This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help me remove SearchQU.com

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I know searchqu is on this laptop along with a whole load of other unwanted nasties im sure.
Id really appreciate it if anyone could give me a hand to know what to get rid of here. Im posting some logs as instructed on this forum.

Thank you in advance for any help :)

DDS Log
———————————————————————————————————
.
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 8.0.7600.16385
Run by [removed] at 15:46:17 on 2011-06-19
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2815.1554 [GMT 3:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Program Files\LG Software\LG OSD\HotKey.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\USB Camera\VM331_STI.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\msconfig.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uDefault_Page_URL = hxxp://www.lge.com
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: CescrtHlpr Object: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.4.19.5\bh\BabylonToolbar.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Babylon IE plugin: {9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Updater For Simppull Toolbar: {c4b8bab4-1667-11df-a242-ba9455d89593} - c:\program files\simppulltoolbar\auxi\simppulltoolbAu.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No File
BHO: TBSB05541 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\veehd plugin\tbunsye48e.tmp\tbcore3.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.4.19.5\BabylonToolbarTlbr.dll
TB: Veehd Plugin: {32ea9cd0-5187-4fe3-b989-b4d1408d2802} - c:\veehd plugin\tbunsye48e.tmp\tbcore3.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [Google Update] "c:\users\b\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe
uRun: [Startw3i] c:\program files\pc speed maximizer\Startw3i.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [LGSR_Menu] "c:\program files\lg software\lg smart recovery\muitransfer\muistartmenu.exe" "c:\program files\lg software\lg smart recovery" updatewithcreateonce software\cyberlink\PowerRecover
mRun: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
mRun: [zOSD] c:\program files\lg software\lg osd\HotKey.exe
mRun: [KeybdUtility] c:\program files\lg software\lg osd\HotKey.exe
mRun: [LG Intelligent Update] "c:\program files\lg_swupdate\giljabistart.exe" Gilautouc
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [331BigDog] c:\program files\usb camera\VM331_STI.EXE
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [AmIcoSinglun] c:\program files\amicosinglun\AmIcoSinglun.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [BabylonToolbar] "c:\program files\babylontoolbar\babylontoolbar\1.4.19.5\BabylonToolbarsrv.exe" /md I
mRun: [Babylon Client] c:\program files\babylon\babylon-pro\Babylon.exe -AutoStart
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [InstantBurn] c:\progra~1\cyberl~1\instan~1\win2k\IBurn.exe
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Translate this web page with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Action.htm
IE: {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7A0D1738-10EA-47FF-92BE-4E137B5BE1A4} - hxxps://mpsnare.iesnare.com/StmOCX.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{14AC0C04-6522-4F06-936D-B079BAB8B709} : DhcpNameServer = 10.100.196.83 10.100.196.84
TCP: Interfaces\{6C46C60A-C15B-4940-943C-9EB3E3B377B1} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{6C46C60A-C15B-4940-943C-9EB3E3B377B1}\052435A4 : DhcpNameServer = 10.23.59.2 10.23.59.6
TCP: Interfaces\{6C46C60A-C15B-4940-943C-9EB3E3B377B1}\36963736F63726 : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{6C46C60A-C15B-4940-943C-9EB3E3B377B1}\C496D637 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{D60E3745-002A-40EA-8EB4-5D5E57E17665} : DhcpNameServer = 10.100.196.83 10.100.196.84
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs:
.
============= SERVICES / DRIVERS ===============
.
R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [2011-5-6 15784]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl1431dd0c;MpKsl1431dd0c;c:\programdata\microsoft\microsoft antimalware\definition updates\{f01825f2-bb91-457a-b2ed-f4d6fa9507f7}\MpKsl1431dd0c.sys [2011-6-19 28752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/12/31 14:33:43];c:\program files\cyberlink\powerdvd9\000.fcl [2009-2-28 87536]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [2011-5-6 162216]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2010-1-19 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-6-11 50688]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 MTsensor32;PU ACPI UTILITY;c:\windows\system32\drivers\PuAcpi32.sys [2009-9-26 14344]
R3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\drivers\netr28.sys [2009-10-25 599040]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-9-26 64544]
R3 vm331avs;USB2.0 UVC 1.3M WebCam;c:\windows\system32\drivers\vm331avs.sys [2009-9-26 996608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\splash.sys\config\DVMExportService.exe [2009-7-8 323584]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-1 136176]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.sys [2009-7-25 25600]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-1-6 112640]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-12-31 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-1 136176]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [2011-1-6 101120]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-8-18 9216]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-1 1343400]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2009-2-13 11520]
S3 wsvd;wsvd;c:\windows\system32\drivers\wsvd.sys [2009-6-5 81704]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [2011-1-12 114688]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [2011-1-12 105088]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-06-19 08:07:26 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f01825f2-bb91-457a-b2ed-f4d6fa9507f7}\MpKsl1431dd0c.sys
2011-06-19 08:07:09 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f01825f2-bb91-457a-b2ed-f4d6fa9507f7}\mpengine.dll
2011-06-17 07:44:34 ——– d—–w- C:\Veehd Plugin
2011-06-16 22:16:25 ——– d—–w- c:\users\b\appdata\local\DDMSettings
2011-06-16 22:14:57 ——– d—–w- c:\program files\common files\PX Storage Engine
2011-06-16 22:14:32 ——– d—–w- c:\program files\common files\DivX Shared
2011-06-16 22:12:29 ——– d—–w- c:\program files\DivX
2011-06-16 22:06:54 ——– d—–w- c:\programdata\DivX
2011-06-16 22:04:06 ——– d—–w- c:\program files\Veehd Plugin
2011-06-16 11:26:37 311296 —-a-w- c:\windows\system32\drivers\srv.sys
2011-06-16 11:26:37 309760 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-06-16 11:26:37 114176 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-16 11:26:35 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2011-06-16 11:26:35 1286016 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-16 11:22:43 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-06-16 11:22:28 78336 —-a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-16 11:22:27 740864 —-a-w- c:\windows\system32\inetcomm.dll
2011-06-16 11:16:09 96256 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 11:16:09 222720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 11:16:09 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-15 20:49:38 ——– d—–w- c:\users\b\appdata\local\Ilivid Player
2011-06-15 20:48:20 ——– dc-h–w- c:\programdata\~0
2011-06-14 16:52:36 1414440 —-a-w- c:\windows\system32\ShellManager310E2D762.dll
2011-06-06 15:26:33 ——– d—–w- c:\users\b\appdata\local\{BDEA8263-60DF-4B62-A4E3-559EDD9FFD4B}
2011-06-02 17:53:02 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-05-27 09:09:48 ——– d—–w- c:\users\b\appdata\roaming\NCH Software
2011-05-25 09:42:24 26496 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-23 18:54:10 ——– d—–r- C:\B-PC
2011-05-23 18:12:29 77824 —-a-w- C:\s_launch.exe
2011-05-23 18:12:29 634880 —-a-w- C:\Updater.exe
2011-05-23 18:12:29 49152 —-a-w- C:\update.exe
2011-05-23 18:12:29 4320702 —-a-w- C:\PuyoF_(backup).exe
2011-05-23 18:12:29 4320702 —-a-w- C:\PuyoF.exe
2011-05-23 18:12:29 36864 —-a-w- C:\SnapUtil.dll
2011-05-23 18:12:29 131072 —-a-w- C:\snapcl.dll
2011-05-23 18:12:29 12400 —-a-w- C:\secdrv.sys
2011-05-23 18:12:29 1187840 —-a-w- C:\SegaLauncher.exe
2011-05-23 18:11:28 ——– d—–w- C:\BGM
2011-05-23 18:11:18 ——– d—–w- C:\VOICE_E
2011-05-23 18:11:09 ——– d—–w- C:\VOICE
2011-05-23 18:11:08 ——– d—–w- C:\SE
2011-05-23 18:11:02 ——– d—–w- C:\BIN
2011-05-22 20:04:52 ——– d—–w- c:\users\b\appdata\local\Cyberlink
2011-05-20 19:52:21 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-05-20 19:52:14 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{973e0f29-9faf-4e39-a80a-2c1e1ba9ad42}\gapaengine.dll
.
==================== Find3M ====================
.
2011-05-28 03:00:02 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-05-13 19:10:18 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-13 18:54:51 353576 —-a-w- c:\windows\system32\msvcr71.dll
2011-05-13 18:54:51 29480 —-a-w- c:\windows\system32\msxml3a.dll
2011-05-02 19:41:20 389120 —-a-w- c:\windows\system32\RegistryHelperLM.ocx
2011-04-22 19:31:50 981504 —-a-w- c:\windows\system32\wininet.dll
2011-04-22 19:31:26 44544 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-22 18:23:59 386048 —-a-w- c:\windows\system32\html.iec
2011-04-09 06:13:06 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:13:06 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56:38 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-03-25 03:06:46 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-03-25 03:06:25 284160 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-03-25 03:06:23 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-03-25 03:06:12 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-03-25 03:06:11 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-03-25 03:06:10 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-03-25 03:06:06 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
.
============= FINISH: 15:46:48.51 ===============

———————————————————————————————————

Hijack this Log

———————————————————————————————————

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:48:31, on 19/06/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Program Files\LG Software\LG OSD\HotKey.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\USB Camera\VM331_STI.EXE
C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\msconfig.exe
C:\Users\b\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\b\Downloads\remove tools\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lge.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\bh\BabylonToolbar.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Updater For Simppull Toolbar - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - C:\Program Files\simppulltoolbar\auxi\simppulltoolbAu.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
O2 - BHO: TBSB05541 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Veehd Plugin\tbunsyE48E.tmp\tbcore3.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarTlbr.dll
O3 - Toolbar: Veehd Plugin - {32EA9CD0-5187-4FE3-B989-B4D1408D2802} - C:\Veehd Plugin\tbunsyE48E.tmp\tbcore3.dll
O4 - HKLM\..\Run: [LGSR_Menu] "C:\Program Files\LG Software\LG Smart Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\LG Software\LG Smart Recovery" UpdateWithCreateOnce Software\CyberLink\PowerRecover
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [zOSD] C:\Program Files\LG Software\LG OSD\HotKey.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\LG OSD\HotKey.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [331BigDog] C:\Program Files\USB Camera\VM331_STI.EXE
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [BabylonToolbar] "C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exe" /md I
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [InstantBurn] C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Google Update] "C:\Users\b\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Startw3i] C:\Program Files\PC Speed Maximizer\Startw3i.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7A0D1738-10EA-47FF-92BE-4E137B5BE1A4} (Stm Class) - https://mpsnare.iesnare.com/StmOCX.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SPLASH.SYS\config\DVMExportService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

–
End of file - 11834 bytes

———————————————————————————————————

OTL


OTL logfile created on: 6/19/2011 3:51:21 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\b\Downloads\remove tools
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 53.62% Memory free
5.50 Gb Paging File | 4.06 Gb Available in Paging File | 73.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148.00 Gb Total Space | 35.15 Gb Free Space | 23.75% Space Free | Partition Type: NTFS
Drive D: | 138.59 Gb Total Space | 32.50 Gb Free Space | 23.45% Space Free | Partition Type: NTFS

Computer Name: B-PC | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/19 15:36:30 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\b\Downloads\remove tools\OTL.exe
PRC - [2011/06/19 15:36:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\b\Downloads\remove tools\HiJackThis.exe
PRC - [2011/04/15 14:01:26 | 000,399,736 | —- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\uTorrent.exe
PRC - [2011/03/30 10:14:52 | 003,265,648 | —- | M] (Babylon Ltd.) – C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
PRC - [2011/03/01 17:43:48 | 000,075,048 | —- | M] (cyberlink) – C:\Program Files\CyberLink\Shared files\brs.exe
PRC - [2011/02/26 08:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:42 | 000,206,360 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/01/19 14:24:16 | 002,499,584 | —- | M] (Vodafone) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
PRC - [2010/01/19 14:24:08 | 000,009,216 | —- | M] (Vodafone) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2009/09/03 21:28:30 | 003,670,016 | —- | M] (LG Electronics) – C:\Program Files\LG Software\LG OSD\HotKey.exe
PRC - [2009/08/19 20:37:32 | 000,536,576 | —- | M] (Vimicro) – C:\Program Files\USB Camera\VM331_STI.EXE
PRC - [2009/08/01 03:10:34 | 000,233,472 | —- | M] (AlcorMicro Co., Ltd.) – C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
PRC - [2009/07/14 04:14:42 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2009/07/14 04:14:41 | 000,354,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\StikyNot.exe
PRC - [2009/07/14 04:14:25 | 000,233,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msconfig.exe
PRC - [2009/07/09 16:10:24 | 000,681,256 | —- | M] (CyberLink Corporation.) – C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe
PRC - [2009/07/06 14:22:04 | 000,087,336 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
PRC - [2008/05/20 03:25:56 | 000,144,688 | —- | M] (LG Electronics Inc.) – C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
PRC - [2008/05/20 03:24:54 | 000,263,472 | —- | M] (LG Electronics Inc.) – C:\Program Files\LG Software\LG Magnifier\Maglev.exe


========== Modules (SafeList) ==========

MOD - [2011/06/19 15:36:30 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\b\Downloads\remove tools\OTL.exe
MOD - [2011/03/29 15:33:42 | 000,236,544 | —- | M] (Babylon Ltd.) – C:\Program Files\Babylon\Babylon-Pro\captlib.dll
MOD - [2010/08/21 08:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/01/01 05:49:05 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/11/11 12:26:42 | 000,206,360 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/01/19 14:24:08 | 000,009,216 | —- | M] (Vodafone) [Auto | Running] – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe – (VMCService)
SRV - [2009/07/14 04:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 04:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/07/08 00:32:46 | 000,323,584 | -H– | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\SPLASH.SYS\config\DVMExportService.exe – (DvmMDES)


========== Driver Services (SafeList) ==========

DRV - [2011/06/19 11:07:27 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F01825F2-BB91-457A-B2ED-F4D6FA9507F7}\MpKsl1431dd0c.sys – (MpKsl1431dd0c)
DRV - [2010/10/24 21:25:38 | 000,054,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2010/10/24 21:25:38 | 000,043,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\MpNWMon.sys – (MpNWMon)
DRV - [2009/11/04 16:59:38 | 000,112,640 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ewusbnet.sys – (ewusbnet)
DRV - [2009/11/04 16:59:38 | 000,102,912 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2009/11/04 16:59:38 | 000,101,120 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ewusbfake.sys – (hwusbfake)
DRV - [2009/08/18 12:06:44 | 000,114,688 | —- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbnet.sys – (ZTEusbnet)
DRV - [2009/08/18 12:06:44 | 000,105,088 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\zteusbvoice.sys – (ZTEusbvoice)
DRV - [2009/08/18 12:06:44 | 000,105,088 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbser6k.sys – (ZTEusbser6k)
DRV - [2009/08/18 12:06:44 | 000,105,088 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbnmea.sys – (ZTEusbnmea)
DRV - [2009/08/18 12:06:44 | 000,105,088 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbmdm6k.sys – (ZTEusbmdm6k)
DRV - [2009/08/18 12:06:44 | 000,009,216 | R— | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\massfilter.sys – (massfilter)
DRV - [2009/08/11 00:33:46 | 000,996,608 | —- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vm331avs.sys – (vm331avs)
DRV - [2009/07/25 02:01:28 | 000,025,600 | —- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AmUStor.sys – (AmUStor)
DRV - [2009/07/14 01:02:47 | 000,050,688 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\L1C62x86.sys – (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV - [2009/07/07 21:05:12 | 000,015,784 | —- | M] (Cyberlink Co.,Ltd.) [Kernel | System | Running] – C:\Windows\System32\drivers\CLBStor.sys – (CLBStor)
DRV - [2009/07/07 21:05:08 | 000,162,216 | —- | M] (CyberLink Corporation.) [File_System | Auto | Running] – C:\Windows\System32\drivers\CLBUDF.sys – (CLBUDF)
DRV - [2009/06/29 10:36:36 | 000,017,920 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvsmu.sys – (nvsmu)
DRV - [2009/06/23 04:20:00 | 009,753,056 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2009/06/05 08:44:28 | 000,014,344 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\PuAcpi32.sys – (MTsensor32)
DRV - [2009/06/05 01:03:28 | 000,081,704 | —- | M] (CyberLink) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\wsvd.sys – (wsvd)
DRV - [2009/05/12 10:19:22 | 000,064,544 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/02/28 14:40:18 | 000,087,536 | —- | M] (CyberLink Corp.) [2010/12/31 14:33:43] [Kernel | Auto | Running] – C:\Program Files\CyberLink\PowerDVD9\000.fcl – ({B154377D-700F-42cc-9474-23858FBDF4BD})
DRV - [2009/02/13 11:02:52 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\wdcsam.sys – (WDC_SAM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lge.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.atcomet.com/m/"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906

FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/06/17 01:15:24 | 000,000,000 | —D | M]

[2011/01/05 06:56:24 | 000,000,000 | —D | M] (No name found) – C:\Users\b\AppData\Roaming\Mozilla\Extensions
[2011/06/14 19:50:27 | 000,000,000 | —D | M] (No name found) – C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\cp93h625.default\extensions
[2011/04/27 17:01:34 | 000,000,000 | —D | M] (Babylon) – C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\cp93h625.default\extensions\[removed]
[2011/02/01 19:05:08 | 000,002,333 | —- | M] () – C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\cp93h625.default\searchplugins\askcom.xml
[2011/05/13 22:01:54 | 000,002,230 | —- | M] () – C:\Users\b\AppData\Roaming\Mozilla\Firefox\Profiles\cp93h625.default\searchplugins\iBryte_playbryte.xml
[2011/01/19 15:36:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/31 13:26:10 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

O1 HOSTS File: ([2009/06/11 00:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (CescrtHlpr Object) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Updater For Simppull Toolbar) - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - File not found
O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No CLSID value found.
O2 - BHO: (TBSB05541 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Veehd Plugin\tbunsyE48E.tmp\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Veehd Plugin) - {32EA9CD0-5187-4FE3-B989-B4D1408D2802} - C:\Veehd Plugin\tbunsyE48E.tmp\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Veehd Plugin) - {32EA9CD0-5187-4FE3-B989-B4D1408D2802} - C:\Veehd Plugin\tbunsyE48E.tmp\tbcore3.dll ()
O4 - HKLM..\Run: [331BigDog] C:\Program Files\USB Camera\VM331_STI.EXE (Vimicro)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe (Babylon Ltd.)
O4 - HKLM..\Run: [BabylonToolbar] C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exe (Babylon Ltd.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [InstantBurn] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [KeybdUtility] C:\Program Files\LG Software\LG OSD\HotKey.exe (LG Electronics)
O4 - HKLM..\Run: [LG Intelligent Update] C:\Program Files\lg_swupdate\giljabistart.exe (BIT LEADER)
O4 - HKLM..\Run: [LG Magnifier] C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe (LG Electronics Inc.)
O4 - HKLM..\Run: [LGSR_Menu] C:\Program Files\LG Software\LG Smart Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [zOSD] C:\Program Files\LG Software\LG OSD\HotKey.exe (LG Electronics)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Startw3i] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Translate this web page with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Translate with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {7A0D1738-10EA-47FF-92BE-4E137B5BE1A4} https://mpsnare.iesnare.com/StmOCX.cab (Stm Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 00:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{4aa5e31b-3fab-11e0-9c08-90e6ba6241d4}\Shell - "" = AutoRun
O33 - MountPoints2\{4aa5e31b-3fab-11e0-9c08-90e6ba6241d4}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{801b7390-1c10-11e0-be9a-002243d33ad4}\Shell - "" = AutoRun
O33 - MountPoints2\{801b7390-1c10-11e0-be9a-002243d33ad4}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c8d14a20-26da-11e0-8023-90e6ba6241d4}\Shell - "" = AutoRun
O33 - MountPoints2\{c8d14a20-26da-11e0-8023-90e6ba6241d4}\Shell\AutoRun\command - "" = "I:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{cd14a404-199e-11e0-8249-002243d33ad4}\Shell - "" = AutoRun
O33 - MountPoints2\{cd14a404-199e-11e0-8249-002243d33ad4}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{cd14a40d-199e-11e0-8249-002243d33ad4}\Shell - "" = AutoRun
O33 - MountPoints2\{cd14a40d-199e-11e0-8249-002243d33ad4}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{e3fddcc9-1e57-11e0-936f-002243d33ad4}\Shell - "" = AutoRun
O33 - MountPoints2\{e3fddcc9-1e57-11e0-936f-002243d33ad4}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{f91792b5-19a6-11e0-87f5-002243d33ad4}\Shell - "" = AutoRun
O33 - MountPoints2\{f91792b5-19a6-11e0-87f5-002243d33ad4}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/18 11:02:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/06/17 10:44:34 | 000,000,000 | —D | C] – C:\Veehd Plugin
[2011/06/17 01:16:25 | 000,000,000 | —D | C] – C:\Users\b\AppData\Local\DDMSettings
[2011/06/17 01:15:11 | 000,000,000 | —D | C] – C:\Users\b\AppData\Roaming\DivX
[2011/06/17 01:14:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PX Storage Engine
[2011/06/17 01:14:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2011/06/17 01:14:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2011/06/17 01:12:29 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2011/06/17 01:06:54 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2011/06/17 01:04:06 | 000,000,000 | —D | C] – C:\Program Files\Veehd Plugin
[2011/06/16 14:17:29 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/06/16 14:17:23 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/16 14:17:22 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/06/16 14:17:22 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/16 14:17:22 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/16 14:17:22 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/06/16 14:17:22 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/16 14:17:21 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/06/16 14:17:21 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/16 14:17:21 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/16 14:17:21 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/16 14:17:21 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/15 23:49:38 | 000,000,000 | —D | C] – C:\Users\b\AppData\Local\Ilivid Player
[2011/06/15 23:48:20 | 000,000,000 | -H-D | C] – C:\ProgramData\~0
[2011/06/14 19:52:36 | 001,414,440 | —- | C] (Nero AG) – C:\Windows\System32\ShellManager310E2D762.dll
[2011/06/14 19:52:10 | 000,000,000 | —D | C] – C:\Users\b\AppData\Roaming\Nero
[2011/06/06 18:26:33 | 000,000,000 | —D | C] – C:\Users\b\AppData\Local\{BDEA8263-60DF-4B62-A4E3-559EDD9FFD4B}
[2011/06/02 20:53:02 | 000,094,208 | —- | C] (DivX, Inc.) – C:\Windows\System32\dpl100.dll
[2011/05/31 17:46:08 | 000,000,000 | —D | C] – C:\Users\b\Documents\Martha Marcy May Marlene (2011) DVDRip XviD-MAX
[2011/05/27 12:09:53 | 000,000,000 | —D | C] – C:\ProgramData\NCH Software
[2011/05/27 12:09:48 | 000,000,000 | —D | C] – C:\Users\b\AppData\Roaming\NCH Software
[2011/05/25 12:42:24 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2011/05/23 21:54:10 | 000,000,000 | R–D | C] – C:\B-PC
[2011/05/23 21:12:29 | 000,049,152 | —- | C] ( ) – C:\update.exe
[2011/05/23 21:12:29 | 000,012,400 | —- | C] (Macrovision Europe Ltd) – C:\secdrv.sys
[2011/05/23 21:11:28 | 000,000,000 | —D | C] – C:\BGM
[2011/05/23 21:11:18 | 000,000,000 | —D | C] – C:\VOICE_E
[2011/05/23 21:11:09 | 000,000,000 | —D | C] – C:\VOICE
[2011/05/23 21:11:08 | 000,000,000 | —D | C] – C:\SE
[2011/05/23 21:11:02 | 000,000,000 | —D | C] – C:\BIN
[2011/05/22 23:04:52 | 000,000,000 | —D | C] – C:\Users\b\AppData\Local\Cyberlink

========== Files - Modified Within 30 Days ==========

[2011/06/19 15:51:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3354398091-65546500-785416632-1000UA.job
[2011/06/19 13:32:58 | 000,016,755 | —- | M] () – C:\Users\b\Desktop\Lamnia_Company_(pptp).pbk
[2011/06/19 13:29:57 | 000,000,406 | -H– | M] () – C:\dvmexp.idx
[2011/06/19 13:05:00 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/19 11:02:35 | 000,009,667 | —- | M] () – C:\Windows\lg_up.ini
[2011/06/19 05:51:00 | 000,000,840 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3354398091-65546500-785416632-1000Core.job
[2011/06/19 01:31:06 | 000,000,220 | —- | M] () – C:\Users\b\Desktop\NVIDIA Control Panel - Shortcut.lnk
[2011/06/18 14:05:00 | 000,000,872 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/18 11:08:06 | 000,010,240 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/18 11:08:06 | 000,010,240 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/18 11:02:42 | 000,002,503 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/18 11:01:16 | 000,000,848 | —- | M] () – C:\Windows\lgcenter.ini
[2011/06/18 11:00:55 | 000,327,680 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2011/06/18 11:00:43 | 000,067,584 | —- | M] () – C:\Windows\bootstat.dat
[2011/06/18 11:00:38 | 2213,965,824 | -HS- | M] () – C:\hiberfil.sys
[2011/06/17 01:15:27 | 000,002,058 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2011/06/17 01:15:27 | 000,001,573 | —- | M] () – C:\Users\b\Desktop\DivX Movies.lnk
[2011/06/17 01:15:05 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2011/06/17 01:04:02 | 001,521,330 | —- | M] () – C:\Users\b\Desktop\Veehd.exe
[2011/06/15 08:40:12 | 000,481,765 | —- | M] () – C:\Users\b\Desktop\Mandy_RP_Extension_to_Sept_2011.pdf
[2011/06/15 01:52:35 | 000,002,369 | —- | M] () – C:\Users\b\Desktop\Google Chrome.lnk
[2011/06/14 19:52:21 | 000,001,024 | —- | M] () – C:\Users\b\.rnd
[2011/06/14 19:52:12 | 000,000,000 | —- | M] () – C:\Windows\Irremote.ini
[2011/06/13 17:59:09 | 000,001,550 | —- | M] () – C:\Users\b\Desktop\Downloads.lnk
[2011/06/06 18:26:24 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/06/06 18:05:51 | 000,633,464 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/06 18:05:51 | 000,112,456 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/02 20:53:02 | 000,094,208 | —- | M] (DivX, Inc.) – C:\Windows\System32\dpl100.dll
[2011/05/28 06:00:02 | 001,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb

========== Files Created - No Company Name ==========

[2011/06/19 01:31:06 | 000,000,220 | —- | C] () – C:\Users\b\Desktop\NVIDIA Control Panel - Shortcut.lnk
[2011/06/18 11:02:42 | 000,002,503 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/17 01:15:27 | 000,001,573 | —- | C] () – C:\Users\b\Desktop\DivX Movies.lnk
[2011/06/17 01:15:05 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2011/06/17 01:14:47 | 000,002,058 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2011/06/17 01:03:43 | 001,521,330 | —- | C] () – C:\Users\b\Desktop\Veehd.exe
[2011/06/15 08:40:11 | 000,481,765 | —- | C] () – C:\Users\b\Desktop\Mandy_RP_Extension_to_Sept_2011.pdf
[2011/06/14 19:52:36 | 000,773,120 | —- | C] () – C:\Windows\System32\NEROINSTAEC43759.DB
[2011/06/14 19:52:12 | 000,000,000 | —- | C] () – C:\Windows\Irremote.ini
[2011/06/13 17:58:12 | 000,001,550 | —- | C] () – C:\Users\b\Desktop\Downloads.lnk
[2011/06/03 20:42:36 | 000,327,680 | —- | C] () – C:\Windows\System32\Ikeext.etl
[2011/05/31 22:24:15 | 000,016,755 | —- | C] () – C:\Users\b\Desktop\Lamnia_Company_(pptp).pbk
[2011/05/23 21:12:29 | 004,320,702 | —- | C] () – C:\PuyoF_(backup).exe
[2011/05/23 21:12:29 | 004,320,702 | —- | C] () – C:\PuyoF.exe
[2011/05/23 21:12:29 | 001,187,840 | —- | C] () – C:\SegaLauncher.exe
[2011/05/23 21:12:29 | 000,634,880 | —- | C] () – C:\Updater.exe
[2011/05/23 21:12:29 | 000,131,072 | —- | C] () – C:\snapcl.dll
[2011/05/23 21:12:29 | 000,077,824 | —- | C] () – C:\s_launch.exe
[2011/05/23 21:12:29 | 000,036,864 | —- | C] () – C:\SnapUtil.dll
[2011/05/23 21:12:29 | 000,000,477 | —- | C] () – C:\update.dat
[2011/05/23 21:12:29 | 000,000,250 | —- | C] () – C:\Updater.ptxml
[2011/05/23 21:12:29 | 000,000,127 | —- | C] () – C:\SEGA PC ƒIƒ“ƒ‰ƒCƒ“ƒ†[ƒU[“o˜^.url
[2011/05/23 21:12:29 | 000,000,067 | —- | C] () – C:\S_LAUNCH.CFG
[2011/04/23 17:29:15 | 000,005,632 | —- | C] () – C:\Users\b\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/23 01:51:43 | 000,000,000 | —- | C] () – C:\Users\b\AppData\Roaming\QD info.ini
[2011/01/05 06:56:12 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/01/01 06:20:07 | 000,009,667 | —- | C] () – C:\Windows\lg_up.ini
[2010/12/31 14:10:13 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/12/31 09:55:28 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/01/10 23:28:36 | 000,154,248 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2009/10/25 13:16:42 | 000,013,931 | —- | C] () – C:\Windows\System32\RaCoInst.dat
[2009/09/26 03:10:12 | 000,000,848 | —- | C] () – C:\Windows\lgcenter.ini
[2009/09/26 03:07:56 | 000,000,234 | —- | C] () – C:\Windows\lgcare.ini
[2009/09/26 02:55:50 | 000,014,344 | —- | C] () – C:\Windows\System32\drivers\PuAcpi32.sys
[2009/09/26 02:54:28 | 000,001,251 | —- | C] () – C:\Windows\vm331Rmv.ini
[2009/09/26 02:50:59 | 000,000,210 | —- | C] () – C:\Windows\lgps.ini
[2009/07/14 07:57:37 | 000,067,584 | —- | C] () – C:\Windows\bootstat.dat
[2009/07/14 07:33:53 | 000,426,384 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 05:05:48 | 000,633,464 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 05:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 05:05:48 | 000,112,456 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 05:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 05:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 05:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 02:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 02:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 02:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 00:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/05/30 01:42:20 | 000,309,248 | —- | C] () – C:\Windows\System32\sqlite36_engine.dll
[2009/03/11 22:01:28 | 000,023,552 | —- | C] () – C:\Windows\System32\DirectCOM.dll

< End of report >



———————————————————————————————————————————-


OTL Extras logfile created on: 6/19/2011 3:51:21 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\b\Downloads\remove tools
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 53.62% Memory free
5.50 Gb Paging File | 4.06 Gb Available in Paging File | 73.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148.00 Gb Total Space | 35.15 Gb Free Space | 23.75% Space Free | Partition Type: NTFS
Drive D: | 138.59 Gb Total Space | 32.50 Gb Free Space | 23.45% Space Free | Partition Type: NTFS

Computer Name: B-PC | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{095C49EB-930B-48E6-BF07-0C99206DA5BB}" = Alcor Micro USB Card Reader
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 25
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = LG Smart Recovery
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C3A1578-21D1-4307-88C5-6487A1F61A01}" = Vodafone Mobile Connect Lite
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{503C66C4-A82B-4A00-8449-F6ECA2280D6E}" = LG OSD
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6f414853-6844-4317-a77c-5ef73a7c4c03}" = MediaSPace Music Videos
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{81717D01-32F6-449C-85E1-41AFD678E545}" = LG Intelligent Update
"{846447E6-F3CB-4DD9-B4AD-5CCBBB610982}" = LG Smart Care
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}" = Ralink RT2860 Wireless LAN Card
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9672CAD2-F310-42D6-9147-E4A4B6ED8395}" = LG Magnifier
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}" = USB2.0 UVC 1.3M WebCam
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{D9DA5C41-964F-455F-B5E7-3664519440E8}_is1" = Bit Che
"{DABD50F7-0001-0002-0003-ABCDEFABCDEF}" = LG Smart Indicator
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{FCF7655B-62C3-4C16-A12D-CC84B33493FB}" = LG Smart On
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AmUStor" = Alcor Micro USB Card Reader
"Babylon" = Babylon
"BabylonToolbar" = Babylon toolbar
"DivX Setup.divx.com" = DivX Setup
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = LG Smart Recovery
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MpcStar" = MpcStar 5.1
"NVIDIA Drivers" = NVIDIA Drivers
"PROPLUS" = Microsoft Office Professional Plus 2007
"The KMPlayer" = The KMPlayer (remove only)
"uTorrent" = µTorrent
"Veehd Plugin" = Veehd Plugin
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


========================


Wow that was long.. Hope I did it OK.. Thanks again for any help :)

Andy
Hello Andy and welcome to the WTT forum.

My username is Astabi and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:

Please do not install/uninstall any programs unless asked to.
Please do not run any scans other than those requested
Please follow all instructions in the order posted
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
If you don't understand something, please don't hesitate to ask for clarification before proceeding
The fixes are specific to your problem and should only be used for this issue on this machine.
Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!


Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.


Thanks,
Astabi
Hello andyorbit,

Please do the following:

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

In your next reply I need:
Log that was saved on the desktop
MBR.dat (attached)

Thanks,
Astabi

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI