This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Icons disappeared

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Both the desktop icons as well as the Start Menu icons have disappeared.

=====================================================
OTL logfile created on: 10/17/2011 9:19:40 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 59.53% Memory free
5.73 Gb Paging File | 4.09 Gb Available in Paging File | 71.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.29 Gb Total Space | 244.76 Gb Free Space | 85.49% Space Free | Partition Type: NTFS
Drive E: | 14.92 Gb Total Space | 6.48 Gb Free Space | 43.43% Space Free | Partition Type: FAT32

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.exe (Gabest)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.71\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (TouchServicePen) – C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
SRV:64bit: - (TabletServicePen) – C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (PCSUService) – C:\Program Files (x86)\PC Speed Up\PCSUService.exe ()
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfmonm) – C:\Windows\SysNative\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (rtl8192Ce) – C:\Windows\SysNative\drivers\rtl8192Ce.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (QIOMem) – C:\Windows\SysNative\drivers\QIOMem.sys (TOSHIBA)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (X5XSEx) – C:\Program Files (x86)\Free Ride Games\X5XSEx.sys (Exent Technologies Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…D&bmod=TSND
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…D&bmod=TSND

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig?brand=TSND&bmod=TSND
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://start.toshiba.com/g/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = AD 4C 47 E0 77 55 DE 40 92 96 6C 02 90 21 3E A3 [binary data]
IE - HKCU\..\URLSearchHook: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\THBExt [2010/12/02 21:05:43 | 000,000,000 | -H-D | M]


Hosts file not found
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg64.dll (Google Inc.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.0\PriceGongIE.dll (PriceGong)
O2 - BHO: (adfabonppr Object) - {26D02F99-AE5B-4533-AD67-E23B4B20D60D} - C:\Windows\$BLSTUN$\qgnnv.dll ()
O2 - BHO: (no name) - {3CEBFA47-ED71-40C4-A94F-53DB8C4142B0} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {6C421C15-A592-498E-BD53-BE06F94E6B53} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (brumabonpgrm Object) - {795F4311-02C9-4B7B-A9BB-78D4FE68A98D} - C:\Windows\$BLSTUN$\lmatn.dll ()
O2 - BHO: (no name) - {7EE26D58-91DB-40F9-A4E9-DCE77C01E57b} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (no name) - {8144B19E-2FA9-489F-8314-1149B426B020} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (MrFroggy Class) - {856E12B5-22D7-4E22-9ACA-EA9A008DD65B} - C:\Program Files (x86)\Minibar\Froggy.dll (TODO: <название компании>)
O2 - BHO: (MinibarBHO) - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - C:\Program Files (x86)\Minibar\Kango.dll (KangoExtensions)
O2 - BHO: (no name) - {B26BE021-867F-4A6B-9CD3-7A121C16277c} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (no name) - {C2FF1D07-D7B9-493F-9A98-1E9E4BA151Db} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (no name) - {E0474CAD-5577-40DE-9296-6C0290213EA3} - C:\Users\Owner\AppData\Local\ShellWMP.dll (Gabest)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Client\YontooIEClient.dll (Yontoo Technology, Inc.)
O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [WebrootTrayApp] C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
O4 - HKCU..\Run: [Apple Update] C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.exe (Gabest)
O4 - HKCU..\Run: [Exetender] C:\Program Files (x86)\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [VirtualStore Update] C:\Users\Owner\AppData\Local\VirtualStore\VirtualStoreUpdate\VirtualStoreupdt32.exe (Gabest)
O4 - HKCU..\Run: [WindowsNotifierVerifier] C:\ProgramData\WindowsNotifierVerifier.dll (Gabest)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O9:64bit: - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Share Your Mood - {AAA38851-3CFF-475F-B5E0-720D3645E4A5} - C:\Program Files (x86)\Minibar\MinibarButton.dll (TODO: )
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20 - AppInit_DLLs: (c:\progra~2\kasper~1\kasper~1\mzvkbd3.dll) - c:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Authentication Packages - (ows\w) - File not found
O30 - LSA: Authentication Packages - (ows\w) - File not found
O30:64bit: - LSA: Security Packages - (iders) - File not found
O30:64bit: - LSA: Security Packages - (ngs…) - File not found
O30:64bit: - LSA: Security Packages - (ecution Options\GoogleUpdate.e) - File not found
O30 - LSA: Security Packages - (ce.exe) - File not found
O30 - LSA: Security Packages - (.0\) - File not found
O30 - LSA: Security Packages - (\) - \ File not found
O30 - LSA: Security Packages - (7\) - File not found
O30 - LSA: Security Packages - (oogleUpdate.e) - File no) - File not found
O30 - LSA: Security Packages - (l) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/22 21:35:22 | 000,000,000 | —- | M] () - E:\AUTORUN_.INF – [ FAT32 ]
O32 - AutoRun File - [2007/03/07 20:47:00 | 000,567,808 | —- | M] () - E:\AutoCorrect Backup Document.doc – [ FAT32 ]
O32 - AutoRun File - [2009/06/22 21:35:22 | 000,000,000 | -H– | M] () - E:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2010/01/08 09:26:22 | 000,068,608 | —- | M] () - E:\AUTOTEXT CHEAT SHEET.doc – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/17 21:16:12 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/09/29 20:51:41 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Google
[2011/09/25 21:19:28 | 000,000,000 | —D | C] – C:\windows\$BLSTUN$
[2011/09/23 20:06:58 | 000,000,000 | -H-D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up
[2011/09/23 20:06:57 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\PC Speed Up
[2011/09/23 19:57:15 | 000,000,000 | -H-D | C] – C:\ProgramData\Free Ride Games
[2011/09/23 19:56:37 | 000,053,314 | —- | C] (Exent Technologies Ltd.) – C:\windows\ExentInfo.exe
[2011/09/23 19:56:26 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Free Ride Games
[2011/09/23 19:56:01 | 000,000,000 | —D | C] – C:\Remote Programs
[2011/09/23 19:55:54 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Minibar
[2011/09/23 19:55:49 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\FaceSmooch Smileys
[2011/09/23 19:55:33 | 000,000,000 | -H-D | C] – C:\ProgramData\Babylon
[2011/09/23 19:52:54 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Surf Canyon
[2011/09/23 19:52:43 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\PriceGong
[2011/09/23 19:49:50 | 000,000,000 | —D | C] – C:\windows\Sun
[2011/09/23 17:13:06 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/09/23 17:00:40 | 000,000,000 | —D | C] – C:\windows\system64
[2011/09/21 08:35:05 | 000,000,000 | —D | C] – C:\windows\SysNative\SPReview
[2011/09/21 08:23:41 | 000,000,000 | —D | C] – C:\windows\SysNative\EventProviders
[2011/09/18 21:27:12 | 000,264,192 | -H– | C] (Gabest) – C:\Users\Owner\AppData\Local\ShellWMP.dll
[2011/09/18 21:27:06 | 000,097,792 | —- | C] (Gabest) – C:\windows\SysWow64\srrstr.dll
[2011/09/18 21:26:58 | 000,097,792 | -H– | C] (Gabest) – C:\ProgramData\WindowsNotifierVerifier.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/17 21:26:18 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/17 21:19:16 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/17 21:17:03 | 000,726,316 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/10/17 21:17:03 | 000,624,178 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/10/17 21:17:03 | 000,106,522 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/10/17 21:12:38 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/10/16 17:34:43 | 000,015,568 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/16 17:34:43 | 000,015,568 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/16 17:26:47 | 2307,280,896 | -HS- | M] () – C:\hiberfil.sys
[2011/10/04 21:06:58 | 000,001,812 | -H– | M] () – C:\Users\Owner\Desktop\iTunes (3).lnk
[2011/10/04 21:06:51 | 000,001,812 | -H– | M] () – C:\Users\Owner\Desktop\iTunes (2).lnk
[2011/09/29 07:46:44 | 000,000,000 | —- | M] () – C:\Users\Owner\AppData\Local\{76A3A698-DD67-450C-B4A6-A6E060AB18C6}
[2011/09/29 06:42:42 | 000,507,904 | -H– | M] () – C:\ProgramData\MyOilHmiRCcG.exe
[2011/09/23 20:39:55 | 000,308,760 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/09/23 19:57:29 | 000,000,064 | —- | M] () – C:\windows\GPlrLanc.dat
[2011/09/23 17:13:06 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/09/21 08:49:44 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msclmd.dll
[2011/09/21 08:49:43 | 000,175,616 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\msclmd.dll
[2011/09/20 20:27:25 | 000,002,369 | -H– | M] () – C:\Users\Owner\Desktop\Google Chrome.lnk
[2011/09/18 21:27:12 | 000,264,192 | -H– | M] (Gabest) – C:\Users\Owner\AppData\Local\ShellWMP.dll
[2011/09/18 21:26:57 | 000,097,792 | -H– | M] (Gabest) – C:\ProgramData\WindowsNotifierVerifier.dll
[2011/09/18 21:26:57 | 000,097,792 | —- | M] (Gabest) – C:\windows\SysWow64\srrstr.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/04 21:06:58 | 000,001,812 | -H– | C] () – C:\Users\Owner\Desktop\iTunes (3).lnk
[2011/10/04 21:06:51 | 000,001,812 | -H– | C] () – C:\Users\Owner\Desktop\iTunes (2).lnk
[2011/09/29 07:46:44 | 000,000,000 | —- | C] () – C:\Users\Owner\AppData\Local\{76A3A698-DD67-450C-B4A6-A6E060AB18C6}
[2011/09/29 06:42:44 | 000,507,904 | -H– | C] () – C:\ProgramData\MyOilHmiRCcG.exe
[2011/09/23 19:57:29 | 000,000,064 | —- | C] () – C:\windows\GPlrLanc.dat
[2011/08/20 11:19:45 | 000,000,533 | —- | C] () – C:\windows\eReg.dat
[2011/07/21 16:22:49 | 000,230,752 | —- | C] () – C:\windows\patchw32.dll
[2011/07/21 16:22:48 | 000,118,176 | —- | C] () – C:\windows\patchw.dll
[2011/03/26 17:52:28 | 000,000,814 | —- | C] () – C:\windows\disney.ini
[2010/12/27 18:28:48 | 000,030,424 | —- | C] () – C:\windows\SysWow64\wrLZMA.dll
[2010/12/25 20:36:05 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/29 05:08:46 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/07/29 05:08:44 | 000,104,796 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/07/29 05:08:42 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/07/29 04:14:38 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/07/29 04:14:38 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/01/16 19:22:37 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\com.gugga.radiomini
[2011/01/16 19:26:32 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\com.livebrush.2205ABAA7E8202CDC1251B1FA1E879364B7BAB52.1
[2011/01/16 21:03:54 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\com.sumopaint.bamboo.E63110E28E55D139F7D67D94E57B73BDB07BA618.1
[2010/12/25 20:21:43 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\Toshiba
[2011/02/11 23:25:09 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\Wacom
[2011/02/11 23:25:11 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2010/12/02 13:40:24 | 000,000,000 | -H-D | M] – C:\Users\Owner\AppData\Roaming\WinBatch
[2011/04/18 12:07:05 | 000,032,576 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/09/10 11:17:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/01/08 09:43:42 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2011/10/16 17:26:47 | 2307,280,896 | -HS- | M] () – C:\hiberfil.sys
[2011/08/16 23:20:07 | 000,389,423 | —- | M] () – C:\ml-20110816232007.xml
[2011/10/16 17:26:48 | 3076,374,528 | -HS- | M] () – C:\pagefile.sys
[2010/10/12 10:02:27 | 000,000,047 | —- | M] () – C:\Status.log

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | -H– | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | -H– | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | -H– | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | -H– | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | -H– | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/13 21:49:38 | 000,000,146 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/20 23:26:58 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\windows\system64] -> \systemroot\system32 -> Mount Point

< End of report >

===========================================

OTL Extras logfile created on: 10/17/2011 9:19:40 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 59.53% Memory free
5.73 Gb Paging File | 4.09 Gb Available in Paging File | 71.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.29 Gb Total Space | 244.76 Gb Free Space | 85.49% Space Free | Partition Type: NTFS
Drive E: | 14.92 Gb Total Space | 6.48 Gb Free Space | 43.43% Space Free | Partition Type: FAT32

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0C682623-8F66-46A8-B9B3-93FE1E66A001}" = iTunes
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client 1.10.01
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{A0E99122-25C1-4CA4-9063-499A2A814EB6}" = TOSHIBA ReelTime
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}" = TOSHIBA Hardware Setup
"{CBD6B23D-41D5-4A46-8019-6208516C9712}" = TOSHIBA Supervisor Password
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"CNXT_AUDIO_HDA" = Conexant HD Audio
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PCSU-SL_is1" = PC Speed Up - Complete uninstall
"Pen Tablet Driver" = Bamboo
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"$BLSTUN$" = Talul-Ads Browser Enhancer
"_{53A908D4-99C6-469B-BC13-F4189F260742}" = Corel Painter Essentials 4
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0D795777-9D60-4692-8386-F2B3F2B5E5BF}" = Label@Once 1.0
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{13597237-E360-4F2B-9A43-332C4E9D5C9C}" = InstallIQ Updater
"{15A60757-91A9-8875-17C4-7E5C4A7E17AF}" = Livebrush Mini
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{53A908D4-99C6-469B-BC13-F4189F260742}" = Corel Painter Essentials 4
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{63015986-2B3F-4B90-9DC8-9C46BD00854F}" = Fiesta
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7EBE79A9-74BF-42BE-8A70-630D2C22373B}_is1" = 01.01.0006
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B287B75-DF8D-40C8-9620-8E4492C38EF1}" = Webroot Software
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = TOSHIBA Application Installer
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AD9E6AC8-27B4-326A-69D1-C8A3549DAC22}" = Bamboo Dock
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BB51B753-9A0C-4D1D-B3EF-A1B936F55796}" = Toshiba Book Place
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CFCA7747-0813-AEBA-886F-732E1CBD79EA}" = MoodTuner
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{E127B28D-1A2A-45C4-A74E-C817E0A74E3E}" = Fiesta
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity_is1" = Audacity 1.2.6
"Bamboo Dock" = Bamboo Dock 3.3
"Barbie® Pet Rescue" = Barbie® Pet Rescue
"com.gugga.radiomini" = MoodTuner
"com.livebrush.2205ABAA7E8202CDC1251B1FA1E879364B7BAB52.1" = Livebrush Mini
"exent_466550" = The Treasures of Montezuma
"exent_575350" = Build-a-lot 2: Town of the Year
"exent_668750" = Insider Tales - Vanished in Rome
"FaceSmooch Smileys" = FaceSmooch Smileys
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{A0E99122-25C1-4CA4-9063-499A2A814EB6}" = TOSHIBA ReelTime
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}" = TOSHIBA Hardware Setup
"InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712}" = TOSHIBA Supervisor Password
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011
"Pen Tablet Driver" = Bamboo
"PriceGong" = PriceGong 2.5.0
"Surf Canyon" = Fast Search by Surf Canyon
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1" = Bamboo Dock
"Webroot Software" = Webroot Software
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"48e4cff94f039634" = Best Buy pc app

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/11/2011 7:32:19 PM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2293

Error - 10/11/2011 7:32:19 PM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2293

Error - 10/11/2011 11:57:35 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce7a313 Faulting module name: mshtml.dll, version: 8.0.7601.17655,
time stamp: 0x4e292507 Exception code: 0xc0000005 Fault offset: 0x00000000000b0738
Faulting
process id: 0x1480 Faulting application start time: 0x01cc886e0c736bb8 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\System32\mshtml.dll
Report
Id: 50e51556-f486-11e0-8fa5-60eb69620d1c

Error - 10/12/2011 6:08:09 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce7a313 Faulting module name: mshtml.dll, version: 8.0.7601.17655,
time stamp: 0x4e292507 Exception code: 0xc0000005 Fault offset: 0x00000000000b0738
Faulting
process id: 0x27c0 Faulting application start time: 0x01cc892b115580ea Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\System32\mshtml.dll
Report
Id: aad66beb-f51e-11e0-8fa5-60eb69620d1c

Error - 10/13/2011 12:22:59 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce7a313 Faulting module name: mshtml.dll, version: 8.0.7601.17655,
time stamp: 0x4e292507 Exception code: 0xc0000005 Fault offset: 0x00000000000bb65d
Faulting
process id: 0x2550 Faulting application start time: 0x01cc895ed094e815 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\System32\mshtml.dll
Report
Id: 07a43ca5-f553-11e0-8fa5-60eb69620d1c

Error - 10/13/2011 1:14:44 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/13/2011 1:14:45 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 837975

Error - 10/13/2011 1:14:45 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 837975

Error - 10/14/2011 1:47:54 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce7a313 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x00000007feebc451 Faulting process
id: 0x1444 Faulting application start time: 0x01cc8a343db4cc76 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 0f47abb2-f628-11e0-8fa5-60eb69620d1c

Error - 10/14/2011 7:52:12 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce7a313 Faulting module name: mshtml.dll, version: 8.0.7601.17655,
time stamp: 0x4e292507 Exception code: 0xc0000005 Fault offset: 0x00000000001a3efb
Faulting
process id: 0x2690 Faulting application start time: 0x01cc8acb91840525 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\System32\mshtml.dll
Report
Id: 88b2d52a-f6bf-11e0-8fa5-60eb69620d1c

[ System Events ]
Error - 9/24/2011 1:02:02 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:02:04 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:02:05 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:02:07 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:02:08 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:02:09 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:35:51 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:36:10 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:36:12 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 9/24/2011 1:36:16 AM | Computer Name = Owner-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.


< End of report >
Hi Jack P,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Let's see if we can get explorer to run.

Open taskmanger
  • click file
  • click New Task(Run…)
  • copy and paste the following line into the open: field
    explorer.exe
  • click ok
Is the taskbar and Start button back on the screen?

Thanks
Yes, the Start button and the taskbar are both on the screen, but they were always there. What is missing is most of the desktop icons and all of the start menu icons. After following your instructions I rebooted the computer and many desktop icons now show up. I'm not sure if that is all of them because it is a friend's computer. The icons are greyed out and when right clicking and selecting "Properties" on them, the Hidden attribute is checked. None of the start menu icons show up except some game icons, such as Solitaire and an iTunes icon.
Hi Jack P,

Sorry I misunderstood. Let's go about this way.

Important- Do Not use any tempory file cleaner programs.

Next

Please download Unhide.exe to your desktop:
  • right click on the Unhide.exe icon and click "Run as Administrator" on your desktop and allow the program to run.
  • Once it's finished check to see if the icons are visible and the items in the programs menu have returned.

Download aswMBR.exe to your desktop.

Right click on the click the aswMBR.exe icon and click "Run as Administrator" to run it .

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • aswMBR log
  • MBR.zip (attached)
Missing items back?

Thanks
After unhider and a reboot, the icons now are NOT checked "Hidden" and icons returned to the Start menu. When I ran aswmbr it began finding a number of infections, but then it blue screened.
Hi Jack P, Try running aswMBR without the Avast scan. You can set it by using the drop dpwn menu just to the left of the scan button. Thanks
Before I read your reply I reran the program and it finished successfully. ===================================== aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-20 00:04:28 —————————– 00:04:28.382 OS Version: Windows x64 6.1.7601 Service Pack 1 00:04:28.382 Number of processors: 2 586 0x2505 00:04:28.382 ComputerName: OWNER-PC UserName: Owner 00:04:33.951 Initialize success 00:04:42.438 AVAST engine defs: 11101901 00:10:23.616 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 00:10:23.632 Disk 0 Vendor: TOSHIBA_ GH10 Size: 305245MB BusType: 3 00:10:23.632 Disk 0 MBR read successfully 00:10:23.647 Disk 0 MBR scan 00:10:23.647 Disk 0 MBR:Alureon-I [Rtk] 00:10:23.663 Disk 0 TDL4@MBR code has been found 00:10:23.663 Disk 0 MBR hidden 00:10:23.663 Disk 0 MBR [TDL4] **ROOTKIT** 00:10:23.679 Disk 0 trace - called modules: 00:10:23.679 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80033c0254]<< 00:10:23.694 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003328790] 00:10:23.694 3 CLASSPNP.SYS[fffff880023b943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800319c050] 00:10:23.710 \Driver\iaStor[0xfffffa800230e9d0] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa80033c0254 00:10:26.643 AVAST engine scan C:\windows 00:10:32.508 AVAST engine scan C:\windows\system32 00:10:53.740 File: C:\windows\system32\consrv.dll **INFECTED** Win32:Malware-gen 00:16:27.978 AVAST engine scan C:\windows\system32\drivers 00:17:36.103 AVAST engine scan C:\Users\Owner 00:17:36.899 File: C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.dll **INFECTED** Win32:Malware-gen 00:17:37.008 File: C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.exe **INFECTED** Win32:Downloader-KIO [Trj] 00:23:43.182 File: C:\Users\Owner\AppData\Local\ShellWMP.dll **INFECTED** Win32:Malware-gen 00:23:43.728 File: C:\Users\Owner\AppData\Local\Temp\21C7.tmp **INFECTED** Win32:Malware-gen 00:23:52.557 File: C:\Users\Owner\AppData\Local\Temp\ED30.tmp **INFECTED** Win32:Malware-gen 00:23:57.986 File: C:\Users\Owner\AppData\Local\Temp\jar_cache4444179813257149267.tmp **INFECTED** Win32:Sirefef-AN [Trj] 00:23:59.765 File: C:\Users\Owner\AppData\Local\Temp\obn.dll **INFECTED** Win32:Malware-gen 00:25:12.632 File: C:\Users\Owner\AppData\Local\Temp\thpm8711120036382760916.tmp **INFECTED** Win32:Malware-gen 00:25:12.820 File: C:\Users\Owner\AppData\Local\Temp\uivjwkxlym **INFECTED** Win32:Malware-gen 00:25:25.331 File: C:\Users\Owner\AppData\Local\VirtualStore\VirtualStoreUpdate\VirtualStoreupdt32.dll **INFECTED** Win32:Malware-gen 00:25:25.471 File: C:\Users\Owner\AppData\Local\VirtualStore\VirtualStoreUpdate\VirtualStoreupdt32.exe **INFECTED** Win32:Downloader-KIO [Trj] 00:26:08.465 File: C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\54397283-21c9a3c7 **INFECTED** Win32:Sirefef-AN [Trj] 00:32:16.440 AVAST engine scan C:\ProgramData 00:40:31.405 File: C:\ProgramData\MyOilHmiRCcG.exe **INFECTED** Win32:Downloader-KOR [Trj] 00:40:42.791 File: C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll **INFECTED** Win32:Adware-gen [Adw] 00:41:02.461 File: C:\ProgramData\WindowsNotifierVerifier.dll **INFECTED** Win32:Malware-gen 00:41:12.564 Scan finished successfully 00:44:43.759 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 00:44:43.776 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.log"

Attachments:

Hi Jack P,

Re-Run aswMBR, you should be able to skip the Avast scan this time.

Click Scan

On completion of the scan

Click the FixButton

[external image: Posted Image]

Be sure to reboot the computer when told to.

Save the log as before and post in your next reply.




Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the aswMBR log and combofix log.

Thanks
OOOps. Sorry. During the repair the EXPIRED (argh) antivirus did a scan also. Right after I selected Fix for aswMBR it asked to reboot and it didn't seem that it was long enough for aswMBR so I though it was the expired antivirus wanting to reboot, so I said NO. Then I realized it was the aswMBR asking for the reboot. I then rebooted manually. After it rebooted, it went into a "Startup Repair" I don't know if this is from Windows 7 or aswMBR. It's been say "Attempting repairs" for a long time now…
The computer kept rebooting and continuing to attempt a repair. It finally ended and says this: ======================================= "Startup Repair cannot repair this computer automatically. Sending more information can help Microsoft create solutions." When I open up "Show problem details" it says: Problem signature Problem Event Name: StartupRepairOffline Problem Signature 01: 6.1.7600.16385 Problem Signature 02: 6.1.7600.16385 Problem Signature 03: unknown Problem Signature 04: 40 Problem Signature 05: AutoFailover Problem Signature 06: 1 Problem Signature 07: MissingOsLoader OS Version: 6.1.7600.2.0.0.256.1 Locale ID: 1033 It also give me 2 options: Send information about this problem (recommended) Don't send ======================================= Does the aswMBR program trying to find problems in the Master Boot Record (MBR)? Is that why I can't now reboot?
Hi Jack P,

Then MBR was infected. The images will be the same for which ever method you use.
  • Retsart the computer by rebooting and pressing and holding F8
  • Select Repair your computer.
    When you reboot you will see this although yours will say windows 7. Click repair my computer
[external image: Posted Image]

Select your operating system
[external image: Posted Image]

Select Command prompt
[external image: Posted Image]

At the command prompt type the following and hit enter


Bootrec.exe /FixMbr

(note the space between .exe and /FixMbr)

Once finished type Exit and hit enter.

Reboot to normal windows and run aswMBR again please. Don't worry we are just getting a scan log.


Or

If You do not have the option to select Repair your computer please do the following. Onl do this if you could not do the steps above.

On a working computer.

Download the recovery console ISO from Here
Also download Imgburn from here and install

Once Imgburn is installed double click the ISO to burn to disc

On the infected computer

  • Insert the disc and select start from the cd
  • Select Repair your computer.
  • Select the operating system you want to repair, and then click Next
  • Select command prompt
  • Type in the following command and hit enter
Bootrec.exe /FixMbr

(note the space between .exe and /FixMbr)

Once finished type Exit and hit enter.

Reboot to normal windows and run aswMBR again please.
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-20 20:17:30 —————————– 20:17:30.523 OS Version: Windows x64 6.1.7601 Service Pack 1 20:17:30.523 Number of processors: 2 586 0x2505 20:17:30.523 ComputerName: OWNER-PC UserName: Owner 20:17:47.885 Initialize success 20:17:59.320 AVAST engine defs: 11101901 20:18:08.649 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:18:08.649 Disk 0 Vendor: TOSHIBA_ GH10 Size: 305245MB BusType: 3 20:18:08.664 Disk 0 MBR read successfully 20:18:08.664 Disk 0 MBR scan 20:18:08.680 Disk 0 Windows 7 default MBR code 20:18:08.680 Service scanning 20:18:12.221 Service KL1 C:\windows\system32\DRIVERS\kl1.sys **LOCKED** 5 20:18:12.237 Service kl2 C:\windows\system32\DRIVERS\kl2.sys **LOCKED** 5 20:18:12.252 Service KLIM6 C:\windows\system32\DRIVERS\klim6.sys **LOCKED** 5 20:18:12.252 Service klmouflt C:\windows\system32\DRIVERS\klmouflt.sys **LOCKED** 5 20:18:18.040 Modules scanning 20:18:18.040 Disk 0 trace - called modules: 20:18:18.071 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 20:18:18.087 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800332a660] 20:18:18.087 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80031a2050] 20:18:18.087 Scan finished successfully 20:25:46.396 Disk 0 MBR has been saved successfully to "E:\0 A Virus\Paul\MBR.dat" 20:25:46.412 The log file has been saved successfully to "E:\0 A Virus\Paul\aswMBR.txt"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI