This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Avira Antivirus disabling automatically? Can't uninstall trend mic

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello guys, annoying problem. Originally what was going on was I kept having the google redirect virus that was sending me to diff websites when I'd run searches. So I ended up going online and downloading a bunch of programs from various sites claiming to be able to assist in fixing it. Malwarebytes, super adware remover, spybot, among others were used. then at some point the problem went from the redirect virus to not being able to even get on the internet after a normal bootup. I had to boot up in safe mode and ended up reading enough to figure out that I thought all the programs I'd downloaded were causing complications, so I uninstalled a bunch of them and ran certain ones, and then my computer was back to working in normal mode and the internet working and all. Now though, my antivirus that I always used, Avira Premium, it won't update and when I open it up it disables after like 6 seconds and says its deactivated. When I try to update it, it tells me "The following error occured:" and then has a picture of what looks like the # 10 but the 1 is a skinny arrow pointing up. I found a thread here on this site that was recommending to download combofix and disable all antivirus before doing so, but when I ran combofix it told me that I had trend micro internet antivirus running, even though I had already uninstalled that program repeatedly and it's not showing up on my program files list anymore. Anyone know what's going on? Help? I can't run combofix if I can't disable trend micro, and I can't disable trend micro since I don't even see where it's installed or running.
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hi Python49

IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
========================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

=======================
NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log and Extras.Txt
3. aswMBR log
Since you guys seem to give very structured and persistent help I'll let the other forum know to lock my thread.

Here's my OTL text:
OTL logfile created on: 9/6/2011 6:23:54 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\CED
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.98 Gb Total Physical Memory | 5.38 Gb Available Physical Memory | 67.42% Memory free
15.95 Gb Paging File | 13.30 Gb Available in Paging File | 83.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 174.66 Gb Total Space | 76.26 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
Drive D: | 502.49 Gb Total Space | 474.31 Gb Free Space | 94.39% Space Free | Partition Type: NTFS
Drive E: | 3.69 Gb Total Space | 0.32 Gb Free Space | 8.63% Space Free | Partition Type: FAT32

Computer Name: CED-PC | User Name: CED | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\CED\OTL.exe (OldTimer Tools)
PRC - C:\Users\CED\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe ()
PRC - C:\32788R22FWJFW\cmd.3XE ()
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\ExpressGateUtil\VAWinService.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\32788R22FWJFW\NirCmd.3XE ()


========== Modules (No Company Name) ==========

MOD - C:\Users\CED\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe ()
MOD - C:\32788R22FWJFW\cmd.3XE ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\32788R22FWJFW\NirCmd.3XE ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirWebService) – C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH)
SRV - (AntiVirMailService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (postgresql-8.4) – C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (VideAceWindowsService) – C:\ExpressGateUtil\VAWinService.exe ()
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ATKGFNEXSrv) – C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (ASLDRService) – C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (OpenVPNService) – C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (FLxHCIc) Fresco Logic xHCI (USB3) – C:\Windows\SysNative\drivers\FLxHCIc.sys (Fresco Logic)
DRV:64bit: - (FLxHCIh) Fresco Logic xHCI (USB3) – C:\Windows\SysNative\drivers\FLxHCIh.sys (Fresco Logic)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBVSTOR) – C:\Windows\SysNative\drivers\rtsuvstor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (btusbflt) – C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:64bit: - (MBfilt) – C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (kbfiltr) – C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SiSGbeLH) – C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (ATKWMIACPIIO) – C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) – C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledItems: {22C7F6C6-8D67-4534-92B5-529A0EC09405}:6.5.0.1234
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z128&form;=ZGAADF&install;_date=20110826&q;="
FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/03/29 12:57:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/03/29 12:57:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/03/29 12:57:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/01 10:10:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/12 05:40:13 | 000,000,000 | —D | M]

[2011/04/29 13:36:55 | 000,000,000 | —D | M] (No name found) – C:\Users\CED\AppData\Roaming\Mozilla\Extensions
[2011/09/06 01:05:22 | 000,000,000 | —D | M] (No name found) – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions
[2011/08/26 08:35:12 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/08/26 08:35:11 | 000,001,945 | —- | M] () – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\searchplugins\bing-zugo.xml
[2011/05/01 01:21:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/08/20 22:37:24 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/04/30 12:46:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/01 10:10:14 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/30 12:46:28 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/12 05:40:12 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old

O1 HOSTS File: ([2011/09/06 01:07:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - File not found
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2:64bit: - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - File not found
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Setwallpaper] File not found
O4:64bit: - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe (ASUS)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [FLxHCIm] C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe (Windows ® Win 7 DDK provider)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nuance PDF Reader-reminder] C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
O4 - HKCU..\Run: [2871788205] File not found
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe (Bodog)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72F31F6A-2D75-42AB-8A76-E388E026FF71}: DhcpNameServer = 4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1FEAF45-691C-4469-9A87-192658CDEE2D}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found
O18:64bit: - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/06 18:24:07 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\CED\aswMBR.exe
[2011/09/06 18:22:28 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Users\CED\OTL.exe
[2011/09/06 11:42:17 | 001,402,672 | —- | C] (Kaspersky Lab ZAO) – C:\Users\CED\tdsskiller.exe
[2011/09/06 11:41:54 | 001,402,672 | —- | C] (Kaspersky Lab ZAO) – C:\Users\CED\Desktop\tdsskiller.exe.part
[2011/09/06 11:04:31 | 000,607,260 | R— | C] (Swearware) – C:\Users\CED\Desktop\dds.scr
[2011/09/06 10:08:06 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/09/06 09:50:25 | 004,197,762 | R— | C] (Swearware) – C:\Users\CED\Desktop\ComboFix.exe
[2011/09/06 09:49:31 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\CED\Desktop\ATF_Cleaner.exe
[2011/09/06 09:10:28 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/09/06 09:10:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/06 09:09:53 | 009,466,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-setup-1.51.1.1800.exe
[2011/09/06 09:09:20 | 000,000,000 | —D | C] – C:\ProgramData\REPORTS
[2011/09/06 09:09:20 | 000,000,000 | —D | C] – C:\ProgramData\LOGFILES
[2011/09/06 09:09:20 | 000,000,000 | —D | C] – C:\ProgramData\INFECTED
[2011/09/06 09:00:31 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Local\CrashDumps
[2011/09/06 09:00:13 | 000,425,984 | —- | C] (Microsoft Corporation) – C:\Users\CED\AppData\Local\rip.exe
[2011/09/06 01:34:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect Uninstaller
[2011/09/06 01:34:55 | 000,000,000 | —D | C] – C:\Program Files\Perfect Uninstaller
[2011/09/06 01:34:11 | 003,485,888 | —- | C] (www.PerfectUninstaller.net ) – C:\Users\CED\Desktop\PerfectUninstaller_Setup.exe
[2011/09/06 01:22:40 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2011/09/06 01:22:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Security Task Manager
[2011/09/06 01:11:29 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/09/06 01:07:36 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/09/06 00:59:27 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/09/06 00:59:27 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/09/06 00:59:27 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/09/06 00:59:23 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/09/06 00:59:21 | 000,000,000 | —D | C] – C:\Qoobox
[2011/09/06 00:49:02 | 004,197,303 | R— | C] (Swearware) – C:\Users\CED\Desktop\Combo-Fix.exe
[2011/09/06 00:14:25 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Local\ElevatedDiagnostics
[2011/09/06 00:04:05 | 052,390,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MRT.exe
[2011/09/06 00:03:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/09/05 23:55:22 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/09/05 23:43:10 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Runscanner.net
[2011/09/05 23:20:44 | 007,748,456 | —- | C] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-rules.exe
[2011/09/05 23:11:12 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Local\NPE
[2011/09/05 23:11:12 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/09/05 20:22:17 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/08/26 08:35:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy MP3 Alarm Clock
[2011/08/26 08:35:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Easy MP3 Alarm Clock
[2011/08/24 21:34:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2011/08/21 13:51:20 | 000,000,000 | —D | C] – C:\Iperpokerclub
[2011/08/20 22:37:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/08/19 19:42:47 | 000,000,000 | —D | C] – C:\Poker4X
[2011/08/16 19:04:41 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bodog Hand Grabber
[2011/08/16 19:04:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bodog Hand Grabber
[2011/08/16 19:04:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bodog Hand Grabber
[2011/08/15 19:18:53 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Microgaming
[2011/08/13 18:51:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\24 Poker
[2011/08/13 18:50:27 | 000,000,000 | —D | C] – C:\Poker
[2011/08/13 18:50:19 | 000,000,000 | —D | C] – C:\Microgaming
[2011/08/13 18:50:13 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CarbonPoker
[2011/08/13 18:50:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\CarbonPoker
[2011/08/12 10:02:05 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Roxio Log Files
[2011/08/10 08:48:54 | 000,000,000 | —D | C] – C:\Windows\SysNative\SPReview
[2011/08/10 00:13:28 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/08/10 00:13:26 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2011/08/10 00:13:26 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2011/08/10 00:13:25 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2011/08/10 00:13:25 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2011/08/10 00:13:25 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2011/08/10 00:13:25 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2011/08/10 00:13:25 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2011/08/10 00:13:25 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2011/08/10 00:13:25 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2011/08/10 00:13:18 | 001,162,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2011/08/10 00:13:18 | 000,421,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2011/08/10 00:13:18 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2011/08/10 00:13:18 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2011/08/10 00:13:18 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/08/10 00:13:18 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/08/10 00:13:18 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/08/10 00:13:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2011/08/10 00:13:18 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/08/10 00:13:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2011/08/10 00:13:17 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/08/10 00:13:17 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/08/10 00:13:17 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/08/10 00:13:17 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/08/10 00:13:17 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/08/10 00:13:16 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/08/10 00:13:16 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/08/10 00:13:16 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/10 00:13:16 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/08/10 00:13:16 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/08/10 00:13:16 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/08/10 00:13:00 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/08/10 00:12:58 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/08/10 00:12:58 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/08/10 00:12:58 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/08/10 00:12:58 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/08/10 00:12:58 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/08/10 00:12:58 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/08/10 00:12:54 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/08/10 00:12:53 | 005,561,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/08/10 00:12:53 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[1 C:\Users\CED\AppData\Local\*.tmp files -> C:\Users\CED\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/06 18:24:16 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\CED\aswMBR.exe
[2011/09/06 18:22:28 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Users\CED\OTL.exe
[2011/09/06 18:05:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/06 11:42:17 | 001,402,672 | —- | M] (Kaspersky Lab ZAO) – C:\Users\CED\tdsskiller.exe
[2011/09/06 11:41:57 | 001,402,672 | —- | M] (Kaspersky Lab ZAO) – C:\Users\CED\Desktop\tdsskiller.exe.part
[2011/09/06 11:36:10 | 000,004,588 | —- | M] () – C:\Users\CED\Desktop\Attach.zip
[2011/09/06 11:05:47 | 000,294,216 | —- | M] () – C:\Users\CED\Desktop\gmer.zip
[2011/09/06 11:04:31 | 000,607,260 | R— | M] (Swearware) – C:\Users\CED\Desktop\dds.scr
[2011/09/06 10:17:01 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/06 10:17:01 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/06 10:13:49 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/06 10:13:49 | 000,624,622 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/09/06 10:13:49 | 000,106,708 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/09/06 10:09:56 | 000,000,408 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/06 10:09:18 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/06 10:09:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/06 10:09:12 | 2129,526,783 | -HS- | M] () – C:\hiberfil.sys
[2011/09/06 09:50:25 | 004,197,762 | R— | M] (Swearware) – C:\Users\CED\Desktop\ComboFix.exe
[2011/09/06 09:49:54 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\CED\Desktop\ATF_Cleaner.exe
[2011/09/06 09:20:12 | 004,104,900 | —- | M] () – C:\Users\CED\Desktop\RootkitBuster_5.00.1041.zip
[2011/09/06 09:10:05 | 009,466,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-setup-1.51.1.1800.exe
[2011/09/06 09:00:21 | 000,000,988 | -HS- | M] () – C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:21 | 000,000,988 | -HS- | M] () – C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\wnkl.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\shbo.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\rplk.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\pycc.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\pbau.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\lhpw.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\jgnm.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\huln.exe
[2011/09/06 09:00:13 | 000,425,984 | —- | M] (Microsoft Corporation) – C:\Users\CED\AppData\Local\rip.exe
[2011/09/06 01:34:58 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/09/06 01:34:11 | 003,485,888 | —- | M] (www.PerfectUninstaller.net ) – C:\Users\CED\Desktop\PerfectUninstaller_Setup.exe
[2011/09/06 01:22:29 | 002,086,240 | —- | M] () – C:\Users\CED\Desktop\SecurityTaskManager_Setup.exe
[2011/09/06 01:16:21 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\{8DD69FA3-6A02-4C59-B5F8-8C877F5EDC0D}
[2011/09/06 01:07:29 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/09/06 00:58:59 | 004,197,303 | R— | M] (Swearware) – C:\Users\CED\Desktop\Combo-Fix.exe
[2011/09/05 23:45:36 | 000,230,767 | —- | M] () – C:\Users\CED\Desktop\runscanner.run
[2011/09/05 23:20:54 | 007,748,456 | —- | M] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-rules.exe
[2011/09/05 23:20:38 | 000,035,229 | —- | M] () – C:\Users\CED\Desktop\3000-8022_4-10804572.html
[2011/09/05 20:25:27 | 001,803,670 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/09/05 20:21:14 | 000,512,992 | —- | M] () – C:\Users\CED\Desktop\sdsetup.exe
[2011/09/03 18:11:41 | 000,111,412 | —- | M] () – C:\Users\CED\Desktop\img0010cm.jpg
[2011/09/03 18:10:49 | 000,249,732 | —- | M] () – C:\Users\CED\Desktop\img0027v.jpg
[2011/09/01 10:10:20 | 000,002,050 | —- | M] () – C:\Users\CED\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/31 02:52:32 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/08/31 02:52:32 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/08/26 08:35:34 | 000,000,982 | —- | M] () – C:\Users\Public\Desktop\Easy MP3 Alarm Clock.lnk
[2011/08/25 18:13:29 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/08/21 13:51:45 | 000,001,492 | —- | M] () – C:\Users\CED\Desktop\Iperpokerclub.lnk
[2011/08/20 22:37:05 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/08/19 19:42:55 | 000,001,404 | —- | M] () – C:\Users\CED\Desktop\Poker4X.lnk
[2011/08/16 19:04:41 | 000,001,115 | —- | M] () – C:\Users\CED\Desktop\Bodog Hand Grabber.lnk
[2011/08/15 22:03:14 | 000,000,000 | —- | M] () – C:\Windows\HMHud.INI
[2011/08/14 20:29:38 | 000,000,114 | —- | M] () – C:\Windows\SysWow64\1744935990
[2011/08/13 18:51:17 | 000,000,895 | —- | M] () – C:\Users\Public\Desktop\24 Poker.lnk
[2011/08/13 18:50:30 | 000,000,695 | —- | M] () – C:\Users\CED\Desktop\Uncover.lnk
[2011/08/13 18:50:18 | 000,001,904 | —- | M] () – C:\Users\CED\Desktop\CarbonPoker.lnk
[2011/08/11 19:20:45 | 000,001,458 | —- | M] () – C:\Users\CED\Desktop\logs - Shortcut.lnk
[2011/08/11 17:46:28 | 1036,403,034 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/08/11 03:18:47 | 000,275,064 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/10 09:01:31 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msclmd.dll
[2011/08/10 09:01:30 | 000,175,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msclmd.dll
[1 C:\Users\CED\AppData\Local\*.tmp files -> C:\Users\CED\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/06 11:36:10 | 000,004,588 | —- | C] () – C:\Users\CED\Desktop\Attach.zip
[2011/09/06 11:05:38 | 000,294,216 | —- | C] () – C:\Users\CED\Desktop\gmer.zip
[2011/09/06 10:10:29 | 000,001,441 | —- | C] () – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/09/06 09:24:00 | 000,000,408 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/06 09:20:07 | 004,104,900 | —- | C] () – C:\Users\CED\Desktop\RootkitBuster_5.00.1041.zip
[2011/09/06 09:00:21 | 000,000,988 | -HS- | C] () – C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:21 | 000,000,988 | -HS- | C] () – C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\wnkl.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\shbo.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\rplk.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\pycc.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\pbau.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\lhpw.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\jgnm.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\huln.exe
[2011/09/06 01:34:58 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/09/06 01:22:29 | 002,086,240 | —- | C] () – C:\Users\CED\Desktop\SecurityTaskManager_Setup.exe
[2011/09/06 01:16:21 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\{8DD69FA3-6A02-4C59-B5F8-8C877F5EDC0D}
[2011/09/06 00:59:27 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/09/06 00:59:27 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/09/06 00:59:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/09/06 00:59:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/09/06 00:59:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/09/05 23:45:35 | 000,230,767 | —- | C] () – C:\Users\CED\Desktop\runscanner.run
[2011/09/05 23:20:37 | 000,035,229 | —- | C] () – C:\Users\CED\Desktop\3000-8022_4-10804572.html
[2011/09/05 20:24:59 | 001,803,670 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/09/05 20:22:17 | 000,512,992 | —- | C] () – C:\Users\CED\Desktop\sdsetup.exe
[2011/09/03 18:11:40 | 000,111,412 | —- | C] () – C:\Users\CED\Desktop\img0010cm.jpg
[2011/09/03 18:10:48 | 000,249,732 | —- | C] () – C:\Users\CED\Desktop\img0027v.jpg
[2011/08/26 08:35:34 | 000,000,982 | —- | C] () – C:\Users\Public\Desktop\Easy MP3 Alarm Clock.lnk
[2011/08/24 21:34:44 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2011/08/21 13:51:45 | 000,001,492 | —- | C] () – C:\Users\CED\Desktop\Iperpokerclub.lnk
[2011/08/19 19:42:55 | 000,001,404 | —- | C] () – C:\Users\CED\Desktop\Poker4X.lnk
[2011/08/16 19:04:41 | 000,001,115 | —- | C] () – C:\Users\CED\Desktop\Bodog Hand Grabber.lnk
[2011/08/15 22:03:14 | 000,000,000 | —- | C] () – C:\Windows\HMHud.INI
[2011/08/13 18:51:17 | 000,000,895 | —- | C] () – C:\Users\Public\Desktop\24 Poker.lnk
[2011/08/13 18:50:30 | 000,000,725 | —- | C] () – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uncover.lnk
[2011/08/13 18:50:30 | 000,000,695 | —- | C] () – C:\Users\CED\Desktop\Uncover.lnk
[2011/08/13 18:50:18 | 000,001,904 | —- | C] () – C:\Users\CED\Desktop\CarbonPoker.lnk
[2011/08/11 19:20:45 | 000,001,458 | —- | C] () – C:\Users\CED\Desktop\logs - Shortcut.lnk
[2011/06/27 19:07:11 | 000,233,472 | —- | C] () – C:\Windows\SysWow64\lame_enc.dll
[2011/06/18 19:27:43 | 000,008,704 | —- | C] () – C:\Users\CED\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/18 02:52:03 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/06/18 02:52:03 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/06/13 13:45:08 | 000,000,060 | —- | C] () – C:\ProgramData\422f8c46
[2011/06/13 02:23:50 | 000,007,605 | —- | C] () – C:\Users\CED\AppData\Local\Resmon.ResmonCfg
[2011/05/18 19:13:21 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/05/01 14:28:21 | 000,743,738 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/29 13:35:02 | 000,001,200 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/03/29 13:35:02 | 000,001,099 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/03/29 13:35:02 | 000,001,099 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/03/29 13:35:01 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/03/29 13:35:01 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/03/29 13:22:18 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009/10/25 22:38:22 | 000,000,176 | —- | C] () – C:\Windows\explorer.exe.config
[2009/07/29 00:20:40 | 000,000,010 | —- | C] () – C:\Windows\SysWow64\ABLKSR.ini
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/09/06 09:22:20 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\.purple
[2011/04/29 13:34:20 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Asus WebStorage
[2011/06/27 01:02:03 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Audacity
[2011/06/18 19:13:53 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\GrabPro
[2011/08/26 20:38:34 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\gtk-2.0
[2011/08/26 20:12:45 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\HEM Data
[2011/09/04 18:47:05 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Microgaming
[2011/06/18 19:13:49 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\OpenCandy
[2011/06/18 19:24:11 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Orbit
[2011/06/18 19:13:57 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\ProgSense
[2011/09/05 23:43:10 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Runscanner.net
[2011/09/01 22:20:26 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\SoftGrid Client
[2011/04/30 13:59:12 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\SystemRequirementsLab
[2011/05/01 14:29:02 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\TP
[2011/09/06 10:09:56 | 000,000,408 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/14 00:08:49 | 000,027,874 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 81 bytes -> C:\Program Files (x86)\Cake Poker 2.0:MID
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:DFC5A2B2

< End of report >



Here's my extras.txt:
OTL Extras logfile created on: 9/6/2011 6:23:55 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\CED
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.98 Gb Total Physical Memory | 5.38 Gb Available Physical Memory | 67.42% Memory free
15.95 Gb Paging File | 13.30 Gb Available in Paging File | 83.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 174.66 Gb Total Space | 76.26 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
Drive D: | 502.49 Gb Total Space | 474.31 Gb Free Space | 94.39% Space Free | Partition Type: NTFS
Drive E: | 3.69 Gb Total Space | 0.32 Gb Free Space | 8.63% Space Free | Partition Type: FAT32

Computer Name: CED-PC | User Name: CED | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources
"{206BD2C5-DE08-4577-A0D7-D441A79D5A3A}" = Windows Live Remote Client Resources
"{289809B1-078A-49F3-83D0-7E51715B3915}" = Windows Live Family Safety
"{28D73032-5DAA-4F83-B154-85105DBCCB92}" = iTunes
"{3946328A-5B3A-434C-A22B-64CF6652FBAD}" = Windows Live Family Safety
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intel® Turbo Boost Technology Monitor
"{401C50F6-B443-43EE-8F27-A80DB19B03FD}" = Windows Live Family Safety
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{45C1C61B-9DA9-4B61-8C89-C76B1746C3AA}" = Fresco Logic USB3.0 Host Controller
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{911519EB-BD75-4B3B-BD17-BA3747C9B854}" = Windows Live Family Safety
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AE91E0F3-C49A-4EF4-8B98-A07BD409EB90}" = Windows Live Remote Service Resources
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources
"{FE4BE0BD-1EDB-4D24-9614-847B3C472887}" = Windows Live Family Safety
"2AA10AB519DC7432D599A0E860206A7DDCC27764" = Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0)
"3BA80AB4C7E9F8497C115C844953A3D4BEB84D21" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1" = Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405)
"7341A1B43E7FE58942EB1E820A17C18305DFBCE6" = Windows Driver Package - Broadcom Bluetooth (01/19/2010 6.2.0.1417)
"85CE3A3657FAE5FD305B143E90E6FC89BA53001C" = Windows Driver Package - Broadcom (BTHUSB) Bluetooth (02/25/2010 6.2.0.9419)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Perfect Uninstaller_is1" = Perfect Uninstaller v6.3.3.9
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000F2A10-9CDF-47BF-9CF2-9AC87567B433}" = Windows Live Photo Common
"{02EE09E7-958A-4E7F-80B6-8BA2D262BD04}" = ASUS AI Recovery
"{03241D8D-2217-42F7-9FCB-6A68D141C14D}" = Windows Live 软件包
"{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{09F56A49-A7B1-4AAB-95B9-D13094254AD1}" = Windows Live UX Platform Language Pack
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{21B49B4A-BBC3-4A09-9C68-6C3CC0B1EA01}" = Windows Live Messenger
"{23181592-0ECD-4A16-81C6-F0424D2DCABF}" = Windows Live UX Platform Language Pack
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common
"{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger
"{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh
"{317D56AC-0DB3-48F5-929A-42032DAC9AD7}" = Windows Live Writer
"{32C01DD0-3260-4D2B-BDB2-36CEC3E5B27A}" = Windows Live UX Platform Language Pack
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{341697D8-9923-445E-B42A-529E5A99CB7A}" = syncables desktop SE
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
"{3A09ED0F-8DDF-47BB-B53D-841AB9D1D3A7}" = Complemento Messenger
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}" = Camtasia Studio 7
"{499DED08-6FA8-4749-8E94-8526CC9D1CA8}" = ExpressGate Cloud
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A275FD1-2F24-4274-8C01-813F5AD1A92D}" = Windows Live Messenger
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{588CE0C0-860B-49A8-AFCF-3C69465B345F}" = Windows Live Mesh
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{622DE1BE-9EDE-49D3-B349-29D64760342A}" = 適用遠端連線的 Windows Live Mesh ActiveX 控制項
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{63AE67AA-1AB1-4565-B4EF-ABBC5C841E8D}" = Windows Live Messenger
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{685DEA21-3622-455A-A41B-89557A168DFD}" = Ad-Aware
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}" = Complément Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7115EEBC-DA7B-434C-B81C-EA5B26EA9A94}" = Windows Live Writer Resources
"{753F0A72-59C3-41CE-A36A-F2DF2079275C}" = Windows Live Mail
"{76046298-768C-492C-8C93-2983C9E3719E}" = Windows Live UX Platform Language Pack
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7B982EBD-D017-4527-BF1A-FC489EC6B100}" = Windows Live 照片库
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7F061FA8-5A87-4758-876B-17EE28B358D0}" = Messenger 浏览器插件
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{903EDF14-4E28-4463-AA5E-4AEE71C0263B}" = Windows Live Movie Maker
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{939C80FA-96C9-44A6-B318-8E7D8BD8481B}" = Messenger Companion
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-00AF-0409-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B11AB9C8-18A6-41DC-98B4-4988CC030136}" = THX TruStudio
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B480904D-F73F-4673-B034-8A5F492C9184}" = Nuance PDF Reader
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF088261-BC81-4FB9-9BA0-7B5B9602D01A}" = Messenger 分享元件
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
"{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{ED86C4AB-D1E5-42CF-BFA3-56BAAE617D4E}" = Windows Live UX Platform Language Pack
"{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心
"{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F992409C-9D10-4AE2-BAEB-B5409AD3785E}" = 用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文)
"{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"5F4EE0CB-CAB9-426E-B314-F3F7B5C79BC2" = Iperpokerclub
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ares" = Ares 2.1.7
"Asus Vibe2.0" = AsusVibe2.0
"ASUS WebStorage" = ASUS WebStorage
"Asus_G73_Screensaver" = Asus_G73_Screensaver
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Premium
"Bodog Hand Grabber" = Bodog Hand Grabber 1.17
"Bodog Poker_is1" = Bodog Poker
"C36BCFC5-25CB-4677-8451-3D9B7E4EFE0C" = Poker4X
"Cake Poker 2.0" = Cake Poker 2.0
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"HoldemManager" = Holdem Manager
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{499DED08-6FA8-4749-8E94-8526CC9D1CA8}" = ExpressGate Cloud
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Mozilla Firefox 6.0.1 (x86 en-US)" = Mozilla Firefox 6.0.1 (x86 en-US)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"OpenVPN" = OpenVPN 2.1_rc15
"Pidgin" = Pidgin
"PokerStars" = PokerStars
"PostgreSQL 8.4" = PostgreSQL 8.4
"Security Task Manager" = Security Task Manager 1.8d
"StartNow Toolbar" = StartNow Toolbar
"SystemRequirementsLab" = System Requirements Lab
"Winamp" = Winamp (remove only)
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CarbonPoker" = CarbonPoker
"Sportsbook.com" = Sportsbook.com

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/6/2011 4:20:42 AM | Computer Name = CED-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 9/6/2011 10:00:28 AM | Computer Name = CED-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Update.exe_Microsoft® Windows® Operating
System, version: 6.1.7601.17514, time stamp: 0x4ce78ecc Faulting module name: ntdll.dll,
version: 6.1.7601.17514, time stamp: 0x4ce7ba58 Exception code: 0xc0000374 Fault
offset: 0x000ce653 Faulting process id: 0x1dc0 Faulting application start time: 0x01cc6c9d4d9bb7dd
Faulting
application path: C:\windows\syswow64\sysprep\Update.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report
Id: 92efa996-d890-11e0-93e2-74f06dc60eba

Error - 9/6/2011 10:04:41 AM | Computer Name = CED-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\CED\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 9/6/2011 10:23:38 AM | Computer Name = CED-PC | Source = Avira AntiVir | ID = 4112
Description = An error occurred during a resource request to the Windows NT system.
The resource has not been allocated. This could be due to an out-of-memory
error or any other system failure. Returned error code: 0x424

Error - 9/6/2011 10:23:39 AM | Computer Name = CED-PC | Source = PostgreSQL | ID = 0
Description = 2011-09-06 09:23:39 CDTFATAL: the database system is starting up

Error - 9/6/2011 11:09:20 AM | Computer Name = CED-PC | Source = Avira AntiVir | ID = 4112
Description = An error occurred during a resource request to the Windows NT system.
The resource has not been allocated. This could be due to an out-of-memory
error or any other system failure. Returned error code: 0x424

Error - 9/6/2011 11:09:22 AM | Computer Name = CED-PC | Source = PostgreSQL | ID = 0
Description = 2011-09-06 10:09:22 CDTFATAL: the database system is starting up

Error - 9/6/2011 11:11:59 AM | Computer Name = CED-PC | Source = MBAMService | ID = 131073
Description =

Error - 9/6/2011 11:11:59 AM | Computer Name = CED-PC | Source = MBAMService | ID = 131073
Description =

Error - 9/6/2011 7:22:49 PM | Computer Name = CED-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\CED\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ System Events ]
Error - 9/3/2011 1:16:13 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:14 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:15 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:16 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:17 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:18 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:19 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/3/2011 1:16:20 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.

Error - 9/4/2011 12:02:39 PM | Computer Name = CED-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:45:33 AM on ?9/?4/?2011 was unexpected.

Error - 9/4/2011 7:42:42 PM | Computer Name = CED-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{13512C70-9DF7-49A1-BDF7-6E10E0F66A14}
because another computer on the network has the same name. The server could not
start.


< End of report >
Here's the aswMBR text: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-06 18:31:12 —————————– 18:31:12.081 OS Version: Windows x64 6.1.7601 Service Pack 1 18:31:12.081 Number of processors: 8 586 0x2A07 18:31:12.083 ComputerName: CED-PC UserName: CED 18:31:13.298 Initialize success 18:32:37.941 AVAST engine defs: 11090601 18:33:24.540 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 18:33:24.546 Disk 0 Vendor: ST975042 0002 Size: 715404MB BusType: 3 18:33:24.601 Disk 0 MBR read successfully 18:33:24.610 Disk 0 MBR scan 18:33:24.620 Disk 0 Windows 7 default MBR code 18:33:24.627 Service scanning 18:33:25.859 Modules scanning 18:33:25.868 Disk 0 trace - called modules: 18:33:25.886 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 18:33:25.897 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80077d0790] 18:33:25.906 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007248b20] 18:33:25.916 5 ACPI.sys[fffff88000f2b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800724e050] 18:33:27.110 AVAST engine scan C:\Windows 18:33:30.462 AVAST engine scan C:\Windows\system32 18:35:25.588 AVAST engine scan C:\Windows\system32\drivers 18:35:39.318 AVAST engine scan C:\Users\CED 18:36:05.290 Disk 0 MBR has been saved successfully to "C:\Users\CED\Desktop\MBR.dat" 18:36:05.305 The log file has been saved successfully to "C:\Users\CED\Desktop\aswMBR.txt"
Hello Python49,

Yes I'm still here, been going though your log which does take awhile. I have to wait till I get off work tonite to finish going though it.
Hi Python49,

I apologize for the delay.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")

For Vista and Windows 7
====================

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features
A list of installed programs will populate
Remove the following programs:

StartNow Toolbar
===============================
NEXT

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total
jotti.org
Kaspersky Virus File Scanner


click on Browse, and upload the following file for analysis:

C:\Windows\SysWow64\1744935990


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
===============================
NEXT

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - prefs.js..extensions.enabledItems: {22C7F6C6-8D67-4534-92B5-529A0EC09405}:6.5.0.1234
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\
    [2011/04/29 13:36:55 | 000,000,000 | —D | M] (No name found) – C:\Users\CED\AppData\Roaming\Mozilla\Extensions
    [2011/09/06 01:05:22 | 000,000,000 | —D | M] (No name found) – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions
    O2:64bit: - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - File not found
    O2:64bit: - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKCU..\Run: [2871788205] File not found
    O18:64bit: - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found
    O18:64bit: - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found
    O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found
    O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found
    [2011/09/06 09:00:21 | 000,000,988 | -HS- | M] () – C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
    [2011/09/06 09:00:21 | 000,000,988 | -HS- | M] () – C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
    [2011/09/06 01:34:58 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\AK083E209605E394C.lie
    [2011/09/06 01:16:21 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\{8DD69FA3-6A02-4C59-B5F8-8C877F5EDC0D}
    [2011/09/06 09:00:21 | 000,000,988 | -HS- | C] () – C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
    [2011/09/06 09:00:21 | 000,000,988 | -HS- | C] () – C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
    [2011/08/26 08:35:12 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:DFC5A2B2
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Please post the results in your next reply.

==================
NEXT

Please delete the old Combofix on your computer and download a new Combofix. If Combofix still complains about Trend Micro just to go ahead with the scan.

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

IMPORTANT - Disable your AntiVirus and AntiSpyware

applications
, usually via a right click on the System Tray icon. They may otherwise

interfere with our tools. If you have difficulty properly disabling your protective

programs, refer to this link

here

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will
    produce a report for you.
  • Please post the C:\ComboFix.txt for further review.

======================
Please include in your next reply:
1. Any problem executing the instructions?
2. virustotal report
3. OTL log
4. Combofix log
5.How is the computer behaving?
Hey, I tried closing avira before running combofix but its already showing that its inactive/disabled, but I found it weird that it doesn't show as a process that's running in task manager and also that when right clicking it from the system tray there's no option like "close" or "exit.". I also wasn't able to disable or close trend micro because it doesn't show up as running anywhere in my task manager or system tray, so I ran combofix anyway like you said. Ad-aware live watch oddly enough was said to be running by combofix as well even after I had right clicked and disabled it as well as closed out of it. Anyway, here are the results/logs you asked for: Jotti's malware scan Filename: 1744935990 Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Thu 8 Sep 2011 23:50:01 (CET) Permalink Additional info File size: 114 bytes Filetype: Unknown MD5: e03b73eea2337acda6ee73c214e3117a SHA1: d7031b0c25c92c3e2a5fc89cdc6a95890e076396 Scanners [ArcaVir] 2011-09-08 Found nothing [F-Secure Anti-Virus] 2011-09-08 Found nothing [Avast! antivirus] 2011-09-08 Found nothing [G DATA] 2011-09-08 Found nothing [Grisoft AVG Anti-Virus] 2011-09-08 Found nothing [Ikarus] 2011-09-08 Found nothing [Avira AntiVir] 2011-09-08 Found nothing [Kaspersky Anti-Virus] 2011-09-08 Found nothing [Softwin BitDefender] 2011-09-08 Found nothing [ESET NOD32] 2011-09-08 Found nothing [ClamAV] 2011-09-08 Found nothing [Panda Antivirus] 2011-09-08 Found nothing [CPsecure] 2011-09-08 Found nothing [Quick Heal] 2011-09-07 Found nothing [Dr.Web] 2011-09-08 Found nothing [Sophos] 2011-09-08 Found nothing [Emsisoft Anti-Malware] 2011-09-08 Found nothing [VirusBlokAda VBA32] 2011-09-08 Found nothing [Frisk F-Prot Antivirus] 2011-09-08 Found nothing [VirusBuster] 2011-09-08 Found nothing OTL Log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Prefs.js: {22C7F6C6-8D67-4534-92B5-529A0EC09405}:6.5.0.1234 removed from extensions.enabledItems File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension not found. C:\Users\CED\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Extensions folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\defaults\preferences folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\defaults folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\locale\en-US folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\locale folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\reactivate folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F} folder moved successfully. C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions folder moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CA1377B-DC1D-4A52-9585-6E06050FAC53}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CA1377B-DC1D-4A52-9585-6E06050FAC53}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\2871788205 deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\tmbp\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF}\ deleted successfully. File {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\tmpx\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E526CB5-7446-41D1-A403-19BFE95E8C23}\ deleted successfully. File {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\tmbp\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF}\ deleted successfully. File {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\tmpx\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E526CB5-7446-41D1-A403-19BFE95E8C23}\ deleted successfully. File {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found not found. C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa moved successfully. C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa moved successfully. C:\Windows\SysWOW64\AK083E209605E394C.lie moved successfully. C:\Users\CED\AppData\Local\{8DD69FA3-6A02-4C59-B5F8-8C877F5EDC0D} moved successfully. File C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa not found. File C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa not found. Folder C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\ not found. ADS C:\ProgramData\Temp:DFC5A2B2 deleted successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: CED ->Temp folder emptied: 48870233 bytes ->Temporary Internet Files folder emptied: 42406408 bytes ->Java cache emptied: 1065738 bytes ->FireFox cache emptied: 332004643 bytes ->Google Chrome cache emptied: 8074237 bytes ->Flash cache emptied: 115513 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56466 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: postgres ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56466 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 126410 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84793 bytes RecycleBin emptied: 138097485 bytes Total Files Cleaned = 545.00 mb OTL by OldTimer - Version 3.2.27.0 log created on 09082011_165054 Files\Folders moved on Reboot… C:\Users\CED\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Combofix log: ComboFix 11-09-08.03 - CED 09/08/2011 16:59:31.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8169.6359 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} AV: Trend Micro Titanium Internet Security *Enabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Trend Micro Titanium Internet Security *Enabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\huln.exe c:\programdata\lhpw.exe c:\programdata\pbau.exe c:\programdata\shbo.exe c:\users\CED\AppData\Local\jgnm.exe c:\users\CED\AppData\Local\pycc.exe c:\users\CED\AppData\Local\rip.exe c:\users\CED\AppData\Local\rplk.exe c:\users\CED\AppData\Local\wnkl.exe c:\users\CED\AppData\Roaming\Microsoft\Windows\Templates\gylv.exe c:\users\CED\AppData\Roaming\Microsoft\Windows\Templates\hepd.exe c:\users\CED\AppData\Roaming\Microsoft\Windows\Templates\paqt.exe c:\users\CED\AppData\Roaming\Microsoft\Windows\Templates\spwt.exe c:\users\CED\AppData\Roaming\Microsoft\Windows\Templates\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa c:\users\CED\aswMBR.exe c:\users\CED\OTL.exe c:\users\CED\tdsskiller.exe . . ((((((((((((((((((((((((( Files Created from 2011-08-08 to 2011-09-08 ))))))))))))))))))))))))))))))) . . 2011-09-08 22:04 . 2011-09-08 22:04 ——– d—–w- c:\users\postgres\AppData\Local\temp 2011-09-08 22:04 . 2011-09-08 22:04 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-09-08 21:50 . 2011-09-08 21:50 ——– d—–w- C:\_OTL 2011-09-07 22:48 . 2011-09-07 22:48 ——– d—–w- c:\users\CED\AppData\Local\Adobe 2011-09-06 14:10 . 2011-07-07 00:52 41272 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-09-06 14:09 . 2011-09-06 14:42 ——– d—–w- c:\programdata\LOGFILES 2011-09-06 14:09 . 2011-09-06 14:09 ——– d—–w- c:\programdata\REPORTS 2011-09-06 14:09 . 2011-09-06 14:09 ——– d—–w- c:\programdata\INFECTED 2011-09-06 14:00 . 2011-09-06 14:00 ——– d—–w- c:\users\CED\AppData\Local\CrashDumps 2011-09-06 06:34 . 2011-09-06 06:34 ——– d—–w- c:\program files\Perfect Uninstaller 2011-09-06 06:22 . 2011-09-06 06:25 ——– d—–w- c:\programdata\SecTaskMan 2011-09-06 06:22 . 2011-09-06 06:22 ——– d—–w- c:\program files (x86)\Security Task Manager 2011-09-06 06:16 . 2011-09-06 06:16 0 —ha-w- c:\users\CED\AppData\Local\BITB77F.tmp 2011-09-06 05:14 . 2011-09-06 05:14 ——– d—–w- c:\users\CED\AppData\Local\ElevatedDiagnostics 2011-09-06 05:03 . 2011-09-06 05:03 ——– d—–w- c:\program files (x86)\ESET 2011-09-06 04:55 . 2011-09-06 04:55 ——– d—–w- c:\programdata\Kaspersky Lab 2011-09-06 04:43 . 2011-09-06 04:43 ——– d—–w- c:\users\CED\AppData\Roaming\Runscanner.net 2011-09-06 04:11 . 2011-09-06 04:21 ——– d—–w- c:\users\CED\AppData\Local\NPE 2011-09-06 04:11 . 2011-09-06 04:11 ——– d—–w- c:\programdata\Norton 2011-09-06 01:22 . 2011-09-06 06:26 ——– d—–w- c:\programdata\PC Tools 2011-08-26 13:35 . 2011-08-26 13:35 ——– d—–w- c:\program files (x86)\Easy MP3 Alarm Clock 2011-08-25 02:34 . 2011-08-25 02:34 ——– d—–w- c:\program files (x86)\Audacity 2011-08-24 06:43 . 2011-07-09 05:26 2048 —-a-w- c:\windows\system32\tzres.dll 2011-08-24 06:43 . 2011-07-09 04:29 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-08-21 18:51 . 2011-09-05 21:45 ——– d—–w- C:\Iperpokerclub 2011-08-17 00:04 . 2011-08-17 00:05 ——– d—–w- c:\program files (x86)\Bodog Hand Grabber 2011-08-16 00:18 . 2011-09-04 23:47 ——– d—–w- c:\users\CED\AppData\Roaming\Microgaming 2011-08-13 23:50 . 2011-08-13 23:50 ——– d—–w- C:\Poker 2011-08-13 23:50 . 2011-08-13 23:50 ——– d—–w- C:\Microgaming 2011-08-13 23:50 . 2011-09-05 06:43 ——– d—–w- c:\program files (x86)\CarbonPoker 2011-08-12 15:02 . 2011-08-12 15:02 ——– d—–w- c:\users\CED\AppData\Roaming\Roxio Log Files 2011-08-10 13:48 . 2011-08-10 13:48 ——– d—–w- c:\windows\system32\SPReview 2011-08-10 05:12 . 2011-06-21 06:20 1188864 —-a-w- c:\windows\system32\wininet.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-25 23:13 . 2011-06-11 22:02 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-08-10 14:01 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2011-08-10 14:01 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2011-07-16 04:26 . 2011-08-10 05:13 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-07-07 00:52 . 2011-06-15 15:26 25912 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-06-29 07:51 . 2011-06-15 07:54 55384 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-06-28 10:31 . 2011-04-30 17:45 88288 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2011-06-28 10:31 . 2011-04-30 17:45 123784 —-a-w- c:\windows\system32\drivers\avipbb.sys 2011-06-24 17:51 . 2011-06-24 17:51 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2011-06-24 17:51 . 2011-06-24 17:51 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-06-24 17:51 . 2011-06-24 17:51 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-06-24 17:51 . 2011-06-24 17:51 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-06-15 07:54 . 2011-06-15 15:42 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-06-11 03:07 . 2011-07-12 17:06 3137536 —-a-w- c:\windows\system32\win32k.sys . . ((((((((((((((((((((((((((((( SnapShot@2011-09-06_06.07.35 ))))))))))))))))))))))))))))))))))))))))) . + 2011-09-08 21:53 . 2011-09-08 21:53 13294 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat - 2011-09-06 02:18 . 2011-09-06 02:18 13294 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat - 2009-07-14 04:54 . 2011-09-06 05:30 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-09-08 21:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-09-06 05:30 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-09-08 21:53 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-09-08 21:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-09-06 05:30 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-29 18:25 . 2011-09-08 21:55 56310 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-09-08 21:55 32116 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2011-04-29 18:15 . 2011-08-24 08:00 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-04-29 18:15 . 2011-09-07 08:00 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-08-24 08:00 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-09-07 08:00 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-04-29 19:44 . 2011-09-06 03:37 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-04-29 19:44 . 2011-09-08 21:55 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:46 . 2011-09-08 21:56 91680 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat - 2009-07-14 04:46 . 2011-09-06 03:39 91680 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2011-04-29 19:44 . 2011-09-08 21:55 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-04-29 19:44 . 2011-09-06 03:37 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-04-29 19:44 . 2011-09-08 21:55 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-04-29 19:44 . 2011-09-06 03:37 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-04-29 18:19 . 2011-09-08 21:55 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-04-29 18:19 . 2011-09-06 03:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-04-29 18:19 . 2011-09-08 21:55 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-04-29 18:19 . 2011-09-06 03:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-04-29 18:19 . 2011-09-08 21:55 8786 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-502504144-530022328-332390238-1001_UserData.bin + 2011-09-08 21:53 . 2011-09-08 21:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-09-06 06:07 . 2011-09-06 06:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-09-08 21:53 . 2011-09-08 21:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-09-06 06:07 . 2011-09-06 06:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 02:36 . 2011-09-08 21:58 624622 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-09-08 21:58 106708 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2011-09-05 19:08 230264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2011-09-08 21:53 230264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-04-19 09:21 . 2011-04-19 09:21 235520 c:\windows\Installer\495fc4.msi - 2009-07-14 04:45 . 2011-09-06 03:39 7112972 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat + 2009-07-14 04:45 . 2011-09-08 21:56 7112972 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat + 2009-07-14 02:34 . 2011-09-07 08:11 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat - 2009-07-14 02:34 . 2011-08-24 08:11 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat - 2011-05-02 04:40 . 2011-09-05 19:08 19886644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-502504144-530022328-332390238-1001-8192.dat + 2011-05-02 04:40 . 2011-09-08 21:53 19886644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-502504144-530022328-332390238-1001-8192.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2011-03-29 3058304] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-30 281768] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "FLxHCIm"="c:\program files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [2010-11-19 37888] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-07 449584] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-3-29 548528] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-11 1083680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer9"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [2011-06-28 340136] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-30 136360] R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-06-28 428200] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 EventSystem32;COM+ Event System ;c:\windows\system32\msoert232.exe [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-29 135664] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-09-02 2152152] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-07 366640] R2 UNS32;Intel® Management and Security Application User Notification Service ;c:\windows\system32\ias32.exe [x] R2 VideAceWindowsService;VideAceWindowsService;c:\expressgateutil\VAWinService.exe [2010-08-21 77312] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-03-29 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-03-29 79360] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-29 135664] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-29 236136] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x] S2 TurboBoost;Intel® Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [x] S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] . . — Other Services/Drivers In Memory — . *Deregistered* - Lavasoft Kernexplorer . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . Contents of the 'Scheduled Tasks' folder . 2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-29 17:45] . 2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-29 17:45] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2009-11-26 05:49 70656 —-a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2009-11-26 05:49 70656 —-a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-22 11075176] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "SynAsusAcpi"="c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe" [BU] "Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://asus.msn.com mStart Page = hxxp://asus.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - yahoo.com . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\postgresql-8.4] "ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\postgresql-8.4] "ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Microsoft\Cryptography\RNG*] "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-09-08 17:06:38 ComboFix-quarantined-files.txt 2011-09-08 22:06 ComboFix2.txt 2011-09-06 06:11 . Pre-Run: 82,034,454,528 bytes free Post-Run: 81,973,682,176 bytes free . - - End Of File - - CBA37CF10CEC991E855C3B5BDC7A0856
Hi Python49,

It would appear that you have more than one anti-virus solution on your machine. Besides AntiVir I can see Titanium Internet Security and Lavasoft Ad-Watch Live! Anti-Virus in the combofix log. Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine. I suggest you remove Lavasoft Ad-Watch Live! Anti-Virus along with the remnants of Titanium Internet Security. If you have any trouble uninstalling these two please let me know. After you are done, if you are not prompted to do so, please reboot your machine. Please advise if the issues continue once you only have one anti-virus on the machine.

Please go to http://esupport.trendmicro.com/solution/en-us/1037161.aspx and run the uninstall tool to remove Titanium Internet Security.


Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features
A list of installed programs will populate
Remove the following programs:

Ad-Aware
=================
NEXT

ComboFix - CFScript

This script is for this user and computer ONLY! Using this tool incorrectly could cause problems with your operating system… preventing it from ever starting again!
You will not have Internet access when you execute ComboFix. All open windows will need to be closed!

Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\users\CED\AppData\Local\BITB77F.tmp


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

==============
NEXT

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with he mbam log. Any remaining issues?
=====================
NEXT

As a Vista or Windows 7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. combofix log
3. MBAM log
4. ESET log
5. Please tell me how the computer is behaving?
the download link for the 64-bit windows 7 version of the program doesnt start downloading when I try, does that link on their site work for you? 64-bit under the windows 7 one
also, in case its relevant/helpful to note, i can't install itunes anymore to get it to work. when i do a fresh install and try to put songs on and then eject it tells me that it can't eject because certain files are in use. and then it will start telling me that itunes is missing certain components and needs to be re-installed

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI