This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

First Redirect Virus, Now updating and download file problem

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

A month ago, I have the internet redirect virus. I tried many ways to correct this problem including combofix, malwarebytes, restore windows to an earlier date, restore windows with original CD, Fronline Registry Cleaner, CCleaner and etc. Finally the redirect virus problem solved. But after that I have other problems. The computer always runs updating once it is turn off and on, but it fails when updating the files in windows update. I also have problems opening documents in words which was downloaded from the email attached file. Words said that the files are disable due to documents caused serious error last time when they were opened. I also run the Active Recovery software but it can only run once and I can`t use it anymore. Problem with Mozilla and I have to uninstall and re-install. The Malwarebytes also showed a message that it is 20 days not updated but when I press the update button, it showed the "Program_Error_Updating(5,0,create file)".

Please help me on this matter. Below is the OTL.txt and Extras.txt details as requested.

Thank you…..


OTL logfile created on: 6/9/2011 11:42:55 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\liynapearl\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

1.99 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 46.30% Memory free
3.98 Gb Paging File | 2.82 Gb Available in Paging File | 70.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.91 Gb Total Space | 125.93 Gb Free Space | 58.32% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.78 Gb Free Space | 57.82% Space Free | Partition Type: NTFS

Computer Name: LIYNAPEARL-PC | User Name: Liyna_ADMIN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\liynapearl\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files\Max PC Booster\PCBVistaService.exe (Max Secure Software)
PRC - C:\Program Files\Max PC Booster\PCBSysTray.exe (Max Secure Software.)
PRC - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Windows\System32\ChgService.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\liynapearl\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\IME\IMEJP10\IMJPTIP.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IMJP10K.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\IMETIP.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\IMEJP10\IMJPAPI.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\IMJKAPI.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\imecfm.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (PCBVistaSvc) – C:\Program Files\Max PC Booster\PCBVistaService.exe (Max Secure Software)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Thpsrv) – C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
SRV - (Change Modem Device Service) – C:\Windows\System32\ChgService.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (SbFw) – C:\Windows\System32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (sbhips) – C:\Windows\System32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\Windows\System32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (sbapifs) – C:\Windows\System32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (SBRE) – C:\Windows\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SBFWIMCLMP) – C:\Windows\System32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\Windows\System32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbdev) – C:\Windows\System32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (Thpevm) – C:\Windows\system32\DRIVERS\Thpevm.SYS (TOSHIBA Corporation)
DRV - (Thpdrv) – C:\Windows\system32\DRIVERS\thpdrv.sys (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (CLBUDF) – C:\Windows\System32\drivers\CLBUDF.sys (CyberLink Corporation.)
DRV - (CLBStor) – C:\Windows\System32\drivers\CLBStor.sys (Cyberlink Co.,Ltd.)
DRV - (cmnsusbser) – C:\Windows\System32\drivers\cmnsusbser.sys (Mobile Connector)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 73 07 C0 EE E6 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.jp/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {749474f5-3972-0174-45ff-a63c3dce6339}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.736
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.25
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=405&q;="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2011/01/31 10:46:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/03/07 09:16:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/03 23:44:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/03 23:44:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/03/07 09:16:06 | 000,000,000 | —D | M]

[2011/05/04 23:13:06 | 000,000,000 | -H-D | M] (No name found) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Extensions
[2011/06/08 15:23:30 | 000,000,000 | —D | M] (No name found) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions
[2011/05/17 22:00:34 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/17 22:00:35 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/06/04 12:25:24 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2011/05/18 16:51:15 | 000,000,000 | —D | M] (Redirect Remover) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2011/05/17 22:00:34 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\[removed]
[2011/06/05 20:36:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/08 00:11:01 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{749474f5-3972-0174-45ff-a63c3dce6339}
[2011/06/05 20:36:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/03/07 09:16:05 | 000,000,000 | —D | M] (Firefox Synchronisation Extension) – C:\PROGRAM FILES\NOKIA\NOKIA OVI SUITE\CONNECTORS\BOOKMARKS CONNECTOR\FIREFOXEXTENSION
[2011/01/31 10:46:29 | 000,000,000 | —D | M] (PC Sync 2 Synchronisation Extension) – C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/10/31 23:16:20 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
File not found (No name found) – C:\PROGRAM FILES\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2010/08/24 18:31:30 | 000,773,120 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2011/04/04 14:03:00 | 000,002,046 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
[2010/10/13 08:38:58 | 000,001,175 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\FLVTube.xml.bak

O1 HOSTS File: ([2011/05/19 19:03:50 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (i-フィルター 5.0 ブラウザヘルパー) - {0FAF6F52-1AD4-4282-9EA1-3EC884DA7AA3} - C:\Program Files\Digital Arts\IFP5\app\bin\ifp5toolbar.dll (デジタルアーツ株式会社)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [InstantBurn] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [PCBSystemTray] C:\Program Files\Max PC Booster\PCBSysTray.exe (Max Secure Software.)
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links using BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Download link using &BitComet; - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 06:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/06/05 20:26:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2011/06/05 20:26:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/06/05 20:25:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/06/05 20:23:13 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2011/06/05 20:21:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2011/06/05 20:19:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2011/06/05 20:17:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2011/06/05 20:14:45 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/06/03 23:44:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/06/03 23:33:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/06/03 23:33:41 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2011/06/03 01:02:54 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/06/03 01:02:52 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2011/06/02 11:42:22 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\CyberLink
[2011/06/02 11:39:59 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Local\Power2Go
[2011/06/02 11:27:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
[2011/06/02 11:27:54 | 000,161,704 | —- | C] (CyberLink Corporation.) – C:\Windows\System32\drivers\CLBUDF.sys
[2011/06/02 11:27:54 | 000,015,784 | —- | C] (Cyberlink Co.,Ltd.) – C:\Windows\System32\drivers\CLBStor.sys
[2011/06/02 11:27:27 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2011/06/02 11:27:13 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/06/01 22:42:24 | 000,000,000 | —D | C] – C:\Program Files\LSoft Technologies
[2011/06/01 22:42:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ File Recovery
[2011/05/29 11:38:21 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2011/05/20 13:04:19 | 000,000,000 | -H-D | C] – C:\Windows\PIF
[2011/05/20 09:59:00 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/20 09:59:00 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/20 09:58:59 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/20 09:58:59 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/20 09:58:59 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/20 09:58:59 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/20 09:58:59 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/20 09:58:59 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/20 09:58:59 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/20 09:58:59 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/20 09:58:59 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/20 09:58:59 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/20 09:58:59 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/20 09:58:59 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/20 09:58:59 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/20 09:58:59 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/20 09:58:59 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/20 09:58:59 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/20 09:58:59 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/20 09:58:56 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/20 09:58:56 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/20 09:58:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/20 09:58:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/20 09:58:56 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/20 09:58:56 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/20 09:58:56 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/20 09:58:56 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/20 09:58:56 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/20 09:58:56 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/20 09:58:56 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/20 09:58:56 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/20 09:58:56 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/20 09:58:56 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/20 09:58:56 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/20 09:58:56 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/20 09:58:56 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/20 09:58:56 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/20 09:58:56 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/20 09:58:56 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/20 09:48:34 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\yahoo!
[2011/05/19 23:18:42 | 000,000,000 | —D | C] – C:\FORMS
[2011/05/19 19:08:24 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/19 19:08:17 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Local\temp
[2011/05/19 19:05:04 | 000,000,000 | —D | C] – C:\Microsoft
[2011/05/19 18:46:37 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/05/19 13:28:36 | 000,000,000 | —D | C] – C:\ProgramData\FrontLine Registry Cleaner
[2011/05/19 13:25:55 | 000,000,000 | —D | C] – C:\temp
[2011/05/19 13:25:13 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner 2010 v1.25
[2011/05/19 12:48:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frontline Registry Cleaner
[2011/05/19 12:48:37 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner
[2011/05/19 12:13:03 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/05/19 12:13:03 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/05/19 12:13:03 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/05/19 12:12:46 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/05/19 12:10:00 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/19 10:30:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/18 23:41:33 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\Malwarebytes
[2011/05/18 23:41:09 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/18 23:41:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/18 23:41:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/18 23:41:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/18 10:15:51 | 000,000,000 | —D | C] – C:\w
[2011/05/18 10:15:50 | 000,000,000 | —D | C] – C:\Cache
[2011/05/18 10:15:45 | 000,000,000 | —D | C] – C:\e
[2011/05/17 17:10:12 | 000,000,000 | —D | C] – C:\Data
[2010/09/24 01:53:00 | 000,850,200 | —- | C] (DivX, Inc. ) – C:\Users\liynapearl\AppData\Roaming\DivXInstaller.exe
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/09 11:17:30 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/09 11:17:30 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/09 11:08:23 | 000,000,674 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/09 11:08:06 | 000,000,437 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2011/06/09 11:07:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/09 11:07:40 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/06/08 15:55:05 | 000,000,678 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/05 21:09:56 | 000,413,512 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/06/05 21:08:25 | 000,001,110 | —- | M] () – C:\Windows\System32\ServiceConfig.xml
[2011/06/05 21:08:25 | 000,000,810 | —- | M] () – C:\Windows\System32\RegistrationConfig.xml
[2011/06/04 12:25:14 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\BitComet.lnk
[2011/06/04 12:17:32 | 000,000,312 | —- | M] () – C:\Windows\System32\SBRC.dat
[2011/06/04 11:55:04 | 000,001,990 | —- | M] () – C:\Users\Liyna_ADMIN\Desktop\CyberLink Power2Go.lnk
[2011/06/04 10:49:43 | 002,677,546 | —- | M] () – C:\Windows\System32\perfh011.dat
[2011/06/04 10:49:43 | 002,078,056 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/04 10:49:43 | 001,549,488 | —- | M] () – C:\Windows\System32\perfc011.dat
[2011/06/04 10:49:43 | 001,509,358 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/03 23:44:19 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/29 23:04:02 | 000,002,503 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/20 09:59:00 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/20 09:59:00 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/20 09:58:59 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/20 09:58:59 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/20 09:58:59 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/20 09:58:59 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/20 09:58:59 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/20 09:58:59 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/20 09:58:59 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/20 09:58:59 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/20 09:58:59 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/20 09:58:59 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/20 09:58:59 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/20 09:58:59 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/20 09:58:59 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/20 09:58:59 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/20 09:58:59 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/20 09:58:59 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/20 09:58:59 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/20 09:58:58 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/20 09:58:56 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/20 09:58:56 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/20 09:58:56 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/20 09:58:56 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/20 09:58:56 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/20 09:58:56 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/20 09:58:56 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/20 09:58:56 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/20 09:58:56 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/20 09:58:56 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/20 09:58:56 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/20 09:58:56 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/20 09:58:56 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/20 09:58:56 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/20 09:58:56 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/20 09:58:56 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/20 09:58:56 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/20 09:58:56 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/20 09:58:56 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/20 09:58:56 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/19 19:03:50 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/05/19 14:38:05 | 000,000,420 | —- | M] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/19 12:48:38 | 000,002,018 | —- | M] () – C:\Users\Public\Desktop\FrontLine Registry Cleaner.lnk
[2011/05/19 10:30:01 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/18 23:41:09 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/17 15:29:59 | 000,000,136 | -H– | M] () – C:\ProgramData\~33545976r
[2011/05/17 15:29:59 | 000,000,112 | -H– | M] () – C:\ProgramData\~33545976
[2011/05/17 15:29:41 | 000,000,336 | -H– | M] () – C:\ProgramData\33545976
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/04 12:25:14 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\BitComet.lnk
[2011/06/03 23:44:19 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/02 11:33:12 | 000,001,990 | —- | C] () – C:\Users\Liyna_ADMIN\Desktop\CyberLink Power2Go.lnk
[2011/06/02 11:27:48 | 000,486,766 | —- | C] () – C:\Windows\CLBUDF.tbl
[2011/05/20 13:03:13 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/05/20 09:58:58 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/19 13:28:42 | 000,000,420 | —- | C] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/19 12:48:38 | 000,002,018 | —- | C] () – C:\Users\Public\Desktop\FrontLine Registry Cleaner.lnk
[2011/05/19 12:13:03 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/19 12:13:03 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/19 12:13:03 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/05/19 12:13:03 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/19 12:13:03 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/05/19 10:30:01 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/18 23:41:09 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/17 15:29:59 | 000,000,136 | -H– | C] () – C:\ProgramData\~33545976r
[2011/05/17 15:29:58 | 000,000,112 | -H– | C] () – C:\ProgramData\~33545976
[2011/05/17 15:29:41 | 000,000,336 | -H– | C] () – C:\ProgramData\33545976
[2011/04/24 15:00:34 | 000,000,312 | —- | C] () – C:\Windows\System32\SBRC.dat
[2010/05/22 15:23:26 | 000,000,008 | —- | C] () – C:\Windows\WININIT.INI
[2010/02/15 14:45:38 | 000,007,600 | -H– | C] () – C:\Users\liynapearl\AppData\Local\Resmon.ResmonCfg
[2010/02/02 01:35:51 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/11/07 07:59:58 | 000,006,656 | —- | C] () – C:\Users\liynapearl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/02 01:22:17 | 000,045,056 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2009/11/02 00:48:43 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/29 17:03:55 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/29 15:11:35 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2009/10/29 14:46:05 | 000,135,168 | —- | C] () – C:\Windows\System32\ChgService.exe
[2009/07/15 00:19:25 | 002,677,546 | —- | C] () – C:\Windows\System32\perfh011.dat
[2009/07/15 00:19:25 | 001,549,488 | —- | C] () – C:\Windows\System32\perfc011.dat
[2009/07/15 00:19:25 | 000,141,988 | —- | C] () – C:\Windows\System32\perfi011.dat
[2009/07/15 00:19:25 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd011.dat
[2009/07/14 13:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 13:33:53 | 000,413,512 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 11:05:48 | 002,078,056 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 11:05:48 | 001,509,358 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 11:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 11:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 11:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 11:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 09:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 08:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 08:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 08:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 06:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/28 04:37:00 | 000,028,672 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2008/10/21 13:59:32 | 000,046,456 | R— | C] () – C:\Windows\System32\exitwx.exe
[2002/11/16 15:37:48 | 000,053,248 | —- | C] () – C:\Windows\System32\ahook.dll

========== LOP Check ==========

[2011/03/10 14:00:14 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Aura4You
[2011/06/09 11:51:33 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\BitComet
[2010/07/09 00:13:22 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2010/05/12 12:34:56 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Ectaco
[2011/05/17 22:00:27 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\GetRightToGo
[2011/05/17 22:00:27 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Juniper Networks
[2009/12/11 22:47:45 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Nokia
[2009/12/11 21:23:11 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\PC Suite
[2010/07/06 19:40:31 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\RLM Software
[2011/05/17 22:00:50 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\solid-mp4-video-converter
[2011/05/17 21:54:25 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Thinstall
[2011/05/17 21:54:25 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Toshiba
[2009/11/01 23:42:29 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\WinBatch
[2011/05/19 14:38:05 | 000,000,420 | —- | M] () – C:\Windows\Tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/27 22:13:30 | 000,032,662 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/11 06:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 10:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/09/05 10:16:40 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/05/19 19:08:15 | 000,021,031 | —- | M] () – C:\ComboFix.txt
[2009/06/11 06:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/09 11:07:40 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/06/09 11:07:39 | 2137,448,448 | -HS- | M] () – C:\pagefile.sys
[2010/02/23 19:28:32 | 000,001,413 | —- | M] () – C:\[23]TCPLibrary.log
[2009/11/25 21:29:51 | 000,000,542 | —- | M] () – C:\[25]TCPLibrary.log
[2010/03/04 16:33:42 | 000,000,542 | —- | M] () – C:\[4]TCPLibrary.log

< %systemroot%\Fonts\*.com >
[2009/07/14 13:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 13:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 13:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 13:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 06:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 10:15:05 | 000,071,168 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNBPP4.DLL
[2009/07/14 10:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 10:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

Invalid Environment Variable: APPDATA

< %ALLUSERSPROFILE%\Favorites\*.* >

Invalid Environment Variable: APPDATA

< %PROGRAMFILES%\*.* >
[2009/07/14 13:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

Invalid Environment Variable: APPDATA

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

Invalid Environment Variable: APPDATA

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-08 06:59:25

========== Alternate Data Streams ==========

@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:96D0C06F
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >
Hi

Below is the extras.txt output



OTL Extras logfile created on: 6/9/2011 11:42:55 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\liynapearl\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

1.99 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 46.30% Memory free
3.98 Gb Paging File | 2.82 Gb Available in Paging File | 70.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.91 Gb Total Space | 125.93 Gb Free Space | 58.32% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.78 Gb Free Space | 57.82% Space Free | Partition Type: NTFS

Computer Name: LIYNAPEARL-PC | User Name: Liyna_ADMIN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn
"{2305B203-951F-4D88-B366-6E86F524390D}" = VIPRE Antivirus Premium
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{5861FBD0-8A6C-4608-AF3F-70EE59BF1FBE}_is1" = Max PC Booster
"{66712EEE-ECBC-4CA6-A474-solid-mp4-video-converter}_is1" = Solid MP4 Video Converter [removed]
"{72C24C23-C53D-11D4-88AB-00809880EBD8}" = TOSHIBA Speech Engines Version V9.50
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C2BF804-A884-4C52-8C3B-2A71A808AA98}" = i-フィルター 5.0
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B27901FA-F157-4049-B1EC-BC43890A1DCC}" = Active@ File Recovery
"{C4EA8443-092F-4818-8B5D-B8E25CC91135}" = TOSHIBA Speech System MT Engine Version 9.0
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F302B04E-C7B3-11D4-88AB-00809880EBD8}" = LaLaVoice V9.60
"7-Zip" = 7-Zip 9.20
"Aura DVD Ripper Professional_is1" = Aura DVD Ripper Professional 1.3.1
"BitComet" = BitComet 1.25
"CCleaner" = CCleaner
"Celcom Broadband Manager" = Celcom Broadband Manager
"Frontline Registry Cleaner1.25" = Frontline Registry Cleaner
"Frontline Registry Cleaner2.0" = Frontline Registry Cleaner
"HSDPA USB Modem SoftBank C01LC_is1" = SoftBank C01LC ユーティリティ バージョン 1.0.0
"InstallShield_{342126B2-10D5-409E-884B-245347A497E1}" = TOSHIBA Bulletin Board
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{42451051-52B5-4D74-920A-BB49861D7253}" = TOSHIBA ReelTime
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Nokia Ovi Suite" = Nokia Ovi Suite
"Nokia PC Internet Access" = Nokia PC インターネットアクセス
"Nokia PC Suite" = Nokia PC Suite
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"Quran in Ms Word_is1" = Quran in Ms Word 1.3
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VLC media player" = VLC media player 1.1.4
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/7/2011 2:05:13 AM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

Error - 6/7/2011 6:05:07 AM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

Error - 6/7/2011 6:05:08 AM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

Error - 6/7/2011 7:05:07 AM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

Error - 6/7/2011 7:05:07 AM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

Error - 6/7/2011 10:11:44 PM | Computer Name = liynapearl-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
PC Suite 7\TIS_Windows7PIM.dll". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/7/2011 11:34:00 PM | Computer Name = liynapearl-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
PC Suite 7\TIS_Windows7PIM.dll". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/7/2011 11:39:44 PM | Computer Name = liynapearl-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "C:\Program Files\Microsoft\Search
Enhancement Pack\Search Box Extension\SrchBxEx.dll".Error in manifest or policy
file "C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dll"
on line 2. Invalid Xml syntax.

Error - 6/8/2011 10:40:29 PM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

Error - 6/8/2011 10:40:30 PM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - 指定されたパスは無効です。

[ System Events ]
Error - 6/8/2011 2:45:52 AM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070020: Windows 7 用更新プログラム (KB2534366).

Error - 6/8/2011 10:08:00 PM | Computer Name = liynapearl-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 6/8/2011 10:08:06 PM | Computer Name = liynapearl-PC | Source = ipnathlp | ID = 34001
Description =

Error - 6/8/2011 10:08:06 PM | Computer Name = liynapearl-PC | Source = ipnathlp | ID = 30013
Description =

Error - 6/8/2011 10:12:35 PM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070020: Windows 7 用更新プログラム (KB2522422).

Error - 6/8/2011 10:12:35 PM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070020: Windows 7 用更新プログラム (KB2511250).

Error - 6/8/2011 10:12:35 PM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070020: Windows 7 用更新プログラム (KB2515325).

Error - 6/8/2011 10:12:35 PM | Computer Name = liynapearl-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070020: Windows 7 用更新プログラム (KB2534366).

Error - 6/8/2011 10:32:57 PM | Computer Name = liynapearl-PC | Source = ipnathlp | ID = 31004
Description =

Error - 6/8/2011 10:38:08 PM | Computer Name = liynapearl-PC | Source = ipnathlp | ID = 31004
Description =


< End of report >
Hi hana,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's see of we can figure out what is going on.

Scan with CKScanner:

  • Please download CKScanner from here to your Desktop.
Make sure that CKScanner.exe is on the your Desktop before running the application!
  • Right-click on CKScanner.exe and select Run as Administrator] then click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify the file saved
  • Double-click on the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.
Scan with WVCheck:

Please download WVCheck and save it to the desktop.

  • Right click on WVCheck.exe and select Run as Administrator and follow the prompts.
  • The scan may take some time depending on the Hard-Drive size.
  • Please post the contents of the notepad file WVCheck_1436_dd-mm-yyyy that can be located on the desktop.
When completed the above, please post back the following in the order asked for:

  • How is you computer performing now, any further symptoms and or problems encountered?
  • CK Scanner Log.
  • WVCheck Log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI