This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Chrome Browser Hijacked

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So in regards to this post:
http://forums.whatthetech.com/index.php?showtopic=120363

I followed through with what conspire had to say but when I opened the GMER program there was the program but not the files needed to follow through with the steps.
Also here is the results of the OTL Scan:

P.S. I will post the "Extras.txt file next post.

Thanks Guys!! :D




OTL logfile created on: 9/10/2011 11:41:09 AM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:UsersGalleryDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 34.89% Memory free
5.93 Gb Paging File | 3.75 Gb Available in Paging File | 63.28% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 450.91 Gb Total Space | 355.52 Gb Free Space | 78.84% Space Free | Partition Type: NTFS
Drive K: | 1.91 Gb Total Space | 0.40 Gb Free Space | 20.64% Space Free | Partition Type: FAT

Computer Name: GALLERY-PC | User Name: Gallery | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersGalleryDownloadsOTL.exe (OldTimer Tools)
PRC - C:Program Files (x86)STOPzilla!SZOptionsFlash.exe (iS3, Inc.)
PRC - C:Program Files (x86)STOPzilla!STOPzilla.exe (iS3, Inc.)
PRC - C:Program Files (x86)Common FilesiS3Anti-SpywareSZScanner.exe (iS3, Inc.)
PRC - C:Program Files (x86)Common FilesiS3Anti-SpywareSZServer.exe (iS3, Inc.)
PRC - C:WindowsKMService.exe ()
PRC - C:WindowsSysWOW64srvany.exe ()
PRC - C:Program Files (x86)uTorrentuTorrent.exe (BitTorrent, Inc.)
PRC - C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (Adobe Systems Incorporated)
PRC - C:Program Files (x86)Dell DataSafe Local BackupComponentsDSUpdateDSUpd.exe (SoftThinks - Dell)
PRC - C:Program Files (x86)Dell DataSafe Local BackupComponentsSchedulerSTService.exe ()
PRC - C:Program Files (x86)Dell DataSafe Local BackupSftService.exe (SoftThinks SAS)
PRC - C:Program Files (x86)Dell Digital DeliveryDeliveryService.exe (Dell Products, LP.)
PRC - C:Program Files (x86)RoxioOEMRoxio BurnRoxioBurnLauncher.exe ()
PRC - C:Program Files (x86)Common FilesJavaJava Updatejucheck.exe (Sun Microsystems, Inc.)
PRC - C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe (Microsoft Corporation)
PRC - C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe (Microsoft Corporation)
PRC - C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe (Intel Corporation)
PRC - C:Program Files (x86)Lexmark 5000 Serieslxdmmon.exe ()
PRC - C:Program Files (x86)Lexmark 5000 Serieslxdmamon.exe ()


========== Modules (No Company Name) ==========

MOD - C:UsersGalleryAppDataLocalGoogleChromeApplication13.0.782.220ppgooglena
clpluginchrome.dll ()
MOD - C:UsersGalleryAppDataLocalGoogleChromeApplication13.0.782.220pdf.dll ()
MOD - C:UsersGalleryAppDataLocalGoogleChromeApplication13.0.782.220avutil-50.dll ()
MOD - C:UsersGalleryAppDataLocalGoogleChromeApplication13.0.782.220avformat-52.dll ()
MOD - C:UsersGalleryAppDataLocalGoogleChromeApplication13.0.782.220avcodec-52.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32IAStorUtil69d837670ac67c4776ea5a
115d64a550IAStorUtil.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Runtime.Remo#e3e3b399b69c
569ab1ed3b0ace2c8c20System.Runtime.Remoting.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Windows.Forms\0d43c5e77ee7b8466700b16d7e7d4bb7System.Windows.Forms.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Drawing9e87dd8fe5d0f925d8
0a6a6eaf74fdb9System.Drawing.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Xml16d2854bf69d59d94e64a9
18365705f1System.Xml.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32WindowsBase6124dbbfd45927c4a6226
d6e6bca6253WindowsBase.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Configuration36d0ed3f2a65
b9d67933ed46dfcd2ccbSystem.Configuration.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System3da7c6c1a0f26ae91883fd8b03
ec192dSystem.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32mscorlib16b68fcaff063835ae0ee348
a1201f2amscorlib.ni.dll ()
MOD - C:Program Files (x86)Dell DataSafe Local BackupComponentsSchedulerSTService.exe ()
MOD - c:Program Files (x86)Common FilesRoxio SharedDLLSharedSQLite352.dll ()
MOD - ?globalrootsystemrootsyswow64mswsock.DLL ()
MOD - C:Program Files (x86)RoxioOEMRoxio BurnRoxioBurnLauncher.exe ()
MOD - C:Program Files (x86)Microsoft OfficeOffice141033GrooveIntlResource.dll ()
MOD - C:Program Files (x86)Common Filesmicrosoft sharedOFFICE14CulturesOFFICE.ODF ()
MOD - C:Program Files (x86)Lexmark 5000 Serieslxdmmon.exe ()
MOD - C:Program Files (x86)Lexmark 5000 Seriesapp4r.monitor.core.dll ()
MOD - C:Program Files (x86)Lexmark 5000 Seriesapp4r.monitor.common.dll ()
MOD - C:Program Files (x86)Lexmark 5000 Seriesapp4r.devmons.mcmdevmon.dll ()
MOD - C:Program Files (x86)Lexmark 5000 Seriesapp4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:Program Files (x86)Lexmark 5000 Serieslxdmamon.exe ()
MOD - C:Program Files (x86)Lexmark 5000 Serieslxdmscw.dll ()
MOD - C:Program Files (x86)Lexmark 5000 Serieslxdmdatr.dll ()
MOD - C:Program Files (x86)Lexmark 5000 Serieslxdmcats.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (mfefire) – C:Program FilesCommon FilesMcAfeeSystemCoremfefire.exe (McAfee, Inc.)
SRV:64bit: - (McShield) – C:Program FilesCommon FilesMcAfeeSystemCoremcshield.exe ()
SRV:64bit: - (mfevtp) – C:WindowsSysNativemfevtps.exe (McAfee, Inc.)
SRV:64bit: - (McODS) – C:Program FilesmcafeeVirusScanmcods.exe (McAfee, Inc.)
SRV:64bit: - (wlcrasvc) – C:Program FilesWindows LiveMeshwlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (McAWFwk) – c:Program FilesmcafeemscMcAWFwk.exe (McAfee, Inc.)
SRV:64bit: - (MSK80Service) – C:Program FilesCommon FilesMcAfeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:Program FilesCommon FilesmcafeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) – C:Program FilesCommon FilesmcafeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:Program FilesCommon FilesmcafeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:Program FilesCommon FilesmcafeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:Program FilesCommon FilesmcafeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:Program FilesCommon FilesMcAfeeMcSvcHostMcSvHost.exe (McAfee, Inc.)
SRV:64bit: - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV:64bit: - (lxdm_device) – C:WindowsSysNativelxdmcoms.exe ( )
SRV:64bit: - (lxdmCATSCustConnectService) – C:WindowsSysNativespoolDRIVERSx643lxdmserv.exe ()
SRV - (szserver) – C:Program Files (x86)Common FilesiS3Anti-SpywareSZServer.exe (iS3, Inc.)
SRV - (KMService) – C:WindowsSysWOW64srvany.exe ()
SRV - (GoToAssist) – C:Program Files (x86)CitrixGoToAssist514g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (AdobeARMservice) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (Adobe Systems Incorporated)
SRV - (SftService) – C:Program Files (x86)Dell DataSafe Local Backupsftservice.EXE (SoftThinks SAS)
SRV - (DellDigitalDelivery) – C:Program Files (x86)Dell Digital DeliveryDeliveryService.exe (Dell Products, LP.)
SRV - (RoxWatch12) – C:Program Files (x86)Common FilesRoxio SharedOEM12.0SharedCOMRoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – C:Program Files (x86)Common FilesRoxio SharedOEM12.0SharedCOMRoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (GamesAppService) – C:Program Files (x86)WildTangent GamesAppGamesAppService.exe (WildTangent, Inc.)
SRV - (sftvsa) – C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe (Intel Corporation)
SRV - (SwitchBoard) – C:Program Files (x86)Common FilesAdobeSwitchBoardSwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:WindowsMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe (Microsoft Corporation)
SRV - (lxdm_device) – C:WindowsSysWow64lxdmcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfehidk) – C:WindowsSysNativedriversmfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:WindowsSysNativedriversmfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:WindowsSysNativedriversmfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:WindowsSysNativedriversmfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:WindowsSysNativedriversmfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:WindowsSysNativedriversmferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:WindowsSysNativedriversmfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:WindowsSysNativedriverscfwids.sys (McAfee, Inc.)
DRV:64bit: - (amdsata) – C:WindowsSysNativedriversamdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:WindowsSysNativedriversamdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:WindowsSysNativedriversTsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:WindowsSysNativedriversHpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:WindowsSysNativedriversTsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (Sftvol) – C:WindowsSysNativedriversSftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:WindowsSysNativedriversSftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:WindowsSysNativedriversSftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:WindowsSysNativedriversSftfslh.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:WindowsSysNativedriversPxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (RTL8167) – C:WindowsSysNativedriversRt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) – C:WindowsSysNativedriversamdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:WindowsSysNativedriverslsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:WindowsSysNativedriversstexstor.sys (Promise Technology)
DRV:64bit: - (igfx) – C:WindowsSysNativedriversigdkmd64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:WindowsSysNativedriversevbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:WindowsSysNativedriversbxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:WindowsSysNativedriversb57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:WindowsSysNativedrivershcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:WindowsSysNativedriversiaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:WindowsSysNativedriversIntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (WimFltr) – C:WindowsSysNativedriversWimFltr.sys (Microsoft Corporation)
DRV - (szkg5) – C:WindowsSySWOW64DRIVERSszkg64.sys (iS3 Inc.)
DRV - (is3srv) – C:WindowsSySWOW64driversis3srv64.sys (iS3 Inc.)
DRV - (WIMMount) – C:WindowsSysWOW64driverswimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://g.msn.com/USCON/23
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://my.yahoo.com/
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF:64bit: - [removed]/JavaPlugin: C:Program FilesJavajre6binnew_pluginnpjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - [removed]/GENUINE: disabled File not found
FF:64bit: - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~2Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/GoogleEarthPlugin: C:Program Files (x86)GoogleGoogle Earthpluginnpgeplugin.dll (Google)
FF - [removed]/JavaPlugin: C:Program Files (x86)Javajre6binnew_pluginnpjp2.dll (Sun Microsystems, Inc.)
FF - [removed]/GENUINE: disabled File not found
FF - [removed]/NpCtrl,version=1.0: c:Program Files (x86)Microsoft Silverlight4.0.60531.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~2MICROS~1Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~2MICROS~1Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3502.0922: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3508.1109: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/Google Update;version=3: C:Program Files (x86)GoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program Files (x86)GoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/GamesAppPresenceDetector,Version=1.0: C:Program Files (x86)WildTangent GamesAppBrowserIntegrationRegistered\0NP_wtapp.dll ()
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program Files (x86)AdobeReader 10.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - [removed]/Google Update;version=3: C:UsersGalleryAppDataLocalGoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:UsersGalleryAppDataLocalGoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 6.0.2extensionsComponents: C:Program Files (x86)Mozilla Firefoxcomponents [2011/09/08 17:14:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 6.0.2extensionsPlugins: C:Program Files (x86)Mozilla Firefoxplugins

[2011/09/08 17:14:39 | 000,000,000 | —D | M] (No name found) – C:UsersGalleryAppDataRoamingMozillaExtensions
[2011/07/29 10:56:10 | 000,000,000 | —D | M] (No name found) – C:UsersGalleryAppDataRoamingMozillaFirefoxProfilesvuc9egsm.defaultexten
sions
[2011/07/29 10:56:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:UsersGalleryAppDataRoamingMozillaFirefoxProfilesvuc9egsm.defaultexten
sions{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/08 17:14:18 | 000,000,000 | —D | M] (No name found) – C:Program Files (x86)Mozilla Firefoxextensions
[2011/09/02 23:18:14 | 000,134,104 | —- | M] (Mozilla Foundation) – C:Program Files (x86)mozilla firefoxcomponentsbrowsercomps.dll
[2011/09/02 17:25:08 | 000,001,538 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsamazon-en-GB.xml
[2011/09/02 17:13:56 | 000,002,252 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsbing.xml
[2011/09/02 17:25:08 | 000,000,947 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginschambers-en-GB.xml
[2011/09/02 17:25:08 | 000,001,180 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginseBay-en-GB.xml
[2011/09/02 17:25:08 | 000,001,135 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsyahoo-en-GB.xml

O1 HOSTS File: ([2010/05/13 17:53:40 | 000,001,204 | —- | M]) - C:WindowsSysNativedriversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:Program Filesmcafeemskmskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:Program FilesCommon FilesmcafeesystemcoreScriptSn.20110729190523.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:Program Filesmcafeemskmskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:Program Files (x86)Common FilesmcafeeSystemCoreScriptSn.20110729190523.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..Run: [AdobeAAMUpdater-1.0] C:Program Files (x86)Common FilesAdobeOOBEPDAppUWAUpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..Run: [DellStage] C:Program Files (x86)Dell StageDell Stagestage_primary.exe ()
O4:64bit: - HKLM..Run: [HotKeysCmds] C:WindowsSysNativehkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [IgfxTray] C:WindowsSysNativeigfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [lxdmamon] C:Program Files (x86)Lexmark 5000 Serieslxdmamon.exe ()
O4:64bit: - HKLM..Run: [lxdmmon.exe] C:Program Files (x86)Lexmark 5000 Serieslxdmmon.exe ()
O4:64bit: - HKLM..Run: [Persistence] C:WindowsSysNativeigfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [RtHDVCpl] C:Program FilesRealtekAudioHDARAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..Run: [] File not found
O4 - HKLM..Run: [AccuWeatherWidget] C:Program Files (x86)Dell StageDell StageAccuWeatheraccuweather.exe ()
O4 - HKLM..Run: [Adobe Reader Speed Launcher] C:Program Files (x86)AdobeReader 10.0ReaderReader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..Run: [AdobeCS5.5ServiceManager] File not found
O4 - HKLM..Run: [AdobeCS5ServiceManager] C:Program Files (x86)Common FilesAdobeCS5ServiceManagerCS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..Run: [Desktop Disc Tool] C:Program Files (x86)RoxioOEMRoxio BurnRoxioBurnLauncher.exe ()
O4 - HKLM..Run: [IAStorIcon] C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe (Intel Corporation)
O4 - HKLM..Run: [Lexmark 5000 Series] C:Program Files (x86)Lexmark 5000 Seriesfm3032.exe ()
O4 - HKLM..Run: [mcui_exe] C:Program FilesMcAfee.comAgentmcagent.exe (McAfee, Inc.)
O4 - HKLM..Run: [RoxWatchTray] C:Program Files (x86)Common FilesRoxio SharedOEM12.0SharedCOMRoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..Run: [SwitchBoard] C:Program Files (x86)Common FilesAdobeSwitchBoardSwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..Run: [uTorrent] C:Program Files (x86)uTorrentuTorrent.exe (BitTorrent, Inc.)
O6 - HKLMSoftwarePoliciesMicrosoftInternet Explorercontrol panel present
O6 - HKLMSoftwarePoliciesMicrosoftInternet Explorerrestrictions present
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktop = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktopChanges = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 5
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O7 - HKCUSoftwarePoliciesMicrosoftInternet Explorercontrol panel present
O7 - HKCUSoftwarePoliciesMicrosoftInternet Explorerrestrictions present
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000001 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000002 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000003 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000004 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000005 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000006 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000007 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000008 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000009 - File not found
O10:64bit: - Protocol_Catalog9Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9Catalog_Entries\000000000010 - File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{4AB245C9-297D-4DAA-AE33-53D1A4286542}: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - ProtocolHandlerhttp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerhttpoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerhttps\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerhttpsoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerlivecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlermsdaipp - No CLSID value found
O18:64bit: - ProtocolHandlermsdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlermsdaippoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlermsnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlermso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerskype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerwlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - ProtocolHandlerwlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - ProtocolHandlerhttp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerhttpoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerhttps\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerhttpsoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlermsdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlermsdaippoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dll (Skype Technologies)
O18 - ProtocolHandlerskype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - ProtocolFiltertext/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSysNativeuserinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:WindowsSysNativeSystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:WindowsSysWow64explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:windowssyswow64userinit.exe) - c:WindowsSysWOW64userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - WinlogonNotifyGoToAssist: DllName - Reg Error: Key error. - File not found
O20:64bit: - WinlogonNotifyigfxcui: DllName - Reg Error: Key error. - C:WindowsSysNativeigfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM..comfile [open] – "%1" %*
O35:64bit: - HKLM..exefile [open] – "%1" %*
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37:64bit: - HKLM…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM…exe [@ = exefile] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O37 - HKCU…exe [@ = exefile] – Reg Error: Key error. File not found


Drivers32:64bit: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:WindowsSysWOW64l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:WindowsSysWow64l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:WindowsSysWow64iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/10 10:51:34 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsMcAfee
[2011/09/10 10:46:07 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsSTOPzilla
[2011/09/10 10:46:05 | 000,000,000 | —D | C] – C:Program Files (x86)STOPzilla!
[2011/09/10 10:46:03 | 000,000,000 | —D | C] – C:Program Files (x86)Common FilesiS3
[2011/09/10 10:46:02 | 000,000,000 | —D | C] – C:ProgramDataSTOPzilla!
[2011/09/09 12:47:18 | 000,000,000 | —D | C] – C:UsersGalleryAppDataRoamingPDAppFlex
[2011/09/09 10:41:26 | 000,000,000 | —D | C] – C:UsersGalleryAppDataRoamingAdobe Mini Bridge CS5
[2011/09/09 10:41:25 | 000,000,000 | —D | C] – C:UsersGalleryAppDataRoamingStageManager.BD092818F67280F4B42B04877600987F01
11B594.1
[2011/09/08 17:14:17 | 000,000,000 | —D | C] – C:Program Files (x86)Mozilla Firefox
[2011/09/08 16:37:19 | 000,000,000 | —D | C] – C:UsersGalleryAppDataRoamingMicrosoftWindowsStart MenuProgramsGoogle Chrome
[2011/09/08 16:00:46 | 000,132,560 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3HTUI5.dll
[2011/09/08 16:00:46 | 000,022,992 | R— | C] (iS3, Inc.) – C:WindowsSysWow64SZIO5.dll
[2011/09/08 16:00:44 | 000,546,256 | R— | C] (iS3, Inc.) – C:WindowsSysWow64SZComp5.dll
[2011/09/08 16:00:44 | 000,480,720 | R— | C] (iS3, Inc.) – C:WindowsSysWow64SZBase5.dll
[2011/09/08 16:00:44 | 000,398,800 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3DBA5.dll
[2011/09/08 16:00:44 | 000,099,792 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3Svc5.dll
[2011/09/08 16:00:44 | 000,067,024 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3Hks5.dll
[2011/09/08 16:00:44 | 000,028,624 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3XDat5.dll
[2011/09/08 16:00:42 | 000,738,768 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3Base5.dll
[2011/09/08 16:00:42 | 000,390,608 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3UI5.dll
[2011/09/08 16:00:42 | 000,230,864 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3Win325.dll
[2011/09/08 16:00:42 | 000,099,792 | R— | C] (iS3, Inc.) – C:WindowsSysWow64IS3Inet5.dll
[2011/09/07 17:01:32 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocalWinZip
[2011/09/07 17:01:22 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsWinZip
[2011/09/07 17:01:04 | 000,000,000 | —D | C] – C:ProgramDataWinZip
[2011/09/07 17:00:57 | 000,000,000 | —D | C] – C:Program Files (x86)WinZip
[2011/09/07 16:50:32 | 000,000,000 | —D | C] – C:Windowssystem64
[2011/09/07 11:57:31 | 000,000,000 | —D | C] – C:ProgramDataregid.1986-12.com.adobe
[2011/09/07 11:29:03 | 000,000,000 | —D | C] – C:UsersGalleryDesktopAdobe Photoshop CS5.1
[2011/09/07 11:28:10 | 000,000,000 | —D | C] – C:UsersGalleryAppDataRoamingcom.adobe.downloadassistant.AdobeDownloadAssist
ant
[2011/09/07 11:28:08 | 000,000,000 | —D | C] – C:Program Files (x86)Adobe Download Assistant
[2011/09/07 11:23:03 | 000,000,000 | —D | C] – C:Program FilesAdobe
[2011/09/07 11:21:44 | 000,000,000 | —D | C] – C:Program FilesCommon FilesAdobe
[2011/09/07 11:20:42 | 000,000,000 | —D | C] – C:Program Files (x86)Adobe Media Player
[2011/09/07 11:20:42 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe
[2011/09/07 11:19:09 | 000,000,000 | —D | C] – C:Program Files (x86)Common FilesAdobe AIR
[2011/09/06 17:14:50 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsGoogle Earth
[2011/09/06 17:13:26 | 000,000,000 | —D | C] – C:Program Files (x86)Google
[2011/09/04 15:34:47 | 000,000,000 | —D | C] – C:UsersGalleryDesktopWind Sculpture videos
[2011/09/02 13:22:08 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocal{50131180-1F22-4C48-B311-DDB7927D8236}
[2011/08/24 15:27:40 | 000,000,000 | —D | C] – C:UsersGalleryDesktopiPad Videos
[2011/08/17 08:17:32 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocalWindows Live
[2011/08/17 08:16:51 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocal{84A5D2FE-651C-46ED-9719-5B5E62AD2EB4}
[2011/08/17 08:15:07 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocal{D5F2E610-6BEA-40DC-A2B6-99B1D6554D2E}
[2011/08/17 08:14:42 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocal{C487F499-3AE4-4219-986B-111C2396E369}
[2011/08/16 09:31:19 | 000,000,000 | —D | C] – C:Program Files (x86)MSECache
[2011/08/13 12:40:56 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocal{A9012C68-12C8-40BF-A298-EF323E905760}
[2011/08/13 12:40:55 | 000,000,000 | —D | C] – C:UsersGalleryAppDataLocal{B1EA1B2F-959B-4769-8E11-2CA08139B643}
[2011/07/30 11:02:03 | 000,356,352 | —- | C] ( ) – C:WindowsSysWow64lxdminpa.dll
[2011/07/30 11:02:03 | 000,339,968 | —- | C] ( ) – C:WindowsSysWow64lxdmiesc.dll
[2011/07/30 11:02:02 | 000,647,168 | —- | C] ( ) – C:WindowsSysWow64lxdmpmui.dll
[2011/07/30 11:02:01 | 001,200,128 | —- | C] ( ) – C:WindowsSysWow64lxdmserv.dll
[2011/07/30 11:02:01 | 000,950,272 | —- | C] ( ) – C:WindowsSysWow64lxdmusb1.dll
[2011/07/30 11:02:00 | 000,663,552 | —- | C] ( ) – C:WindowsSysWow64lxdmhbn3.dll
[2011/07/30 11:02:00 | 000,565,248 | —- | C] ( ) – C:WindowsSysWow64lxdmlmpm.dll
[2011/07/30 11:02:00 | 000,320,432 | —- | C] ( ) – C:WindowsSysWow64lxdmih.exe
[2011/07/30 11:02:00 | 000,053,248 | —- | C] ( ) – C:WindowsSysWow64lxdmprox.dll
[2011/07/30 11:01:59 | 000,860,160 | —- | C] ( ) – C:WindowsSysWow64lxdmcomc.dll
[2011/07/30 11:01:59 | 000,598,960 | —- | C] ( ) – C:WindowsSysWow64lxdmcoms.exe
[2011/07/30 11:01:59 | 000,365,488 | —- | C] ( ) – C:WindowsSysWow64lxdmcfg.exe
[2011/07/30 11:01:59 | 000,364,544 | —- | C] ( ) – C:WindowsSysWow64lxdmcomm.dll

========== Files - Modified Within 30 Days ==========

[2011/09/10 11:25:04 | 000,000,916 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2182563222-658159406-3346191950-1000UA.job
[2011/09/10 11:18:08 | 000,000,900 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2011/09/10 10:58:47 | 000,021,296 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/10 10:58:47 | 000,021,296 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/10 10:55:16 | 000,780,156 | —- | M] () – C:WindowsSysNativePerfStringBackup.INI
[2011/09/10 10:55:16 | 000,664,984 | —- | M] () – C:WindowsSysNativeperfh009.dat
[2011/09/10 10:55:16 | 000,125,462 | —- | M] () – C:WindowsSysNativeperfc009.dat
[2011/09/10 10:51:50 | 000,000,480 | —- | M] () – C:WindowsSysNativedriverskgpcpy.cfg
[2011/09/10 10:50:46 | 000,000,896 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2011/09/10 10:50:29 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2011/09/10 10:50:25 | 2388,381,696 | -HS- | M] () – C:hiberfil.sys
[2011/09/09 15:25:01 | 000,000,864 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2182563222-658159406-3346191950-1000Core.job
[2011/09/08 16:37:43 | 000,002,328 | —- | M] () – C:UsersGalleryDesktopGoogle Chrome.lnk
[2011/09/08 16:00:46 | 000,132,560 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3HTUI5.dll
[2011/09/08 16:00:46 | 000,022,992 | R— | M] (iS3, Inc.) – C:WindowsSysWow64SZIO5.dll
[2011/09/08 16:00:44 | 000,546,256 | R— | M] (iS3, Inc.) – C:WindowsSysWow64SZComp5.dll
[2011/09/08 16:00:44 | 000,480,720 | R— | M] (iS3, Inc.) – C:WindowsSysWow64SZBase5.dll
[2011/09/08 16:00:44 | 000,398,800 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3DBA5.dll
[2011/09/08 16:00:44 | 000,099,792 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3Svc5.dll
[2011/09/08 16:00:44 | 000,067,024 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3Hks5.dll
[2011/09/08 16:00:44 | 000,028,624 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3XDat5.dll
[2011/09/08 16:00:42 | 000,738,768 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3Base5.dll
[2011/09/08 16:00:42 | 000,390,608 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3UI5.dll
[2011/09/08 16:00:42 | 000,230,864 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3Win325.dll
[2011/09/08 16:00:42 | 000,099,792 | R— | M] (iS3, Inc.) – C:WindowsSysWow64IS3Inet5.dll
[2011/09/08 10:26:20 | 000,151,552 | —- | M] () – C:WindowsKMService.exe
[2011/09/08 10:26:20 | 000,008,192 | —- | M] () – C:WindowsSysWow64srvany.exe
[2011/09/07 17:01:22 | 000,002,249 | —- | M] () – C:UsersPublicDesktopWinZip.lnk
[2011/09/07 16:37:45 | 005,019,576 | —- | M] () – C:WindowsSysNativeFNTCACHE.DAT
[2011/09/07 12:00:14 | 000,001,037 | —- | M] () – C:UsersGalleryDesktopAdobe Photoshop CS5 (64 Bit).lnk
[2011/09/07 11:28:08 | 000,001,033 | —- | M] () – C:UsersPublicDesktopAdobe Download Assistant.lnk
[2011/09/06 17:14:50 | 000,002,286 | —- | M] () – C:UsersPublicDesktopGoogle Earth.lnk
[2011/08/26 10:08:51 | 000,002,021 | —- | M] () – C:UsersPublicDesktopAdobe Reader X.lnk
[2011/08/16 15:48:26 | 001,802,240 | —- | M] () – C:UsersGalleryDocumentsCall tracker.accdb
[2011/08/12 15:29:24 | 000,043,103 | —- | M] () – C:UsersGalleryDesktopmartin-mask-face-jay-brabant.JPG
[2011/08/12 15:17:44 | 000,031,004 | —- | M] () – C:UsersGalleryDesktopmartin-mask-jay-brabant.JPG

========== Files Created - No Company Name ==========

[2011/09/10 10:51:50 | 000,000,480 | —- | C] () – C:WindowsSysNativedriverskgpcpy.cfg
[2011/09/08 17:14:21 | 000,001,152 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsMozilla Firefox.lnk
[2011/09/08 16:37:43 | 000,002,328 | —- | C] () – C:UsersGalleryDesktopGoogle Chrome.lnk
[2011/09/08 10:26:53 | 000,151,552 | —- | C] () – C:WindowsKMService.exe
[2011/09/08 10:26:53 | 000,008,192 | —- | C] () – C:WindowsSysWow64srvany.exe
[2011/09/07 17:01:22 | 000,002,249 | —- | C] () – C:UsersPublicDesktopWinZip.lnk
[2011/09/07 12:00:14 | 000,001,037 | —- | C] () – C:UsersGalleryDesktopAdobe Photoshop CS5 (64 Bit).lnk
[2011/09/07 11:57:08 | 000,001,055 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Photoshop CS5.1 (64 Bit).lnk
[2011/09/07 11:55:52 | 000,001,187 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Bridge CS5.1.lnk
[2011/09/07 11:55:24 | 000,001,280 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Device Central CS5.5.lnk
[2011/09/07 11:54:27 | 000,001,381 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Extension Manager CS5.5.lnk
[2011/09/07 11:54:20 | 000,001,553 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe ExtendScript Toolkit CS5.5.lnk
[2011/09/07 11:28:08 | 000,001,045 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Download Assistant.lnk
[2011/09/07 11:28:08 | 000,001,033 | —- | C] () – C:UsersPublicDesktopAdobe Download Assistant.lnk
[2011/09/07 11:23:19 | 000,001,037 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Photoshop CS5 (64 Bit).lnk
[2011/09/07 11:21:42 | 000,001,171 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Bridge CS5.lnk
[2011/09/07 11:21:24 | 000,001,264 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Device Central CS5.lnk
[2011/09/07 11:19:51 | 000,001,355 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Extension Manager CS5.lnk
[2011/09/07 11:19:43 | 000,001,521 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe ExtendScript Toolkit CS5.lnk
[2011/09/07 11:19:11 | 000,000,999 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdobe Help.lnk
[2011/09/06 17:14:50 | 000,002,286 | —- | C] () – C:UsersPublicDesktopGoogle Earth.lnk
[2011/09/06 17:13:32 | 000,000,900 | —- | C] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2011/09/06 17:13:31 | 000,000,896 | —- | C] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2011/08/26 10:08:51 | 000,002,021 | —- | C] () – C:UsersPublicDesktopAdobe Reader X.lnk
[2011/08/16 15:48:03 | 001,802,240 | —- | C] () – C:UsersGalleryDocumentsCall tracker.accdb
[2011/08/16 09:32:12 | 000,002,537 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsMicrosoft Office Excel Viewer.lnk
[2011/08/12 15:29:24 | 000,043,103 | —- | C] () – C:UsersGalleryDesktopmartin-mask-face-jay-brabant.JPG
[2011/08/12 15:17:44 | 000,031,004 | —- | C] () – C:UsersGalleryDesktopmartin-mask-jay-brabant.JPG
[2011/07/30 11:02:03 | 000,385,024 | —- | C] () – C:WindowsSysWow64lxdmcomx.dll
[2011/07/30 11:02:03 | 000,348,160 | —- | C] () – C:WindowsSysWow64lxdminst.dll
[2011/07/30 09:33:26 | 000,000,376 | —- | C] () – C:WindowsODBC.INI
[2011/07/19 02:02:18 | 000,982,220 | —- | C] () – C:WindowsSysWow64igkrng500.bin
[2011/07/19 02:02:18 | 000,134,592 | —- | C] () – C:WindowsSysWow64igfcg500.bin
[2011/07/19 02:02:18 | 000,092,216 | —- | C] () – C:WindowsSysWow64igfcg500m.bin
[2011/07/19 02:02:17 | 000,439,300 | —- | C] () – C:WindowsSysWow64igcompkrng500.bin
[2011/02/10 09:10:51 | 000,765,624 | —- | C] () – C:WindowsSysWow64PerfStringBackup.INI
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:Windowsbootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:WindowsSysWow64NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:WindowsSysWow64dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:Windowsmib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:WindowsSysWow64BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:WindowsSysWow64msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:WindowsSysWow64mlang.dat

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%*.* >
[2011/07/19 02:14:04 | 000,029,798 | RH– | M] () – C:dell.sdr
[2011/09/10 10:50:25 | 2388,381,696 | -HS- | M] () – C:hiberfil.sys
[2011/09/10 10:50:26 | 3184,508,928 | -HS- | M] () – C:pagefile.sys

< %systemroot%Fonts*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2010/11/10 00:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:WindowsWLXPGSS.SCR

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:Program Files (x86)desktop.ini

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2007/10/24 14:35:40 | 000,000,177 | -HS- | M] () – C:UsersGalleryAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop (1).ini
[2011/07/29 12:26:18 | 000,000,221 | -HS- | M] () – C:UsersGalleryAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:Windowssystem64] -> systemrootsystem32 -> Mount Point

< End of report >

Extras.Txt:


OTL Extras logfile created on: 9/10/2011 11:41:09 AM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:UsersGalleryDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 34.89% Memory free
5.93 Gb Paging File | 3.75 Gb Available in Paging File | 63.28% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 450.91 Gb Total Space | 355.52 Gb Free Space | 78.84% Space Free | Partition Type: NTFS
Drive K: | 1.91 Gb Total Space | 0.40 Gb Free Space | 20.64% Space Free | Partition Type: FAT

Computer Name: GALLERY-PC | User Name: Gallery | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClasses]
.url[@ = InternetShortcut] – C:WindowsSysNativerundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSysWow64control.exe (Microsoft Corporation)

[HKEY_CURRENT_USERSOFTWAREClasses]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:Program Files (x86)AdobeAdobe Bridge CS5.1Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:Program Files (x86)AdobeAdobe Bridge CS5.1Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcVol]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{26A24AE4-039D-4CA4-87B4-2F86416024FF}" = Java™ 6 Update 24 (64-bit)
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"HDMI" = Intel® Graphics Media Accelerator Driver
"Lexmark 5000 Series" = Lexmark 5000 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-dell" = WildTangent Games App (Dell Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{79872596-B887-E700-8D56-CADBC78BA5DE}" = Adobe Download Assistant
"{7B0180DE-6A86-4600-BD2A-25D5A20EE7F8}" = STOPzilla
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}" = Dell MusicStage
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8B88634-7F90-402F-B66A-86429755F6A5}" = eBay
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA31EA7B-7917-4000-949B-38E91F848A25}" = Internet Explorer
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.0) MUI
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{C16A92EF-017B-4839-9C75-FBADB5A1FA27}" = TrustedID
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}" = WinZip 15.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2EBA7C0-8072-447F-856D-FFEE8D15B23B}" = Dell Stage
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E9F88884-EECC-455E-BB2A-C784868C1A35}" = Dell Digital Delivery
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"GoToAssist" = GoToAssist 8.0.0.514
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"Mozilla Firefox 6.0.2 (x86 en-GB)" = Mozilla Firefox 6.0.2 (x86 en-GB)
"MSC" = McAfee SecurityCenter
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"uTorrent" = µTorrent
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WT089409" = Bejeweled 2 Deluxe
"WT089410" = Blackhawk Striker 2
"WT089411" = Build-a-lot 2
"WT089412" = Cake Mania
"WT089413" = Chuzzle Deluxe
"WT089414" = Diner Dash 2 Restaurant Rescue
"WT089415" = Dora's World Adventure
"WT089418" = FATE
"WT089420" = Jewel Quest
"WT089422" = Jewel Quest Solitaire 2
"WT089426" = Poker Superstars III
"WT089430" = Virtual Villagers 4 - The Tree of Life
"WT089433" = Polar Golfer
"WT089434" = Escape Whisper Valley ™
"WT089440" = Namco All-Stars PAC-MAN
"WT089443" = Bounce Symphony
"WT089444" = Final Drive Nitro
"WT089445" = Penguins!
"WT089446" = Wedding Dash - Ready, Aim, Love!
"WT089448" = Zuma Deluxe
"WT089450" = Farm Frenzy
"WT089452" = Plants vs. Zombies - Game of the Year
"WT089499" = Final Drive Fury
"WT089503" = Samantha Swift
"WT089507" = Luxor
"WT089508" = Polar Bowler

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi Euphoriks,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it.

Click the "Scan" button to start scan.

On completion of the scan click save log, save it to your desktop and post in your next reply.

===================================================

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


===================================================

In you next reply, please post the following:
  • MBAM log
  • aswMBR log
  • Rootkit Unhooker log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI