This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

could do with some help please

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi guys, im unfortunately back, with my pc which is close to being thrown in the bin (or out the window).
it started a few weeks ago, symtoms are:
-non reponsive programs Permantly
-takes a good 30mins to get online
-pages over lap each other and leave white patch in place of window
-videos are disrupted, very difficlut to watch any vid say off youtube etc
-when i close a window it starts at the top then closes in blocks downwards and all my desktop icons are missing for good 30 secs after window has gone
-no virtual memory messages

these are just a few things i can mention,ive changed my virus pro to online armor from avg, as this was taking massive amount of memory, ive disabled some of the extras on firefox, ran MB scan and spybot, done eset online scan all found nothing, just wondering if software issue if not malware any help very appriciated, and sorry if ive some to wrong section, its been a while :wub: xx

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:47:07, on 21/06/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Online Armor\OAcat.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Online Armor\oasrv.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Online Armor\a2\AVGate.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\WinPcap\rpcapd.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Online Armor\OAui.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Online Armor\OAhlp.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://format.packardbell.com/cgi-bin/redi…amp;key=IESTART
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redi…amp;key=IESTART
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\APPS\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\OAui.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1491025595-1780334667-4173316225-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=8&key=IESTART
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Online Armor\OAcat.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Online Armor\oasrv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - (no file)

–
End of file - 8177 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi Mowman thanks for your time,
TDSSKiller did not find any infections, i have posted log anyway.
📎TDSSKiller.2.5.5.0_22.06.2011_09.19.25_log.txt
📎Extras.Txt
📎OTL.Txt


OTL logfile created on: 22/06/2011 09:24:52 - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Access Granted\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

511.48 Mb Total Physical Memory | 165.29 Mb Available Physical Memory | 32.32% Memory free
1.22 Gb Paging File | 0.56 Gb Available in Paging File | 46.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 121.54 Gb Free Space | 81.55% Space Free | Partition Type: NTFS
Drive E: | 7.45 Gb Total Space | 0.94 Gb Free Space | 12.67% Space Free | Partition Type: FAT32
Drive F: | 483.56 Mb Total Space | 108.11 Mb Free Space | 22.36% Space Free | Partition Type: FAT

Computer Name: SN048919120306 | User Name: Access Granted | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Access Granted\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - C:\Program Files\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsi Software GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
PRC - C:\Program Files\Online Armor\a2\avgate.exe (Emsi Software GmbH)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\system32\slserv.exe (Smart Link)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Access Granted\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Online Armor\oawatch.dll (Emsi Software GmbH)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wtsapi32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\winsta.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (VCSSecS) Virtual CD v4 Security service (SDK - Version) – File not found
SRV - (AppMgmt) – File not found
SRV - (AffinegyService) – File not found
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\OAcat.exe (Emsi Software GmbH)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (SLService) – C:\WINDOWS\System32\slserv.exe (Smart Link)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (RapportCerberus_26762) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (oahlpXX) – C:\WINDOWS\system32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\WINDOWS\system32\drivers\OAnet.sys (Emsisoft)
DRV - (OADevice) – C:\WINDOWS\system32\drivers\OADriver.sys ()
DRV - (OAmon) – C:\WINDOWS\system32\drivers\OAmon.sys (Emsisoft)
DRV - (Sftvol) – C:\WINDOWS\system32\drivers\Sftvolxp.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\WINDOWS\system32\drivers\Sftredirxp.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\WINDOWS\system32\drivers\Sftplayxp.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\WINDOWS\system32\drivers\Sftfsxp.sys (Microsoft Corporation)
DRV - (AFGSp50) – C:\WINDOWS\system32\drivers\AFGSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys (Smart Link)
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Smart Link)
DRV - (Slntamr) – C:\WINDOWS\system32\drivers\slntamr.sys (Smart Link)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys (Smart Link)
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys (Smart Link)
DRV - (RecAgent) – C:\WINDOWS\system32\DRIVERS\RecAgent.sys (Smart Link)
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys (Smart Link)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (vcsmpdrv) – C:\WINDOWS\system32\drivers\vcsmpdrv.sys (H+H Software GmbH)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redi…amp;key=IESTART
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://format.packardbell.com/cgi-bin/redi…amp;key=IESTART
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7
FF - prefs.js..extensions.enabledItems: avg@igeared:6.011.025.001
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4de2a7dd&v;=7.004.022.004&i;=26&tp;=ab&iy;=&ychte;=uk&lng;=en-GB&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/26 23:07:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/26 23:07:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/03 22:27:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/03 12:57:50 | 000,000,000 | —D | M]

[2011/01/19 17:57:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Access Granted\Application Data\Mozilla\Extensions
[2011/06/21 14:43:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Access Granted\Application Data\Mozilla\Firefox\Profiles\5euyt50z.default\extensions
[2011/01/23 21:56:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Access Granted\Application Data\Mozilla\Firefox\Profiles\5euyt50z.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/29 17:54:55 | 000,000,000 | —D | M] (YouTube to MP3) – C:\Documents and Settings\Access Granted\Application Data\Mozilla\Firefox\Profiles\5euyt50z.default\extensions\[removed]
[2011/06/02 14:53:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/03 12:57:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/02 14:53:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\ACCESS GRANTED\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5EUYT50Z.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\ACCESS GRANTED\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5EUYT50Z.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\ACCESS GRANTED\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5EUYT50Z.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\ACCESS GRANTED\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5EUYT50Z.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\ACCESS GRANTED\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5EUYT50Z.DEFAULT\EXTENSIONS\[removed]
[2011/05/03 12:57:07 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/26 16:39:22 | 000,000,000 | —D | M] (OneClick YouTube Downloader) – C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ONECLICKYOUTUBEDOWNLOADER
[2011/05/03 22:27:16 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 09:00:00 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/06/06 17:10:32 | 000,434,784 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14965 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\APPS\BAE\BAE.DLL (Your Company Name)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\OAui.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 57344
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 57344
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Access Granted\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Access Granted\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\Iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\Iyvu9_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (61093680697573376)

========== Files/Folders - Created Within 30 Days ==========

[2011/06/22 09:21:36 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Access Granted\Desktop\OTL.exe
[2011/06/22 09:19:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Desktop\tdsskiller
[2011/06/21 14:45:54 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/06/21 14:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Start Menu\Programs\HiJackThis
[2011/06/20 17:16:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/06/20 15:01:13 | 000,000,000 | —D | C] – C:\Program Files\NCH Swift Sound
[2011/06/20 15:01:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\NCH Swift Sound
[2011/06/20 14:38:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\My Documents\AltoMP3
[2011/06/20 14:24:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Akamai
[2011/06/20 13:50:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\Audacity
[2011/06/20 10:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Local Settings\Application Data\Trusteer
[2011/06/20 10:18:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\Trusteer
[2011/06/20 10:18:04 | 000,000,000 | —D | C] – C:\Program Files\Trusteer
[2011/06/20 10:18:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Rapport
[2011/06/20 10:16:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2011/06/16 20:41:33 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/06/16 20:41:28 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2011/06/16 20:36:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\ElevatedDiagnostics
[2011/06/16 16:50:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2011/06/16 16:48:59 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2011/06/15 22:21:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/06/15 22:19:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/06/15 22:18:48 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspt.dll
[2011/06/15 22:18:48 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsnl.dll
[2011/06/15 22:18:48 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsru.dll
[2011/06/15 22:18:48 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsptb.dll
[2011/06/15 22:18:48 | 000,266,240 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsko.dll
[2011/06/15 22:18:48 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrstr.dll
[2011/06/15 22:18:48 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssl.dll
[2011/06/15 22:18:48 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssk.dll
[2011/06/15 22:18:48 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspl.dll
[2011/06/15 22:18:48 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsth.dll
[2011/06/15 22:18:48 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssv.dll
[2011/06/15 22:18:48 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsno.dll
[2011/06/15 22:18:48 | 000,229,376 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszhc.dll
[2011/06/15 22:18:48 | 000,126,976 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszht.dll
[2011/06/15 22:18:47 | 000,335,872 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsar.dll
[2011/06/15 22:18:47 | 000,331,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshe.dll
[2011/06/15 22:18:47 | 000,286,720 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfr.dll
[2011/06/15 22:18:47 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsit.dll
[2011/06/15 22:18:47 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrses.dll
[2011/06/15 22:18:47 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsel.dll
[2011/06/15 22:18:47 | 000,278,528 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsde.dll
[2011/06/15 22:18:47 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsesm.dll
[2011/06/15 22:18:47 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsja.dll
[2011/06/15 22:18:47 | 000,262,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshu.dll
[2011/06/15 22:18:47 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsda.dll
[2011/06/15 22:18:47 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfi.dll
[2011/06/15 22:18:47 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrseng.dll
[2011/06/15 22:18:47 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrscs.dll
[2011/06/15 22:18:47 | 000,145,000 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcolor.exe
[2011/06/15 22:18:46 | 013,895,272 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcpl.dll
[2011/06/15 22:18:46 | 000,111,208 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvmctray.dll
[2011/06/15 22:18:41 | 000,543,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/06/15 22:18:41 | 000,054,272 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvwddi.dll
[2011/06/15 22:16:08 | 000,899,688 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco3220150.dll
[2011/06/15 22:16:08 | 000,865,896 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco322090.dll
[2011/06/09 20:10:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/06/09 20:09:26 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/06/09 11:48:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\OnlineArmor
[2011/06/09 11:48:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\OnlineArmor
[2011/06/09 11:48:13 | 000,025,192 | —- | C] (Emsisoft) – C:\WINDOWS\System32\drivers\OAmon.sys
[2011/06/09 11:48:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Online Armor
[2011/06/09 11:48:12 | 000,029,464 | —- | C] (Emsisoft) – C:\WINDOWS\System32\drivers\OAnet.sys
[2011/06/09 11:48:07 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2011/06/06 11:14:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\AVG
[2011/06/06 11:12:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/06/03 12:25:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\Auslogics
[2011/06/03 12:25:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2011/06/03 12:24:53 | 000,000,000 | —D | C] – C:\Program Files\Auslogics
[2011/06/03 11:46:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Access Granted\Start Menu\Programs\Administrative Tools
[2011/06/02 15:03:07 | 000,000,000 | —D | C] – C:\Program Files\SystemRequirementsLab
[2011/06/02 14:53:53 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/02 14:53:53 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/02 14:53:53 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/02 14:22:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab
[2011/05/31 12:33:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\WinPatrol
[2011/05/31 12:32:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinPatrol
[2011/05/31 12:32:44 | 000,000,000 | —D | C] – C:\Program Files\BillP Studios
[2011/05/31 12:32:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/05/31 12:21:19 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/05/26 16:39:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\ProgSense
[2011/05/26 16:39:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\GrabPro
[2011/05/26 16:39:27 | 000,000,000 | —D | C] – C:\downloads
[2011/05/26 16:39:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Orbit
[2011/05/26 16:39:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Local Settings\Application Data\OpenCandy
[2011/05/26 16:39:19 | 000,000,000 | —D | C] – C:\Program Files\Orbitdownloader
[2011/05/26 16:39:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\Orbit
[2011/05/26 16:39:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\OpenCandy
[2 C:\Documents and Settings\Access Granted\My Documents\*.tmp files -> C:\Documents and Settings\Access Granted\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/22 09:21:37 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Access Granted\Desktop\OTL.exe
[2011/06/22 09:17:47 | 001,309,375 | —- | M] () – C:\Documents and Settings\Access Granted\Desktop\tdsskiller.zip
[2011/06/22 09:07:20 | 000,001,557 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/06/22 09:04:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/22 09:03:58 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2011/06/21 14:46:10 | 000,002,465 | —- | M] () – C:\Documents and Settings\Access Granted\Desktop\HiJackThis.lnk
[2011/06/21 14:28:06 | 000,018,944 | —- | M] () – C:\Documents and Settings\Access Granted\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/21 13:29:52 | 001,190,999 | —- | M] () – C:\Documents and Settings\Access Granted\My Documents\Extended%20Services%20Whole%20of%20Blackpool%20Template.pdf
[2011/06/20 22:22:53 | 000,273,344 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/06/20 22:22:53 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/06/20 22:22:40 | 000,273,344 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/06/20 18:26:18 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\switchShakeIcon.job
[2011/06/20 15:01:23 | 000,000,805 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Switch Sound File Converter.lnk
[2011/06/20 13:31:49 | 000,001,056 | —- | M] () – C:\Documents and Settings\Access Granted\Desktop\Shortcut to iTunes Library.lnk
[2011/06/20 10:37:51 | 000,073,728 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCFDRTM.VER
[2011/06/18 21:17:18 | 000,435,840 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/18 21:17:18 | 000,069,572 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/16 21:18:13 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/06/16 19:33:14 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/15 22:18:30 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/06/15 21:47:21 | 000,000,281 | -HS- | M] () – C:\BOOT.INI
[2011/06/12 21:23:03 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/09 20:10:33 | 000,001,545 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/06/06 17:10:32 | 000,434,784 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/06/06 16:36:58 | 000,164,272 | —- | M] () – C:\Documents and Settings\Access Granted\My Documents\http___www.studentfinance.direct.gov.uk_pls_portal_docs_PAGE_DPIPG001_DPIPS
001_SFE_CCG1_1112.PDF_backtoPage=https___secure.studentfinance.direct.gov.uk_prot
ocol_1112_pages_EvidenceTracking.pdf
[2011/05/31 15:52:53 | 000,434,580 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20110606-171032.backup
[2011/05/26 16:45:12 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/26 16:39:24 | 000,000,747 | —- | M] () – C:\Documents and Settings\Access Granted\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/05/26 16:39:23 | 000,000,729 | —- | M] () – C:\Documents and Settings\Access Granted\Desktop\Orbit.lnk
[2011/05/25 08:26:15 | 000,054,272 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvwddi.dll
[2011/05/25 08:26:14 | 000,274,432 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspt.dll
[2011/05/25 08:26:14 | 000,270,336 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsru.dll
[2011/05/25 08:26:14 | 000,270,336 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsptb.dll
[2011/05/25 08:26:14 | 000,258,048 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrstr.dll
[2011/05/25 08:26:14 | 000,258,048 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssl.dll
[2011/05/25 08:26:14 | 000,258,048 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssk.dll
[2011/05/25 08:26:14 | 000,258,048 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspl.dll
[2011/05/25 08:26:14 | 000,253,952 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsth.dll
[2011/05/25 08:26:14 | 000,253,952 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssv.dll
[2011/05/25 08:26:14 | 000,253,952 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsno.dll
[2011/05/25 08:26:14 | 000,229,376 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszhc.dll
[2011/05/25 08:26:14 | 000,126,976 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszht.dll
[2011/05/25 08:26:13 | 000,282,624 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsit.dll
[2011/05/25 08:26:13 | 000,274,432 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsnl.dll
[2011/05/25 08:26:13 | 000,270,336 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsja.dll
[2011/05/25 08:26:13 | 000,266,240 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsko.dll
[2011/05/25 08:26:13 | 000,262,144 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshu.dll
[2011/05/25 08:26:12 | 000,331,776 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshe.dll
[2011/05/25 08:26:12 | 000,286,720 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfr.dll
[2011/05/25 08:26:12 | 000,249,856 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfi.dll
[2011/05/25 08:26:11 | 000,282,624 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrses.dll
[2011/05/25 08:26:11 | 000,282,624 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsel.dll
[2011/05/25 08:26:11 | 000,278,528 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsde.dll
[2011/05/25 08:26:11 | 000,274,432 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsesm.dll
[2011/05/25 08:26:11 | 000,249,856 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrseng.dll
[2011/05/25 08:26:10 | 000,335,872 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsar.dll
[2011/05/25 08:26:10 | 000,253,952 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsda.dll
[2011/05/25 08:26:10 | 000,249,856 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrscs.dll
[2011/05/25 08:26:09 | 000,111,208 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvmctray.dll
[2011/05/25 08:26:03 | 013,895,272 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcpl.dll
[2011/05/25 08:26:01 | 000,145,000 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcolor.exe
[2011/05/25 08:26:00 | 000,543,336 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/05/25 08:25:58 | 016,068,608 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvoglnt.dll
[2011/05/25 08:25:58 | 000,061,440 | —- | M] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/05/25 08:25:57 | 013,004,800 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/05/25 08:25:57 | 005,332,992 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuda.dll
[2011/05/25 08:25:57 | 002,808,936 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/05/25 08:25:57 | 002,123,582 | —- | M] () – C:\WINDOWS\System32\nvdata.data
[2011/05/25 08:25:57 | 002,082,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/05/25 08:25:57 | 000,899,688 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco3220150.dll
[2011/05/25 08:25:57 | 000,865,896 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco322090.dll
[2011/05/25 08:25:57 | 000,003,249 | —- | M] () – C:\WINDOWS\System32\nvinfo.pb
[2011/05/25 08:25:56 | 012,753,664 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv4_mini.sys
[2011/05/25 08:25:56 | 004,198,272 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nv4_disp.dll
[2011/05/25 08:25:56 | 002,328,576 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvapi.dll
[2 C:\Documents and Settings\Access Granted\My Documents\*.tmp files -> C:\Documents and Settings\Access Granted\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/22 09:17:46 | 001,309,375 | —- | C] () – C:\Documents and Settings\Access Granted\Desktop\tdsskiller.zip
[2011/06/21 14:45:55 | 000,002,465 | —- | C] () – C:\Documents and Settings\Access Granted\Desktop\HiJackThis.lnk
[2011/06/21 13:29:52 | 001,190,999 | —- | C] () – C:\Documents and Settings\Access Granted\My Documents\Extended%20Services%20Whole%20of%20Blackpool%20Template.pdf
[2011/06/20 22:18:56 | 000,003,249 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2011/06/20 18:26:15 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\switchShakeIcon.job
[2011/06/20 15:01:23 | 000,000,811 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Switch Sound File Converter.lnk
[2011/06/20 15:01:23 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Switch Sound File Converter.lnk
[2011/06/20 13:31:49 | 000,001,056 | —- | C] () – C:\Documents and Settings\Access Granted\Desktop\Shortcut to iTunes Library.lnk
[2011/06/16 17:16:58 | 000,001,557 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/06/15 22:18:30 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/06/15 22:18:30 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/06/15 22:18:30 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/06/15 22:18:30 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/06/15 22:16:07 | 002,123,582 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/06/09 20:10:33 | 000,001,545 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/06/09 11:48:13 | 000,039,048 | —- | C] () – C:\WINDOWS\System32\drivers\oahlp32.sys
[2011/06/09 11:48:12 | 000,205,864 | —- | C] () – C:\WINDOWS\System32\drivers\OADriver.sys
[2011/06/06 16:36:58 | 000,164,272 | —- | C] () – C:\Documents and Settings\Access Granted\My Documents\http___www.studentfinance.direct.gov.uk_pls_portal_docs_PAGE_DPIPG001_DPIPS
001_SFE_CCG1_1112.PDF_backtoPage=https___secure.studentfinance.direct.gov.uk_prot
ocol_1112_pages_EvidenceTracking.pdf
[2011/05/26 16:39:24 | 000,000,747 | —- | C] () – C:\Documents and Settings\Access Granted\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/05/26 16:39:23 | 000,000,729 | —- | C] () – C:\Documents and Settings\Access Granted\Desktop\Orbit.lnk
[2011/04/27 20:05:19 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2011/02/18 16:23:10 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2011/02/15 22:15:37 | 000,000,158 | —- | C] () – C:\Documents and Settings\Access Granted\Application Data\wklnhst.dat
[2011/01/21 18:41:51 | 000,000,030 | —- | C] () – C:\WINDOWS\iedit.INI
[2011/01/21 18:35:19 | 000,018,944 | —- | C] () – C:\Documents and Settings\Access Granted\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/19 17:36:07 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/01/13 15:49:18 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2011/01/13 15:46:06 | 000,003,439 | —- | C] () – C:\WINDOWS\mozver.dat
[2011/01/13 15:42:25 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/01/13 15:39:24 | 000,000,514 | —- | C] () – C:\WINDOWS\System32\SETUPPC.INI
[2011/01/13 15:33:42 | 000,007,584 | —- | C] () – C:\WINDOWS\HDReg.ini
[2011/01/13 15:32:28 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/01/13 15:17:47 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\RTCOMDLL.dll
[2011/01/13 15:17:47 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2011/01/13 15:17:47 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2005/05/20 15:05:02 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/05/12 14:24:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 18:13:32 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 18:03:24 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 17:55:57 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 17:48:11 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 17:46:35 | 000,251,088 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 17:38:12 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 17:38:09 | 000,435,840 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 17:38:09 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 17:38:09 | 000,069,572 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 17:38:09 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 17:38:08 | 000,004,541 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 17:38:06 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 17:38:04 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 17:37:57 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 17:37:57 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 17:37:48 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 17:37:40 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2011/06/20 14:12:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Audacity
[2011/06/03 12:34:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Auslogics
[2011/06/06 11:18:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\AVG
[2011/02/24 18:20:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\AVG10
[2011/06/16 20:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\ElevatedDiagnostics
[2011/05/26 19:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\GrabPro
[2011/03/26 13:43:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Leadertech
[2011/01/26 23:07:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Local
[2011/06/20 15:01:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\NCH Swift Sound
[2011/01/20 22:04:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\OD2
[2011/06/09 11:49:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\OnlineArmor
[2011/05/26 16:39:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\OpenCandy
[2011/06/22 09:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Orbit
[2011/05/12 22:46:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\PhotoScape
[2011/05/26 16:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\ProgSense
[2011/05/26 00:34:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\SoftGrid Client
[2011/06/15 21:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab
[2011/02/15 22:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Template
[2011/05/19 12:46:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\TP
[2011/06/20 10:18:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Trusteer
[2011/01/19 22:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\Ulead Systems
[2011/05/31 12:33:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\WinPatrol
[2011/01/29 20:28:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Access Granted\Application Data\{90140011-0061-0409-0000-0000000FF1CE}
[2011/02/18 16:23:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Affinegy
[2011/06/09 12:11:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/02/24 18:17:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/05/31 12:32:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/06/09 11:39:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/06/20 17:16:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/01/13 15:37:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OD2
[2011/06/09 12:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OnlineArmor
[2011/06/07 00:10:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/20 10:16:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2011/01/13 15:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/01/13 15:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/01/29 20:28:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Virtualized Applications
[2011/04/25 22:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2011/01/30 15:09:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/06/20 18:26:18 | 000,000,296 | —- | M] () – C:\WINDOWS\Tasks\switchShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/01/13 15:28:50 | 000,000,210 | RHS- | M] () – C:\BOOT.BAK
[2011/06/15 21:47:21 | 000,000,281 | -HS- | M] () – C:\BOOT.INI
[2004/08/04 15:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/01/13 16:07:20 | 000,006,569 | —- | M] () – C:\DWNLOG.TXT
[2011/06/22 09:03:58 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2011/01/13 15:31:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/01/13 15:33:19 | 000,000,886 | -H– | M] () – C:\IPH.PH
[2011/04/27 23:55:48 | 005,748,345 | —- | M] () – C:\Lemmings.log
[2011/01/13 16:07:20 | 000,006,569 | —- | M] () – C:\MCDLOG.TXT
[2011/01/13 15:31:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 15:00:00 | 000,047,564 | —- | M] () – C:\NTDETECT.COM
[2011/01/29 20:01:49 | 000,250,048 | —- | M] () – C:\NTLDR
[2011/06/22 09:03:57 | 804,495,360 | -HS- | M] () – C:\pagefile.sys
[2011/06/22 09:21:25 | 000,051,046 | —- | M] () – C:\TDSSKiller.2.5.5.0_22.06.2011_09.19.25_log.txt
[2011/01/13 16:07:20 | 000,000,000 | —- | M] () – C:\UPDFLOP.TAG

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 17:58:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 17:46:06 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 17:46:06 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 17:46:06 | 000,847,872 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/01/29 20:05:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2004/06/09 15:26:16 | 000,005,120 | —- | M] () – C:\WINDOWS\system32\THUMBS.DB
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/01/29 20:18:17 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Access Granted\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 18:04:54 | 000,000,079 | —- | M] () – C:\Documents and Settings\Access Granted\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/06/22 09:21:37 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Access Granted\Desktop\OTL.exe
[2011/01/19 17:29:52 | 001,029,000 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\Access Granted\Desktop\SkypeSetup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/01/29 20:18:17 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Access Granted\Favorites\Desktop.ini
[2011/06/20 15:01:34 | 000,000,260 | —- | M] () – C:\Documents and Settings\Access Granted\Favorites\NCH Software Download Site.lnk
[2011/01/26 23:21:49 | 000,000,258 | —- | M] () – C:\Documents and Settings\Access Granted\Favorites\NCH Software Download.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/06/22 09:07:40 | 000,049,152 | —- | M] () – C:\Documents and Settings\Access Granted\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-18 20:17:45

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B

< End of report >






OTL Extras logfile created on: 22/06/2011 09:24:52 - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Access Granted\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

511.48 Mb Total Physical Memory | 165.29 Mb Available Physical Memory | 32.32% Memory free
1.22 Gb Paging File | 0.56 Gb Available in Paging File | 46.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 121.54 Gb Free Space | 81.55% Space Free | Partition Type: NTFS
Drive E: | 7.45 Gb Total Space | 0.94 Gb Free Space | 12.67% Space Free | Partition Type: FAT32
Drive F: | 483.56 Mb Total Space | 108.11 Mb Free Space | 22.36% Space Free | Partition Type: FAT

Computer Name: SN048919120306 | User Name: Access Granted | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" = C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe:LocalSubNet:Enabled:Wireless Manager – (Affinegy LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%ProgramFiles%\AOL 9.0\aol.exe" = %ProgramFiles%\AOL 9.0\aol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" = C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe:LocalSubNet:Enabled:Wireless Manager – (Affinegy LLC)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 25
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A065EA0-0EEC-4E94-A2A0-40812576C122}" = Ulead PhotoImpact 10 SE
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}" = Macromedia Shockwave Player
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0061-0409-0000-0000000FF1CE}" = Microsoft Office Home and Student 2010 - English
"{90140011-0062-0409-0000-0000000FF1CE}" = Microsoft Office Home and Business 2010 - English
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{92482FB3-C05B-41C6-89E7-75D985602A6E}" = System Requirements Lab
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.85
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"2B0D8F3C-18AD-4D8E-879A-74A867C5C3CB_is1" = Wireless Manager
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"DivX Setup.divx.com" = DivX Setup
"ESET Online Scanner" = ESET Online Scanner v3
"GameSpy Arcade" = GameSpy Arcade
"Indeo® software" = Indeo® software
"Lemmings Revolution" = Lemmings Revolution
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0.1 (x86 en-GB)" = Mozilla Firefox 4.0.1 (x86 en-GB)
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"OnlineArmor_is1" = Online Armor 5.0
"Orbit_is1" = Orbit Downloader
"PhotoScape" = PhotoScape
"Picasa2" = Picasa 2
"Prism" = Prism Video File Converter
"Rapport_msi" = Rapport
"SpywareBlaster_is1" = SpywareBlaster 4.4
"Switch" = Switch Sound File Converter
"SystemRequirementsLab" = System Requirements Lab
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 20/06/2011 09:56:29 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1001
Description = Fault bucket -1896177309.

Error - 20/06/2011 09:56:29 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1001
Description = Fault bucket -1896177309.

Error - 20/06/2011 09:56:29 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1001
Description = Fault bucket -1896177309.

Error - 20/06/2011 09:56:29 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1001
Description = Fault bucket -1896177309.

Error - 20/06/2011 10:04:10 | Computer Name = SN048919120306 | Source = Application Error | ID = 1000
Description = Faulting application switch.exe, version 0.0.0.0, faulting module
ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.

Error - 20/06/2011 12:13:30 | Computer Name = SN048919120306 | Source = Application Error | ID = 1001
Description = Fault bucket -1799807627.

Error - 20/06/2011 17:20:01 | Computer Name = SN048919120306 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 20/06/2011 17:20:05 | Computer Name = SN048919120306 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 21/06/2011 09:33:12 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1002
Description = Hanging application prism.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21/06/2011 09:33:24 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1001
Description = Fault bucket 11474549.

[ System Events ]
Error - 20/06/2011 06:51:44 | Computer Name = SN048919120306 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.4 for the Network Card with network
address 001485778F4D has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 20/06/2011 17:29:10 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The AffinegyService service failed to start due to the following error:
%%3

Error - 20/06/2011 17:29:10 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The Virtual CD v4 Security service (SDK - Version) service failed
to start due to the following error: %%3

Error - 20/06/2011 17:30:03 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.

Error - 21/06/2011 05:50:50 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The AffinegyService service failed to start due to the following error:
%%3

Error - 21/06/2011 05:50:50 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The Virtual CD v4 Security service (SDK - Version) service failed
to start due to the following error: %%3

Error - 21/06/2011 17:11:27 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The AffinegyService service failed to start due to the following error:
%%3

Error - 21/06/2011 17:11:27 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The Virtual CD v4 Security service (SDK - Version) service failed
to start due to the following error: %%3

Error - 22/06/2011 04:05:04 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The AffinegyService service failed to start due to the following error:
%%3

Error - 22/06/2011 04:05:04 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The Virtual CD v4 Security service (SDK - Version) service failed
to start due to the following error: %%3


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
📎ComboFix.txt ComboFix 11-06-21.08 - Access Granted 22/06/2011 12:01:52.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.296 [GMT 1:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: Online Armor ++ *Disabled/Updated* {8A358D6D-9E8B-4685-9491-3F4817DF49A8} FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66} FW: Online Armor Firewall *Disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A} ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Documents and Settings\Access Granted\Application Data\Local C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(2).ddr C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(3).ddr C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(4).ddr C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(5).ddr C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(6).ddr C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\.ddr C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\0.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\1.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\2.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\3.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\4.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\5.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\settings.ddi C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(2).ddp C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(3).ddp C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(4).ddp C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(5).ddp C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(6).ddp C:\Documents and Settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab\srlproxy_cyri_4.1.72.0A.dll C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll C:\Documents and Settings\Access Granted\Application Data\SystemRequirementsLab\SystemRequirmentsLab_cyri_4.1.72.0.msi C:\Program Files\WinPCap C:\Program Files\WinPCap\daemon_mgm.exe C:\Program Files\WinPCap\npf_mgm.exe C:\Program Files\WinPCap\rpcapd.exe C:\WINDOWS\system32\drivers\npf.sys C:\WINDOWS\system32\Packet.dll C:\WINDOWS\system32\pthreadVC.dll C:\WINDOWS\system32\Thumbs.db C:\WINDOWS\system32\WanPacket.dll C:\WINDOWS\system32\wpcap.dll ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_NPF ——-\Service_NPF ((((((((((((((((((((((((( Files Created from 2011-05-22 to 2011-06-22 )))))))))))))))))))))))))))))))
ComboFix 11-06-21.08 - Access Granted 22/06/2011 13:30:47.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.286 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Online Armor ++ *Disabled/Updated* {8A358D6D-9E8B-4685-9491-3F4817DF49A8}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: Online Armor Firewall *Disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(2).ddr
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(3).ddr
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(4).ddr
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(5).ddr
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\(6).ddr
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\.ddr
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\0.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\1.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\2.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\3.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\4.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\5.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\settings.ddi
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(2).ddp
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(3).ddp
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(4).ddp
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(5).ddp
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\(6).ddp
c:\documents and settings\Access Granted\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp
c:\documents and settings\Access Granted\Application Data\SystemRequirementsLab\srlproxy_cyri_4.1.72.0A.dll
c:\documents and settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
c:\documents and settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
c:\documents and settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
c:\documents and settings\Access Granted\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
c:\documents and settings\Access Granted\Application Data\SystemRequirementsLab\SystemRequirmentsLab_cyri_4.1.72.0.msi
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\Thumbs.db
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-05-22 to 2011-06-22 )))))))))))))))))))))))))))))))
.
.
2011-06-21 13:45 . 2011-06-21 13:45 388096 —-a-r- c:\documents and settings\Access Granted\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-06-21 13:45 . 2011-06-21 13:45 ——– d—–w- c:\program files\Trend Micro
2011-06-20 16:16 . 2011-06-20 16:16 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2011-06-20 14:01 . 2011-06-20 14:01 ——– d—–w- c:\program files\NCH Swift Sound
2011-06-20 14:01 . 2011-06-20 14:01 ——– d—–w- c:\documents and settings\Access Granted\Application Data\NCH Swift Sound
2011-06-20 13:24 . 2011-06-20 21:28 ——– d—–w- c:\program files\Common Files\Akamai
2011-06-20 12:50 . 2011-06-20 13:12 ——– d—–w- c:\documents and settings\Access Granted\Application Data\Audacity
2011-06-20 09:19 . 2011-06-20 09:19 ——– d—–w- c:\documents and settings\Access Granted\Local Settings\Application Data\Trusteer
2011-06-20 09:18 . 2011-06-20 09:18 ——– d—–w- c:\documents and settings\Access Granted\Application Data\Trusteer
2011-06-20 09:18 . 2011-06-20 09:18 ——– d—–w- c:\program files\Trusteer
2011-06-20 09:16 . 2011-06-20 09:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Trusteer
2011-06-16 19:41 . 2011-04-21 13:37 105472 ——w- c:\windows\system32\dllcache\mup.sys
2011-06-16 19:41 . 2011-04-29 19:07 852480 ——w- c:\windows\system32\dllcache\vgx.dll
2011-06-16 19:36 . 2011-06-16 19:36 ——– d—–w- c:\documents and settings\Access Granted\Application Data\ElevatedDiagnostics
2011-06-15 21:21 . 2011-06-15 21:21 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2011-06-15 21:19 . 2011-06-15 21:19 ——– d—–w- c:\documents and settings\UpdatusUser
2011-06-15 21:19 . 2011-06-15 21:19 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA
2011-06-15 21:16 . 2011-05-25 07:25 899688 —-a-w- c:\windows\system32\nvdispco3220150.dll
2011-06-15 21:16 . 2011-05-25 07:25 865896 —-a-w- c:\windows\system32\nvgenco322090.dll
2011-06-09 19:09 . 2011-06-09 19:09 ——– d—–w- c:\program files\iPod
2011-06-09 10:48 . 2011-06-09 11:16 ——– d—–w- c:\documents and settings\All Users\Application Data\OnlineArmor
2011-06-09 10:48 . 2011-06-09 10:49 ——– d—–w- c:\documents and settings\Access Granted\Application Data\OnlineArmor
2011-06-09 10:48 . 2011-04-06 12:02 39048 —-a-w- c:\windows\system32\drivers\oahlp32.sys
2011-06-09 10:48 . 2011-04-06 12:01 25192 —-a-w- c:\windows\system32\drivers\OAmon.sys
2011-06-09 10:48 . 2011-04-06 12:01 29464 —-a-w- c:\windows\system32\drivers\OAnet.sys
2011-06-09 10:48 . 2011-04-06 12:01 205864 —-a-w- c:\windows\system32\drivers\OADriver.sys
2011-06-09 10:48 . 2011-06-22 11:20 ——– d—–w- c:\program files\Online Armor
2011-06-03 11:25 . 2011-06-03 11:34 ——– d—–w- c:\documents and settings\Access Granted\Application Data\Auslogics
2011-06-03 11:24 . 2011-06-04 09:55 ——– d—–w- c:\program files\Auslogics
2011-06-02 14:03 . 2011-06-15 21:06 ——– d—–w- c:\program files\SystemRequirementsLab
2011-05-31 11:33 . 2011-05-31 11:33 ——– d—–w- c:\documents and settings\Access Granted\Application Data\WinPatrol
2011-05-31 11:32 . 2011-05-31 11:32 ——– d—–w- c:\program files\BillP Studios
2011-05-31 11:32 . 2011-05-31 11:32 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallMate
2011-05-26 15:39 . 2011-05-26 15:39 ——– d—–w- c:\documents and settings\Access Granted\Application Data\ProgSense
2011-05-26 15:39 . 2011-06-17 08:05 ——– d—–w- C:\downloads
2011-05-26 15:39 . 2011-05-26 18:25 ——– d—–w- c:\documents and settings\Access Granted\Application Data\GrabPro
2011-05-26 15:39 . 2011-05-26 20:34 ——– d—–w- c:\documents and settings\Access Granted\Local Settings\Application Data\OpenCandy
2011-05-26 15:39 . 2011-06-22 11:14 ——– d—–w- c:\documents and settings\Access Granted\Application Data\Orbit
2011-05-26 15:39 . 2011-05-26 15:39 ——– d—–w- c:\program files\Orbitdownloader
2011-05-26 15:39 . 2011-05-26 15:39 ——– d—–w- c:\documents and settings\Access Granted\Application Data\OpenCandy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-20 09:37 . 2011-01-20 20:24 73728 —-a-w- c:\windows\ALCFDRTM.VER
2011-05-26 15:45 . 2011-05-18 15:22 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-25 07:25 . 2011-01-13 15:03 61440 —-a-w- c:\windows\system32\OpenCL.dll
2011-05-25 07:25 . 2011-01-13 15:03 16068608 —-a-w- c:\windows\system32\nvoglnt.dll
2011-05-25 07:25 . 2011-01-13 15:03 2082408 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-05-25 07:25 . 2011-01-13 15:03 5332992 —-a-w- c:\windows\system32\nvcuda.dll
2011-05-25 07:25 . 2011-01-13 15:03 13004800 —-a-w- c:\windows\system32\nvcompiler.dll
2011-05-25 07:25 . 2011-01-13 15:03 2808936 —-a-w- c:\windows\system32\nvcuvid.dll
2011-05-25 07:25 . 2011-01-13 15:03 4198272 —-a-w- c:\windows\system32\nv4_disp.dll
2011-05-25 07:25 . 2011-01-13 15:03 2328576 —-a-w- c:\windows\system32\nvapi.dll
2011-05-25 07:25 . 2011-01-13 15:03 12753664 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-05-02 15:31 . 2004-08-10 16:56 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2004-08-10 16:37 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-28 13:34 . 2011-04-28 13:34 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-04-25 14:47 . 2004-08-10 16:38 667136 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 14:47 . 2004-08-10 16:38 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-04-25 14:47 . 2004-08-10 16:37 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-04-25 12:56 . 2004-08-10 16:37 369664 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2004-08-10 16:38 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-04-14 04:07 . 2011-05-03 11:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-14 01:40 . 2011-05-03 11:57 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-04-06 15:20 . 2011-04-06 15:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-05-03 21:27 . 2011-04-25 21:48 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-15 2557952]
"@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2011-06-10 2477544]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-05-25 13895272]
"NvMediaCenter"="NvMCTray.dll" [2011-05-25 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-05-04 1632360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2011-5-26 1843000]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-07 16:51 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2006-03-15 23:07 421888 —-a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 17:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-09-10 18:29 77824 —-a-w- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-01-07 12:12 253672 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-01-13 14:38 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Manager]
2007-10-16 17:57 585728 —-a-w- c:\program files\Virgin Broadband Wireless\Wireless Manager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL ACS"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\APPS\\SKYPE\\Phone\\Skype.exe"=
"c:\\APPS\\skype\\Plugin Manager\\skypePM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [28/04/2011 14:34 53816]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [09/06/2011 11:48 205864]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [09/06/2011 11:48 25192]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [09/06/2011 11:48 29464]
R1 RapportCerberus_26762;RapportCerberus_26762;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys [20/06/2011 10:18 57144]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [28/04/2011 14:34 66360]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [28/04/2011 14:34 158904]
R1 vcsmpdrv;vcsmpdrv;c:\windows\system32\drivers\vcsmpdrv.sys [13/01/2011 15:42 49024]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 03:33 821664]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [15/06/2011 22:19 2214504]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [09/06/2011 11:48 381512]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [28/04/2011 14:34 870200]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 02:10 483688]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 23:23 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 23:23 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 23:23 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 23:23 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 02:10 209768]
S1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [09/06/2011 11:48 39048]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [09/06/2011 11:48 4326472]
S2 VCSSecS;Virtual CD v4 Security service (SDK - Version); [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 11:50]
.
2011-06-20 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2011-06-20 14:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=8&key=IESTART
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Access Granted\Application Data\Mozilla\Firefox\Profiles\5euyt50z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4de2a7dd&v=7.004.022.004&i=26&tp=ab&iy=&ychte=uk&lng=en-GB&q=
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-22 13:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-06-22 13:40:43
ComboFix-quarantined-files.txt 2011-06-22 12:40
.
Pre-Run: 130,932,539,392 bytes free
Post-Run: 130,886,586,368 bytes free
.
- - End Of File - - FF3D250E503BD44AD9D0D2185ABA42BA
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    [2011/06/06 11:14:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Access Granted\Application Data\AVG
    [2011/06/06 11:12:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
    [2011/06/09 12:11:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
    
    @Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
    @Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
    
    
    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )




Any improvement?
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Folder C:\Documents and Settings\Access Granted\Application Data\AVG\ not found. Folder C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011\ not found. C:\Documents and Settings\All Users\Application Data\AVG10 folder moved successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B deleted successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Access Granted ->Temp folder emptied: 313117 bytes ->Temporary Internet Files folder emptied: 1052638 bytes ->Java cache emptied: 161724 bytes ->FireFox cache emptied: 63629091 bytes ->Flash cache emptied: 6888 bytes User: Administrator ->Temp folder emptied: 16384 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->FireFox cache emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 16384 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->FireFox cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32835 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 49219 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->FireFox cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 62.00 mb OTL by OldTimer - Version 3.2.24.1 log created on 06222011_141246 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
not that i can tell, as soon as the desktop comes up and i try to open a window, it is non responsive and is still sending error reports and telling me it is firefox! do you think i should uninstall this and maybe stick to windows or another program, it also takes ages to load the pc and im wondering do i have the correct programs starting up or are there any that can stop running on startup?
I cannot see any more signs of malware in the logs and you say you have already ran ESET and MBAM so i think we are done in that respect.


511.48 Mb Total Physical Memory | 165.29 Mb Available Physical Memory | 32.32% Memory free

You do not seem to have much Ram installed so that could be the problem.You also have Spybot,Winpatrol and Spywareblaster all installed,these take up resources.You could try uninstalling all these plus any other unneeded programs and see if that helps.
hi Mowman after your reply it was brought to my attention that i only had 512mb of ram but i have 2 512mb installled in tower, i have opened it up and made sure they were both in and one musnt have been in properly, the pc has been for a new harddrive and dvd replacement so it must have been dislodged. Thanks for your time the pc is running faster now, :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI