This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

please help me read the log and understand if everyting is ok


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:15:12 μμ, on 18/7/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\autoclk.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\PROGRA~1\Raptr\raptr_im.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=101916
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - (no file)
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Vuze Remote - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Raptr] C:\PROGRA~1\Raptr\raptrstub.exe –startup
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\CONN-X SAGEM Fast 800\dslmon.exe
O4 - Global Startup: PGPtray.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: PGPmapih.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: PGP RDD Service - PGP Corporation - C:\Program Files\PGP Corporation\PGP Desktop\RDDService.exe
O23 - Service: PGPserv - PGP Corporation - C:\Windows\system32\PGPserv.exe
O23 - Service: UFD Command Service (UFDSVC) - Generic - C:\Windows\system32\ufdsvc.exe

–
End of file - 6901 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Jeff thank you for your email i will follow your instruction thanks for your help. i look forward for the rest of the emails aleka
Hi aleka,

You are asking if everything is ok…what symptoms, if any, are making you think that your system might be infected?


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please let me know about any symptoms you might be experiencing with your system, post both of the logs created by DDS and post the log created by aswMBR.exe. :)
hi jeff, sorry i havent reply sooner i did not had any specific symproms, i just want to see if everything is ok you told me to download DDS. i did but i have some problems. it runs and then the black screen disappears without saving anywhere. i cannot find it in order to post the results… i post the log created by aswMBR aswMBR version 0.9.8.977 Copyright© 2011 AVAST Software Run date: 2011-07-22 15:27:32 —————————– 15:27:32.797 OS Version: Windows 6.1.7601 Service Pack 1 15:27:32.797 Number of processors: 4 586 0x2A07 15:27:32.798 ComputerName: CATRINE-JUNE-PC UserName: catrine-june 15:27:43.859 Initialize success 15:28:46.056 AVAST engine defs: 11072200 15:29:27.729 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 15:29:27.731 Disk 0 Vendor: ST3500418AS CC46 Size: 476940MB BusType: 3 15:29:27.742 Disk 0 MBR read successfully 15:29:27.744 Disk 0 MBR scan 15:29:27.747 Disk 0 Windows 7 default MBR code 15:29:27.750 Disk 0 scanning sectors +976771072 15:29:27.838 Disk 0 scanning C:\Windows\system32\drivers 15:29:41.213 Service scanning 15:29:41.653 Service MpKsl33da9e70 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A85EBC93-9362-4DF5-AD73-7939821750F1}\MpKsl33da9e70.sys **LOCKED** 3 15:29:41.656 Service MpKsl7e5e8414 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A85EBC93-9362-4DF5-AD73-7939821750F1}\MpKsl7e5e8414.sys **LOCKED** 3 15:29:41.659 Service MpKslb53ae3cd c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5DA733C7-9D2E-4EEB-88B2-B9313C82743A}\MpKslb53ae3cd.sys **LOCKED** 3 15:29:41.662 Service MpKsld15e3d18 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{95A58093-8627-41EC-A2B8-BE430D5EB421}\MpKsld15e3d18.sys **LOCKED** 32 15:29:41.665 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32 15:29:42.284 Modules scanning 15:29:46.473 Disk 0 trace - called modules: 15:29:46.490 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 15:29:46.494 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x856d65e8] 15:29:46.498 3 CLASSPNP.SYS[8880459e] -> nt!IofCallDriver -> [0x851fc328] 15:29:46.509 5 ACPI.sys[886923d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x851eb908] 15:29:49.985 AVAST engine scan C:\Windows 15:29:52.391 AVAST engine scan C:\Windows\system32 15:32:23.200 AVAST engine scan C:\Windows\system32\drivers 15:32:35.314 AVAST engine scan C:\Users\catrine-june 15:33:24.952 Disk 0 MBR has been saved successfully to "C:\Users\catrine-june\Desktop\MBR.dat" 15:33:24.953 The log file has been saved successfully to "C:\Users\catrine-june\Desktop\aswMBR.txt" 15:34:31.979 AVAST engine scan C:\ProgramData 15:35:17.188 Scan finished successfully 16:34:05.217 Disk 0 MBR has been saved successfully to "C:\Users\catrine-june\Desktop\MBR.dat" 16:34:05.268 The log file has been saved successfully to "C:\Users\catrine-june\Desktop\aswMBR.txt" dear jeff, i will be out of the city for the next 15 days because of my vacations. i will follow whatever instructions you sent me when i will return. thank you aleka
Hi aleka,

  • Download OTL to your desktop.
  • Double click on the icon [external image: Posted Image] to run it. Make sure all other windows are closed and to let it run uninterrupted.
    (***If running Windows Vista, right-click the icon and Run as Administrator***)
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

In your next reply please post the logs created by OTL. :)

Note: When you return go ahead and PM me so that we can pick back up again. Have a nice vacation. :)
DEAR JEFF

i did as you asked. i think that you will have a ploblem reading the secong log of EXTRA because the replay is in my language - GREEK

thanks for your help
have a nice summer

OTL logfile created on: 7/22/2011 9:43:51 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\catrine-june\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Greece | Language: ELL | Date Format: d/M/yyyy

1.98 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.99% Memory free
3.97 Gb Paging File | 2.47 Gb Available in Paging File | 62.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 435.24 Gb Free Space | 93.45% Space Free | Partition Type: NTFS
Drive D: | 767.22 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CATRINE-JUNE-PC | User Name: catrine-june | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\catrine-june\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\PROGRA~1\Raptr\raptr_im.exe (Raptr, Inc)
PRC - C:\PROGRA~1\Raptr\raptr.exe (Raptr, Inc)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\PROGRA~1\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\PROGRA~1\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe (PGP Corporation)
PRC - C:\Program Files\PGP Corporation\PGP Desktop\RDDService.exe (PGP Corporation)
PRC - C:\Windows\System32\PGPserv.exe (PGP Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Windows\autoclk.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\catrine-june\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\PROGRA~1\Raptr\ltc_help32-51289.dll (Raptr Inc.)
MOD - C:\Windows\System32\PGPmapih.dll (PGP Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (NAUpdate) – C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (PGP RDD Service) – C:\Program Files\PGP Corporation\PGP Desktop\RDDService.exe (PGP Corporation)
SRV - (PGPserv) – C:\Windows\System32\PGPserv.exe (PGP Corporation)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (UFDSVC) – C:\Windows\System32\ufdsvc.exe (Generic)


========== Driver Services (SafeList) ==========

DRV - (MpKsld15e3d18) – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{95A58093-8627-41EC-A2B8-BE430D5EB421}\MpKsld15e3d18.sys (Microsoft Corporation)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (PGPwded) – C:\Windows\System32\drivers\PGPwded.sys (PGP Corporation)
DRV - (PGPdisk) – C:\Windows\System32\drivers\PGPdisk.sys (PGP Corporation)
DRV - (PGPsdkDriver) – C:\Windows\System32\drivers\PGPsdk.sys (PGP Corporation)
DRV - (pgpfs) – C:\Windows\System32\Drivers\PGPfsfd.sys (PGP Corporation)
DRV - (Pgpwdefs) – C:\Windows\system32\DRIVERS\Pgpwdefs.sys (PGP Corporation)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (MEI) Intel® – C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (RTL8187B) – C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (DgiVecp) – C:\Windows\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (SSPORT) – C:\Windows\System32\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (e4usbaw) – C:\Windows\System32\drivers\e4usbaw.sys (Analog Devices Inc.)
DRV - (IKANLOADER2) General Purpose USB Driver (e4ldr.sys) – C:\Windows\System32\drivers\e4ldr.sys (Analog Deivces)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o;=101916
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://gr.msn.com/?mkt=el-gr&ocid;=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = el
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6B 2B 01 26 A4 BD CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://eu.ask.com/?l=dis&o;=101916"
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:3.3.3.2
FF - prefs.js..extensions.enabledItems: avg@igeared:7.005.030.004
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1390
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4dd8d4b5&v;=7.005.030.004&i;=23&tp;=ab&iy;=&ychte;=us&lng;=el&q;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2011/06/10 23:50:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/07/13 21:21:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/26 20:18:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/15 19:17:52 | 000,000,000 | —D | M]

[2011/01/27 01:00:07 | 000,000,000 | —D | M] (No name found) – C:\Users\catrine-june\AppData\Roaming\mozilla\Extensions
[2011/07/22 21:29:29 | 000,000,000 | —D | M] (No name found) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions
[2011/05/01 21:51:50 | 000,000,000 | —D | M] (Softonic-Eng7 Community Toolbar) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2011/07/06 18:15:18 | 000,000,000 | —D | M] (Vuze Remote Community Toolbar) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/05/01 21:51:49 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions\[removed]
[2011/07/18 13:54:14 | 000,002,572 | —- | M] () – C:\Users\catrine-june\AppData\Roaming\Mozilla\Firefox\Profiles\q3hcs7kw.default\searchplugins\askcom.xml
[2011/07/15 19:17:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\mozilla firefox\extensions
[2011/07/15 19:17:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/07/13 21:21:10 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/06/10 23:50:07 | 000,000,000 | —D | M] ("urn:mozilla:install-manifest" em:id="avg@igeared" em:name="AVG Security Toolbar" em:version="7.005.030.004" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) – C:\PROGRAM FILES\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED
[2011/05/09 22:43:04 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/07/15 19:17:37 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/10 18:17:27 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/03/10 18:17:27 | 000,000,760 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/03/10 18:17:27 | 000,001,219 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-el.xml

O1 HOSTS File: ([2011/02/13 16:17:42 | 000,429,948 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14798 more lines…
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [autoclk] C:\Windows\autoclk.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Raptr] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\PGPlsp.dll (PGP Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\PGPlsp.dll (PGP Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (PGPmapih.dll) - C:\Windows\System32\PGPmapih.dll (PGP Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 00:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/15 19:30:45 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/07/15 19:30:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/07/15 19:17:52 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/07/15 19:17:52 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/07/15 19:17:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/07/15 19:17:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/07/15 19:17:32 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/07/13 21:22:00 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2011/07/13 21:22:00 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2011/07/13 21:22:00 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2011/07/13 21:22:00 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2011/07/13 21:22:00 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/07/13 21:22:00 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2011/07/13 21:22:00 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2011/07/13 21:22:00 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2011/07/13 21:22:00 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2011/07/13 21:21:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2011/07/13 21:21:59 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011/07/13 21:21:58 | 000,271,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2011/07/13 21:21:57 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/07/13 21:21:53 | 002,334,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/07/11 22:29:10 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Local\{B11EC3C1-2735-4FEA-AF25-B6611B48128A}
[2011/07/06 21:57:22 | 000,000,000 | —D | C] – C:\Windows\System32\SPReview
[2011/07/06 21:56:28 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Roaming\Nero
[2011/07/06 21:53:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nero
[2011/07/06 21:53:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
[2011/07/06 21:53:18 | 000,000,000 | —D | C] – C:\Program Files\Nero
[2011/07/06 21:53:08 | 000,000,000 | —D | C] – C:\ProgramData\Nero
[2011/07/06 21:40:57 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_40.dll
[2011/07/06 21:39:52 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2011/07/06 19:34:20 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Roaming\Media Player Classic
[2011/07/06 19:03:50 | 000,000,000 | —D | C] – C:\Users\catrine-june\Desktop\GREEK MOVIES - ALL TIME 10 GREEK MOVIES - ΟΙ 10 ΚΑΛΥΤΕΡΕΣ ΕΛΛΗΝΙΚΕΣ ΤΑΙΝΙΕΣ_files
[2011/07/06 18:38:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/07/06 18:37:56 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack
[2011/07/06 18:23:23 | 000,000,000 | —D | C] – C:\Users\catrine-june\Documents\Vuze Downloads
[2011/07/06 18:18:58 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr
[2011/07/06 18:18:49 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Roaming\Raptr
[2011/07/06 18:18:49 | 000,000,000 | —D | C] – C:\Program Files\Raptr
[2011/07/06 18:17:35 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Roaming\Azureus
[2011/07/06 18:15:19 | 000,000,000 | —D | C] – C:\Program Files\Vuze
[2011/07/06 18:15:10 | 000,000,000 | —D | C] – C:\Program Files\Vuze_Remote
[2011/07/06 18:15:10 | 000,000,000 | —D | C] – C:\Users\catrine-june\AppData\Local\Conduit
[2011/06/29 11:43:03 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2011/06/29 11:43:03 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2011/06/29 11:43:03 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2011/06/29 11:43:02 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2011/06/29 11:43:02 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2011/06/29 11:43:02 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\catrine-june\Desktop\*.tmp files -> C:\Users\catrine-june\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/22 16:40:40 | 000,014,832 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/22 16:40:40 | 000,014,832 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/22 15:21:24 | 125,025,595 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/07/22 15:20:23 | 000,618,354 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/07/22 15:20:23 | 000,562,266 | —- | M] () – C:\Windows\System32\perfh008.dat
[2011/07/22 15:20:23 | 000,107,376 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/07/22 15:20:23 | 000,090,566 | —- | M] () – C:\Windows\System32\perfc008.dat
[2011/07/22 15:15:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/22 15:15:39 | 1596,973,056 | -HS- | M] () – C:\hiberfil.sys
[2011/07/21 21:31:07 | 000,091,742 | —- | M] () – C:\Users\catrine-june\Desktop\IECMailNo13.zip.pgp
[2011/07/21 21:21:53 | 000,046,978 | —- | M] () – C:\Users\catrine-june\Desktop\ToC-117.pdf
[2011/07/15 19:17:36 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/07/15 19:17:36 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/07/15 19:17:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/07/15 19:17:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/07/15 19:10:40 | 000,001,114 | —- | M] () – C:\Users\catrine-june\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/07/14 17:44:46 | 000,286,496 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/07/13 21:21:30 | 000,000,930 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/07/08 00:32:04 | 004,836,323 | —- | M] () – C:\Users\catrine-june\Desktop\wv983.pdf
[2011/07/06 22:04:25 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msclmd.dll
[2011/07/06 21:54:04 | 000,002,831 | —- | M] () – C:\Users\Public\Desktop\Nero Burning ROM 10.lnk
[2011/07/06 19:03:52 | 000,029,790 | —- | M] () – C:\Users\catrine-june\Desktop\GREEK MOVIES - ALL TIME 10 GREEK MOVIES - ΟΙ 10 ΚΑΛΥΤΕΡΕΣ ΕΛΛΗΝΙΚΕΣ ΤΑΙΝΙΕΣ.htm
[2011/07/06 18:15:43 | 000,001,805 | —- | M] () – C:\Users\catrine-june\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/06/29 22:44:34 | 002,603,483 | —- | M] () – C:\Users\catrine-june\Desktop\furtherreadclass3.zip.pgp
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\catrine-june\Desktop\*.tmp files -> C:\Users\catrine-june\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/21 21:31:07 | 000,091,742 | —- | C] () – C:\Users\catrine-june\Desktop\IECMailNo13.zip.pgp
[2011/07/21 21:22:00 | 000,046,978 | —- | C] () – C:\Users\catrine-june\Desktop\ToC-117.pdf
[2011/07/08 00:32:09 | 004,836,323 | —- | C] () – C:\Users\catrine-june\Desktop\wv983.pdf
[2011/07/06 21:54:04 | 000,002,831 | —- | C] () – C:\Users\Public\Desktop\Nero Burning ROM 10.lnk
[2011/07/06 19:03:49 | 000,029,790 | —- | C] () – C:\Users\catrine-june\Desktop\GREEK MOVIES - ALL TIME 10 GREEK MOVIES - ΟΙ 10 ΚΑΛΥΤΕΡΕΣ ΕΛΛΗΝΙΚΕΣ ΤΑΙΝΙΕΣ.htm
[2011/07/06 18:38:00 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/07/06 18:15:43 | 000,001,805 | —- | C] () – C:\Users\catrine-june\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/07/06 18:15:43 | 000,001,805 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
[2011/06/29 22:34:00 | 002,603,483 | —- | C] () – C:\Users\catrine-june\Desktop\furtherreadclass3.zip.pgp
[2011/04/03 13:03:10 | 000,022,723 | —- | C] () – C:\Windows\System32\SUGG1l3.DLL
[2011/02/05 19:49:55 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/01/27 14:56:33 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/01/27 00:50:52 | 000,000,168 | —- | C] () – C:\Windows\adidsl.ini
[2011/01/27 00:50:52 | 000,000,021 | —- | C] () – C:\Windows\Fast800.ini
[2011/01/27 00:50:33 | 000,143,360 | —- | C] () – C:\Windows\adiras.exe
[2011/01/27 00:50:33 | 000,127,456 | —- | C] () – C:\Windows\System32\IPDETECT.EXE
[2011/01/27 00:50:31 | 000,152,126 | —- | C] () – C:\Windows\System32\drivers\L1E9P2.BIN
[2011/01/27 00:50:31 | 000,152,126 | —- | C] () – C:\Windows\System32\drivers\L1E9P1.BIN
[2011/01/27 00:50:31 | 000,152,126 | —- | C] () – C:\Windows\System32\drivers\L1E9P0.BIN
[2011/01/27 00:50:31 | 000,152,126 | —- | C] () – C:\Windows\System32\drivers\L1E9I2.BIN
[2011/01/27 00:50:31 | 000,152,126 | —- | C] () – C:\Windows\System32\drivers\L1E9I1.BIN
[2011/01/27 00:50:31 | 000,152,126 | —- | C] () – C:\Windows\System32\drivers\L1E9I0.BIN
[2011/01/27 00:50:31 | 000,126,976 | —- | C] () – C:\Windows\System32\coclassfast.dll
[2011/01/27 00:50:31 | 000,046,892 | —- | C] () – C:\Windows\System32\ADADIX16.DLL
[2011/01/27 00:50:31 | 000,024,576 | —- | C] () – C:\Windows\enddisk32.exe
[2011/01/27 00:50:30 | 000,152,308 | —- | C] () – C:\Windows\System32\drivers\L1E4I2.BIN
[2011/01/27 00:50:30 | 000,152,306 | —- | C] () – C:\Windows\System32\drivers\L1E4I1.BIN
[2011/01/27 00:50:30 | 000,152,306 | —- | C] () – C:\Windows\System32\drivers\L1E4I0.BIN
[2011/01/27 00:50:30 | 000,152,146 | —- | C] () – C:\Windows\System32\drivers\L1E4P2.BIN
[2011/01/27 00:50:30 | 000,152,145 | —- | C] () – C:\Windows\System32\drivers\L1E4P1.BIN
[2011/01/27 00:50:30 | 000,152,145 | —- | C] () – C:\Windows\System32\drivers\L1E4P0.BIN
[2011/01/27 00:50:30 | 000,152,036 | —- | C] () – C:\Windows\System32\drivers\L1E4D2.BIN
[2011/01/27 00:50:30 | 000,152,034 | —- | C] () – C:\Windows\System32\drivers\L1E4D1.BIN
[2011/01/27 00:50:30 | 000,152,034 | —- | C] () – C:\Windows\System32\drivers\L1E4D0.BIN
[2011/01/27 00:50:30 | 000,022,395 | —- | C] () – C:\Windows\System32\drivers\fpga.bin
[2011/01/27 00:30:16 | 000,001,126 | —- | C] () – C:\Windows\adiras.ini
[2011/01/27 00:30:11 | 000,176,128 | —- | C] () – C:\Windows\autoclk.exe
[2011/01/23 05:58:49 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2011/01/23 05:55:41 | 000,002,110 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/01/12 22:42:54 | 000,000,280 | —- | C] () – C:\Windows\System32\PGPsdk.dll.sig
[2010/05/05 04:21:48 | 000,023,040 | —- | C] () – C:\Windows\System32\atitmpxx.dll
[2010/04/19 18:30:11 | 000,562,266 | —- | C] () – C:\Windows\System32\perfh008.dat
[2010/04/19 18:30:11 | 000,369,984 | —- | C] () – C:\Windows\System32\perfi008.dat
[2010/04/19 18:30:11 | 000,090,566 | —- | C] () – C:\Windows\System32\perfc008.dat
[2010/04/19 18:30:11 | 000,045,182 | —- | C] () – C:\Windows\System32\perfd008.dat
[2010/03/25 18:56:00 | 000,203,331 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/07/14 07:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 07:33:53 | 000,286,496 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 05:05:48 | 000,618,354 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 05:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 05:05:48 | 000,107,376 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 05:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 05:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 05:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 02:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 02:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 02:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 00:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/02/18 20:55:20 | 000,294,912 | —- | C] () – C:\Windows\System32\ATIODE.exe
[2009/02/03 23:52:02 | 000,045,056 | —- | C] () – C:\Windows\System32\ATIODCLI.exe
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI

========== LOP Check ==========

[2011/03/07 20:15:46 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\AVG
[2011/02/05 19:44:21 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\AVG10
[2011/07/19 00:56:11 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\Azureus
[2011/02/19 22:00:10 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\com.w3i.FlipToast
[2011/02/16 23:07:59 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\Network Associates
[2011/02/27 18:49:30 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\PGP Corporation
[2011/07/22 19:16:18 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\Raptr
[2011/07/21 23:47:48 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\SoftGrid Client
[2011/02/05 20:56:58 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\TP
[2011/02/19 21:51:06 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\Uniblue
[2011/02/19 21:42:35 | 000,000,000 | —D | M] – C:\Users\catrine-june\AppData\Roaming\Windows Live Writer
[2011/05/01 08:55:37 | 000,032,604 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >





AND THE EXTRA


OTL Extras logfile created on: 7/22/2011 9:41:24 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\catrine-june\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Greece | Language: ELL | Date Format: d/M/yyyy

1.98 Gb Total Physical Memory | 0.93 Gb Available Physical Memory | 47.09% Memory free
3.97 Gb Paging File | 2.51 Gb Available in Paging File | 63.17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 435.24 Gb Free Space | 93.45% Space Free | Partition Type: NTFS
Drive D: | 767.22 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CATRINE-JUNE-PC | User Name: catrine-june | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04C8A6AB-76DD-4A57-8013-FD2464B23759}" = Microsoft Antimalware Service EL-GR Language Pack
"{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{13FAE3E3-283E-4BF4-8FE5-17D256EDDD77}" = Windows Live UX Platform Language Pack
"{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{1E1300BC-6DBA-476B-8CCF-4AA81ED4DF6A}" = AVG 2011
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3ABC7CFA-A6F5-3870-A59C-B856DA1DA4F4}" = Microsoft .NET Framework 4 Client Profile ELL Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{402B502A-4735-4B03-B38F-1640CD3C531B}" = Windows Live Sync
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = CONN-X SAGEM Fast 800
"{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7485492C-CD85-43CA-A4A7-ABD665BB66CE}" = Windows Live Family Safety
"{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7F18F75E-A395-4273-A73E-C87CD0705D9B}" = PGP Desktop
"{80490945-CE48-45CF-9CCA-CA0EF44D9FE4}" = AVG 2011
"{859B9BCA-5376-4566-9F88-C6C9DAA7A925}" = Microsoft Security Client EL-GR Language Pack
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A1A6E9B-5A71-4D33-AD0D-B4E6C6ED7522}" = Microsoft Antimalware Service EL-GR Language Pack
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-006D-0408-0000-0000000FF1CE}" = Microsoft Office "Χρήση με ένα κλικ" 2010
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90140011-0066-0408-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Ελληνικά
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-00AF-0408-0000-0000000FF1CE}" = Πρόγραμμα προβολής του Microsoft PowerPoint
"{96403552-88D1-429F-9C92-388B814B885E}" = Messenger Companion
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9ABC0A6-DC01-4102-BEC9-86974A73B214}" = Windows Live Remote Client Resources
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail
"{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker
"{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live
"{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D378BEA1-912E-4827-B9DB-D3B2C3D0BD4A}" = Windows Live Remote Service Resources
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG" = AVG 2011
"conduitEngine" = Conduit Engine
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.2.0 (Standard)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ELL Language Pack" = Πακέτο γλωσσών για τα Ελληνικά του Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.18)" = Mozilla Firefox (3.6.18)
"Office14.Click2Run" = Microsoft Office "Χρήση με ένα κλικ" 2010
"Raptr" = Raptr
"Samsung CLP-300 Series" = Samsung CLP-300 Series
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"WinLiveSuite" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/6/2011 10:23:19 AM | Computer Name = catrine-june-PC | Source = SideBySide | ID = 16842815
Description = Η δημιουργία περιβάλλοντος ενεργοποίησης απέτυχε για το "c:\program
files\spybot - search & destroy\DelZip179.dll". Παρουσιάστηκε σφάλμα στο αρχείο
διακήρυξης ή πολιτικής "c:\program files\spybot - search & destroy\DelZip179.dll"
στη γραμμή 8. Η τιμή "*" του χαρακτηριστικού "language" στο στοιχείο "assemblyIdentity"
δεν είναι έγκυρη.

Error - 7/6/2011 2:51:19 PM | Computer Name = catrine-june-PC | Source = Application Error | ID = 1000
Description = Όνομα ελαττωματικής εφαρμογής ufdsvc.exe, έκδοση 1.0.0.9, χρονική
σήμανση 0x441e4822 Όνομα ελαττωματικής λειτουργικής μονάδας ufdsvc.exe, έκδοση 1.0.0.9,
χρονική σήμανση 0x441e4822 Κωδικός εξαίρεσης: 0xc0000005 Μετατόπιση σφάλματος: 0x00007854
Αναγνωριστικό
ελαττωματικής διεργασίας: 0x8d0 Χρόνος έναρξης ελαττωματικής εφαρμογής: 0x01cc3c0da897e6b2
Διαδρομή
ελαττωματικής εφαρμογής: C:\Windows\system32\ufdsvc.exe Διαδρομή ελλατωματικής λειτουργικής
μονάδας:C:\Windows\system32\ufdsvc.exe Αναγνωριστικό αναφοράς:ef3a2615-a800-11e0-addf-d027883e356f

Error - 7/6/2011 2:51:25 PM | Computer Name = catrine-june-PC | Source = Application Error | ID = 1000
Description = Όνομα ελαττωματικής εφαρμογής dslmon.exe, έκδοση 1.0.0.1, χρονική
σήμανση 0x44ae56e2 Όνομα ελαττωματικής λειτουργικής μονάδας ntdll.dll, έκδοση 6.1.7600.16695,
χρονική σήμανση 0x4cc7ab44 Κωδικός εξαίρεσης: 0xc0000005 Μετατόπιση σφάλματος: 0x00055bcc
Αναγνωριστικό
ελαττωματικής διεργασίας: 0xff8 Χρόνος έναρξης ελαττωματικής εφαρμογής: 0x01cc3c0db0d8b2a0
Διαδρομή
ελαττωματικής εφαρμογής: C:\Program Files\SAGEM\CONN-X SAGEM Fast 800\dslmon.exe
Διαδρομή
ελλατωματικής λειτουργικής μονάδας:C:\Windows\SYSTEM32\ntdll.dll Αναγνωριστικό αναφοράς:f2800a75-a800-11e0-addf-d027883e356f

Error - 7/6/2011 2:57:12 PM | Computer Name = catrine-june-PC | Source = VSS | ID = 12305
Description =

Error - 7/6/2011 5:31:02 PM | Computer Name = catrine-june-PC | Source = SideBySide | ID = 16842815
Description = Η δημιουργία περιβάλλοντος ενεργοποίησης απέτυχε για το "c:\program
files\spybot - search & destroy\DelZip179.dll". Παρουσιάστηκε σφάλμα στο αρχείο
διακήρυξης ή πολιτικής "c:\program files\spybot - search & destroy\DelZip179.dll"
στη γραμμή 8. Η τιμή "*" του χαρακτηριστικού "language" στο στοιχείο "assemblyIdentity"
δεν είναι έγκυρη.

Error - 7/10/2011 3:42:56 AM | Computer Name = catrine-june-PC | Source = ESENT | ID = 215
Description = WinMail (5532) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 7/10/2011 3:43:07 AM | Computer Name = catrine-june-PC | Source = Application Error | ID = 1000
Description = Όνομα ελαττωματικής εφαρμογής dslmon.exe, έκδοση 1.0.0.1, χρονική
σήμανση 0x44ae56e2 Όνομα ελαττωματικής λειτουργικής μονάδας ntdll.dll, έκδοση 6.1.7601.17514,
χρονική σήμανση 0x4ce7b96e Κωδικός εξαίρεσης: 0xc0000005 Μετατόπιση σφάλματος: 0x00056612
Αναγνωριστικό
ελαττωματικής διεργασίας: 0x177c Χρόνος έναρξης ελαττωματικής εφαρμογής: 0x01cc3ed4fec62bba
Διαδρομή
ελαττωματικής εφαρμογής: C:\Program Files\SAGEM\CONN-X SAGEM Fast 800\dslmon.exe
Διαδρομή
ελλατωματικής λειτουργικής μονάδας:C:\Windows\SYSTEM32\ntdll.dll Αναγνωριστικό αναφοράς:403a3e89-aac8-11e0-857e-d027883e356f

Error - 7/10/2011 8:16:12 AM | Computer Name = catrine-june-PC | Source = SideBySide | ID = 16842815
Description = Η δημιουργία περιβάλλοντος ενεργοποίησης απέτυχε για το "c:\program
files\spybot - search & destroy\DelZip179.dll". Παρουσιάστηκε σφάλμα στο αρχείο
διακήρυξης ή πολιτικής "c:\program files\spybot - search & destroy\DelZip179.dll"
στη γραμμή 8. Η τιμή "*" του χαρακτηριστικού "language" στο στοιχείο "assemblyIdentity"
δεν είναι έγκυρη.

Error - 7/10/2011 5:30:53 PM | Computer Name = catrine-june-PC | Source = SideBySide | ID = 16842815
Description = Η δημιουργία περιβάλλοντος ενεργοποίησης απέτυχε για το "c:\program
files\spybot - search & destroy\DelZip179.dll". Παρουσιάστηκε σφάλμα στο αρχείο
διακήρυξης ή πολιτικής "c:\program files\spybot - search & destroy\DelZip179.dll"
στη γραμμή 8. Η τιμή "*" του χαρακτηριστικού "language" στο στοιχείο "assemblyIdentity"
δεν είναι έγκυρη.

Error - 7/11/2011 1:48:44 AM | Computer Name = catrine-june-PC | Source = Application Error | ID = 1000
Description = Όνομα ελαττωματικής εφαρμογής dslmon.exe, έκδοση 1.0.0.1, χρονική
σήμανση 0x44ae56e2 Όνομα ελαττωματικής λειτουργικής μονάδας ntdll.dll, έκδοση 6.1.7601.17514,
χρονική σήμανση 0x4ce7b96e Κωδικός εξαίρεσης: 0xc0000005 Μετατόπιση σφάλματος: 0x00056612
Αναγνωριστικό
ελαττωματικής διεργασίας: 0x1034 Χρόνος έναρξης ελαττωματικής εφαρμογής: 0x01cc3f8e31252c81
Διαδρομή
ελαττωματικής εφαρμογής: C:\Program Files\SAGEM\CONN-X SAGEM Fast 800\dslmon.exe
Διαδρομή
ελλατωματικής λειτουργικής μονάδας:C:\Windows\SYSTEM32\ntdll.dll Αναγνωριστικό αναφοράς:6fd2eb46-ab81-11e0-9e82-d027883e356f

[ System Events ]
Error - 7/11/2011 10:25:43 AM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
1 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/11/2011 10:25:43 AM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
2 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/11/2011 10:25:43 AM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
3 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/11/2011 10:25:48 AM | Computer Name = catrine-june-PC | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας General Purpose USB Driver
(e4ldr.sys) εξαιτίας του ακόλουθου σφάλματος: %%1058

Error - 7/13/2011 2:13:37 PM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
0 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/13/2011 2:13:37 PM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
1 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/13/2011 2:13:37 PM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
2 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/13/2011 2:13:37 PM | Computer Name = catrine-june-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Οι δυνατότητες διαχείρισης της απόδοσης ισχύος για τον επεξεργαστή
3 στην ομάδα 0 απενεργοποιήθηκαν λόγω προβλήματος με το υλικολογισμικό. Ζητήστε
από τον κατασκευαστή του υπολογιστή ενημερωμένες εκδόσεις υλικολογισμικού.

Error - 7/13/2011 2:13:42 PM | Computer Name = catrine-june-PC | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας General Purpose USB Driver
(e4ldr.sys) εξαιτίας του ακόλουθου σφάλματος: %%1058

Error - 7/13/2011 2:14:08 PM | Computer Name = catrine-june-PC | Source = Service Control Manager | ID = 7034
Description = Η λειτουργία της υπηρεσίας UFD Command Service τερματίστηκε αναπάντεχα.
Αυτό συνέβη 1 φορά(ές).


< End of report >
Hi aleka,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Reg Error: Key error. File not found
    IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
    FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:3.3.3.2
    FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.5.0.12
    [2011/05/01 21:51:50 | 000,000,000 | —D | M] (Softonic-Eng7 Community Toolbar) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
    [2011/07/06 18:15:18 | 000,000,000 | —D | M] (Vuze Remote Community Toolbar) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
    [2011/05/01 21:51:49 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\catrine-june\AppData\Roaming\mozilla\Firefox\Profiles\q3hcs7kw.default\extensions\[removed]
    O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
    O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    @Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
    
    :Files
    ipconfig /flushdns
    
    :Commands
    [purity]
    [resethosts]
    [clearallrestorepoints]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI