This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus Wrecked My Computer

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have installed AVG Free Virus Scan, Super AntiSpyware, Free Window Registry Repair and these programs tend to show me virus and malware, fixes or deletes them, then just kinda sit there. I have attempted uninstalls of unneeded programs to no avail, and several "not responding"'s and the slow speed and sometime-y availability of executable files is annoying.

The biggest change I noticed is with the IE, which I have uninstalled, when I would type in a website or search, the website I typed would rarely go throught to that destination. It appears that my path was hijacked and I'd end up at some generic carp** website that it was not my intention to go to.

I went to "Are you Infected" and was successful at pulling up the first program, OTL, with results I will post below.

OTL.txt


OTL logfile created on: 10/16/2011 8:42:19 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Kezia Black\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 61.70% Memory free
2.60 Gb Paging File | 2.00 Gb Available in Paging File | 76.85% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 27.55 Gb Free Space | 39.47% Space Free | Partition Type: NTFS
Drive F: | 3.73 Gb Total Space | 1.71 Gb Free Space | 45.78% Space Free | Partition Type: FAT32
Drive G: | 2.80 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SKYNET | User Name: Kezia Black | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kezia Black\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\SYSTEM32\CSHelper.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - c:\Program Files\McAfee.com\Agent\Mcdetect.exe (McAfee, Inc)
PRC - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe ()
PRC - c:\Program Files\McAfee.com\Agent\McTskshd.exe (McAfee, Inc)
PRC - C:\WINDOWS\SYSTEM32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll ()
MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\Locales\en-US.dll ()
MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avutil-51.dll ()
MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avformat-53.dll ()
MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avcodec-53.dll ()
MOD - C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gcswf32.dll ()
MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\WINDOWS\SYSTEM32\sbe.dll ()
MOD - C:\WINDOWS\SYSTEM32\quartz.dll ()
MOD - C:\WINDOWS\SYSTEM32\CSHelper.exe ()
MOD - C:\WINDOWS\SYSTEM32\msdmo.dll ()
MOD - C:\WINDOWS\SYSTEM32\devenum.dll ()
MOD - C:\WINDOWS\SYSTEM32\cpwmon2k.dll ()
MOD - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe ()


========== Win32 Services (SafeList) ==========

SRV - (RoxLiveShare9) – File not found
SRV - (HidServ) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (CSHelper) – C:\WINDOWS\SYSTEM32\CSHelper.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (McDetect.exe) – c:\Program Files\McAfee.com\Agent\Mcdetect.exe (McAfee, Inc)
SRV - (mi-raysat_3dsmax8) – C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe ()
SRV - (McTskshd.exe) – c:\Program Files\McAfee.com\Agent\McTskshd.exe (McAfee, Inc)
SRV - (mcupdmgr.exe) – C:\Program Files\McAfee.com\Agent\mcupdmgr.exe (McAfee, Inc)
SRV - (KodakCCS) – C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe (Eastman Kodak Company)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\SYSTEM32\DRIVERS\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\SYSTEM32\DRIVERS\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (WinDriver6) – C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (MCSTRM) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DcCam) – C:\WINDOWS\SYSTEM32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (Exportit) – C:\WINDOWS\SYSTEM32\DRIVERS\ExportIt.sys (Eastman Kodak Company)
DRV - (DcPTP) – C:\WINDOWS\SYSTEM32\DRIVERS\DcPtp.sys (Eastman Kodak Company)
DRV - (DcLps) – C:\WINDOWS\SYSTEM32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DCFS2K) – C:\WINDOWS\SYSTEM32\DRIVERS\DCFS2k.sys (Eastman Kodak Company)
DRV - (DcFpoint) – C:\WINDOWS\SYSTEM32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (ha10kx2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap17v2k) – C:\WINDOWS\SYSTEM32\DRIVERS\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\SYSTEM32\DRIVERS\haP16v2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys (Creative Technology Ltd)
DRV - (HSFHWBS2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys (Creative Technology Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://news.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://mail.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://us.mg2.mail.yahoo.com/dc/launch?.rand=cnjqbkjjnc5nk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://m.www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@copysafe.net: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Ekwensi Black\Application Data\Move Networks\plugins\npqmp071705000014.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Documents and Settings\Kezia Black\Application Data\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Firefox\Profiles\gvyb3h59.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/10/16 20:05:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/20 20:29:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/20 20:29:38 | 000,000,000 | —D | M]

[2008/09/01 13:27:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Extensions
[2011/04/08 22:24:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Firefox\Profiles\gvyb3h59.default\extensions
[2010/07/24 10:26:04 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Firefox\Profiles\gvyb3h59.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/30 18:33:43 | 000,000,000 | —D | M] () – C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Firefox\Profiles\gvyb3h59.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2010/11/21 19:58:57 | 000,000,000 | —D | M] (FoxTab) – C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Firefox\Profiles\gvyb3h59.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2011/04/20 22:34:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/01 23:37:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/13 12:13:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/18 19:22:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/20 22:34:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2008/02/07 21:46:12 | 000,087,360 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2008/02/07 21:46:20 | 000,091,448 | —- | M] () – C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2008/02/07 21:46:16 | 000,021,824 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2007/03/16 17:27:00 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcm80.dll
[2007/03/16 17:27:00 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcp80.dll
[2007/03/16 17:27:00 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcr80.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/02/07 21:48:26 | 000,419,136 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2008/08/19 18:55:37 | 000,221,184 | —- | M] (CNN) – C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
[2007/10/25 10:17:00 | 000,237,568 | —- | M] (Virtools SA) – C:\Program Files\mozilla firefox\plugins\npvirtools.dll
[2007/03/09 19:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2008/02/07 21:46:12 | 000,024,384 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2010/07/10 18:21:12 | 000,001,469 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober84845984.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Turner Media Plugin 1.0.0.10 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
CHR - plugin: 3D Life Player (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvirtools.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Documents and Settings\Ekwensi Black\Application Data\Move Networks\plugins\npqmp071705000014.dll
CHR - plugin: Free Realms Installer (Enabled) = C:\Documents and Settings\Kezia Black\Application Data\Mozilla\Firefox\Profiles\gvyb3h59.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Documents and Settings\Kezia Black\Application Data\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1829_0\

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [MCUpdateExe] C:\Program Files\McAfee.com\Agent\mcupdate.exe (McAfee, Inc)
O4 - HKLM..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\RunOnce: [NSSInstallation] C:\WINDOWS\System32\Adobe\Shockwave 11\nssstub.exe (Symantec Corporation)
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: &Yahoo! Search - C:\Program Files\Yahoo!\Common [2009/11/14 21:13:06 | 000,000,000 | —D | M]
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Yahoo! &Dictionary - C:\Program Files\Yahoo!\Common [2009/11/14 21:13:06 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps - C:\Program Files\Yahoo!\Common [2009/11/14 21:13:06 | 000,000,000 | —D | M]
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://mypoints.worldwinner.com/games/v47/…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} http://www.otxresearch.com/OTXMedia/OTXMedia.dll (OTXMovie Class)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {97770E5B-2028-48AC-B4DA-1F991376D2B6} http://download.copysafe.net/plugins5/inst…rs/Copysafe.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/InstFred.ocx (NOXLATE)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} http://www.worldwinner.com/games/v44/golfsol/golfsol.cab (GolfSol Control)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{43486BBD-D98F-4AEA-B6C1-A6C5D735A28C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kezia Black\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/03 21:27:10 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1999/03/25 14:27:08 | 000,001,716 | —- | M] () - C:\AUTORUN.INF – [ NTFS ]
O32 - AutoRun File - [2005/08/11 11:13:54 | 000,004,840 | —- | M] () - C:\AUTORUN.PNF – [ NTFS ]
O32 - AutoRun File - [2004/08/10 08:00:00 | 000,000,110 | R— | M] () - G:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{02ec98f3-1709-11dd-99ad-0013200ebf50}\Shell - "" = AutoRun
O33 - MountPoints2\{02ec98f3-1709-11dd-99ad-0013200ebf50}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{02ec98f3-1709-11dd-99ad-0013200ebf50}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{e5ec596e-d48a-11d9-97e4-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ec596e-d48a-11d9-97e4-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e5ec596e-d48a-11d9-97e4-806d6172696f}\Shell\AutoRun\command - "" = G:\SETUP.EXE – [2004/08/10 08:00:00 | 001,314,816 | R— | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\SYSTEM32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\SYSTEM32\vp6vfw.dll (On2.com)
Drivers32: wave - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/16 20:39:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Kezia Black\My Documents\Downloads
[2011/10/16 20:31:01 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/10/16 20:05:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Kezia Black\Application Data\AVG2012
[2011/10/16 20:04:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/16 13:16:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Kezia Black\Start Menu\Programs\Google Chrome
[2011/10/16 11:50:35 | 000,000,000 | —D | C] – C:\Program Files\Free Window Registry Repair
[2007/06/07 18:50:43 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\KILLAPPS.EXE
[1980/01/01 01:00:00 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[1980/01/01 01:00:00 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/16 20:37:19 | 000,000,434 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{82A48E88-0A85-4E50-B493-6981FF067CF3}.job
[2011/10/16 20:31:04 | 000,000,392 | —- | M] () – C:\WINDOWS\tasks\NSSstub.job
[2011/10/16 20:26:55 | 004,932,286 | —- | M] () – C:\WINDOWS\{00000003-00000000-00000000-00001102-00000008-10011102}.CDF
[2011/10/16 20:26:37 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/10/16 20:26:24 | 000,000,815 | —- | M] () – C:\Documents and Settings\Kezia Black\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/10/16 20:25:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/10/16 20:24:52 | 000,030,624 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000003-00000000-00000000-00001102-00000008-10011102}.rfx
[2011/10/16 20:24:52 | 000,030,624 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000003-00000000-00000000-00001102-00000008-10011102}.rfx
[2011/10/16 20:24:52 | 000,029,772 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000003-00000000-00000000-00001102-00000008-10011102}.rfx
[2011/10/16 20:24:52 | 000,029,772 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000003-00000000-00000000-00001102-00000008-10011102}.rfx
[2011/10/16 20:24:52 | 000,002,796 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000003-00000000-00000000-00001102-00000008-10011102}.rfx
[2011/10/16 20:24:52 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/10/16 20:24:52 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/10/16 20:20:10 | 000,001,002 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3845572240-3741254854-3386662376-1006UA.job
[2011/10/16 20:02:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/16 18:18:41 | 135,028,818 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/10/16 18:18:12 | 000,020,102 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/10/16 13:35:23 | 000,000,209 | RHS- | M] () – C:\BOOT.INI
[2011/10/16 13:20:00 | 000,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3845572240-3741254854-3386662376-1006Core.job
[2011/10/16 13:16:24 | 000,002,330 | —- | M] () – C:\Documents and Settings\Kezia Black\Desktop\Google Chrome.lnk
[2011/10/16 13:16:24 | 000,002,308 | —- | M] () – C:\Documents and Settings\Kezia Black\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/16 12:33:16 | 000,508,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/16 12:02:04 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/16 11:50:36 | 000,000,718 | —- | M] () – C:\Documents and Settings\Kezia Black\Desktop\Free Window Registry Repair.lnk
[2011/10/16 11:50:06 | 000,799,120 | —- | M] () – C:\Documents and Settings\Kezia Black\My Documents\RegpairSetup.exe
[2011/09/22 20:47:45 | 000,000,525 | —- | M] () – C:\hpfr3420.xml
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/16 13:16:24 | 000,002,330 | —- | C] () – C:\Documents and Settings\Kezia Black\Desktop\Google Chrome.lnk
[2011/10/16 13:16:24 | 000,002,308 | —- | C] () – C:\Documents and Settings\Kezia Black\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/16 13:15:25 | 000,001,002 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3845572240-3741254854-3386662376-1006UA.job
[2011/10/16 13:15:24 | 000,000,950 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3845572240-3741254854-3386662376-1006Core.job
[2011/10/16 11:50:36 | 000,000,718 | —- | C] () – C:\Documents and Settings\Kezia Black\Desktop\Free Window Registry Repair.lnk
[2011/10/16 11:50:11 | 000,799,120 | —- | C] () – C:\Documents and Settings\Kezia Black\My Documents\RegpairSetup.exe
[2011/04/19 23:37:26 | 000,013,474 | -HS- | C] () – C:\Documents and Settings\Kezia Black\Local Settings\Application Data\6vn137o21jcqg4041
[2011/04/19 23:37:26 | 000,013,470 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6vn137o21jcqg4041
[2010/10/17 16:04:40 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/09/19 17:32:54 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kezia Black\Application Data\PFP120JPR.{PB
[2010/09/19 17:32:54 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kezia Black\Application Data\PFP120JCM.{PB
[2010/08/13 00:48:21 | 000,000,000 | —- | C] () – C:\WINDOWS\mtstack.INI
[2009/07/24 16:59:14 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2009/03/21 10:26:29 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2009/01/02 18:14:26 | 000,000,511 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\hpothb07.tif
[2009/01/02 18:14:26 | 000,000,373 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\hpothb07.dat
[2008/12/08 16:19:31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\CSHelper.exe
[2008/11/12 19:07:48 | 000,000,094 | —- | C] () – C:\WINDOWS\Dvm.LS\x00\x00\x00\x00
Hello and :welcome:
I'm RedCar92 and my name is Bill, I'll be glad to help you with your computer problems.

  • Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear. Malware removal can be stressful but we will clean it.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperative and could require a full reinstall of your OS, losing all your programs and data.

Stay with this topic until I give you the all clean post.
Greetings KezB,
First
Your logs indicate that you have more than one anti-virus program installed on your system. It is important to use only one active anti-virus because they interfere with each other causing serious system slow down, they may miss a virus and they may interfere with the diagnostic programs that we use. Please uninstall all but one.
Try using the unistaller accosiated with the AV you wish to uninstall. Go to Start -> All Programs -> (AV to uninstall) look for uninstall.exe and run it.
Should you have trouble you can down load the uninstaller from here
AVG http://www.avg.com/us-en/utilities (use the first one AVG Remover (32bit)
or
McAfee http://download.mcafee.com/products/licens…atches/MCPR.exe

Next
The otl.txt log that you posted is incomplete.
Can you find the otl.txt (it may be in downloads folder) open, select all, copy and post. Repeat this for the Extras.txt file.
If you cannot find the files then cut and past OTL.exe to your desktop and rerun. The logs should then save to your desktop.

Next
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
    Click Scan
  • On completion of the scan, click the Fix button.
  • Wait for the tool to report 'Infection fixed successfully', and reboot when prompted.
  • When it has rebooted, post the contents of the aswMBR.txt in your next reply.

Logs to post:
  • aswMBR.txt
  • otl.txt
  • Extras.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI