nsnd
Topic Starter
I recently had some issues where my Google Chrome browser was redirecting me. I would search for a term using Google, and click on a result. Once I clicked the result, a new tab would open and redirect me to some random website (random to me). I ended up scanning my computer with Malwarebytes' and Avast Antivirus.
After the scans were complete, I removed the files and restarted. The redirecting seems to have stopped, but now I can't update Malwarebytes'. Since I couldn't update Malwarebytes', I tried using Super Anti Spyware. SAS won't update either. I came here and read the "Are you Infected". I decided to run the OTL program since I'd never heard of it
. Here are the two reports:
After the scans were complete, I removed the files and restarted. The redirecting seems to have stopped, but now I can't update Malwarebytes'. Since I couldn't update Malwarebytes', I tried using Super Anti Spyware. SAS won't update either. I came here and read the "Are you Infected". I decided to run the OTL program since I'd never heard of it
OTL logfile created on: 6/21/2011 3:45:46 PM - Run 1 OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Nsnd\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.99 Gb Total Physical Memory | 4.35 Gb Available Physical Memory | 72.57% Memory free 11.98 Gb Paging File | 10.00 Gb Available in Paging File | 83.45% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 448.74 Gb Total Space | 153.72 Gb Free Space | 34.26% Space Free | Partition Type: NTFS Drive D: | 16.72 Gb Total Space | 2.70 Gb Free Space | 16.17% Space Free | Partition Type: NTFS Drive E: | 99.02 Mb Total Space | 92.44 Mb Free Space | 93.35% Space Free | Partition Type: FAT32 Drive F: | 664.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: NSND-PC | User Name: Nsnd | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Nsnd\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\GoZone\GoZone_iSync.exe (Virgin HealthMiles Inc.) PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) PRC - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe () PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () PRC - C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe () PRC - C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe (Lexmark International Inc.) PRC - C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.) PRC - C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.) PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.) PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.) PRC - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.) PRC - C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe () PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) PRC - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) ========== Modules (SafeList) ========== MOD - C:\Users\Nsnd\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation) MOD - C:\Program Files (x86)\Unlocker\UnlockerHook.dll () MOD - C:\Program Files (x86)\DigitalPersona\Bin\DpOFeedb.dll (DigitalPersona, Inc.) MOD - C:\Program Files (x86)\DigitalPersona\Bin\DpOSet.dll (DigitalPersona, Inc.) ========== Win32 Services (SafeList) ========== SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company) SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe (IDT, Inc.) SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.) SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (Andrea Electronics Corporation) SRV:64bit: - (lxdn_device) – C:\Windows\SysNative\lxdncoms.exe ( ) SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (DpHost) – C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.) SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.) SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.) SRV - (ufad-ws60) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.) SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.) SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (lxdn_device) – C:\Windows\SysWow64\lxdncoms.exe ( ) SRV - (PSI_SVC_2) – C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) ========== Driver Services (SafeList) ========== DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software) DRV:64bit: - (HssDrv) – C:\Windows\SysNative\drivers\HssDrv.sys (AnchorFree Inc.) DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company) DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company) DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (HID) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation) DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (NETw5s64) Intel(R) – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation) DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.) DRV:64bit: - (vmkbd) – C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.) DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.) DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.) DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.) DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.) DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.) DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.) DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.) DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation) DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation) DRV:64bit: - (enecir) – C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.) DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.) DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.) DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.) DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell) DRV:64bit: - (netw5v64) Intel(R) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation) DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation) DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.) DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies) DRV:64bit: - (pnetmdm) – C:\Windows\SysNative\drivers\pnetmdm64.sys (June Fabrics Technology) DRV - (vstor2-ws60) – C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.) DRV - (ISODrive) – C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys (EZB Systems, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://apps.ko.com/myko IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/29 19:02:24 | 000,000,000 | —D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/07/01 10:49:14 | 000,000,000 | —D | M] O1 HOSTS File: ([2011/06/19 15:08:11 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found O2 - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found. O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [HPToneControl] C:\Program Files\Hewlett-Packard\HPToneControl\HPToneCtl.exe (Hewlett-Packard ) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe () O4 - HKLM..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.) O4 - HKLM..\Run: [EzPrint] C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe (Lexmark International Inc.) O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [lxdnmon.exe] C:\Program Files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe () O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe () O4 - HKLM..\Run: [vmware-tray] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.) O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation) O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) O4 - Startup: C:\Users\Nsnd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoZone iSync.lnk = C:\Program Files (x86)\GoZone\GoZone_iSync.exe (Virgin HealthMiles Inc.) O4 - Startup: C:\Users\Nsnd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} https://apps.ko.com/dwa8W.cab (Domino Web Access 8 Control) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed] O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] – "%1" %* O35:64bit: - HKLM\..exefile [open] – "%1" %* O35 - HKLM\..comfile [open] – "%1" %* O35 - HKLM\..exefile [open] – "%1" %* O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %* O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %* O37 - HKLM\…com [@ = ComFile] – "%1" %* O37 - HKLM\…exe [@ = exefile] – "%1" %* Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.dvacm - C:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.MPEGacm - C:\Program Files (x86)\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.) Drivers32: msacm.ulmp3acm - C:\Program Files (x86)\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll () Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org) Drivers32: VIDC.VMnc - C:\Windows\SysWow64\vmnc.dll (VMware, Inc.) Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011/06/21 15:36:52 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\Nsnd\Desktop\OTL.exe [2011/06/20 19:46:17 | 000,000,000 | —D | C] – C:\MGtools [2011/06/20 19:44:41 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2011/06/20 19:44:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/06/20 19:44:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011/06/20 19:34:48 | 000,000,000 | —D | C] – C:\Users\Nsnd\AppData\Roaming\SUPERAntiSpyware.com [2011/06/20 19:34:48 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com [2011/06/20 19:34:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware [2011/06/20 19:34:45 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE [2011/06/20 19:34:42 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware [2011/06/19 15:08:13 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN [2011/06/19 14:59:20 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe [2011/06/19 14:59:20 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe [2011/06/19 14:59:20 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe [2011/06/19 14:59:14 | 000,000,000 | —D | C] – C:\Windows\ERDNT [2011/06/19 14:59:08 | 000,000,000 | —D | C] – C:\Qoobox [2011/06/19 14:58:56 | 000,000,000 | —D | C] – C:\32788R22FWJFW [2011/06/19 14:55:36 | 004,130,419 | R— | C] (Swearware) – C:\Users\Nsnd\Desktop\ComboFix.exe [2011/06/18 17:16:40 | 000,000,000 | —D | C] – C:\Config.Msi [2011/06/16 15:50:01 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll [2011/06/16 15:50:00 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll [2011/06/16 15:50:00 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll [2011/06/16 15:50:00 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll [2011/06/16 15:49:59 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec [2011/06/16 15:49:59 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec [2011/06/16 15:49:59 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll [2011/06/16 15:49:59 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll [2011/06/16 15:49:59 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll [2011/06/16 15:49:59 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll [2011/06/16 15:49:59 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll [2011/06/16 15:49:59 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll [2011/06/16 15:49:59 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe [2011/06/16 15:49:59 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe [2011/06/16 15:49:54 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll [2011/06/16 15:49:54 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll [2011/06/16 15:49:53 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll [2011/06/12 16:26:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java [2011/06/12 16:24:13 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe [2011/06/12 16:24:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe [2011/06/12 16:24:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe [2011/06/03 19:09:15 | 000,000,000 | —D | C] – C:\Users\Nsnd\AppData\Local\{BB8EFA2C-C894-49FD-91E5-0BE1B2962B73} [2011/06/02 19:53:30 | 000,000,000 | —D | C] – C:\Users\Nsnd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker [2011/06/02 19:36:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft [2011/06/02 19:35:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unlocker [2011/06/02 19:27:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield [2011/05/24 15:45:50 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys [2011/05/24 08:22:14 | 000,000,000 | —D | C] – C:\Users\Nsnd\AppData\Local\{EACF0CD5-A4DF-4846-839B-809F71F15A69} [2011/05/24 08:17:49 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe [2011/05/24 08:17:49 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe [2010/05/13 09:44:46 | 001,101,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdnserv.dll [2010/05/13 09:44:46 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdncomc.dll [2010/05/13 09:44:46 | 000,843,776 | —- | C] ( ) – C:\Windows\SysWow64\lxdnusb1.dll [2010/05/13 09:44:46 | 000,663,552 | —- | C] ( ) – C:\Windows\SysWow64\lxdnhbn3.dll [2010/05/13 09:44:46 | 000,647,168 | —- | C] ( ) – C:\Windows\SysWow64\lxdnpmui.dll [2010/05/13 09:44:46 | 000,589,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdncoms.exe [2010/05/13 09:44:46 | 000,569,344 | —- | C] ( ) – C:\Windows\SysWow64\lxdnlmpm.dll [2010/05/13 09:44:46 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxdncomm.dll [2010/05/13 09:44:46 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxdninpa.dll [2010/05/13 09:44:46 | 000,360,448 | —- | C] ( ) – C:\Windows\SysWow64\lxdncfg.exe [2010/05/13 09:44:46 | 000,339,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdniesc.dll [2010/05/13 09:44:46 | 000,315,392 | —- | C] ( ) – C:\Windows\SysWow64\lxdnih.exe [2010/05/13 09:44:46 | 000,053,248 | —- | C] ( ) – C:\Windows\SysWow64\lxdnprox.dll [2 C:\*.tmp files -> C:\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/06/21 15:37:04 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Nsnd\Desktop\OTL.exe [2011/06/21 15:32:04 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/06/21 15:32:04 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/06/21 15:14:37 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/06/21 15:13:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat [2011/06/21 15:13:12 | 529,694,719 | -HS- | M] () – C:\hiberfil.sys [2011/06/21 05:06:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/06/20 20:27:03 | 000,266,209 | —- | M] () – C:\MGlogs.zip [2011/06/20 19:44:41 | 000,001,069 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/06/20 19:34:45 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2011/06/19 15:08:11 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts [2011/06/19 14:55:55 | 004,130,419 | R— | M] (Swearware) – C:\Users\Nsnd\Desktop\ComboFix.exe [2011/06/19 09:01:05 | 597,032,710 | —- | M] () – C:\Windows\MEMORY.DMP [2011/06/18 23:08:13 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll [2011/06/18 23:08:13 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe [2011/06/18 23:08:13 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe [2011/06/18 23:08:13 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe [2011/06/18 18:25:22 | 000,001,979 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk [2011/06/18 17:47:11 | 005,033,928 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT [2011/06/15 04:49:00 | 000,002,340 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk [2011/06/14 18:22:42 | 000,743,938 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI [2011/06/14 18:22:42 | 000,635,630 | —- | M] () – C:\Windows\SysNative\perfh009.dat [2011/06/14 18:22:42 | 000,111,758 | —- | M] () – C:\Windows\SysNative\perfc009.dat [2011/06/02 19:35:52 | 000,001,176 | —- | M] () – C:\Users\Nsnd\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickStores.lnk [2011/06/02 05:02:29 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2011/05/29 09:11:20 | 000,025,912 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys [2011/05/24 17:11:44 | 000,000,126 | —- | M] () – C:\Users\Nsnd\JavaConnect.ini [2 C:\*.tmp files -> C:\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/06/20 19:46:20 | 000,266,209 | —- | C] () – C:\MGlogs.zip [2011/06/20 19:44:41 | 000,001,069 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/06/20 19:34:45 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2011/06/19 14:59:20 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe [2011/06/19 14:59:20 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe [2011/06/19 14:59:20 | 000,098,816 | —- | C] () – C:\Windows\sed.exe [2011/06/19 14:59:20 | 000,080,412 | —- | C] () – C:\Windows\grep.exe [2011/06/19 14:59:20 | 000,068,096 | —- | C] () – C:\Windows\zip.exe [2011/06/18 18:25:22 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2011/06/18 18:25:22 | 000,001,979 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk [2011/06/02 19:35:52 | 000,001,176 | —- | C] () – C:\Users\Nsnd\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickStores.lnk [2011/05/24 14:05:48 | 000,000,126 | —- | C] () – C:\Users\Nsnd\JavaConnect.ini [2011/01/01 18:46:08 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI [2010/10/16 10:23:20 | 000,006,656 | —- | C] () – C:\Users\Nsnd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/09/26 19:52:59 | 000,000,092 | —- | C] () – C:\Users\Nsnd\AppData\Local\fusioncache.dat [2010/09/26 19:49:13 | 000,757,008 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI [2010/08/07 19:31:43 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll [2010/05/14 14:48:06 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini [2010/05/13 09:44:46 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\LXDNinst.dll [2010/05/13 09:44:46 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\lxdncomx.dll [2010/04/29 19:53:57 | 000,000,848 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys [2010/04/29 19:02:04 | 000,023,113 | —- | C] () – C:\Windows\hpqins15.dat [2010/04/18 02:48:30 | 000,209,040 | —- | C] () – C:\Windows\SysWow64\IVIresizeW7.dll [2010/04/18 02:48:30 | 000,204,944 | —- | C] () – C:\Windows\SysWow64\IVIresizeA6.dll [2010/04/18 02:48:30 | 000,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeP6.dll [2010/04/18 02:48:30 | 000,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeM6.dll [2010/04/18 02:48:30 | 000,192,656 | —- | C] () – C:\Windows\SysWow64\IVIresizePX.dll [2010/04/18 02:48:30 | 000,024,720 | —- | C] () – C:\Windows\SysWow64\IVIresize.dll [2010/04/18 02:20:16 | 000,000,283 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini [2010/04/18 02:20:16 | 000,000,224 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini [2009/07/23 19:49:04 | 000,782,336 | —- | C] () – C:\Windows\SysWow64\lxdndrs.dll [2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat [2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT [2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat [2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin [2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 14:59:36 | 001,498,564 | —- | C] () – C:\Windows\SysWow64\igkrng400.bin [2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat [2009/05/14 13:46:40 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\lxdncaps.dll [2008/11/15 11:02:26 | 001,866,670 | —- | C] () – C:\Windows\SysWow64\libfftw3f-3.dll [2008/04/05 10:53:24 | 000,140,288 | —- | C] () – C:\Windows\SysWow64\avsfilter.dll [2007/10/02 14:51:10 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\lxdncnv4.dll [2005/09/12 20:09:34 | 000,004,608 | —- | C] () – C:\Windows\SysWow64\AvsRecursion.dll [2004/01/29 21:44:56 | 001,627,136 | —- | C] () – C:\Windows\SysWow64\fftw3.dll [2004/01/23 19:35:44 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\avisynth_c.dll ========== LOP Check ========== [2011/04/11 20:37:51 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\Bullzip [2010/04/29 18:54:48 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\DigitalPersona [2011/02/08 21:33:28 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\HandBrake [2010/05/13 05:45:13 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\LolClient [2010/05/08 19:37:10 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1 [2011/06/19 14:48:18 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\mjusbsp [2010/06/11 21:43:15 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\Mumble [2010/05/02 15:28:00 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\OpenOffice.org [2010/04/30 22:14:28 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\Trillian [2011/02/08 15:10:09 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\TS3Client [2010/04/29 19:55:15 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\Ulead Systems [2011/06/14 18:19:42 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\uTorrent [2010/11/27 02:26:00 | 000,000,000 | —D | M] – C:\Users\Nsnd\AppData\Roaming\Windows Live Writer [2009/07/13 22:08:49 | 000,031,894 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2010/11/07 15:02:37 | 000,001,024 | —- | M] () – C:\.rnd [2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr [2011/06/19 15:13:15 | 000,017,997 | —- | M] () – C:\ComboFix.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt [2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt [2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt [2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt [2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini [2011/06/21 15:13:12 | 529,694,719 | -HS- | M] () – C:\hiberfil.sys [2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini [2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll [2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll [2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll [2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll [2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll [2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll [2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll [2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll [2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll [2011/06/20 20:27:03 | 000,266,209 | —- | M] () – C:\MGlogs.zip [2011/06/21 15:13:21 | 2137,915,391 | -HS- | M] () – C:\pagefile.sys [2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp [2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab [2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI [2 C:\*.tmp files -> C:\*.tmp -> ] < %systemroot%\Fonts\*.com > [2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont [2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont [2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont [2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont < %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini > [2009/06/10 13:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini < %systemroot%\Fonts\*.ini2 > < %systemroot%\Fonts\*.exe > < %systemroot%\system32\spool\prtprocs\w32x86\*.* > < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > [2011/01/13 01:47:35 | 000,038,848 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr [2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Microsoft\*.* > < %PROGRAMFILES%\*.* > [2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav > < %PROGRAMFILES%\bak. /s > < %systemroot%\system32\bak. /s > < %ALLUSERSPROFILE%\Start Menu\*.lnk /x > < %systemroot%\system32\config\systemprofile\*.dat /x > < %systemroot%\*.config > < %systemroot%\system32\*.db > < %PROGRAMFILES%\Internet Explorer\*.dat > < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x > [2010/04/29 19:20:33 | 000,000,221 | -HS- | M] () – C:\Users\Nsnd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini < %USERPROFILE%\Desktop\*.exe >\ [2011/02/27 15:24:00 | 158,067,944 | —- | M] () – C:\Users\Nsnd\Desktop\OOo_3.3.0_Win_x86_install-wJRE_en-US.exe [2011/06/21 15:37:04 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Nsnd\Desktop\OTL.exe < %PROGRAMFILES%\Common Files\*.* > < %systemroot%\*.src > < %systemroot%\install\*.* > < %systemroot%\system32\DLL\*.* > < %systemroot%\system32\HelpFiles\*.* > < %systemroot%\system32\rundll\*.* > < %systemroot%\winn32\*.* > < %systemroot%\Java\*.* > < %systemroot%\system32\test\*.* > < %systemroot%\system32\Rundll32\*.* > < %systemroot%\AppPatch\Custom\*.* > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > < End of report >
OTL Extras logfile created on: 6/21/2011 3:45:46 PM - Run 1 OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Nsnd\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.99 Gb Total Physical Memory | 4.35 Gb Available Physical Memory | 72.57% Memory free 11.98 Gb Paging File | 10.00 Gb Available in Paging File | 83.45% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 448.74 Gb Total Space | 153.72 Gb Free Space | 34.26% Space Free | Partition Type: NTFS Drive D: | 16.72 Gb Total Space | 2.70 Gb Free Space | 16.17% Space Free | Partition Type: NTFS Drive E: | 99.02 Mb Total Space | 92.44 Mb Free Space | 93.35% Space Free | Partition Type: FAT32 Drive F: | 664.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: NSND-PC | User Name: Nsnd | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = ChromeHTML] – Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] – "%1" %* File not found cmdfile [open] – "%1" %* File not found comfile [open] – "%1" %* File not found exefile [open] – "%1" %* File not found helpfile [open] – Reg Error: Key error. htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation) InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] – "%1" %* File not found regfile [merge] – Reg Error: Key error. scrfile [config] – "%1" File not found scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found scrfile [open] – "%1" /S File not found txtfile [edit] – Reg Error: Key error. Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [Browse with Corel Paint Shop Pro Photo X2] – "C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.) Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] – Reg Error: Value error. Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] – "%1" %* cmdfile [open] – "%1" %* comfile [open] – "%1" %* cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] – "%1" %* helpfile [open] – Reg Error: Key error. piffile [open] – "%1" %* regfile [merge] – Reg Error: Key error. scrfile [config] – "%1" scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] – "%1" /S txtfile [edit] – Reg Error: Key error. Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [Browse with Corel Paint Shop Pro Photo X2] – "C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.) Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] – Reg Error: Value error. Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour "{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64 "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{62A20ECA-920E-4052-BF77-88C78DD20FAA}" = Validity Sensors DDK "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64 "{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard "{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64 "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64 "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{D0584F36-2BDB-43DF-9168-AD0EE9AD95F6}" = HP Tone Control "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F74D69E5-ECFD-45D1-A87A-341208ADD7CC}" = DigitalPersona Personal 4.11 "Bullzip PDF Printer_is1" = Bullzip PDF Printer 4.0.0.463 "FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver "HP Smart Web Printing" = HP Smart Web Printing 4.60 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "NVIDIA Drivers" = NVIDIA Drivers "SynTPDeinstKey" = Synaptics Pointing Device Driver "TeamSpeak 3 Client" = TeamSpeak 3 Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{0665989D-2BD9-428B-B433-EF648427C8B0}" = HP User Guides 0143 "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86 "{1288DF14-8024-430B-BF5D-656AC952818D}" = Kruptos 2 Professional "{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5 "{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3764E0E0-6AAE-11DE-6784-0C73653918BE}" = Invision "{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7 "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform "{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{64E72FB1-2343-4977-B4A8-262CD53D0BD3}" = Corel Paint Shop Pro Photo X2 "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync "{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{95C5F81D-0779-4932-BE83-32AAF814F4B9}" = League of Legends "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}" = VMware Workstation "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0) "{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010 "{CDACF7D5-F9FE-4315-BA3E-E1DA75CA4C7A}" = XSplit "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = VideoStudio "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "avast5" = avast! Free Antivirus "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "ffdshow_is1" = ffdshow v1.1.3611 [2010-10-06] "Google Chrome" = Google Chrome "GoZone iSync" = GoZone iSync "GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70 "HandBrake" = HandBrake 0.9.5 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = Corel VideoStudio 12 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "mIRC" = mIRC "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "PdaNet_is1" = PdaNet for Android 2.45 "PowerISO" = PowerISO "ShiftWindow_is1" = ShiftWindow 1.02 "Steam App 440" = Team Fortress 2 "UltraISO_is1" = UltraISO Premium V9.35 "Unlocker" = Unlocker 1.9.1 "VMware_Workstation" = VMware Workstation "Winamp" = Winamp "Windows Media Encoder 9" = Windows Media Encoder 9 Series "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "XviD4PSP5" = XviD4PSP 5.0 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "AikaOnline" = AikaOnline "Winamp Detect" = Winamp Detector Plug-in ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 5/3/2011 7:56:13 AM | Computer Name = Nsnd-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 5/3/2011 7:56:13 AM | Computer Name = Nsnd-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6053 Error - 5/3/2011 7:56:13 AM | Computer Name = Nsnd-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6053 Error - 5/5/2011 10:35:57 PM | Computer Name = Nsnd-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 5/6/2011 1:06:34 AM | Computer Name = Nsnd-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error - 5/6/2011 3:32:38 AM | Computer Name = Nsnd-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 5/7/2011 3:49:34 AM | Computer Name = Nsnd-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 5/7/2011 7:29:34 PM | Computer Name = Nsnd-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error - 5/11/2011 12:33:03 AM | Computer Name = Nsnd-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 5/11/2011 7:22:23 AM | Computer Name = Nsnd-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . [ DigitalPersona Pro Events ] Error - 5/2/2010 11:29:12 PM | Computer Name = Nsnd-PC | Source = DigitalPersona Pro | ID = 17827841 Description = One-to-one fingerprint match failed. [ System Events ] Error - 6/19/2011 5:21:33 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7000 Description = The Hotspot Shield Monitoring Service service failed to start due to the following error: %%2 Error - 6/19/2011 6:03:50 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7030 Description = The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error - 6/19/2011 6:06:05 PM | Computer Name = Nsnd-PC | Source = Application Popup | ID = 1060 Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error - 6/19/2011 6:06:38 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7030 Description = The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error - 6/19/2011 6:06:46 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7030 Description = The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error - 6/19/2011 6:07:50 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7000 Description = The Hotspot Shield Monitoring Service service failed to start due to the following error: %%2 Error - 6/20/2011 10:42:58 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7000 Description = The Hotspot Shield Monitoring Service service failed to start due to the following error: %%2 Error - 6/20/2011 10:48:51 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7022 Description = The Windows Update service hung on starting. Error - 6/21/2011 7:44:37 AM | Computer Name = Nsnd-PC | Source = bowser | ID = 8003 Description = Error - 6/21/2011 6:13:25 PM | Computer Name = Nsnd-PC | Source = Service Control Manager | ID = 7000 Description = The Hotspot Shield Monitoring Service service failed to start due to the following error: %%2 < End of report >