dat
[2009/01/24 13:51:25 | 000,147,192 | —- | C] () – C:\Windows\System32\guard32.dll
[2008/09/03 17:40:40 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2008/08/07 22:11:55 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/25 19:56:42 | 000,000,000 | -H– | C] () – C:\ProgramData\LauncherAccess.dt
[2008/07/25 19:54:06 | 000,005,632 | —- | C] () – C:\Windows\System32\drivers\StarOpen.sys
[2008/07/14 09:08:13 | 000,107,520 | —- | C] () – C:\Windows\System32\UnCasino5.exe
[2008/04/19 16:08:36 | 000,000,059 | —- | C] () – C:\Windows\wininit.ini
[2008/03/28 09:52:35 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2008/03/28 09:52:32 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/03/28 09:52:31 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/03/28 09:52:31 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2007/09/28 21:41:02 | 000,235,520 | -H– | C] () – C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,270,632 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,647,164 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,124,162 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/10/27 08:26:56 | 000,069,632 | —- | C] () – C:\Windows\System32\vuins32.dll

========== Custom Scans ==========


< %Temp%\smtmp\*.* /s >
[2010/10/03 14:20:28 | 000,002,477 | -H– | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\1\Programs\Serif Applications\PhotoPlus SE\PhotoPlus SE.lnk
[2011/05/23 22:31:15 | 000,000,286 | -HS- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\2\desktop.ini
[2008/07/01 19:19:58 | 000,000,930 | -H– | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\2\IsoBuster.lnk
[2011/05/23 22:31:15 | 000,000,948 | -H– | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\2\Launch Internet Explorer Browser.lnk
[2010/12/12 20:21:51 | 000,001,753 | -H– | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\2\Mozilla Firefox.lnk
[2006/11/02 13:50:41 | 000,000,240 | -H– | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\2\Window Switcher.lnk
[2007/09/08 17:14:39 | 000,000,943 | -H– | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\2\Windows Media Player.lnk
[2010/02/14 12:01:19 | 000,000,877 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Acrobat_com.lnk
[2010/02/14 12:03:29 | 000,001,892 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Adobe Reader 9.lnk
[2011/05/11 13:53:01 | 000,000,835 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\AVG 2011.lnk
[2009/09/15 17:44:49 | 000,000,867 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\BBC iPlayer Desktop.lnk
[2010/11/22 17:47:49 | 000,000,923 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Championship Manager 01-02.lnk
[2009/01/24 14:23:41 | 000,000,953 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\COMODO Internet Security.lnk
[2008/05/29 10:45:44 | 000,000,174 | -HS- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\desktop.ini
[2010/03/12 11:26:30 | 000,000,770 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\EPSON Scan.lnk
[2010/10/14 08:56:45 | 000,001,952 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Macromedia Dreamweaver 8.lnk
[2009/01/25 12:59:45 | 000,001,897 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Medieval II Total War.lnk
[2010/12/12 20:21:51 | 000,001,729 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Mozilla Firefox.lnk
[2010/08/21 15:51:13 | 000,001,731 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\QuickTime Player.lnk
[2010/10/03 14:20:29 | 000,002,033 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\Serif PhotoPlus SE.lnk
[2011/05/30 01:55:40 | 000,000,864 | —- | M] () – C:\Users\Stefan\AppData\Local\Temp\smtmp\4\VLC media player.lnk

========== Alternate Data Streams ==========

@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
Hi hodsons1,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:files
xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\3 "%AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C

:Commands
[purity]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI