This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer needs overhaul

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is responding very slowly. Browsers take forever to go from site to site. Mozilla Firefox takes forever to connect to sites. Not sure if hijacked or have infections or what. Please use you expertise and return my computer to normalcy. Thanks
Here is my Hijack this log



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:36:04 AM, on 10/14/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Richard\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: vshare.tv Bar Toolbar - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files\vshare.tv_Bar\prxtbvsha.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: vshare.tv Bar - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files\vshare.tv_Bar\prxtbvsha.dll
O2 - BHO: Updater For Simppull Toolbar - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - (no file)
O2 - BHO: Complitly - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\Richard\Application Data\Complitly\Complitly.dll
O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: vshare.tv Bar Toolbar - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files\vshare.tv_Bar\prxtbvsha.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsGui.exe" /hideGUI
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1281501938125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe

–
End of file - 6944 bytes
Hello richwigs


My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hi richwigs


IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R3 - URLSearchHook: vshare.tv Bar Toolbar - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files\vshare.tv_Bar\prxtbvsha.dll
O2 - BHO: vshare.tv Bar - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files\vshare.tv_Bar\prxtbvsha.dll
O2 - BHO: Updater For Simppull Toolbar - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - (no file)
O2 - BHO: Complitly - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\Richard\Application Data\Complitly\Complitly.dll
O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: vshare.tv Bar Toolbar - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files\vshare.tv_Bar\prxtbvsha.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.
  • Reboot Your System
=====================
NEXT

IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
========================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check Scan All Users
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

=======================
NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log and Extras.Txt
3. aswMBR log
4. Hows the computer running?
OTL

OTL logfile created on: 10/16/2011 12:04:28 AM - Run 1
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Documents and Settings\Richard\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.44 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 76.26% Memory free
4.28 Gb Paging File | 3.82 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 444.20 Gb Free Space | 95.37% Space Free | Partition Type: NTFS

Computer Name: EVILEMPIRE1 | User Name: Richard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Richard\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Spyware Doctor\pctsGui.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
PRC - C:\WINDOWS\system32\dlcccoms.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
MOD - C:\Program Files\Spyware Doctor\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\Spyware Doctor\UserModeFileCache.dll ()
MOD - C:\Program Files\Spyware Doctor\avengine\sdkBSCtrl.dll ()
MOD - C:\Program Files\ASUS WiFi-AP Solo\acAuth.dll ()
MOD - C:\Program Files\ASUS WiFi-AP Solo\EnumDevLib.dll ()
MOD - C:\WINDOWS\system32\dlccserv.dll ()
MOD - C:\WINDOWS\system32\dlcclmpm.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccpplc.dll ()
MOD - C:\WINDOWS\system32\dlcccoms.exe ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccomc.dll ()
MOD - C:\WINDOWS\system32\dlccprox.dll ()
MOD - C:\WINDOWS\system32\dlccusb1.dll ()
MOD - C:\WINDOWS\system32\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccdrec.dll ()
MOD - C:\WINDOWS\system32\dlcccnv4.dll ()


========== Win32 Services (SafeList) ==========

SRV - (aspnet_state) – File not found
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ()


========== Driver Services (SafeList) ==========

DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportCerberus_29574) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\29574\RapportCerberus32_29574.sys ()
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ADIDTSFiltService) – C:\WINDOWS\system32\drivers\adidts.sys (Analog Devices, Inc.)
DRV - (SjyPkt) – C:\WINDOWS\system32\drivers\SjyPkt.sys (Windows ® 2000 DDK provider)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://vshare.toolbarhome.com/?hp=df
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "vshare.tv Bar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/09 10:59:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/24 22:12:29 | 000,000,000 | —D | M]

[2010/08/11 21:57:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard\Application Data\Mozilla\Extensions
[2011/09/27 17:17:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions
[2011/09/24 15:48:01 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/27 17:16:54 | 000,000,000 | —D | M] (vshare.tv Bar Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}
[2011/09/27 17:17:00 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/08/27 19:51:40 | 000,000,000 | —D | M] (BetterLinks) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\[removed]
[2011/01/01 23:31:05 | 000,001,919 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\bing-zugo.xml
[2011/08/31 11:26:36 | 000,000,929 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\conduit.xml
[2010/11/17 22:41:47 | 000,002,689 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\search-defender.xml
[2011/05/10 12:48:19 | 000,001,583 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\web-search.xml
[2011/10/09 10:59:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/09/29 01:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/31 05:38:58 | 000,082,944 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011/09/28 19:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Complitly plugin for chrome = C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.1_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\

O1 HOSTS File: ([2010/09/22 18:06:42 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ASUS WiFi-AP Solo.lnk = C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe (ASUSTek Computer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1281501938125 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB34C3F4-5CD3-4F21-94B5-CB6BAF3B9CBB}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 23:09:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/15 23:57:33 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Richard\Desktop\aswMBR.exe
[2011/10/15 23:56:19 | 000,583,168 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Richard\Desktop\OTL.exe
[2011/10/14 12:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\PCTools
[2011/10/14 12:19:39 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Richard\Recent
[2011/10/14 12:14:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\PC Cleaners
[2011/10/14 12:14:32 | 005,356,304 | —- | C] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2011/10/14 12:14:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/10/09 10:49:35 | 000,000,000 | —D | C] – C:\8017a49069b9c72076
[2011/09/25 19:00:08 | 000,056,336 | —- | C] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[2011/09/24 22:13:02 | 000,000,000 | —D | C] – C:\Program Files\Complitly
[2011/09/24 22:13:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\Complitly
[2011/09/24 22:12:43 | 000,000,000 | —D | C] – C:\Program Files\vshare.tv_Bar
[2011/09/24 22:12:22 | 000,000,000 | —D | C] – C:\Program Files\vShare.tv plugin
[2011/09/19 17:15:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/09/19 17:14:58 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/09/19 17:14:51 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/09/19 17:09:09 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/09/18 17:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\vShare
[2011/09/18 12:15:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\StreamTorrent
[2006/12/20 16:58:02 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\dlcciesc.dll
[2006/12/20 16:47:32 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\dlccinpa.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/16 00:03:45 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/16 00:03:27 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/16 00:03:23 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2011/10/16 00:03:22 | 000,276,202 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/10/16 00:03:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/15 23:57:39 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Richard\Desktop\aswMBR.exe
[2011/10/15 23:56:21 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Richard\Desktop\OTL.exe
[2011/10/15 23:53:00 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/14 12:14:03 | 005,356,304 | —- | M] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2011/10/10 14:54:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/09 11:00:04 | 000,000,742 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/09 11:00:04 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/09 10:53:51 | 000,405,372 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/09 10:53:51 | 000,062,350 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/09 10:40:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/10/09 10:37:03 | 000,001,784 | —- | M] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103656.reg
[2011/10/09 10:36:26 | 000,096,532 | —- | M] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103614.reg
[2011/10/08 12:35:59 | 000,024,064 | —- | M] () – C:\Documents and Settings\Richard\My Documents\982B1400
[2011/10/05 02:54:10 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/09/27 20:42:18 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/25 19:00:08 | 000,056,336 | —- | M] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[2011/09/24 22:11:01 | 001,400,408 | —- | M] () – C:\Documents and Settings\Richard\Desktop\vshare-plugin-v7.exe
[2011/09/19 17:15:43 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/09/16 03:05:54 | 000,681,086 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/09 11:00:04 | 000,000,742 | —- | C] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/09 11:00:04 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/09 11:00:03 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/09 10:36:57 | 000,001,784 | —- | C] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103656.reg
[2011/10/09 10:36:16 | 000,096,532 | —- | C] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103614.reg
[2011/09/24 22:11:01 | 001,400,408 | —- | C] () – C:\Documents and Settings\Richard\Desktop\vshare-plugin-v7.exe
[2011/09/19 17:15:43 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/05 02:28:13 | 000,054,996 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/10 19:16:57 | 000,003,584 | —- | C] () – C:\Documents and Settings\Richard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/11 21:57:26 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/08/10 23:38:53 | 000,023,714 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/08/10 23:38:51 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/08/10 23:38:48 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/08/10 23:38:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/08/10 23:11:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/10 23:06:51 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/10 17:20:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/10 17:17:12 | 000,260,640 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/03 22:55:32 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2007/02/14 16:23:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlccih.exe
[2007/02/14 16:23:18 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcccoms.exe
[2007/02/14 16:23:18 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcccfg.exe
[2007/02/07 12:57:16 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\dlcccoin.dll
[2007/01/26 07:11:42 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2007/01/26 07:11:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2007/01/26 07:09:58 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2007/01/26 06:59:04 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2007/01/26 06:58:30 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2007/01/26 06:57:38 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2007/01/26 06:57:18 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2007/01/26 06:53:46 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2007/01/22 02:24:50 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2006/12/20 17:08:24 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlccpmui.dll
[2006/12/20 17:06:58 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlccserv.dll
[2006/12/20 17:01:04 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcccomm.dll
[2006/12/20 16:59:24 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcclmpm.dll
[2006/12/20 16:55:40 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlccpplc.dll
[2006/12/20 16:54:54 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcccomc.dll
[2006/12/20 16:54:20 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccprox.dll
[2006/12/20 16:46:50 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlccusb1.dll
[2006/12/20 16:42:36 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcchbn3.dll
[2005/08/18 06:26:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll
[2005/04/01 11:44:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcccnv4.dll
[2004/08/04 01:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,405,372 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,062,350 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2010/08/14 20:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/08/27 19:52:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2011/10/14 12:14:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/10/16 00:03:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/23 19:45:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2010/10/24 10:08:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/08/28 15:08:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011/08/28 15:12:41 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2011/05/10 18:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Trusteer
[2010/10/25 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Auslogics
[2011/10/16 00:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Complitly
[2011/07/13 17:39:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\GARMIN
[2011/10/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\PC Cleaners
[2011/10/14 12:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\PCTools
[2011/09/14 23:54:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\simppulltoolbar
[2011/09/18 12:15:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\StreamTorrent
[2011/04/23 19:46:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Trusteer
[2011/09/18 17:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\vShare
[2010/08/22 22:38:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\WeatherBug
[2011/10/16 00:03:23 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 206 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >
EXTRAS

OTL Extras logfile created on: 10/16/2011 12:04:28 AM - Run 1
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Documents and Settings\Richard\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.44 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 76.26% Memory free
4.28 Gb Paging File | 3.82 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 444.20 Gb Free Space | 95.37% Space Free | Partition Type: NTFS

Computer Name: EVILEMPIRE1 | User Name: Richard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dlcccoms.exe" = C:\WINDOWS\system32\dlcccoms.exe:*:Enabled:Dell 924 Server – ()
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\StreamTorrent 1.0\StreamTorrent.exe" = C:\Program Files\StreamTorrent 1.0\StreamTorrent.exe:*:Enabled:StreamTorrent Media Player


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4FFBB818-B13C-11E0-931D-B2664824019B}_is1" = Complitly
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B3F4499-32E6-470D-8586-E6C03420F889}" = ASUS WiFi-AP Solo
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Betsharks" = Betsharks
"CCleaner" = CCleaner
"Google Chrome" = Google Chrome
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"MPlayer" = MPlayer (remove only)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"P2PFilter" = P2PFilter 3.0.5
"Rapport_msi" = Rapport
"Shockwave" = Shockwave
"SopCast" = SopCast 3.2.9
"Spyware Doctor" = Spyware Doctor
"vShare.tv plugin" = vShare.tv plugin 1.3
"vshare.tv_Bar Toolbar" = vshare.tv Bar Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/14/2011 10:00:06 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x071112b0.

Error - 10/14/2011 11:15:26 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x067412b0.

Error - 10/15/2011 12:45:42 AM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x06e912b0.

Error - 10/15/2011 1:15:14 PM | Computer Name = EVILEMPIRE1 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 7.0.1.4288, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/15/2011 5:41:05 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x076d12b0.

Error - 10/15/2011 5:47:08 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x073212b0.

Error - 10/15/2011 7:05:45 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x080c12b0.

Error - 10/15/2011 7:36:04 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x08c712b0.

Error - 10/15/2011 9:04:02 PM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x057712b0.

Error - 10/16/2011 12:00:12 AM | Computer Name = EVILEMPIRE1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 14.0.835.202, faulting module
unknown, version 0.0.0.0, fault address 0x05ba12b0.

[ System Events ]
Error - 10/12/2011 7:19:51 PM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/13/2011 6:29:47 PM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/13/2011 8:51:59 PM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/14/2011 7:25:11 AM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/14/2011 10:48:56 AM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/15/2011 11:44:11 AM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/15/2011 5:18:07 PM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 10/16/2011 12:45:50 AM | Computer Name = EVILEMPIRE1 | Source = Print | ID = 6161
Description = The document computer needs overhaul owned by Richard failed to print
on printer Dell Photo AIO Printer 924. Data type: LEMF. Size of the spool file
in bytes: 5234281. Number of bytes printed: 5234281. Total number of pages in the
document: 5. Number of pages printed: 0. Client machine: \\EVILEMPIRE1. Win32 error
code returned by the print processor: 0 (0x0).

Error - 10/16/2011 12:47:43 AM | Computer Name = EVILEMPIRE1 | Source = Print | ID = 6161
Description = The document computer needs overhaul owned by Richard failed to print
on printer Dell Photo AIO Printer 924. Data type: LEMF. Size of the spool file
in bytes: 1114064. Number of bytes printed: 1114064. Total number of pages in the
document: 1. Number of pages printed: 0. Client machine: \\EVILEMPIRE1. Win32 error
code returned by the print processor: 0 (0x0).

Error - 10/16/2011 1:03:28 AM | Computer Name = EVILEMPIRE1 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747


< End of report >
aswMBR

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-16 00:14:51
—————————–
00:14:51.484 OS Version: Windows 5.1.2600 Service Pack 3
00:14:51.484 Number of processors: 2 586 0xF06
00:14:51.484 ComputerName: EVILEMPIRE1 UserName: Richard
00:15:00.531 Initialize success
00:15:16.921 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-12
00:15:16.921 Disk 0 Vendor: ST3500418AS CC38 Size: 476940MB BusType: 3
00:15:18.937 Disk 0 MBR read successfully
00:15:18.937 Disk 0 MBR scan
00:15:18.937 Disk 0 Windows XP default MBR code
00:15:18.953 Disk 0 scanning sectors +976752000
00:15:19.000 Disk 0 scanning C:\WINDOWS\system32\drivers
00:15:24.937 Service scanning
00:15:25.984 Modules scanning
00:15:28.093 Disk 0 trace - called modules:
00:15:28.109 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
00:15:28.109 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a644ab8]
00:15:28.109 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> [0x8a633bb8]
00:15:28.109 5 PCTCore.sys[b7eacb63] -> nt!IofCallDriver -> \Device\00000072[0x8a6aa948]
00:15:28.109 7 ACPI.sys[b7f5f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-12[0x8a635d98]
00:15:28.125 Scan finished successfully
00:15:37.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Richard\Desktop\MBR.dat"
00:15:37.625 The log file has been saved successfully to "C:\Documents and Settings\Richard\Desktop\aswMBR.txt"



Please include in your next reply:
1. Any problem executing the instructions?
No problems

4. Hows the computer running?
Seems a little better. I can go to 3 or 4 websites with no problems before it hits a wall and just sits there at connecting. Firefox also opens faster than before
Hi richwigs,

Did you intentionally installed these program?

vShare.tv plugin 1.3
vshare.tv Bar Toolbar

===============
NEXT

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
    [2011/10/09 10:59:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
    CHR - Extension: Complitly plugin for chrome = C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.1_0\
    O3 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
    O3 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O33 - MountPoints2\E\Shell - "" = AutoRun
    O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
    [2011/09/24 22:13:02 | 000,000,000 | —D | C] – C:\Program Files\Complitly
    [2011/09/24 22:13:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\Complitly
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2011/10/08 12:35:59 | 000,024,064 | —- | M] () – C:\Documents and Settings\Richard\My Documents\982B1400
    [2010/08/14 20:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
    [2011/08/28 15:12:41 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
    [2011/10/16 00:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Complitly
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL fix log
3. answer to question about vShare.tv
How is the computer behaving?
No I did not install those programs.

OTL Log

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17\ deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions folder moved successfully.
C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.1_0\icons folder moved successfully.
C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.1_0 folder moved successfully.
Registry value HKEY_USERS\S-1-5-21-220523388-1958367476-1801674531-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{043C5167-00BB-4324-AF7E-62013FAEDACF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found.
Registry value HKEY_USERS\S-1-5-21-220523388-1958367476-1801674531-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
File E:\LaunchU3.exe -a not found.
C:\Program Files\Complitly\[removed]\defaults\preferences folder moved successfully.
C:\Program Files\Complitly\[removed]\defaults folder moved successfully.
C:\Program Files\Complitly\[removed]\chrome\content folder moved successfully.
C:\Program Files\Complitly\[removed]\chrome folder moved successfully.
C:\Program Files\Complitly\[removed] folder moved successfully.
C:\Program Files\Complitly\chrome folder moved successfully.
C:\Program Files\Complitly folder moved successfully.
C:\Documents and Settings\Richard\Application Data\Complitly\64 folder moved successfully.
C:\Documents and Settings\Richard\Application Data\Complitly folder moved successfully.
C:\WINDOWS\002856_.tmp deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCall.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla17.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla18.exe deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla19.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla2.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla20.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla21.dll deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseCustomCalla21.exe deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP\WiseData.ini deleted successfully.
C:\WINDOWS\95431C66CF9A4913BFFF6050785AFB65.TMP folder deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET4.tmp deleted successfully.
C:\WINDOWS\SET8.tmp deleted successfully.
C:\WINDOWS\System32\ConduitEngine.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\Documents and Settings\Richard\My Documents\982B1400 moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\update\prepare folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\update\backup folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\update folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Temp folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\scanlogs folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Log folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\emc folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Dumps folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\CfgAll folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Cfg folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\AvgApi folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\AvgAm folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\admincli folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~0 folder moved successfully.
Folder C:\Documents and Settings\Richard\Application Data\Complitly\ not found.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56504 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 34307 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 65670 bytes

User: Richard
->Temp folder emptied: 1589511354 bytes
->Temporary Internet Files folder emptied: 327974 bytes
->FireFox cache emptied: 546830845 bytes
->Google Chrome cache emptied: 419848445 bytes
->Flash cache emptied: 6537926 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 712388 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 607507 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1493290 bytes

Total Files Cleaned = 2,447.00 mb


OTL by OldTimer - Version 3.2.30.0 log created on 10182011_200032

Files\Folders moved on Reboot…
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\TF5KL0PI\control[1].htm moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_110.dat moved successfully.

Registry entries deleted on Reboot…
Hi richwigs

Please go to Start>Control Panel>Add Remove Programs. On the list you should find an

entry for vShare.tv plugin 1.3 and and vshare.tv Bar Toolbar. Click Remove and allow Windows

to completely remove each one in turn.Then reboot your computer to complete this part of the process.
=========================
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://vshare.toolbarhome.com/?hp=df
    FF - prefs.js..browser.search.defaultthis.engineName: "vshare.tv Bar Customized Web Search"
    FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
    [2011/09/27 17:16:54 | 000,000,000 | —D | M] (vshare.tv Bar Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}
    [2011/08/31 05:38:58 | 000,082,944 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
    CHR - Extension: vshare plugin = C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
    [2011/09/24 22:12:43 | 000,000,000 | —D | C] – C:\Program Files\vshare.tv_Bar
    [2011/09/24 22:12:22 | 000,000,000 | —D | C] – C:\Program Files\vShare.tv plugin
    [2011/09/24 22:11:01 | 001,400,408 | —- | M] () – C:\Documents and Settings\Richard\Desktop\vshare-plugin-v7.exe
    [2011/09/18 17:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\vShare
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
    ========================
    NEXT

    You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

    Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

    Please post back with he mbam log. Any remaining issues?
    =========================
    NEXT

    *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



    Go here to run an online scannner from
    ESET

    (Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

=============================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. Malwarebytes log
4. ESET log
5. How is the computer behaving?
I was able to remove the plugin but have not been able to remove the toolbar. When I click change/remove it pauses for about 1 second, flashes, then does not remove the program. Do I need to continue with the steps above without removing the toolbar? OR is there some other way to remove the toolbar?

Hi richwigs



Run revouninstaller then go ahead and run MBAM and ESET.

Download Revo Uninstaller
  • Double click the installation file on the desktop to run the installer.
  • Let it install to the default location.
  • Double click the new Revo Uninstaller Icon on the desktop to start the program.
You will now see a list of installed programs that Revo Uninstaller can remove.
  • Locate the program you are uninstalling vshare.tv Bar Toolbar
  • Right Click the Icon then choose Uninstall.
  • Click yes to the warning and choose the Uninstall Mode
  • Choose the Advanced option and then click Next.
  • This will launch the programs built in uninstaller. Be patient it can take several seconds.
  • Once the uninstaller is done click Next.
  • Revo Uninstaller will now scan for leftover information. Be patient it can take several seconds.
  • Once this scan is done click Next.
  • You will then be presented of the leftover entries found by Revo Uninstaller
  • Look at ALL of the entries to ensure they relate to the program you are uninstalling.
  • Next click Select All > Delete to remove the entries.
  • Click Next.
  • If there are any program file folders left over you will be presented with a list to be removed.
  • Again look at ALL of the entries to ensure they are related to the program you are uninstalling.
  • Click Select All > Delete to remove the entries.
  • Click Finish to go back to the uninstall list.
  • Close the program

After this has finished, reboot and then run MBAM and ESET.
MBAM
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8001

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/22/2011 3:43:41 PM
mbam-log-2011-10-22 (15-43-41).txt

Scan type: Quick scan
Objects scanned: 157318
Time elapsed: 2 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ESET
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=10c55cc54e05f245a3093b1b3df5f9ca
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-10-22 09:38:34
# local_time=2011-10-22 04:38:34 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 36671571 36671571 0 0
# compatibility_mode=2560 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=45861
# found=0
# cleaned=0
# scan_time=1201
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=10c55cc54e05f245a3093b1b3df5f9ca
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-10-22 10:02:45
# local_time=2011-10-22 05:02:45 (-0600, Central Daylight Time)
# country="United States"
# lang=9
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 36673126 36673126 0 0
# compatibility_mode=2560 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=46048
# found=0
# cleaned=0
# scan_time=1098


Firefox still takes awhile to load and gets hung up, but is alot better. Google chrome runs really well until it crashes from the flash player.
Hi richwigs

Almost done :thumbup: would like you to Rerun OTL one more time, I would like to check and make sure we got everything.
===============
NEXT

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Please post the OTL log and Security Check log.
OTL

OTL logfile created on: 10/24/2011 11:38:21 PM - Run 2
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Documents and Settings\Richard\Desktop\pc programs
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.44 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 55.57% Memory free
4.28 Gb Paging File | 2.99 Gb Available in Paging File | 69.83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 437.11 Gb Free Space | 93.85% Space Free | Partition Type: NTFS

Computer Name: EVILEMPIRE1 | User Name: Richard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Richard\Desktop\pc programs\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Spyware Doctor\pctsGui.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
PRC - C:\WINDOWS\system32\dlcccoms.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\14.0.835.202\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\14.0.835.202\Locales\en-US.dll ()
MOD - C:\Program Files\Google\Chrome\Application\14.0.835.202\avutil-51.dll ()
MOD - C:\Program Files\Google\Chrome\Application\14.0.835.202\avformat-53.dll ()
MOD - C:\Program Files\Google\Chrome\Application\14.0.835.202\avcodec-53.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}\components\RadioWMPCoreGecko7.dll ()
MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
MOD - C:\Program Files\Spyware Doctor\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\Spyware Doctor\UserModeFileCache.dll ()
MOD - C:\Program Files\Spyware Doctor\avengine\sdkBSCtrl.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\ASUS WiFi-AP Solo\acAuth.dll ()
MOD - C:\Program Files\ASUS WiFi-AP Solo\EnumDevLib.dll ()
MOD - C:\WINDOWS\system32\dlccserv.dll ()
MOD - C:\WINDOWS\system32\dlcclmpm.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccpplc.dll ()
MOD - C:\WINDOWS\system32\dlcccoms.exe ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccomc.dll ()
MOD - C:\WINDOWS\system32\dlccprox.dll ()
MOD - C:\WINDOWS\system32\dlccusb1.dll ()
MOD - C:\WINDOWS\system32\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccdrec.dll ()
MOD - C:\WINDOWS\system32\dlcccnv4.dll ()


========== Win32 Services (SafeList) ==========

SRV - (aspnet_state) – File not found
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ()


========== Driver Services (SafeList) ==========

DRV - (RapportCerberus_32029) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus32_32029.sys ()
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (Revoflt) – C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ADIDTSFiltService) – C:\WINDOWS\system32\drivers\adidts.sys (Analog Devices, Inc.)
DRV - (SjyPkt) – C:\WINDOWS\system32\drivers\SjyPkt.sys (Windows ® 2000 DDK provider)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://vshare.toolbarhome.com/?hp=df
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "vshare.tv Bar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/09 10:59:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/20 17:35:40 | 000,000,000 | —D | M]

[2010/08/11 21:57:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard\Application Data\Mozilla\Extensions
[2011/09/27 17:17:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions
[2011/09/24 15:48:01 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/27 17:16:54 | 000,000,000 | —D | M] (vshare.tv Bar Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}
[2011/09/27 17:17:00 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/08/27 19:51:40 | 000,000,000 | —D | M] (BetterLinks) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\[removed]
[2011/01/01 23:31:05 | 000,001,919 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\bing-zugo.xml
[2011/08/31 11:26:36 | 000,000,929 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\conduit.xml
[2010/11/17 22:41:47 | 000,002,689 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\search-defender.xml
[2011/05/10 12:48:19 | 000,001,583 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\web-search.xml
[2011/09/29 01:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/28 19:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2010/09/22 18:06:42 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ASUS WiFi-AP Solo.lnk = C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe (ASUSTek Computer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1281501938125 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB34C3F4-5CD3-4F21-94B5-CB6BAF3B9CBB}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 23:09:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/22 15:50:43 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/10/22 15:29:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Local Settings\Application Data\VS Revo Group
[2011/10/22 15:29:36 | 000,027,064 | —- | C] (VS Revo Group) – C:\WINDOWS\System32\drivers\revoflt.sys
[2011/10/22 15:29:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro
[2011/10/22 15:29:34 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2011/10/18 20:00:32 | 000,000,000 | —D | C] – C:\_OTL
[2011/10/14 12:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\PCTools
[2011/10/14 12:19:39 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Richard\Recent
[2011/10/14 12:14:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\PC Cleaners
[2011/10/14 12:14:32 | 005,356,304 | —- | C] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2011/10/14 12:14:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/10/09 10:49:35 | 000,000,000 | —D | C] – C:\8017a49069b9c72076
[2011/09/25 19:00:08 | 000,056,336 | —- | C] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[2006/12/20 16:58:02 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\dlcciesc.dll
[2006/12/20 16:47:32 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\dlccinpa.dll
[11 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/24 22:58:03 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/24 17:18:21 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/24 17:17:38 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/24 17:17:33 | 000,276,202 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/10/24 17:17:33 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2011/10/24 17:17:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/23 09:41:01 | 000,260,640 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/23 03:04:34 | 000,684,498 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/10/23 03:03:11 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/10/22 15:29:37 | 000,000,943 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2011/10/17 14:54:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/14 12:14:03 | 005,356,304 | —- | M] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2011/10/09 11:00:04 | 000,000,742 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/09 11:00:04 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/09 10:53:51 | 000,405,372 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/09 10:53:51 | 000,062,350 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/09 10:40:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/10/09 10:37:03 | 000,001,784 | —- | M] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103656.reg
[2011/10/09 10:36:26 | 000,096,532 | —- | M] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103614.reg
[2011/10/05 02:54:10 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/10/03 03:35:11 | 005,971,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/09/27 20:42:18 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/26 11:41:20 | 000,611,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\uiautomationcore.dll
[2011/09/26 11:41:20 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\oleaccrc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleaccrc.dll
[2011/09/25 19:00:08 | 000,056,336 | —- | M] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[11 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/23 03:02:53 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/10/22 15:29:36 | 000,000,943 | —- | C] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2011/10/09 11:00:04 | 000,000,742 | —- | C] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/09 11:00:04 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/09 11:00:03 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/09 10:36:57 | 000,001,784 | —- | C] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103656.reg
[2011/10/09 10:36:16 | 000,096,532 | —- | C] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103614.reg
[2011/02/05 02:28:13 | 000,054,996 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/10 19:16:57 | 000,003,584 | —- | C] () – C:\Documents and Settings\Richard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/11 21:57:26 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/08/10 23:38:53 | 000,023,714 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/08/10 23:38:51 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/08/10 23:38:48 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/08/10 23:38:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/08/10 23:11:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/10 23:06:51 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/10 17:20:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/10 17:17:12 | 000,260,640 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/03 22:55:32 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2007/02/14 16:23:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlccih.exe
[2007/02/14 16:23:18 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcccoms.exe
[2007/02/14 16:23:18 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcccfg.exe
[2007/02/07 12:57:16 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\dlcccoin.dll
[2007/01/26 07:11:42 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2007/01/26 07:11:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2007/01/26 07:09:58 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2007/01/26 06:59:04 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2007/01/26 06:58:30 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2007/01/26 06:57:38 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2007/01/26 06:57:18 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2007/01/26 06:53:46 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2007/01/22 02:24:50 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2006/12/20 17:08:24 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlccpmui.dll
[2006/12/20 17:06:58 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlccserv.dll
[2006/12/20 17:01:04 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcccomm.dll
[2006/12/20 16:59:24 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcclmpm.dll
[2006/12/20 16:55:40 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlccpplc.dll
[2006/12/20 16:54:54 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcccomc.dll
[2006/12/20 16:54:20 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccprox.dll
[2006/12/20 16:46:50 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlccusb1.dll
[2006/12/20 16:42:36 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcchbn3.dll
[2005/08/18 06:26:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll
[2005/04/01 11:44:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcccnv4.dll
[2004/08/04 01:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,405,372 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,062,350 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >

Security Check

Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
ESET Online Scanner v3
Antivirus up to date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Adobe Flash Player ( 10.3.183.10) Flash Player Out of Date!
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

ThreatFire TFService.exe
``````````End of Log````````````

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI