This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus stole my identity

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last night I was online looking at my credit card bill when my screen turned grey and a form came up which basically said from time to time we might ask you to confirm your identity by answering questions. This is pretty reasonable of my credit card company to do they've done similar things before and I thought nothing of it and provided my information. Later that night the same form popped up while I was on Ebay only this time it had the ebay symbol where my credit card companies symbol once was. I called up the company and they told me I have a virus. I closed out the card and everything but it still managed to steal a lot of sensitive information which is pretty upsetting. I downloaded new antivirus software and I think it helped a little but upon startup its still picking things up which makes me think that I haven't fully gotten it out. Thank You I greatly appreciate your help.

OTL logfile created on: 10/15/2011 10:45:39 PM - Run 1
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Users\Zach\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 42.26% Memory free
8.00 Gb Paging File | 5.75 Gb Available in Paging File | 71.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 50.71 Gb Free Space | 34.02% Space Free | Partition Type: NTFS
Drive D: | 138.31 Gb Total Space | 42.73 Gb Free Space | 30.90% Space Free | Partition Type: NTFS

Computer Name: HALOBOT | User Name: Zach | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Zach\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Users\Zach\AppData\Local\Temp\_flashUpdate.exe (Adobe)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\ProgramData\TVersity\Media Server\MediaServer.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe (ASUSTek.)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\Direct Console\DCHelper.exe (ASUSTek.)
PRC - C:\Program Files\ATKOSD2\ATKOSD2.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe ()
PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
PRC - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()
PRC - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Lavasoft\Ad-Aware\PrivacyClean.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\7fb80e48899821b64471f8e7ac2d08b7\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\OLED.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\SysInfo.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\OvrClk.dll ()
MOD - C:\Program Files\ATKOSD2\ATKOSD2.exe ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\LED.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\OUTLOOK.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\MSN.dll ()
MOD - C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll ()
MOD - C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll ()
MOD - C:\Program Files (x86)\McAfee\Common Framework\ccme_base.dll ()
MOD - C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll ()
MOD - C:\Program Files\ATKGFNEX\AGFNEX.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
SRV:64bit: - (spmgr) – C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()
SRV:64bit: - (ADSMService) – C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe ()
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Akamai) – c:\Program Files (x86)\Common Files\Akamai\netsession_win_b31de1e.dll ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (McAfeeFramework) – C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (TVersityMediaServer) – C:\ProgramData\TVersity\Media Server\MediaServer.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (atksgt) – C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) – C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (itecir) – C:\Windows\SysNative\drivers\itecir.sys (ITE Tech. Inc. )
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (kbfiltr) – C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (AsDsm) – C:\Windows\SysNative\drivers\AsDsm.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ATK64AMD.sys ()
DRV:64bit: - (ghaio) – C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys ()
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV:64bit: - (ASMMAP64) – C:\Program Files\ATKGFNEX\ASMMAP64.sys ()
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/?src=aim&ncid;=snsusaimc00000001
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 CD 62 1C 6D 58 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5643

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {4D144BC3-23FB-47de-90C5-63CCB0139CCF}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\Zach\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files (x86)\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/30 17:52:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\Firefox [2011/04/07 20:40:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/04/08 03:00:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/15 19:37:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/08 19:21:21 | 000,000,000 | —D | M]

[2009/12/21 07:13:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Zach\AppData\Roaming\Mozilla\Extensions
[2011/10/15 22:32:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions
[2010/07/14 23:20:27 | 000,000,000 | —D | M] (TradeManager-Plugin) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}
[2011/10/15 22:32:03 | 000,000,000 | —D | M] (BitDefender QuickScan) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/06/23 18:27:29 | 000,000,000 | —D | M] (Battlefield Heroes Updater) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\[removed]
[2011/05/09 23:17:51 | 000,000,000 | —D | M] (Microsoft Default Manager) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\DefaultManager@Microsoft
[2010/08/23 22:44:24 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\[removed]
[2011/04/07 21:20:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/10/27 09:48:22 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/10/15 19:37:54 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/03/21 17:54:40 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll
[2011/09/23 22:06:23 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/10/18 16:26:03 | 000,001,262 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111014203551.dll (McAfee, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (TVersitybar Toolbar) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111014203551.dll (McAfee, Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (TVersitybar Toolbar) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (TVersitybar Toolbar) - {66BD2442-241B-44CD-8C7A-B51037053CDB} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ATKOSD2\ATKOSD2.exe ()
O4 - HKLM..\Run: [Bing Bar] C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [DirectConsole2] C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe (ASUSTek.)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [{E22BFFC5-EF5B-4268-4826-4F92A8E30BA0}] C:\Users\Zach\AppData\Roaming\Ciakku\nypea.exe (deWjgeajjh)
O4 - HKCU..\Run: [Adobe update service] c:\Users\Zach\AppData\Local\Temp\_flashUpdate.exe (Adobe)
O4 - HKCU..\Run: [Windows SafeAssist] C:\Users\Zach\AppData\Roaming\winlogon.exe File not found
O4 - HKCU..\Run: [Windows Update] C:\Users\Zach\AppData\Local\Temp\service2.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF1CDD5E-055A-4BF3-869E-2C903087B17F}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\SysWOW64\MPK\MPK.exe) - File not found
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/22 00:46:32 | 000,000,297 | RHS- | M] () - D:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{596674bc-6a21-11df-b5b5-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{596674bc-6a21-11df-b5b5-806e6f6e6963}\Shell\AutoRun\command - "" = H:\Setup.exe
O33 - MountPoints2\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\Shell - "" = AutoRun
O33 - MountPoints2\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\Shell\AutoRun\command - "" = H:\EN_Fallout_3_DLC.EXE
O33 - MountPoints2\{aa33cafe-c47b-11de-bad1-00235401dab9}\Shell - "" = AutoRun
O33 - MountPoints2\{aa33cafe-c47b-11de-bad1-00235401dab9}\Shell\AutoRun\command - "" = F:\autoplay.exe
O33 - MountPoints2\{b3d89b61-18c1-11df-8b2b-00235401dab9}\Shell - "" = AutoRun
O33 - MountPoints2\{b3d89b61-18c1-11df-8b2b-00235401dab9}\Shell\AutoRun\command - "" = H:\autorun.exe -auto
O33 - MountPoints2\{bb35d8f4-c447-11de-b773-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bb35d8f4-c447-11de-b773-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{cab46915-ef84-11de-85d8-00235401dab9}\Shell - "" = AutoRun
O33 - MountPoints2\{cab46915-ef84-11de-85d8-00235401dab9}\Shell\AutoRun\command - "" = I:\AUTOSTARTER.EXE
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AUTOSTARTER.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecx.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Program Files (x86)\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/15 22:37:11 | 000,583,168 | —- | C] (OldTimer Tools) – C:\Users\Zach\Desktop\OTL.exe
[2011/10/15 22:32:42 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\QuickScan
[2011/10/15 22:23:59 | 000,000,000 | —D | C] – C:\rsit
[2011/10/15 19:23:20 | 000,069,376 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/10/15 19:23:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/10/15 19:19:46 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/10/14 20:43:58 | 000,000,000 | —D | C] – C:\QUARANTINE
[2011/10/14 20:40:20 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/14 20:40:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/10/14 20:36:27 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\McAfee
[2011/10/14 20:35:51 | 000,099,056 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\MfeOtlkAddin.dll
[2011/10/14 20:35:51 | 000,074,848 | —- | C] (McAfee, Inc.) – C:\Windows\SysWow64\MfeOtlkAddin.dll
[2011/10/14 20:35:51 | 000,022,816 | —- | C] (McAfee, Inc.) – C:\Windows\SysWow64\MFEOtlk.dll
[2011/10/14 20:35:50 | 000,009,984 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2011/10/14 20:35:49 | 000,217,696 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2011/10/14 20:35:49 | 000,153,952 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeapfk.sys
[2011/10/14 20:35:49 | 000,097,960 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2011/10/14 20:35:48 | 000,607,152 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfehidk.sys
[2011/10/14 20:35:25 | 000,281,544 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2011/10/14 20:35:24 | 000,156,248 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2011/10/14 20:35:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2011/10/14 20:35:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/10/14 20:34:12 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2011/10/14 20:34:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2011/10/14 20:34:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\McAfee
[2011/10/12 08:46:44 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Uxvih
[2011/10/12 08:46:44 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Urizoh
[2011/10/12 08:46:32 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Ocatoz
[2011/10/12 08:46:32 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Ciakku
[2011/10/11 19:59:41 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/11 19:59:40 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/11 19:59:40 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/10/11 19:59:40 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/10/11 19:59:40 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/11 19:59:40 | 000,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/11 19:59:40 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/11 19:59:40 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/11 19:59:39 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/11 19:59:39 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 19:58:51 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/10/11 19:58:50 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/10/11 19:58:50 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/11 19:58:50 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/10/11 19:58:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/11 19:58:50 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/11 19:58:50 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/11 19:58:49 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/10/11 19:58:49 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/10/11 19:58:49 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/11 19:58:49 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/11 19:58:49 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/10/11 19:58:49 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/10/11 19:58:49 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/10/11 19:58:49 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/10/11 19:58:46 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/11 19:58:46 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/05 21:58:36 | 000,000,000 | —D | C] – C:\Users\Zach\Desktop\h
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Zach\AppData\Roaming\*.tmp files -> C:\Users\Zach\AppData\Roaming\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/15 22:37:20 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Users\Zach\Desktop\OTL.exe
[2011/10/15 22:23:43 | 000,935,175 | —- | M] () – C:\Users\Zach\Desktop\RSITx64.exe
[2011/10/15 22:12:43 | 000,013,472 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/15 22:12:43 | 000,013,472 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/15 22:05:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/15 22:05:06 | 3220,623,360 | -HS- | M] () – C:\hiberfil.sys
[2011/10/15 19:38:01 | 000,002,055 | —- | M] () – C:\Users\Zach\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/15 19:25:37 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/10/15 19:23:21 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/10/14 20:40:20 | 000,002,971 | —- | M] () – C:\Users\Zach\Desktop\HiJackThis.lnk
[2011/10/14 20:35:07 | 000,281,544 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2011/10/14 20:35:07 | 000,156,248 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2011/10/14 20:35:06 | 000,607,152 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfehidk.sys
[2011/10/14 20:35:06 | 000,099,056 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\MfeOtlkAddin.dll
[2011/10/14 20:35:06 | 000,097,960 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2011/10/14 20:35:05 | 000,217,696 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2011/10/14 20:35:05 | 000,153,952 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeapfk.sys
[2011/10/14 20:35:05 | 000,009,984 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2011/10/14 20:35:00 | 000,074,848 | —- | M] (McAfee, Inc.) – C:\Windows\SysWow64\MfeOtlkAddin.dll
[2011/10/14 20:35:00 | 000,022,816 | —- | M] (McAfee, Inc.) – C:\Windows\SysWow64\MFEOtlk.dll
[2011/10/13 22:29:03 | 023,766,005 | —- | M] () – C:\Users\Zach\Desktop\DVD Music Video.wmv
[2011/10/13 22:26:05 | 149,417,833 | —- | M] () – C:\Users\Zach\Desktop\DVD Format video.wmv
[2011/10/13 21:52:00 | 043,397,983 | —- | M] () – C:\Users\Zach\Desktop\The Way Vinny Lives 720p.wmv
[2011/10/13 21:19:08 | 263,417,811 | —- | M] () – C:\Users\Zach\Desktop\Final Cut 720p.wmv
[2011/10/13 20:58:41 | 000,061,910 | —- | M] () – C:\Users\Zach\Documents\123.wlmp
[2011/10/12 08:47:31 | 000,000,000 | -H– | M] () – C:\Users\Zach\AppData\Roaming\EfgJhIrJK1fh
[2011/10/12 08:46:31 | 000,000,000 | -H– | M] () – C:\Users\Zach\AppData\Roaming\E067ehkGGdtg
[2011/10/12 08:39:39 | 000,045,056 | —- | M] () – C:\Windows\SysNative\acovcnt.exe
[2011/10/12 08:36:18 | 004,982,672 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/11 22:51:06 | 000,793,636 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/11 22:51:06 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/11 22:51:06 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/11 21:56:28 | 442,849,805 | —- | M] () – C:\Users\Zach\Desktop\Final Cut.wmv
[2011/10/07 22:12:57 | 000,040,103 | —- | M] () – C:\Users\Zach\Desktop\apd-25.pdf
[2011/10/07 22:00:58 | 000,266,431 | —- | M] () – C:\Users\Zach\Desktop\apd5draft.pdf
[2011/10/07 20:06:59 | 000,192,921 | —- | M] () – C:\Users\Zach\Desktop\apd-19.pdf
[2011/09/22 16:04:48 | 005,088,407 | —- | M] () – C:\Users\Zach\Desktop\Kool and the Gang - Ladies Night (Best Version & HQ)-[www.flvto.com].mp3
[2011/09/20 00:31:20 | 128,503,483 | —- | M] () – C:\Users\Zach\Desktop\Memories Mixup.wmv
[2011/09/19 02:16:19 | 000,773,482 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/16 21:56:42 | 000,023,890 | —- | M] () – C:\Users\Zach\Documents\music video.wlmp
[2011/09/16 21:52:08 | 043,333,983 | —- | M] () – C:\Users\Zach\Desktop\The Way Vinny Lives Final.wmv
[2011/09/16 21:24:25 | 021,949,987 | —- | M] () – C:\Users\Zach\Desktop\music video.wmv
[2011/09/16 00:38:12 | 006,715,609 | —- | M] () – C:\Users\Zach\Desktop\Facebook___Paul_Puczko__39_s_Videos__vinnys_18th_birthday_bash.wmv
[2011/09/15 23:11:46 | 000,059,869 | —- | M] () – C:\Users\Zach\Desktop\maspeth_sign.jpg
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Zach\AppData\Roaming\*.tmp files -> C:\Users\Zach\AppData\Roaming\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/15 22:23:36 | 000,935,175 | —- | C] () – C:\Users\Zach\Desktop\RSITx64.exe
[2011/10/15 19:23:21 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/10/14 20:40:20 | 000,002,971 | —- | C] () – C:\Users\Zach\Desktop\HiJackThis.lnk
[2011/10/13 22:27:31 | 023,766,005 | —- | C] () – C:\Users\Zach\Desktop\DVD Music Video.wmv
[2011/10/13 22:18:02 | 149,417,833 | —- | C] () – C:\Users\Zach\Desktop\DVD Format video.wmv
[2011/10/13 21:49:33 | 043,397,983 | —- | C] () – C:\Users\Zach\Desktop\The Way Vinny Lives 720p.wmv
[2011/10/13 20:59:04 | 263,417,811 | —- | C] () – C:\Users\Zach\Desktop\Final Cut 720p.wmv
[2011/10/12 08:47:31 | 000,000,000 | -H– | C] () – C:\Users\Zach\AppData\Roaming\EfgJhIrJK1fh
[2011/10/12 08:46:31 | 000,000,000 | -H– | C] () – C:\Users\Zach\AppData\Roaming\E067ehkGGdtg
[2011/10/11 21:18:56 | 442,849,805 | —- | C] () – C:\Users\Zach\Desktop\Final Cut.wmv
[2011/10/07 22:12:57 | 000,040,103 | —- | C] () – C:\Users\Zach\Desktop\apd-25.pdf
[2011/10/07 22:00:58 | 000,266,431 | —- | C] () – C:\Users\Zach\Desktop\apd5draft.pdf
[2011/10/07 20:06:59 | 000,192,921 | —- | C] () – C:\Users\Zach\Desktop\apd-19.pdf
[2011/09/22 16:04:41 | 005,088,407 | —- | C] () – C:\Users\Zach\Desktop\Kool and the Gang - Ladies Night (Best Version & HQ)-[www.flvto.com].mp3
[2011/09/20 00:35:26 | 000,061,910 | —- | C] () – C:\Users\Zach\Documents\123.wlmp
[2011/09/20 00:21:16 | 128,503,483 | —- | C] () – C:\Users\Zach\Desktop\Memories Mixup.wmv
[2011/09/16 21:49:35 | 043,333,983 | —- | C] () – C:\Users\Zach\Desktop\The Way Vinny Lives Final.wmv
[2011/09/16 21:23:09 | 021,949,987 | —- | C] () – C:\Users\Zach\Desktop\music video.wmv
[2011/09/16 01:02:23 | 000,023,890 | —- | C] () – C:\Users\Zach\Documents\music video.wlmp
[2011/09/16 00:38:08 | 006,715,609 | —- | C] () – C:\Users\Zach\Desktop\Facebook___Paul_Puczko__39_s_Videos__vinnys_18th_birthday_bash.wmv
[2011/09/15 23:11:45 | 000,059,869 | —- | C] () – C:\Users\Zach\Desktop\maspeth_sign.jpg
[2011/05/31 19:58:11 | 000,773,482 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/04/07 21:07:37 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/10/21 08:36:06 | 000,000,000 | —- | C] () – C:\Users\Zach\AppData\Roaming\chrtmp
[2010/10/18 18:44:47 | 001,048,576 | —- | C] () – C:\Users\Zach\AppData\Roaming\test_file58.test
[2010/10/10 18:28:59 | 000,000,227 | —- | C] () – C:\Windows\PowerReg.dat
[2010/10/10 18:28:55 | 000,045,568 | —- | C] () – C:\Windows\UniFish3.exe
[2010/05/21 05:00:26 | 000,008,050 | —- | C] () – C:\Users\Zach\AppData\Roaming\com.koingosw.AlarmClockPro9.xml
[2010/03/15 05:31:48 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/01/26 19:11:24 | 000,000,533 | —- | C] () – C:\Windows\eReg.dat
[2010/01/10 22:30:02 | 000,941,784 | —- | C] () – C:\Windows\SysWow64\drivers\CAMTHWDM.sys
[2009/12/23 03:51:26 | 000,215,016 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2009/12/23 03:51:25 | 002,427,248 | —- | C] () – C:\Windows\SysWow64\pbsvc_heroes.exe
[2009/12/23 03:51:25 | 000,075,064 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2009/12/15 16:53:49 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CmdLineExt03.dll
[2009/12/10 20:38:13 | 000,020,992 | —- | C] () – C:\Users\Zach\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/29 04:28:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2009/10/31 17:11:37 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\acccore
[2010/09/23 16:54:10 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Arti
[2011/10/12 08:46:32 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Ciakku
[2010/01/07 22:13:33 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\DAEMON Tools Pro
[2011/06/17 00:38:10 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Lionhead Studios
[2010/05/28 02:27:51 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Mount&Blade; Warband
[2011/08/22 00:14:45 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Mount&Blade; With Fire and Sword
[2011/04/15 22:20:46 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Mp3tag
[2010/02/21 21:44:16 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\NCH Swift Sound
[2011/10/14 20:50:09 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Ocatoz
[2010/01/10 22:27:27 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\ooVoo Details
[2009/10/29 03:57:16 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Opera
[2011/03/04 00:08:22 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Petroglyph
[2011/10/15 22:32:47 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\QuickScan
[2009/12/25 03:45:04 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Red Alert 3
[2009/12/31 00:05:29 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\SPORE
[2010/06/11 19:34:37 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\SystemRequirementsLab
[2010/07/05 02:34:18 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\The Creative Assembly
[2011/04/16 00:20:31 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\tidysongs15.27F6A35B76E5883BF9E6FEE514586561E60595CA.1
[2011/04/16 00:02:13 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\tidysongs16
[2011/10/07 01:18:59 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Tropico 3
[2011/10/12 08:46:44 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Urizoh
[2011/10/12 08:46:44 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Uxvih
[2010/07/28 01:11:52 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Webcammax
[2010/05/02 13:05:44 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Xilisoft Corporation
[2011/03/10 22:39:15 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Xyan
[2011/09/16 20:45:07 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2011/10/15 19:08:18 | 000,099,415 | —- | M] () – C:\aaw7boot.log
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/10/29 01:58:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2008/09/27 20:32:24 | 000,021,315 | —- | M] () – C:\devlist.txt
[2008/09/27 20:32:21 | 000,000,009 | —- | M] () – C:\Finish.log
[2008/08/14 03:13:27 | 001,048,576 | RH– | M] () – C:\G50V.BIN
[2008/08/20 06:47:00 | 000,000,013 | —- | M] () – C:\G50VT_VISTA.10
[2011/10/15 22:05:06 | 3220,623,360 | -HS- | M] () – C:\hiberfil.sys
[2009/10/31 17:11:25 | 000,001,088 | -H– | M] () – C:\IPH.PH
[2007/06/30 01:17:42 | 000,000,019 | —- | M] () – C:\KQ21.txt
[2008/08/08 03:22:19 | 000,000,030 | —- | M] () – C:\NERO.LOG
[2008/07/04 00:35:34 | 000,000,021 | —- | M] () – C:\NIS2008.TXT
[2007/03/15 19:18:45 | 000,000,025 | —- | M] () – C:\OFFICE2007_Q.TXT
[2011/10/15 22:05:10 | 4294,168,576 | -HS- | M] () – C:\pagefile.sys
[2008/09/27 07:17:23 | 000,000,146 | —- | M] () – C:\Pass.txt
[2008/07/24 05:05:52 | 000,002,386 | —- | M] () – C:\Patch.LOG
[2008/05/12 00:29:53 | 000,000,020 | —- | M] () – C:\READER_Q.TXT
[2009/12/06 11:11:33 | 000,000,607 | —- | M] () – C:\RHDSetup.log
[2009/12/06 11:18:55 | 000,000,163 | —- | M] () – C:\setup.log
[2006/05/15 20:22:24 | 000,000,005 | —- | M] () – C:\Store.LOG
[2007/09/06 19:24:34 | 000,000,023 | —- | M] () – C:\V60.TXT

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/29 03:54:54 | 000,000,221 | -HS- | M] () – C:\Users\Zach\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/02/13 20:29:14 | 005,348,619 | —- | M] ( ) – C:\Users\Zach\Desktop\K-Lite_Codec_Pack_570_Basic.exe
[2011/10/15 22:37:20 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Users\Zach\Desktop\OTL.exe
[2011/10/15 22:23:43 | 000,935,175 | —- | M] () – C:\Users\Zach\Desktop\RSITx64.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:28:51 PM, on 10/15/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Zach\AppData\Local\Temp\_flashUpdate.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\Direct Console\DCHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Zach\Desktop\OTL.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Microsoft\Office Live\OfficeLiveSignIn.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5643
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
R3 - URLSearchHook: TVersitybar Toolbar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: TVersitybar Toolbar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111014203551.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
O3 - Toolbar: &Windows; Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
O3 - Toolbar: TVersitybar Toolbar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DirectConsole2] C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Bing Bar] "C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKCU\..\Run: [Windows Update] C:\Users\Zach\AppData\Local\Temp\service2.exe
O4 - HKCU\..\Run: [Windows SafeAssist] C:\Users\Zach\AppData\Roaming\winlogon.exe
O4 - HKCU\..\Run: [Adobe update service] c:\users\zach\appdata\local\temp\_flashupdate.exe
O4 - HKCU\..\Run: [{E22BFFC5-EF5B-4268-4826-4F92A8E30BA0}] C:\Users\Zach\AppData\Roaming\Ciakku\nypea.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-69817189-2322404834-165591724-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-69817189-2322404834-165591724-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - Unknown owner - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\ProgramData\TVersity\Media Server\MediaServer.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14629 bytes

I tried running dds but it said cannot find path.
:welcome:

Sorry for the delay but things get a bit hectic around here.

What I would do to start is use a known clean computer and change all your passwords for accounts that you frequent like online shopping or banking.


Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5643
    O33 - MountPoints2\{596674bc-6a21-11df-b5b5-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{596674bc-6a21-11df-b5b5-806e6f6e6963}\Shell\AutoRun\command - "" = H:\Setup.exe
    O33 - MountPoints2\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\Shell - "" = AutoRun
    O33 - MountPoints2\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\Shell\AutoRun\command - "" = H:\EN_Fallout_3_DLC.EXE
    O33 - MountPoints2\{aa33cafe-c47b-11de-bad1-00235401dab9}\Shell - "" = AutoRun
    O33 - MountPoints2\{aa33cafe-c47b-11de-bad1-00235401dab9}\Shell\AutoRun\command - "" = F:\autoplay.exe
    O33 - MountPoints2\{b3d89b61-18c1-11df-8b2b-00235401dab9}\Shell - "" = AutoRun
    O33 - MountPoints2\{b3d89b61-18c1-11df-8b2b-00235401dab9}\Shell\AutoRun\command - "" = H:\autorun.exe -auto
    O33 - MountPoints2\{bb35d8f4-c447-11de-b773-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{bb35d8f4-c447-11de-b773-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe
    O33 - MountPoints2\{cab46915-ef84-11de-85d8-00235401dab9}\Shell - "" = AutoRun
    O33 - MountPoints2\{cab46915-ef84-11de-85d8-00235401dab9}\Shell\AutoRun\command - "" = I:\AUTOSTARTER.EXE
    O33 - MountPoints2\H\Shell - "" = AutoRun
    O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AUTOSTARTER.EXE
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /release /c
    ipconfig /renew /c
    ipconfig /flushdns /c
    
    
    
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed
========== PROCESSES ==========
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{596674bc-6a21-11df-b5b5-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{596674bc-6a21-11df-b5b5-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{596674bc-6a21-11df-b5b5-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{596674bc-6a21-11df-b5b5-806e6f6e6963}\ not found.
File H:\Setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a5cb3c0b-ef88-11de-adaf-00235401dab9}\ not found.
File H:\EN_Fallout_3_DLC.EXE not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa33cafe-c47b-11de-bad1-00235401dab9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa33cafe-c47b-11de-bad1-00235401dab9}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa33cafe-c47b-11de-bad1-00235401dab9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa33cafe-c47b-11de-bad1-00235401dab9}\ not found.
File F:\autoplay.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3d89b61-18c1-11df-8b2b-00235401dab9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b3d89b61-18c1-11df-8b2b-00235401dab9}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3d89b61-18c1-11df-8b2b-00235401dab9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b3d89b61-18c1-11df-8b2b-00235401dab9}\ not found.
File H:\autorun.exe -auto not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bb35d8f4-c447-11de-b773-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bb35d8f4-c447-11de-b773-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bb35d8f4-c447-11de-b773-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bb35d8f4-c447-11de-b773-806e6f6e6963}\ not found.
File E:\setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cab46915-ef84-11de-85d8-00235401dab9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cab46915-ef84-11de-85d8-00235401dab9}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cab46915-ef84-11de-85d8-00235401dab9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cab46915-ef84-11de-85d8-00235401dab9}\ not found.
File I:\AUTOSTARTER.EXE not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found.
File H:\AUTOSTARTER.EXE not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /release /c >
Windows IP Configuration
No operation can be performed on Local Area Connection while it has its media disconnected.
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::ad17:8cd1:19f7:75d5%12
Default Gateway . . . . . . . . . :
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Local Area Connection* 11:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter 6TO4 Adapter:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:cb7:3535:bd93:d294
Link-local IPv6 Address . . . . . : fe80::cb7:3535:bd93:d294%14
Default Gateway . . . . . . . . . : ::
Tunnel adapter Reusable Microsoft 6To4 Adapter:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.[removed]:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Local Area Connection* 9:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{3592B3D2-7F36-4518-9222-AE77266A2D62}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
C:\Users\Zach\Desktop\cmd.bat deleted successfully.
C:\Users\Zach\Desktop\cmd.txt deleted successfully.
< ipconfig /renew /c >
Windows IP Configuration
No operation can be performed on Local Area Connection while it has its media disconnected.
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . : [removed]
Link-local IPv6 Address . . . . . : fe80::ad17:8cd1:19f7:75d5%12
IPv4 Address. . . . . . . . . . . : 192.168.0.17
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.1
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Local Area Connection* 11:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter 6TO4 Adapter:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:cb7:3535:bd93:d294
Link-local IPv6 Address . . . . . : fe80::cb7:3535:bd93:d294%14
Default Gateway . . . . . . . . . : ::
Tunnel adapter Reusable Microsoft 6To4 Adapter:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Local Area Connection* 9:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{3592B3D2-7F36-4518-9222-AE77266A2D62}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
C:\Users\Zach\Desktop\cmd.bat deleted successfully.
C:\Users\Zach\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Zach\Desktop\cmd.bat deleted successfully.
C:\Users\Zach\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes

User: Zach
->Temp folder emptied: 2141385184 bytes
->Temporary Internet Files folder emptied: 77193519 bytes
->Java cache emptied: 56186771 bytes
->FireFox cache emptied: 52243242 bytes
->Opera cache emptied: 67740014 bytes
->Flash cache emptied: 559996 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 401408 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 154421835 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67843 bytes
RecycleBin emptied: 19766 bytes

Total Files Cleaned = 2,432.00 mb


OTL by OldTimer - Version 3.2.30.0 log created on 10242011_200047

Files\Folders moved on Reboot…
C:\Users\Zach\AppData\Local\Temp\McAfeeLogs\UpdaterUI_HALOBOT.log moved successfully.
C:\Users\Zach\AppData\Local\Temp\McAfeeLogs\UpdaterUI_HALOBOT_error.log moved successfully.
C:\Users\Zach\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Zach\AppData\Local\Temp\ppcrlui_5016_3 moved successfully.

Registry entries deleted on Reboot…

OTL logfile created on: 10/24/2011 8:15:16 PM - Run 2
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Users\Zach\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 53.79% Memory free
8.00 Gb Paging File | 6.21 Gb Available in Paging File | 77.61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 51.76 Gb Free Space | 34.73% Space Free | Partition Type: NTFS
Drive D: | 138.31 Gb Total Space | 42.68 Gb Free Space | 30.85% Space Free | Partition Type: NTFS
Drive E: | 1.96 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: HALOBOT | User Name: Zach | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Zach\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\ProgramData\TVersity\Media Server\MediaServer.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe (ASUSTek.)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\Direct Console\DCHelper.exe (ASUSTek.)
PRC - C:\Program Files\ATKOSD2\ATKOSD2.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe ()
PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
PRC - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()
PRC - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\sqlite.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\OLED.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\SysInfo.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\OvrClk.dll ()
MOD - C:\Program Files\ATKOSD2\ATKOSD2.exe ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\LED.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\OUTLOOK.dll ()
MOD - C:\Program Files (x86)\ASUS\Direct Console\MSN.dll ()
MOD - C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll ()
MOD - C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll ()
MOD - C:\Program Files (x86)\McAfee\Common Framework\ccme_base.dll ()
MOD - C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll ()
MOD - C:\Program Files\ATKGFNEX\AGFNEX.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
SRV:64bit: - (spmgr) – C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ()
SRV:64bit: - (ADSMService) – C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe ()
SRV - (Akamai) – c:\Program Files (x86)\Common Files\Akamai\netsession_win_807ba95.dll ()
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (McAfeeFramework) – C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (TVersityMediaServer) – C:\ProgramData\TVersity\Media Server\MediaServer.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (atksgt) – C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) – C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (itecir) – C:\Windows\SysNative\drivers\itecir.sys (ITE Tech. Inc. )
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (kbfiltr) – C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (AsDsm) – C:\Windows\SysNative\drivers\AsDsm.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ATK64AMD.sys ()
DRV:64bit: - (ghaio) – C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys ()
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV:64bit: - (ASMMAP64) – C:\Program Files\ATKGFNEX\ASMMAP64.sys ()
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/?src=aim&ncid;=snsusaimc00000001
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 CD 62 1C 6D 58 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {4D144BC3-23FB-47de-90C5-63CCB0139CCF}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\Zach\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files (x86)\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/30 17:52:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\Firefox [2011/04/07 20:40:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/04/08 03:00:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/15 19:37:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/08 19:21:21 | 000,000,000 | —D | M]

[2009/12/21 07:13:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Zach\AppData\Roaming\Mozilla\Extensions
[2011/10/15 22:32:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions
[2010/07/14 23:20:27 | 000,000,000 | —D | M] (TradeManager-Plugin) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}
[2011/10/15 22:32:03 | 000,000,000 | —D | M] (BitDefender QuickScan) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/06/23 18:27:29 | 000,000,000 | —D | M] (Battlefield Heroes Updater) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\[removed]
[2011/05/09 23:17:51 | 000,000,000 | —D | M] (Microsoft Default Manager) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\DefaultManager@Microsoft
[2010/08/23 22:44:24 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\u22zyga5.default\extensions\[removed]
[2011/04/07 21:20:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/10/27 09:48:22 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/10/15 19:37:54 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/03/21 17:54:40 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll
[2011/09/23 22:06:23 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/10/24 20:00:57 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111014203551.dll (McAfee, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (TVersitybar Toolbar) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111014203551.dll (McAfee, Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (TVersitybar Toolbar) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (TVersitybar Toolbar) - {66BD2442-241B-44CD-8C7A-B51037053CDB} - C:\Program Files (x86)\TVersitybar\tbTVer.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ATKOSD2\ATKOSD2.exe ()
O4 - HKLM..\Run: [Bing Bar] C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [DirectConsole2] C:\Program Files (x86)\ASUS\Direct Console\Direct Console.exe (ASUSTek.)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [{E22BFFC5-EF5B-4268-4826-4F92A8E30BA0}] C:\Users\Zach\AppData\Roaming\Ciakku\nypea.exe File not found
O4 - HKCU..\Run: [Adobe update service] c:\users\zach\appdata\local\temp\_flashupdate.exe File not found
O4 - HKCU..\Run: [Windows SafeAssist] C:\Users\Zach\AppData\Roaming\winlogon.exe File not found
O4 - HKCU..\Run: [Windows Update] C:\Users\Zach\AppData\Local\Temp\service2.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF1CDD5E-055A-4BF3-869E-2C903087B17F}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\SysWOW64\MPK\MPK.exe) - File not found
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/22 00:46:32 | 000,000,297 | RHS- | M] () - D:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/24 20:00:47 | 000,000,000 | —D | C] – C:\_OTL
[2011/10/15 23:30:42 | 000,607,260 | R— | C] (Swearware) – C:\Users\Zach\Desktop\dds.scr
[2011/10/15 22:37:11 | 000,583,168 | —- | C] (OldTimer Tools) – C:\Users\Zach\Desktop\OTL.exe
[2011/10/15 22:32:42 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\QuickScan
[2011/10/15 22:23:59 | 000,000,000 | —D | C] – C:\rsit
[2011/10/15 19:23:20 | 000,069,376 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/10/15 19:23:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/10/15 19:19:46 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/10/14 20:43:58 | 000,000,000 | —D | C] – C:\QUARANTINE
[2011/10/14 20:40:20 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/14 20:40:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/10/14 20:36:27 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\McAfee
[2011/10/14 20:35:51 | 000,099,056 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\MfeOtlkAddin.dll
[2011/10/14 20:35:51 | 000,074,848 | —- | C] (McAfee, Inc.) – C:\Windows\SysWow64\MfeOtlkAddin.dll
[2011/10/14 20:35:51 | 000,022,816 | —- | C] (McAfee, Inc.) – C:\Windows\SysWow64\MFEOtlk.dll
[2011/10/14 20:35:50 | 000,009,984 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2011/10/14 20:35:49 | 000,217,696 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2011/10/14 20:35:49 | 000,153,952 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeapfk.sys
[2011/10/14 20:35:49 | 000,097,960 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2011/10/14 20:35:48 | 000,607,152 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfehidk.sys
[2011/10/14 20:35:25 | 000,281,544 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2011/10/14 20:35:24 | 000,156,248 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2011/10/14 20:35:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2011/10/14 20:35:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/10/14 20:34:12 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2011/10/14 20:34:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2011/10/14 20:34:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\McAfee
[2011/10/12 08:46:44 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Uxvih
[2011/10/12 08:46:44 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Urizoh
[2011/10/12 08:46:32 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Ocatoz
[2011/10/12 08:46:32 | 000,000,000 | —D | C] – C:\Users\Zach\AppData\Roaming\Ciakku
[2011/10/11 19:59:41 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/11 19:59:40 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/11 19:59:40 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/10/11 19:59:40 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/10/11 19:59:40 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/11 19:59:40 | 000,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/11 19:59:40 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/11 19:59:40 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/11 19:59:39 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/11 19:59:39 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 19:58:51 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/10/11 19:58:50 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/10/11 19:58:50 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/11 19:58:50 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/10/11 19:58:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/11 19:58:50 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/11 19:58:50 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/11 19:58:49 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/10/11 19:58:49 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/10/11 19:58:49 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/11 19:58:49 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/11 19:58:49 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/10/11 19:58:49 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/10/11 19:58:49 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/10/11 19:58:49 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/10/11 19:58:46 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/11 19:58:46 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/05 21:58:36 | 000,000,000 | —D | C] – C:\Users\Zach\Desktop\h
[1 C:\Users\Zach\AppData\Roaming\*.tmp files -> C:\Users\Zach\AppData\Roaming\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/24 20:17:03 | 005,443,514 | —- | M] () – C:\Users\Zach\Desktop\StormingHeaven.pdf
[2011/10/24 20:12:36 | 000,013,472 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/24 20:12:36 | 000,013,472 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/24 20:09:06 | 000,045,056 | —- | M] () – C:\Windows\SysNative\acovcnt.exe
[2011/10/24 20:05:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/24 20:05:14 | 3220,623,360 | -HS- | M] () – C:\hiberfil.sys
[2011/10/24 20:00:57 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2011/10/22 20:54:28 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/10/22 20:54:28 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/10/15 23:30:43 | 000,607,260 | R— | M] (Swearware) – C:\Users\Zach\Desktop\dds.scr
[2011/10/15 22:37:20 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Users\Zach\Desktop\OTL.exe
[2011/10/15 22:23:43 | 000,935,175 | —- | M] () – C:\Users\Zach\Desktop\RSITx64.exe
[2011/10/15 19:38:01 | 000,002,055 | —- | M] () – C:\Users\Zach\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/15 19:25:37 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/10/15 19:25:36 | 000,016,432 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2011/10/15 19:23:21 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/10/14 20:40:20 | 000,002,971 | —- | M] () – C:\Users\Zach\Desktop\HiJackThis.lnk
[2011/10/14 20:35:07 | 000,281,544 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2011/10/14 20:35:07 | 000,156,248 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2011/10/14 20:35:06 | 000,607,152 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfehidk.sys
[2011/10/14 20:35:06 | 000,099,056 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\MfeOtlkAddin.dll
[2011/10/14 20:35:06 | 000,097,960 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2011/10/14 20:35:05 | 000,217,696 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2011/10/14 20:35:05 | 000,153,952 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeapfk.sys
[2011/10/14 20:35:05 | 000,009,984 | —- | M] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2011/10/14 20:35:00 | 000,074,848 | —- | M] (McAfee, Inc.) – C:\Windows\SysWow64\MfeOtlkAddin.dll
[2011/10/14 20:35:00 | 000,022,816 | —- | M] (McAfee, Inc.) – C:\Windows\SysWow64\MFEOtlk.dll
[2011/10/13 22:29:03 | 023,766,005 | —- | M] () – C:\Users\Zach\Desktop\DVD Music Video.wmv
[2011/10/13 22:26:05 | 149,417,833 | —- | M] () – C:\Users\Zach\Desktop\DVD Format video.wmv
[2011/10/13 21:52:00 | 043,397,983 | —- | M] () – C:\Users\Zach\Desktop\The Way Vinny Lives 720p.wmv
[2011/10/13 21:19:08 | 263,417,811 | —- | M] () – C:\Users\Zach\Desktop\Final Cut 720p.wmv
[2011/10/13 20:58:41 | 000,061,910 | —- | M] () – C:\Users\Zach\Documents\123.wlmp
[2011/10/12 08:47:31 | 000,000,000 | -H– | M] () – C:\Users\Zach\AppData\Roaming\EfgJhIrJK1fh
[2011/10/12 08:46:31 | 000,000,000 | -H– | M] () – C:\Users\Zach\AppData\Roaming\E067ehkGGdtg
[2011/10/12 08:36:18 | 004,982,672 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/11 22:51:06 | 000,793,636 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/11 22:51:06 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/11 22:51:06 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/11 21:56:28 | 442,849,805 | —- | M] () – C:\Users\Zach\Desktop\Final Cut.wmv
[2011/10/07 22:12:57 | 000,040,103 | —- | M] () – C:\Users\Zach\Desktop\apd-25.pdf
[2011/10/07 22:00:58 | 000,266,431 | —- | M] () – C:\Users\Zach\Desktop\apd5draft.pdf
[2011/10/07 20:06:59 | 000,192,921 | —- | M] () – C:\Users\Zach\Desktop\apd-19.pdf
[1 C:\Users\Zach\AppData\Roaming\*.tmp files -> C:\Users\Zach\AppData\Roaming\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/24 20:16:51 | 005,443,514 | —- | C] () – C:\Users\Zach\Desktop\StormingHeaven.pdf
[2011/10/18 19:25:06 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/10/18 19:25:06 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/10/16 00:31:55 | 000,016,432 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2011/10/15 22:23:36 | 000,935,175 | —- | C] () – C:\Users\Zach\Desktop\RSITx64.exe
[2011/10/15 19:23:21 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/10/14 20:40:20 | 000,002,971 | —- | C] () – C:\Users\Zach\Desktop\HiJackThis.lnk
[2011/10/13 22:27:31 | 023,766,005 | —- | C] () – C:\Users\Zach\Desktop\DVD Music Video.wmv
[2011/10/13 22:18:02 | 149,417,833 | —- | C] () – C:\Users\Zach\Desktop\DVD Format video.wmv
[2011/10/13 21:49:33 | 043,397,983 | —- | C] () – C:\Users\Zach\Desktop\The Way Vinny Lives 720p.wmv
[2011/10/13 20:59:04 | 263,417,811 | —- | C] () – C:\Users\Zach\Desktop\Final Cut 720p.wmv
[2011/10/12 08:47:31 | 000,000,000 | -H– | C] () – C:\Users\Zach\AppData\Roaming\EfgJhIrJK1fh
[2011/10/12 08:46:31 | 000,000,000 | -H– | C] () – C:\Users\Zach\AppData\Roaming\E067ehkGGdtg
[2011/10/11 21:18:56 | 442,849,805 | —- | C] () – C:\Users\Zach\Desktop\Final Cut.wmv
[2011/10/07 22:12:57 | 000,040,103 | —- | C] () – C:\Users\Zach\Desktop\apd-25.pdf
[2011/10/07 22:00:58 | 000,266,431 | —- | C] () – C:\Users\Zach\Desktop\apd5draft.pdf
[2011/10/07 20:06:59 | 000,192,921 | —- | C] () – C:\Users\Zach\Desktop\apd-19.pdf
[2011/05/31 19:58:11 | 000,773,482 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/04/07 21:07:37 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/10/21 08:36:06 | 000,000,000 | —- | C] () – C:\Users\Zach\AppData\Roaming\chrtmp
[2010/10/18 18:44:47 | 001,048,576 | —- | C] () – C:\Users\Zach\AppData\Roaming\test_file58.test
[2010/10/10 18:28:59 | 000,000,227 | —- | C] () – C:\Windows\PowerReg.dat
[2010/10/10 18:28:55 | 000,045,568 | —- | C] () – C:\Windows\UniFish3.exe
[2010/05/21 05:00:26 | 000,008,050 | —- | C] () – C:\Users\Zach\AppData\Roaming\com.koingosw.AlarmClockPro9.xml
[2010/03/15 05:31:48 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/01/26 19:11:24 | 000,000,533 | —- | C] () – C:\Windows\eReg.dat
[2010/01/10 22:30:02 | 000,941,784 | —- | C] () – C:\Windows\SysWow64\drivers\CAMTHWDM.sys
[2009/12/23 03:51:26 | 000,215,016 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2009/12/23 03:51:25 | 002,427,248 | —- | C] () – C:\Windows\SysWow64\pbsvc_heroes.exe
[2009/12/23 03:51:25 | 000,075,064 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2009/12/15 16:53:49 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CmdLineExt03.dll
[2009/12/10 20:38:13 | 000,020,992 | —- | C] () – C:\Users\Zach\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/29 04:28:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2009/10/31 17:11:37 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\acccore
[2010/09/23 16:54:10 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Arti
[2011/10/16 00:31:53 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Ciakku
[2010/01/07 22:13:33 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\DAEMON Tools Pro
[2011/06/17 00:38:10 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Lionhead Studios
[2010/05/28 02:27:51 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Mount&Blade; Warband
[2011/08/22 00:14:45 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Mount&Blade; With Fire and Sword
[2011/04/15 22:20:46 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Mp3tag
[2010/02/21 21:44:16 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\NCH Swift Sound
[2011/10/14 20:50:09 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Ocatoz
[2010/01/10 22:27:27 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\ooVoo Details
[2009/10/29 03:57:16 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Opera
[2011/03/04 00:08:22 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Petroglyph
[2011/10/15 22:32:47 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\QuickScan
[2009/12/25 03:45:04 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Red Alert 3
[2009/12/31 00:05:29 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\SPORE
[2010/06/11 19:34:37 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\SystemRequirementsLab
[2010/07/05 02:34:18 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\The Creative Assembly
[2011/04/16 00:20:31 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\tidysongs15.27F6A35B76E5883BF9E6FEE514586561E60595CA.1
[2011/04/16 00:02:13 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\tidysongs16
[2011/10/07 01:18:59 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Tropico 3
[2011/10/12 08:46:44 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Urizoh
[2011/10/16 00:31:53 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Uxvih
[2010/07/28 01:11:52 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Webcammax
[2010/05/02 13:05:44 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Xilisoft Corporation
[2011/03/10 22:39:15 | 000,000,000 | —D | M] – C:\Users\Zach\AppData\Roaming\Xyan
[2011/09/16 20:45:07 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
:notworthy: Thank You so much by the way !
You were being redirected to a bad site and we fixed it

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-27 22:04:41 —————————– 22:04:41.398 OS Version: Windows x64 6.1.7600 22:04:41.398 Number of processors: 2 586 0x1706 22:04:41.399 ComputerName: HALOBOT UserName: Zach 22:04:42.946 Initialize success 22:05:34.322 AVAST engine defs: 11102701 22:05:54.226 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:05:54.228 Disk 0 Vendor: ST932042 SD13 Size: 305245MB BusType: 3 22:05:54.231 Disk 0 MBR read error 0 22:05:54.233 Disk 0 MBR scan 22:05:54.241 Disk 0 unknown MBR code 22:05:54.244 MBR BIOS signature not found 0 22:05:54.248 Service scanning 22:05:55.764 Service ASUSProcObsrv E:\I386\AsPrOb64.sys **LOCKED** 21 22:06:00.623 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 22:06:02.653 Modules scanning 22:06:02.657 Disk 0 trace - called modules: 22:06:02.672 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys spfz.sys hal.dll 22:06:02.676 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004d15060] 22:06:02.682 3 CLASSPNP.SYS[fffff88000c0143f] -> nt!IofCallDriver -> [0xfffffa8004b76840] 22:06:02.688 5 ACPI.sys[fffff8800100b781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004b7b050] 22:06:04.430 AVAST engine scan C:\Windows 22:06:13.229 AVAST engine scan C:\Windows\system32 22:11:22.188 AVAST engine scan C:\Windows\system32\drivers 22:11:53.489 AVAST engine scan C:\Users\Zach 22:21:55.635 AVAST engine scan C:\ProgramData 22:27:22.718 Scan finished successfully 22:27:54.886 Disk 0 MBR has been saved successfully to "C:\Users\Zach\Desktop\MBR.dat" 22:27:54.913 The log file has been saved successfully to "C:\Users\Zach\Desktop\aswMBR.txt" Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8033 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 10/27/2011 10:14:59 PM mbam-log-2011-10-27 (22-14-55).txt Scan type: Quick scan Objects scanned: 196546 Time elapsed: 7 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 3 Registry Data Items Infected: 0 Folders Infected: 17 Files Infected: 123 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> No action taken. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Update (Backdoor.IRCBot) -> Value: Windows Update -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows SafeAssist (Trojan.Agent) -> Value: Windows SafeAssist -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{E22BFFC5-EF5B-4268-4826-4F92A8E30BA0} (Trojan.ZbotR.Gen) -> Value: {E22BFFC5-EF5B-4268-4826-4F92A8E30BA0} -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\programdata\MPK (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\2 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\CPDA (Refog.Keylogger) -> No action taken. c:\programdata\MPK\CPDM (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger (Refog.Keylogger) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\relevantknowledge (Spyware.MarketScore) -> No action taken. c:\Windows\System32\MPK (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Images (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Images (Refog.Keylogger) -> No action taken. Files Infected: c:\Users\Zach\AppData\Roaming\efgjhirjk1fh (Stolen.Data) -> No action taken. c:\programdata\MPK\M0000 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger.lnk (Refog.Keylogger) -> No action taken. c:\programdata\MPK\S0000 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\D0000 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_7233639699 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_7268361921 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_7372534838 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_7407253357 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_7441976389 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_7476699306 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_8414217361 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\i40152_8448939583 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\S0000 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\1\t40154_8132123843 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\2\D0000 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\2\S0000 (Refog.Keylogger) -> No action taken. c:\programdata\MPK\CPDM\cpfm.bin (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger\get discount!.lnk (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger\order now!.lnk (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger\refog free keylogger on the web.lnk (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger\refog free keylogger.lnk (Refog.Keylogger) -> No action taken. c:\programdata\MPK\refog free keylogger\uninstall refog free keylogger.lnk (Refog.Keylogger) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\relevantknowledge\about relevantknowledge.lnk (Spyware.MarketScore) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\relevantknowledge\privacy policy and user license agreement.lnk (Spyware.MarketScore) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\relevantknowledge\Support.lnk (Spyware.MarketScore) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\relevantknowledge\uninstall instructions.lnk (Spyware.MarketScore) -> No action taken. c:\Windows\System32\MPK\French.lng (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\German.lng (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\icon_1.ico (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\MPK64.exe (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Romanian.lng (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Spanish.lng (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\sqlite3.dll (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\unins000.dat (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\unins000.exe (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\computer.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\delivery.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\file.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\filters.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\internet.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\invisible.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\logging.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\log_size.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\password.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\programs.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\update.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\English\users_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Images\english.gif (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Images\german.gif (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Images\russian.gif (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> No action taken. c:\Windows\System32\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\French.lng (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\German.lng (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\icon_1.ico (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\MPK64.exe (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Romanian.lng (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Spanish.lng (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\sqlite3.dll (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\unins000.dat (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\unins000.exe (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\alarms.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\computer.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\delivery.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\file.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\filters.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\internet.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\invisible.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\logging.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\log_size.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\password.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\programs.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\update.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\English\users_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Images\english.gif (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Images\german.gif (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Images\russian.gif (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> No action taken. c:\Windows\SysWOW64\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> No action taken. Sorry for posting this so late i j have just been using computers at my school library and avoiding this one
You had or still have a key logger on your system that has been capturing all your keystrokes and sending them back to an unknown author,

Your bank, sites like eBay, PayPal will never send you a email asking to update personal info, the link in those emails will take you to a spoofed site that actually looks pretty close to the legit one, you should always delete that email and use your browser to go to the real site . Your going to have to bite the bullet on this one and realize that you where scammed, what you need to do is contact your bank and credit card company and give them a fraud alert, have them cancel your credit card and issue you a new one, have them close your banking account and reopen a new one, thats the only way around this along with removing the bad software on your system.

Malwarebytes found all that bad stuff but you had it set to TAKE NO ACTION, that garbage needs to be removed, run Malwarebytes again and this time besure to select REMOVE SELECTED and check everything it finds, then post the log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI