This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop Keep Logging Out and Freeze

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear forum experts …

Hope everyone is doing fine and well here.

I had a serious problems with my laptop recently, which kept freezing and lately … restart by itself (again and again). I would be very grateful if i can seek any advice from this forum experts. I enclosed this log from HijackThis …


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:29:22, on 20/10/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Kim Joi\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [ServiceManager.exe] "C:\Program Files (x86)\Virgin Media\Service Manager\ServiceManager.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files (x86)\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKLM\..\Run: [PCTools FGuard] "C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: SccallinTcp - {A69B197E-BF0D-4986-A0D1-FB5D9FEF0D37} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_310debf0\AESTSr64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Virgin Media Security (Radialpoint Security Services) - Virgin Media - C:\Program Files (x86)\Virgin Media\Security\RpsSecurityAwareR.exe
O23 - Service: RadialpointIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Virgin Media Security Firewall (RP_FWS) - Virgin Media - C:\Program Files (x86)\Virgin Media\Security\Fws.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\PC Tools Security\pctsSvc.exe
O23 - Service: ServicepointService - Radialpoint Inc. - C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_310debf0\STacSV64.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12932 bytes


Appreciate any kind of help here. Many thanks again.

JazzBiondi
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Dear mowman … thanks for your time n kind consideration looking into this problem of my laptop. For your info, i have to run all the instructions given by you on Safe Mode (with networking) because this is the only method which allows me to do all the scans etc. Here are the log generated by TDSSKiller …

21:15:24.0248 1548 TDSS rootkit removing tool [removed] Oct 21 2011 11:23:48
21:15:24.0387 1548 ============================================================
21:15:24.0387 1548 Current date / time: 2011/10/21 21:15:24.0387
21:15:24.0387 1548 SystemInfo:
21:15:24.0387 1548
21:15:24.0387 1548 OS Version: 6.0.6002 ServicePack: 2.0
21:15:24.0387 1548 Product type: Workstation
21:15:24.0387 1548 ComputerName: KIMJOI-PC
21:15:24.0387 1548 UserName: Kim Joi
21:15:24.0387 1548 Windows directory: C:\Windows
21:15:24.0387 1548 System windows directory: C:\Windows
21:15:24.0387 1548 Running under WOW64
21:15:24.0387 1548 Processor architecture: Intel x64
21:15:24.0387 1548 Number of processors: 2
21:15:24.0387 1548 Page size: 0x1000
21:15:24.0387 1548 Boot type: Safe boot with network
21:15:24.0387 1548 ============================================================
21:15:25.0487 1548 Initialize success
21:15:30.0486 1532 ============================================================
21:15:30.0486 1532 Scan started
21:15:30.0486 1532 Mode: Manual;
21:15:30.0486 1532 ============================================================
21:15:30.0999 1532 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
21:15:31.0001 1532 ACPI - ok
21:15:31.0088 1532 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
21:15:31.0091 1532 adp94xx - ok
21:15:31.0157 1532 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
21:15:31.0159 1532 adpahci - ok
21:15:31.0179 1532 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
21:15:31.0181 1532 adpu160m - ok
21:15:31.0202 1532 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
21:15:31.0204 1532 adpu320 - ok
21:15:31.0346 1532 AFD (0cc146c4addea45791b18b1e2659f4a9) C:\Windows\system32\drivers\afd.sys
21:15:31.0349 1532 AFD - ok
21:15:31.0405 1532 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
21:15:31.0406 1532 agp440 - ok
21:15:31.0469 1532 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
21:15:31.0470 1532 aic78xx - ok
21:15:31.0509 1532 aliide (9544c2c55541c0c6bfd7b489d0e7d430) C:\Windows\system32\drivers\aliide.sys
21:15:31.0510 1532 aliide - ok
21:15:31.0554 1532 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
21:15:31.0555 1532 amdide - ok
21:15:31.0586 1532 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
21:15:31.0587 1532 AmdK8 - ok
21:15:31.0931 1532 amdkmdag (60216b0e704584de6d5a9f59e9c34c47) C:\Windows\system32\DRIVERS\atikmdag.sys
21:15:31.0986 1532 amdkmdag - ok
21:15:32.0072 1532 amdkmdap (6b4e9261b613b047a9a145f328889968) C:\Windows\system32\DRIVERS\atikmpag.sys
21:15:32.0075 1532 amdkmdap - ok
21:15:32.0159 1532 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
21:15:32.0160 1532 arc - ok
21:15:32.0203 1532 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
21:15:32.0204 1532 arcsas - ok
21:15:32.0227 1532 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
21:15:32.0228 1532 AsyncMac - ok
21:15:32.0272 1532 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
21:15:32.0273 1532 atapi - ok
21:15:32.0579 1532 atikmdag (60216b0e704584de6d5a9f59e9c34c47) C:\Windows\system32\DRIVERS\atikmdag.sys
21:15:32.0632 1532 atikmdag - ok
21:15:32.0717 1532 BCM42RLY (a7c9995ba861fce78b2ceaae61d39fd7) C:\Windows\system32\drivers\BCM42RLY.sys
21:15:32.0718 1532 BCM42RLY - ok
21:15:32.0847 1532 BCM43XX (912012b708a7d8e8ce2ee55afb663dff) C:\Windows\system32\DRIVERS\bcmwl664.sys
21:15:32.0857 1532 BCM43XX - ok
21:15:32.0962 1532 bdfsfltr (151390d51a96867f5142ba708d044b6b) C:\Windows\system32\drivers\bdfsfltr.sys
21:15:32.0965 1532 bdfsfltr - ok
21:15:33.0053 1532 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
21:15:33.0054 1532 blbdrive - ok
21:15:33.0137 1532 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
21:15:33.0138 1532 bowser - ok
21:15:33.0165 1532 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
21:15:33.0165 1532 BrFiltLo - ok
21:15:33.0200 1532 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
21:15:33.0201 1532 BrFiltUp - ok
21:15:33.0264 1532 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
21:15:33.0265 1532 Brserid - ok
21:15:33.0278 1532 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
21:15:33.0279 1532 BrSerWdm - ok
21:15:33.0292 1532 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
21:15:33.0293 1532 BrUsbMdm - ok
21:15:33.0303 1532 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
21:15:33.0304 1532 BrUsbSer - ok
21:15:33.0316 1532 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
21:15:33.0317 1532 BTHMODEM - ok
21:15:33.0386 1532 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
21:15:33.0388 1532 cdfs - ok
21:15:33.0428 1532 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
21:15:33.0429 1532 cdrom - ok
21:15:33.0488 1532 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
21:15:33.0489 1532 circlass - ok
21:15:33.0517 1532 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
21:15:33.0525 1532 CLFS - ok
21:15:33.0609 1532 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys
21:15:33.0609 1532 CmBatt - ok
21:15:33.0620 1532 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
21:15:33.0621 1532 cmdide - ok
21:15:33.0656 1532 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys
21:15:33.0657 1532 Compbatt - ok
21:15:33.0688 1532 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
21:15:33.0689 1532 crcdisk - ok
21:15:33.0788 1532 CtClsFlt (11f13042577705093612c6a123caf12f) C:\Windows\system32\DRIVERS\CtClsFlt.sys
21:15:33.0790 1532 CtClsFlt - ok
21:15:33.0892 1532 DefragFS (afaaa345fceb1ac24e0d63d85a7775fd) C:\Windows\system32\drivers\DefragFS.sys
21:15:33.0893 1532 DefragFS - ok
21:15:33.0963 1532 DfsC (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
21:15:33.0964 1532 DfsC - ok
21:15:34.0039 1532 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
21:15:34.0041 1532 disk - ok
21:15:34.0140 1532 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
21:15:34.0141 1532 drmkaud - ok
21:15:34.0367 1532 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
21:15:34.0373 1532 DXGKrnl - ok
21:15:34.0556 1532 e1express (17d40652ef3e55eeae187a89df40965a) C:\Windows\system32\DRIVERS\e1e6032e.sys
21:15:34.0559 1532 e1express - ok
21:15:34.0618 1532 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
21:15:34.0620 1532 E1G60 - ok
21:15:34.0656 1532 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
21:15:34.0657 1532 Ecache - ok
21:15:34.0738 1532 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
21:15:34.0741 1532 elxstor - ok
21:15:34.0756 1532 ErrDev (991fab6aa066e1214efb5b496fb7959a) C:\Windows\system32\drivers\errdev.sys
21:15:34.0757 1532 ErrDev - ok
21:15:34.0798 1532 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
21:15:34.0799 1532 exfat - ok
21:15:34.0838 1532 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
21:15:34.0840 1532 fastfat - ok
21:15:34.0851 1532 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
21:15:34.0851 1532 fdc - ok
21:15:34.0887 1532 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
21:15:34.0888 1532 FileInfo - ok
21:15:34.0915 1532 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
21:15:34.0916 1532 Filetrace - ok
21:15:34.0926 1532 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
21:15:34.0927 1532 flpydisk - ok
21:15:34.0971 1532 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
21:15:34.0973 1532 FltMgr - ok
21:15:35.0036 1532 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
21:15:35.0037 1532 Fs_Rec - ok
21:15:35.0067 1532 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
21:15:35.0068 1532 gagp30kx - ok
21:15:35.0157 1532 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:15:35.0158 1532 GEARAspiWDM - ok
21:15:35.0261 1532 HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
21:15:35.0263 1532 HdAudAddService - ok
21:15:35.0314 1532 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
21:15:35.0320 1532 HDAudBus - ok
21:15:35.0344 1532 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
21:15:35.0345 1532 HidBth - ok
21:15:35.0362 1532 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
21:15:35.0363 1532 HidIr - ok
21:15:35.0420 1532 HidUsb (128e2da8483fdd4dd0c7b3f9abd6f323) C:\Windows\system32\DRIVERS\hidusb.sys
21:15:35.0420 1532 HidUsb - ok
21:15:35.0481 1532 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
21:15:35.0482 1532 HpCISSs - ok
21:15:35.0539 1532 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
21:15:35.0544 1532 HTTP - ok
21:15:35.0562 1532 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
21:15:35.0563 1532 i2omp - ok
21:15:35.0620 1532 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
21:15:35.0621 1532 i8042prt - ok
21:15:35.0646 1532 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
21:15:35.0648 1532 iaStorV - ok
21:15:35.0667 1532 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
21:15:35.0668 1532 iirsp - ok
21:15:35.0725 1532 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
21:15:35.0726 1532 intelide - ok
21:15:35.0761 1532 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
21:15:35.0762 1532 intelppm - ok
21:15:35.0824 1532 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:15:35.0825 1532 IpFilterDriver - ok
21:15:35.0856 1532 IpInIp - ok
21:15:35.0868 1532 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
21:15:35.0870 1532 IPMIDRV - ok
21:15:35.0881 1532 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
21:15:35.0882 1532 IPNAT - ok
21:15:35.0935 1532 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
21:15:35.0936 1532 IRENUM - ok
21:15:35.0947 1532 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
21:15:35.0947 1532 isapnp - ok
21:15:35.0992 1532 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
21:15:35.0994 1532 iScsiPrt - ok
21:15:36.0008 1532 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
21:15:36.0009 1532 iteatapi - ok
21:15:36.0020 1532 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
21:15:36.0021 1532 iteraid - ok
21:15:36.0110 1532 k57nd60a (1d7aab58f4e21697af8f46eaa81823dd) C:\Windows\system32\DRIVERS\k57nd60a.sys
21:15:36.0113 1532 k57nd60a - ok
21:15:36.0147 1532 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
21:15:36.0148 1532 kbdclass - ok
21:15:36.0161 1532 kbdhid (bf8783a5066cfecf45095459e8010fa7) C:\Windows\system32\DRIVERS\kbdhid.sys
21:15:36.0162 1532 kbdhid - ok
21:15:36.0220 1532 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
21:15:36.0224 1532 KSecDD - ok
21:15:36.0234 1532 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
21:15:36.0235 1532 ksthunk - ok
21:15:36.0273 1532 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
21:15:36.0274 1532 lltdio - ok
21:15:36.0313 1532 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
21:15:36.0314 1532 LSI_FC - ok
21:15:36.0325 1532 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
21:15:36.0327 1532 LSI_SAS - ok
21:15:36.0389 1532 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
21:15:36.0390 1532 LSI_SCSI - ok
21:15:36.0416 1532 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
21:15:36.0417 1532 luafv - ok
21:15:36.0430 1532 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
21:15:36.0431 1532 megasas - ok
21:15:36.0503 1532 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
21:15:36.0506 1532 MegaSR - ok
21:15:36.0591 1532 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
21:15:36.0592 1532 Modem - ok
21:15:36.0609 1532 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
21:15:36.0610 1532 monitor - ok
21:15:36.0628 1532 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
21:15:36.0629 1532 mouclass - ok
21:15:36.0665 1532 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
21:15:36.0666 1532 mouhid - ok
21:15:36.0705 1532 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
21:15:36.0707 1532 MountMgr - ok
21:15:36.0771 1532 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
21:15:36.0772 1532 mpio - ok
21:15:36.0795 1532 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
21:15:36.0796 1532 mpsdrv - ok
21:15:36.0808 1532 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
21:15:36.0810 1532 Mraid35x - ok
21:15:36.0844 1532 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
21:15:36.0845 1532 MRxDAV - ok
21:15:36.0901 1532 mrxsmb (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:15:36.0902 1532 mrxsmb - ok
21:15:36.0955 1532 mrxsmb10 (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:15:36.0957 1532 mrxsmb10 - ok
21:15:36.0971 1532 mrxsmb20 (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:15:36.0973 1532 mrxsmb20 - ok
21:15:37.0027 1532 msahci (aa459f2ab3ab603c357ff117cae3d818) C:\Windows\system32\drivers\msahci.sys
21:15:37.0028 1532 msahci - ok
21:15:37.0080 1532 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
21:15:37.0081 1532 msdsm - ok
21:15:37.0113 1532 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
21:15:37.0114 1532 Msfs - ok
21:15:37.0173 1532 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
21:15:37.0173 1532 msisadrv - ok
21:15:37.0246 1532 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
21:15:37.0247 1532 MSKSSRV - ok
21:15:37.0260 1532 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
21:15:37.0260 1532 MSPCLOCK - ok
21:15:37.0276 1532 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
21:15:37.0277 1532 MSPQM - ok
21:15:37.0323 1532 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
21:15:37.0325 1532 MsRPC - ok
21:15:37.0355 1532 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
21:15:37.0355 1532 mssmbios - ok
21:15:37.0380 1532 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
21:15:37.0380 1532 MSTEE - ok
21:15:37.0405 1532 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
21:15:37.0406 1532 Mup - ok
21:15:37.0483 1532 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
21:15:37.0485 1532 NativeWifiP - ok
21:15:37.0534 1532 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
21:15:37.0539 1532 NDIS - ok
21:15:37.0594 1532 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
21:15:37.0595 1532 NdisTapi - ok
21:15:37.0617 1532 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
21:15:37.0618 1532 Ndisuio - ok
21:15:37.0651 1532 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
21:15:37.0652 1532 NdisWan - ok
21:15:37.0678 1532 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
21:15:37.0679 1532 NDProxy - ok
21:15:37.0696 1532 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
21:15:37.0697 1532 NetBIOS - ok
21:15:37.0738 1532 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
21:15:37.0740 1532 netbt - ok
21:15:37.0776 1532 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
21:15:37.0777 1532 nfrd960 - ok
21:15:37.0819 1532 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
21:15:37.0820 1532 Npfs - ok
21:15:37.0840 1532 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
21:15:37.0841 1532 nsiproxy - ok
21:15:37.0903 1532 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
21:15:37.0913 1532 Ntfs - ok
21:15:37.0933 1532 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
21:15:37.0934 1532 Null - ok
21:15:37.0960 1532 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
21:15:37.0962 1532 nvraid - ok
21:15:37.0978 1532 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
21:15:37.0979 1532 nvstor - ok
21:15:38.0002 1532 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
21:15:38.0003 1532 nv_agp - ok
21:15:38.0012 1532 NwlnkFlt - ok
21:15:38.0022 1532 NwlnkFwd - ok
21:15:38.0111 1532 OA008Ufd (404b0121ae1a75d9a63b6934eb07c258) C:\Windows\system32\DRIVERS\OA008Ufd.sys
21:15:38.0112 1532 OA008Ufd - ok
21:15:38.0154 1532 OA008Vid (126885007e8f601861165fc77c93f1be) C:\Windows\system32\DRIVERS\OA008Vid.sys
21:15:38.0156 1532 OA008Vid - ok
21:15:38.0235 1532 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
21:15:38.0236 1532 ohci1394 - ok
21:15:38.0312 1532 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
21:15:38.0313 1532 Parport - ok
21:15:38.0344 1532 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
21:15:38.0345 1532 partmgr - ok
21:15:38.0354 1532 PCAMp60a64 - ok
21:15:38.0394 1532 PCASp60a64 - ok
21:15:38.0441 1532 PCD5SRVC{048DBD20-445E8C82-05040104} - ok
21:15:38.0681 1532 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\dell support center\pcdsrvc_x64.pkms
21:15:38.0725 1532 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - ok
21:15:38.0833 1532 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
21:15:38.0834 1532 pci - ok
21:15:38.0889 1532 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
21:15:38.0889 1532 pciide - ok
21:15:38.0921 1532 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
21:15:38.0923 1532 pcmcia - ok
21:15:38.0985 1532 PCTCore (52fa4369e262b047ebd3a37155e30074) C:\Windows\system32\drivers\PCTCore64.sys
21:15:38.0988 1532 PCTCore - ok
21:15:39.0022 1532 pctDS (ff43e3b1687e4e2140de6349ea5c7372) C:\Windows\system32\drivers\pctDS64.sys
21:15:39.0025 1532 pctDS - ok
21:15:39.0094 1532 pctEFA (60e9a05852af7e9cb11237c00aee4ccf) C:\Windows\system32\drivers\pctEFA64.sys
21:15:39.0099 1532 pctEFA - ok
21:15:39.0169 1532 pctgntdi (c48d8681d70b409cfe288f6b3bc162e6) C:\Windows\System32\drivers\pctgntdi64.sys
21:15:39.0171 1532 pctgntdi - ok
21:15:39.0204 1532 pctplsg (b63e8192aa065fcd23cac1309da32a3d) C:\Windows\System32\drivers\pctplsg64.sys
21:15:39.0205 1532 pctplsg - ok
21:15:39.0259 1532 PCTSD (8da7df6075472233cc5a9734bf973b2e) C:\Windows\system32\Drivers\PCTSD64.sys
21:15:39.0261 1532 PCTSD - ok
21:15:39.0349 1532 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
21:15:39.0353 1532 PEAUTH - ok
21:15:39.0434 1532 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
21:15:39.0435 1532 PptpMiniport - ok
21:15:39.0455 1532 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
21:15:39.0456 1532 Processor - ok
21:15:39.0516 1532 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
21:15:39.0517 1532 PSched - ok
21:15:39.0600 1532 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
21:15:39.0601 1532 PxHlpa64 - ok
21:15:39.0824 1532 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
21:15:39.0833 1532 ql2300 - ok
21:15:40.0210 1532 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
21:15:40.0211 1532 ql40xx - ok
21:15:40.0275 1532 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
21:15:40.0276 1532 QWAVEdrv - ok
21:15:40.0571 1532 R300 (60216b0e704584de6d5a9f59e9c34c47) C:\Windows\system32\DRIVERS\atikmdag.sys
21:15:40.0624 1532 R300 - ok
21:15:40.0754 1532 RadialpointIDSDriver (324659000db5f843c2ff8c77ba53e752) C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys
21:15:40.0759 1532 RadialpointIDSDriver - ok
21:15:40.0775 1532 RadialpointIDSEH - ok
21:15:40.0811 1532 RadialpointIDSFilter (468f26b8487758e82987ee695cc38ced) C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSFilter.sys
21:15:40.0812 1532 RadialpointIDSFilter - ok
21:15:41.0046 1532 RapportCerberus_32029 (68b15a9a2a35d7afa3bda1fb9edb84d0) C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus64_32029.sys
21:15:41.0056 1532 RapportCerberus_32029 - ok
21:15:41.0218 1532 RapportEI64 (9f59cc485c023e2d41789ad31d5ccc2c) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
21:15:41.0221 1532 RapportEI64 - ok
21:15:41.0311 1532 RapportKE64 (9aa4a536cee7a09b2e03d4d423a9f718) C:\Windows\system32\Drivers\RapportKE64.sys
21:15:41.0312 1532 RapportKE64 - ok
21:15:41.0509 1532 RapportPG64 (e6baeb47476ab92878bf613f538211de) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
21:15:41.0511 1532 RapportPG64 - ok
21:15:41.0599 1532 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
21:15:41.0600 1532 RasAcd - ok
21:15:41.0654 1532 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:15:41.0655 1532 Rasl2tp - ok
21:15:41.0691 1532 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
21:15:41.0692 1532 RasPppoe - ok
21:15:41.0728 1532 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
21:15:41.0729 1532 RasSstp - ok
21:15:41.0772 1532 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
21:15:41.0774 1532 rdbss - ok
21:15:41.0794 1532 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:15:41.0795 1532 RDPCDD - ok
21:15:41.0823 1532 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
21:15:41.0825 1532 rdpdr - ok
21:15:41.0839 1532 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
21:15:41.0840 1532 RDPENCDD - ok
21:15:41.0869 1532 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
21:15:41.0870 1532 RDPWD - ok
21:15:41.0955 1532 rimmptsk (6faf5b04bedc66d300d9d233b2d222f0) C:\Windows\system32\DRIVERS\rimmpx64.sys
21:15:41.0956 1532 rimmptsk - ok
21:15:42.0012 1532 rimsptsk (67f50c31713106fd1b0f286f86aa2b2e) C:\Windows\system32\DRIVERS\rimspx64.sys
21:15:42.0013 1532 rimsptsk - ok
21:15:42.0054 1532 rismxdp (4d7ef3d46346ec4c58784db964b365de) C:\Windows\system32\DRIVERS\rixdpx64.sys
21:15:42.0055 1532 rismxdp - ok
21:15:42.0128 1532 RPPKT (fe15c4c61b51159e8c826b64ff89b1ea) C:\Windows\system32\DRIVERS\rp_pkt64.sys
21:15:42.0129 1532 RPPKT - ok
21:15:42.0156 1532 RPSKT (98f7aa362690324afa5c328c48cec932) C:\Windows\system32\DRIVERS\rp_skt64.sys
21:15:42.0158 1532 RPSKT - ok
21:15:42.0192 1532 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
21:15:42.0193 1532 rspndr - ok
21:15:42.0278 1532 RTHDMIAzAudService (c618475866f6a7129f64a55961c1bb8b) C:\Windows\system32\drivers\RtHDMIVX.sys
21:15:42.0281 1532 RTHDMIAzAudService - ok
21:15:42.0312 1532 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
21:15:42.0313 1532 sbp2port - ok
21:15:42.0414 1532 sdbus (be100bc2be2513314c717bb2c4cfff10) C:\Windows\system32\DRIVERS\sdbus.sys
21:15:42.0415 1532 sdbus - ok
21:15:42.0449 1532 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
21:15:42.0449 1532 secdrv - ok
21:15:42.0483 1532 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
21:15:42.0484 1532 Serenum - ok
21:15:42.0495 1532 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
21:15:42.0497 1532 Serial - ok
21:15:42.0507 1532 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
21:15:42.0508 1532 sermouse - ok
21:15:42.0606 1532 sffdisk (3a19c899bcf0ea24cfec2038e6a489db) C:\Windows\system32\DRIVERS\sffdisk.sys
21:15:42.0606 1532 sffdisk - ok
21:15:42.0616 1532 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
21:15:42.0617 1532 sffp_mmc - ok
21:15:42.0635 1532 sffp_sd (fdca63a2eee528585eb66ceac183ec22) C:\Windows\system32\DRIVERS\sffp_sd.sys
21:15:42.0636 1532 sffp_sd - ok
21:15:42.0658 1532 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
21:15:42.0659 1532 sfloppy - ok
21:15:42.0681 1532 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
21:15:42.0682 1532 SiSRaid2 - ok
21:15:42.0693 1532 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
21:15:42.0694 1532 SiSRaid4 - ok
21:15:42.0732 1532 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
21:15:42.0733 1532 Smb - ok
21:15:42.0763 1532 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
21:15:42.0764 1532 spldr - ok
21:15:49.0506 1532 srv (e3f0ec9182afdcd0a4ebc36e0c0a16b9) C:\Windows\system32\DRIVERS\srv.sys
21:16:53.0431 1532 Suspicious file (NoAccess): C:\Windows\system32\DRIVERS\srv.sys. md5: e3f0ec9182afdcd0a4ebc36e0c0a16b9
21:16:53.0725 1532 srv ( LockedFile.Multi.Generic ) - warning
21:16:53.0725 1532 srv - detected LockedFile.Multi.Generic (1)
21:16:53.0851 1532 srv2 (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys
21:16:53.0855 1532 srv2 - ok
21:16:53.0924 1532 srvnet (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys
21:16:53.0927 1532 srvnet - ok
21:16:53.0968 1532 StarOpen - ok
21:16:54.0062 1532 STHDA (02e784fa49032f84964db90a3ed81890) C:\Windows\system32\DRIVERS\stwrt64.sys
21:16:54.0071 1532 STHDA - ok
21:16:54.0115 1532 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
21:16:54.0115 1532 swenum - ok
21:16:54.0143 1532 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
21:16:54.0144 1532 Symc8xx - ok
21:16:54.0157 1532 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
21:16:54.0159 1532 Sym_hi - ok
21:16:54.0176 1532 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
21:16:54.0178 1532 Sym_u3 - ok
21:16:54.0217 1532 SynTP (79a93ec9d224b1f43c0e2f023d61dca3) C:\Windows\system32\DRIVERS\SynTP.sys
21:16:54.0219 1532 SynTP - ok
21:16:54.0304 1532 Tcpip (4dad14118fbcf7c609f2a4ce21fbcc5f) C:\Windows\system32\drivers\tcpip.sys
21:16:54.0337 1532 Tcpip - ok
21:16:54.0374 1532 Tcpip6 (4dad14118fbcf7c609f2a4ce21fbcc5f) C:\Windows\system32\DRIVERS\tcpip.sys
21:16:54.0383 1532 Tcpip6 - ok
21:16:54.0422 1532 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
21:16:54.0424 1532 tcpipreg - ok
21:16:54.0455 1532 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
21:16:54.0457 1532 TDPIPE - ok
21:16:54.0469 1532 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
21:16:54.0471 1532 TDTCP - ok
21:16:54.0503 1532 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
21:16:54.0506 1532 tdx - ok
21:16:54.0541 1532 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
21:16:54.0542 1532 TermDD - ok
21:16:54.0570 1532 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:16:54.0572 1532 tssecsrv - ok
21:16:54.0629 1532 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
21:16:54.0631 1532 tunmp - ok
21:16:54.0707 1532 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
21:16:54.0709 1532 tunnel - ok
21:16:54.0744 1532 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
21:16:54.0747 1532 uagp35 - ok
21:16:54.0800 1532 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
21:16:54.0806 1532 udfs - ok
21:16:54.0833 1532 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
21:16:54.0836 1532 uliagpkx - ok
21:16:54.0869 1532 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
21:16:54.0875 1532 uliahci - ok
21:16:54.0886 1532 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
21:16:54.0890 1532 UlSata - ok
21:16:54.0915 1532 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
21:16:54.0920 1532 ulsata2 - ok
21:16:54.0949 1532 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
21:16:54.0951 1532 umbus - ok
21:16:55.0019 1532 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
21:16:55.0021 1532 USBAAPL64 - ok
21:16:55.0089 1532 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
21:16:55.0091 1532 usbccgp - ok
21:16:55.0102 1532 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
21:16:55.0105 1532 usbcir - ok
21:16:55.0147 1532 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
21:16:55.0149 1532 usbehci - ok
21:16:55.0178 1532 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
21:16:55.0184 1532 usbhub - ok
21:16:55.0234 1532 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
21:16:55.0236 1532 usbohci - ok
21:16:55.0257 1532 usbprint (acfee697af477021bb3ec78c5431fed2) C:\Windows\system32\drivers\usbprint.sys
21:16:55.0267 1532 usbprint - ok
21:16:55.0305 1532 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:16:55.0307 1532 USBSTOR - ok
21:16:55.0338 1532 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
21:16:55.0339 1532 usbuhci - ok
21:16:55.0357 1532 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
21:16:55.0359 1532 vga - ok
21:16:55.0369 1532 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
21:16:55.0370 1532 VgaSave - ok
21:16:55.0381 1532 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
21:16:55.0383 1532 viaide - ok
21:16:55.0408 1532 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
21:16:55.0410 1532 volmgr - ok
21:16:55.0447 1532 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
21:16:55.0456 1532 volmgrx - ok
21:16:55.0496 1532 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
21:16:55.0502 1532 volsnap - ok
21:16:55.0521 1532 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
21:16:55.0525 1532 vsmraid - ok
21:16:55.0550 1532 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
21:16:55.0552 1532 WacomPen - ok
21:16:55.0622 1532 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
21:16:55.0624 1532 Wanarp - ok
21:16:55.0629 1532 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
21:16:55.0631 1532 Wanarpv6 - ok
21:16:55.0660 1532 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
21:16:55.0662 1532 Wd - ok
21:16:55.0699 1532 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
21:16:55.0722 1532 Wdf01000 - ok
21:16:55.0813 1532 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys
21:16:55.0814 1532 WmiAcpi - ok
21:16:55.0882 1532 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
21:16:55.0884 1532 WpdUsb - ok
21:16:55.0919 1532 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
21:16:55.0920 1532 ws2ifsl - ok
21:16:55.0995 1532 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:16:55.0998 1532 WUDFRd - ok
21:16:56.0065 1532 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0
21:16:56.0077 1532 \Device\Harddisk0\DR0 - ok
21:16:56.0096 1532 Boot (0x1200) (5137cb185b10339b529ca2ccd62b8a85) \Device\Harddisk0\DR0\Partition0
21:16:56.0097 1532 \Device\Harddisk0\DR0\Partition0 - ok
21:16:56.0101 1532 Boot (0x1200) (428213715005a632f6f6616a4574be24) \Device\Harddisk0\DR0\Partition1
21:16:56.0102 1532 \Device\Harddisk0\DR0\Partition1 - ok
21:16:56.0104 1532 ============================================================
21:16:56.0104 1532 Scan finished
21:16:56.0104 1532 ============================================================
21:16:56.0115 0792 Detected object count: 1
21:16:56.0115 0792 Actual detected object count: 1
21:17:39.0046 0792 srv ( LockedFile.Multi.Generic ) - skipped by user
21:17:39.0046 0792 srv ( LockedFile.Multi.Generic ) - User select action: Skip
21:20:33.0628 0440 Deinitialize success


Here are the contents from OTL.Txt …

OTL logfile created on: 21/10/2011 21:24:13 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kim Joi\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.99 Gb Total Physical Memory | 2.97 Gb Available Physical Memory | 74.29% Memory free
8.16 Gb Paging File | 7.29 Gb Available in Paging File | 89.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 24.75 Gb Free Space | 11.34% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 6.88 Gb Free Space | 46.95% Space Free | Partition Type: NTFS

Computer Name: KIMJOI-PC | User Name: Kim Joi | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kim Joi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe (Radialpoint Inc.)
PRC - C:\Program Files (x86)\Virgin Media\Security\RpsSecurityAwareR.exe (Virgin Media)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_310debf0\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (PDEngine) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV:64bit: - (PDAgent) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_310debf0\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (wltrysvc) – C:\Windows\SysNative\WLTRYSVC.EXE ()
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (RapportMgmtService) – C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (sdCoreService) – C:\Program Files (x86)\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (ServicepointService) – C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe (Radialpoint Inc.)
SRV - (sdAuxService) – C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (scan) – C:\Program Files (x86)\Virgin Media\Security\BitDefender\scan.dll (S.C. BitDefender S.R.L)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Radialpoint Security Services) – C:\Program Files (x86)\Virgin Media\Security\RpsSecurityAwareR.exe (Virgin Media)
SRV - (RP_FWS) – C:\Program Files (x86)\Virgin Media\Security\Fws.exe (Virgin Media)
SRV - (RadialpointIDSAgent) – C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (RapportKE64) – C:\Windows\SysNative\Drivers\RapportKE64.sys (Trusteer Ltd.)
DRV:64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys (PC Tools)
DRV:64bit: - (PCTSD) – C:\Windows\SysNative\Drivers\PCTSD64.sys (PC Tools)
DRV:64bit: - (pctplsg) – C:\Windows\SysNative\drivers\pctplsg64.sys (PC Tools)
DRV:64bit: - (pctgntdi) – C:\Windows\SysNative\drivers\pctgntdi64.sys (PC Tools)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (R300) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\DRIVERS\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (pctEFA) – C:\Windows\SysNative\drivers\pctEFA64.sys (PC Tools)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (pctDS) – C:\Windows\SysNative\drivers\pctDS64.sys (PC Tools)
DRV:64bit: - (RPSKT) Security Services Driver (x64) – C:\Windows\SysNative\DRIVERS\rp_skt64.sys (Radialpoint Inc.)
DRV:64bit: - (RPPKT) Radialpoint Filter (x64) – C:\Windows\SysNative\DRIVERS\rp_pkt64.sys (Radialpoint, Inc.)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (DefragFS) – C:\Windows\SysNative\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (OA008Vid) – C:\Windows\SysNative\DRIVERS\OA008Vid.sys (Creative Technology Ltd.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (OA008Ufd) – C:\Windows\SysNative\DRIVERS\OA008Ufd.sys (Creative Technology Ltd.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\BCM42RLY.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\DRIVERS\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (e1express) Intel® – C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV - (RapportCerberus_32029) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus64_32029.sys ()
DRV - (RapportPG64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (RapportEI64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RadialpointIDSDriver) – C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys (AVG Technologies )
DRV - (RadialpointIDSFilter) – C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys (AVG Technologies )
DRV - (RadialpointIDSEH) – C:\Windows\SysWOW64\drivers\AVGIDSEH.sys (AVG Technologies )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?p=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF:64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Virgin Media\Service Manager\nprpspa.dll (Virgin Media)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Virgin Media\Service Manager\nprpspa.dll (Virgin Media)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools Security\BDT\Firefox\ [2011/10/18 19:03:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/03 12:45:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/17 07:26:53 | 000,000,000 | —D | M]

[2010/02/03 11:21:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Kim Joi\AppData\Roaming\mozilla\Extensions
[2011/06/30 22:45:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Kim Joi\AppData\Roaming\mozilla\Firefox\Profiles\92zjqexr.default\extensions
[2010/04/28 07:01:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Kim Joi\AppData\Roaming\mozilla\Firefox\Profiles\92zjqexr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/14 20:19:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/19 21:14:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 18:56:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/09 19:42:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/13 22:56:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/28 21:34:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/14 20:19:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/03 12:45:48 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/03 12:45:46 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/10/03 12:45:46 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/10/03 12:45:46 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/10/03 12:45:46 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/03 12:45:46 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\SysNative\WLTRAY.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ServiceManager.exe] C:\Program Files (x86)\Virgin Media\Service Manager\ServiceManager.exe (Virgin Media)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TaskTray] File not found
O4 - Startup: C:\Users\Kim Joi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E8CDE203-D99D-4C02-9E23-577802E6DF54}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O22 - SharedTaskScheduler: {A69B197E-BF0D-4986-A0D1-FB5D9FEF0D37} - SccallinTcp - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{44690977-3777-11df-8235-002219f85526}\Shell - "" = AutoRun
O33 - MountPoints2\{44690977-3777-11df-8235-002219f85526}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{b67c296a-84db-11de-ad4f-002219f85526}\Shell - "" = AutoRun
O33 - MountPoints2\{b67c296a-84db-11de-ad4f-002219f85526}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/10/21 21:19:54 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Kim Joi\Desktop\OTL.exe
[2011/10/21 21:14:19 | 000,000,000 | —D | C] – C:\Users\Kim Joi\Desktop\tdsskiller
[2011/10/21 11:24:50 | 001,561,392 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Kim Joi\Desktop\TDSSKiller.exe
[2011/10/20 21:05:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2011/10/18 19:03:34 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2011/10/18 19:03:30 | 002,189,264 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2011/10/18 19:03:27 | 001,533,904 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2011/10/18 18:58:38 | 000,816,016 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2011/10/18 18:58:38 | 000,452,872 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2011/10/18 18:58:37 | 000,336,512 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctgntdi64.sys
[2011/10/18 18:58:37 | 000,143,384 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2011/10/18 18:58:34 | 000,360,696 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTCore64.sys
[2011/10/18 18:58:33 | 000,228,392 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTSD64.sys
[2011/10/18 18:58:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011/10/18 18:58:25 | 000,092,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2011/10/18 18:58:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Tools Security
[2011/10/18 13:53:01 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/10/18 09:51:59 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{2C50EFE8-8E1F-431A-9E5C-FE1E0FA3C99D}
[2011/10/18 09:50:48 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{DD01CAF2-6DE4-4A34-9958-5A4F2E6E7671}
[2011/10/16 09:29:39 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{00F3442F-8DBB-4DC4-9895-159D32B52582}
[2011/10/16 09:29:28 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{4DF39974-8A62-440E-8E67-08B2EC51F5BD}
[2011/10/15 21:28:59 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{E6AED512-DAD0-460C-B4DE-150AADBA4D05}
[2011/10/15 21:28:48 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{4CD6D7CB-8D51-4230-A323-5D1A0C1B7591}
[2011/10/15 09:28:20 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{FA0E5ABC-CFF7-49E8-8773-72259FE06DCB}
[2011/10/15 09:28:08 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{B950077C-2132-4DDC-BF64-CCF76DCCA389}
[2011/10/14 10:02:09 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{3D8F6D0B-DAE0-4444-8EC9-2DB06AD7A101}
[2011/10/14 10:01:58 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{05ECCA1C-ED11-4343-88FF-9528CE04C291}
[2011/10/13 09:01:29 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{4950077F-6F1E-4B1D-A388-2081C753A3E5}
[2011/10/13 09:01:18 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{179F4CB6-9D80-4F6F-9BE0-7E547B25A046}
[2011/10/13 07:32:13 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/13 07:32:12 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/13 07:32:09 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/13 07:32:08 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/13 07:32:07 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/13 07:32:07 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/13 07:32:07 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/13 07:32:06 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/13 07:32:05 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/12 23:56:21 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 23:56:20 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 23:56:20 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 23:56:20 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 23:56:20 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 23:56:20 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 23:56:02 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 23:56:02 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 23:56:02 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 23:56:02 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 23:56:02 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 23:56:02 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 23:56:01 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 23:56:01 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/12 07:53:19 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{E789ED02-97F5-4201-B1DA-6AD98304AFBE}
[2011/10/12 07:53:07 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{051E9BBE-2E73-4F2B-AF32-DAFD24666049}
[2011/10/11 09:23:11 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{591A0A93-2436-43B4-A4F3-D619CF26202B}
[2011/10/11 09:23:00 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{6E5005B8-C65D-402A-BC82-DB163DBF4297}
[2011/10/10 10:23:16 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{5C8543C3-BFDF-4242-A71D-4173221DE786}
[2011/10/10 10:23:04 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{3A4C55F1-A40A-4E3A-B827-2A662367C407}
[2011/10/09 18:50:43 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{B695F8D5-D1A8-41C4-8272-8A17266E9E49}
[2011/10/09 18:50:32 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{DEAAF780-BEC3-4FC7-ADD3-3AB4BBAB2D17}
[2011/10/07 21:53:20 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{B8CCBA75-6627-49AF-BEEA-D84CB8DFB3BE}
[2011/10/07 21:53:08 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{A9F308A0-ED67-4680-A9D1-AB373C5AE701}
[2011/10/06 19:00:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/10/06 18:28:01 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{8F2278AB-9B6D-4959-B016-401520A28BD2}
[2011/10/06 18:27:50 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{2077E4BD-2228-42BD-8958-4CB3751C0B2C}
[2011/10/05 17:53:38 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{D4AA1EFA-88A9-4588-9436-B8C835FF68A6}
[2011/10/05 17:53:23 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{43B40FF3-B3F9-481B-AB71-A6B581D354BE}
[2011/10/04 08:02:49 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{0B120D13-00B9-40CD-88ED-70B1BE4B7616}
[2011/10/04 08:02:38 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{04D00421-BA7C-4CDE-91E3-ACECDECEAACC}
[2011/10/03 08:03:04 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{623D98E2-0645-4371-A948-66532E4DC304}
[2011/10/03 08:02:53 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{AD29AFFB-7D3D-4668-A1BC-DEE0D5616295}
[2011/09/30 21:18:37 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{998F4C08-BFE3-49EA-8000-3DBC94874DDD}
[2011/09/30 21:18:26 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{801B6427-7779-4620-9D57-6C425305DB73}
[2011/09/29 22:24:35 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{79719E62-5577-4791-A1FC-D910F9638441}
[2011/09/29 22:24:20 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{507B6DCC-7559-4228-A088-6F5718494F04}
[2011/09/27 15:58:27 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{02CF9718-1075-4EFF-B893-F639BA1ABA4C}
[2011/09/27 15:58:09 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{DECEB90A-C595-41A2-916D-1750258349C0}
[2011/09/26 10:22:39 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{9D47BA98-B26E-4F73-92CB-43627BDABCD8}
[2011/09/26 10:22:28 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{C4EA6B88-95FA-4119-B008-AF287D5EFDFD}
[2011/09/23 22:51:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2011/09/23 22:51:42 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\Google
[2011/09/22 16:01:55 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{A3EB6876-76A3-4F5B-AD61-21E8D4EA05DD}
[2011/09/22 16:01:44 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{E6C7FDDE-70BD-4F6F-BFE2-5BC41C510DD2}
[2009/08/28 18:07:54 | 008,270,752 | —- | C] (Dell, Inc. ) – C:\Users\Kim Joi\AppData\Roaming\DataSafeDotNet.exe

========== Files - Modified Within 30 Days ==========

[2011/10/21 21:19:55 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Kim Joi\Desktop\OTL.exe
[2011/10/21 21:14:19 | 001,561,392 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Kim Joi\Desktop\TDSSKiller.exe
[2011/10/21 21:10:05 | 001,542,471 | —- | M] () – C:\Users\Kim Joi\Desktop\tdsskiller.zip
[2011/10/21 20:57:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/21 09:41:31 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/10/21 09:24:30 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/21 09:24:30 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/21 09:24:08 | 598,278,430 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/10/21 07:55:30 | 000,097,280 | —- | M] () – C:\Users\Kim Joi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/21 07:46:48 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/21 07:46:48 | 000,607,600 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/21 07:46:48 | 000,107,478 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/20 22:47:09 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/20 21:05:37 | 000,000,844 | —- | M] () – C:\Users\Kim Joi\Desktop\SpywareBlaster.lnk
[2011/10/20 20:15:31 | 000,002,243 | —- | M] () – C:\Windows\epplauncher.mif
[2011/10/20 19:58:45 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/18 21:24:09 | 000,000,732 | —- | M] () – C:\Users\Kim Joi\AppData\Local\d3d9caps64.dat
[2011/10/18 19:06:44 | 002,908,726 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/10/18 18:58:33 | 000,001,842 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011/10/15 07:17:06 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/14 08:19:03 | 000,381,176 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/06 19:00:23 | 000,002,117 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/02 07:05:52 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011/10/02 07:05:52 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/09/25 19:00:08 | 000,064,272 | —- | M] (Trusteer Ltd.) – C:\Windows\SysNative\drivers\RapportKE64.sys

========== Files Created - No Company Name ==========

[2011/10/21 21:10:02 | 001,542,471 | —- | C] () – C:\Users\Kim Joi\Desktop\tdsskiller.zip
[2011/10/21 09:24:08 | 598,278,430 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/10/20 21:05:37 | 000,000,844 | —- | C] () – C:\Users\Kim Joi\Desktop\SpywareBlaster.lnk
[2011/10/20 20:15:31 | 000,002,243 | —- | C] () – C:\Windows\epplauncher.mif
[2011/10/18 21:24:09 | 000,000,732 | —- | C] () – C:\Users\Kim Joi\AppData\Local\d3d9caps64.dat
[2011/10/18 19:03:53 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2011/10/18 19:03:41 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2011/10/18 19:03:34 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2011/10/18 19:03:30 | 000,002,125 | —- | C] () – C:\Windows\UDB.zip
[2011/10/18 19:03:30 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2011/10/18 18:58:40 | 002,908,726 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/10/18 18:58:33 | 000,001,842 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011/10/06 19:00:23 | 000,002,117 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/01 23:25:10 | 000,000,564 | —- | C] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011/09/23 22:52:02 | 000,000,900 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/23 22:52:00 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/19 22:10:32 | 000,059,904 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/03/17 18:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/01/30 10:25:09 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/01/30 10:25:09 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/05/23 21:14:24 | 000,001,025 | —- | C] () – C:\Windows\SysWow64\sysprs7.dll
[2010/05/23 21:14:24 | 000,000,205 | —- | C] () – C:\Windows\SysWow64\lsprst7.dll
[2009/12/07 20:05:54 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/07 20:05:15 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/12/07 20:04:34 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/14 10:15:19 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/11 22:12:42 | 000,097,280 | —- | C] () – C:\Users\Kim Joi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/10 19:15:21 | 000,006,836 | —- | C] () – C:\Users\Kim Joi\AppData\Local\d3d9caps.dat
[2009/07/09 12:49:52 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2009/07/09 10:49:13 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/07/09 10:18:22 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/04/25 04:58:05 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/01/21 03:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 16:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 13:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 13:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 10:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin

========== LOP Check ==========

[2010/09/27 22:11:41 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\Leawo
[2011/04/17 07:31:46 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\PCDr
[2010/03/23 12:52:14 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\Trusteer
[2011/10/18 19:16:42 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\uTorrent
[2010/06/01 07:58:43 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\Virgin Broadband
[2011/05/13 19:13:37 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\Virgin Media
[2010/09/27 23:19:57 | 000,000,000 | —D | M] – C:\Users\Kim Joi\AppData\Roaming\WinAVI
[2011/10/02 07:05:52 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011/10/02 07:05:52 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/10/21 09:31:12 | 000,032,580 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/10/21 09:41:31 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/06/24 12:22:20 | 000,546,872 | —- | M] (Microsoft Corporation) – C:\bootmgr.efi
[2009/07/09 13:02:59 | 000,003,437 | RH– | M] () – C:\dell.sdr
[2011/02/21 23:44:26 | 000,001,615 | —- | M] () – C:\InstallHelper.log
[2010/09/27 23:28:16 | 000,001,363 | —- | M] () – C:\MP4debug.log
[2006/12/02 05:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/10/21 20:56:53 | 308,223,999 | -HS- | M] () – C:\pagefile.sys
[2011/10/21 21:20:33 | 000,075,252 | —- | M] () – C:\TDSSKiller.2.6.12.0_21.10.2011_21.15.24_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 16:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 16:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 16:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/12/07 22:46:09 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 04:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/01 19:14:20 | 000,000,286 | -HS- | M] () – C:\Users\Kim Joi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/10/21 21:19:55 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Kim Joi\Desktop\OTL.exe
[2011/10/21 21:14:19 | 001,561,392 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Kim Joi\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2009/12/07 23:38:14 | 000,008,192 | —- | M] () – C:\Windows\SECURITY\Database\edb.chk
[2009/12/07 23:37:44 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edb.log
[2009/12/07 23:37:43 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00001.jrs
[2009/12/07 23:37:44 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00002.jrs
[2009/12/07 23:37:43 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbtmp.log
[2009/12/07 23:37:44 | 001,056,768 | —- | M] () – C:\Windows\SECURITY\Database\tmp.edb

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/08/05 11:58:58 | 000,000,402 | -HS- | M] () – C:\Users\Kim Joi\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Files - Unicode (All) ==========
[2009/09/09 09:20:26 | 000,000,036 | —- | M] ()(C:\Windows\SysWow64\???????????????????????????????????????g) – C:\Windows\SysWow64\㩃停潲牧浡䘠汩獥⠠㡸⤶噜物楧牂慯扤湡層䍐畧牡層慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
[2009/09/09 09:20:26 | 000,000,036 | —- | C] ()(C:\Windows\SysWow64\???????????????????????????????????????g) – C:\Windows\SysWow64\㩃停潲牧浡䘠汩獥⠠㡸⤶噜物楧牂慯扤湡層䍐畧牡層慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >


Here are the contents from Extras.Txt …

OTL Extras logfile created on: 21/10/2011 21:24:13 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kim Joi\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.99 Gb Total Physical Memory | 2.97 Gb Available Physical Memory | 74.29% Memory free
8.16 Gb Paging File | 7.29 Gb Available in Paging File | 89.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 24.75 Gb Free Space | 11.34% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 6.88 Gb Free Space | 46.95% Space Free | Partition Type: NTFS

Computer Name: KIMJOI-PC | User Name: Kim Joi | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = CC 9D DE 83 8D 77 CA 01 [binary data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{447C973A-DF4A-4DC5-8BA4-FB90BBE19F94}" = lport=10046 | protocol=6 | dir=in | name=bitcomet 10046 tcp |
"{52D9A3F2-1E71-445A-81D1-4FBE9A8DF8EB}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{7C724D71-5D84-4C34-8B87-8281C93A18EB}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{A1862B1E-88A4-4635-9504-DE5F19A93E41}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C64E20A0-E52B-454A-AF01-55BB91DEF2EB}" = lport=10046 | protocol=17 | dir=in | name=bitcomet 10046 udp |
"{CAEB73AE-91F3-4EBC-84B0-E21198BCE4DA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{E9EF3AC3-B45D-471A-ADD6-39EA1017A1C2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{025A5E10-8F40-43B2-8303-BB24F4D573E3}" = protocol=6 | dir=in | app=c:\program files (x86)\virgin broadband wireless\wireless manager.exe |
"{035B8F23-7C89-4327-81D7-5E0FDC57A473}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{0DB792C8-A32C-4661-9943-617375AAA93C}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{3CB5D1E5-F22F-47B6-8C3E-A388D10A3C35}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{55020879-8B81-4353-AAD4-0F434AEDFB5A}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{5824EFBC-545D-44D6-BB9D-70906E8AA2CB}" = protocol=17 | dir=in | app=c:\program files (x86)\virgin broadband wireless\wireless manager.exe |
"{5D7EB647-0437-4190-ACE3-72CBAF3144B9}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{6B2F4B64-6004-4365-8FB9-00C7B373DFBA}" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{6DA56347-55A6-4CD0-80BD-67C211F305B4}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{6F4AED77-3F08-40BB-9FCC-50539F823712}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{7295FF3E-A448-499C-9A09-59E87FDA4EA4}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8A4B7B31-7089-4FFD-80F0-984AEF3F39EB}" = protocol=6 | dir=in | app=c:\program files (x86)\virgin media\service manager\servicepointservice.exe |
"{9D995497-5DAE-4515-AA30-F516A73D6984}" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{A553FA81-C49A-415E-A9C5-A8791F491EA3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A70D9C82-7676-400F-9D77-BC48425D1EA2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{B659D0F4-2E31-4DE3-89B2-7DFF081996B9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C6320869-C147-487F-8C27-9C3885CD1846}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{CDAB1602-E2E1-4D1C-B6B0-A9AD9E5BFDDE}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{CDBF9BD3-EAFF-4380-98F0-A809CB8C0C5B}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{D642F64A-E05F-46B4-AB0D-308BBE922456}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{DCA3B283-01D4-468B-9495-DFC08FAB7DC6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E4B7BF78-3882-48CB-A578-53A30834E601}" = protocol=17 | dir=in | app=c:\program files (x86)\virgin media\service manager\servicepointservice.exe |
"{E664869A-024B-4F80-9C65-9208A5B1FA6B}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{F1B0E03A-F7BA-4DF0-8B28-9F58113F1F4E}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000F870E-BCF6-F19F-A154-B3488407F467}" = ccc-utility64
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416013FF}" = Java™ 6 Update 13 (64-bit)
"{3C5E60F1-0821-4B07-97EA-84EB5A927CF6}" = MobileMe Control Panel
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{561F2FBF-6781-4D86-854F-E690942FCD59}" = RPS RpsCore64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6C30F9EF-5032-925C-1905-D87E8472EB85}" = ATI Catalyst Install Manager
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{997C9EC4-B53D-479D-81B7-0AEC8D174BA1}" = iTunes
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CA0D2F09-F811-48D4-843E-C87696C6A9D9}" = Bonjour
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E87F997C-3E93-6DAD-1AE6-619002BA9623}" = ccc-utility64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"Creative OA008" = Integrated Webcam Driver (1.04.01.0601)
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Dell Touchpad
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CE69E03-1021-EB74-0836-C706CADC213A}" = Catalyst Control Center Localization Korean
"{0E33EC53-22CE-426C-A88B-2AAC231BAC85}" = Catalyst Control Center - Branding
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14021E77-2FC1-4972-8C51-08808CD62838}_is1" = Leawo Free MP4 Converter version 2.5.0.5
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15F7FA6D-8FC5-08FD-2727-8AE6811A2A0D}" = CCC Help Russian
"{180BEABD-453E-4047-96B4-4F86EE605589}" = CCC Help Danish
"{181A0114-24D5-9E74-0138-4C8C27ED3EAC}" = Catalyst Control Center Graphics Light
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1E5196FA-47EF-F0C7-847B-960F3349E9B5}" = CCC Help Finnish
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2094F083-B28B-AFFD-4075-49E803BE17B7}" = CCC Help Italian
"{2116C03A-7111-9669-8009-9FD7F5AABA20}" = Catalyst Control Center Graphics Full New
"{23467AA2-058A-1064-40C5-E0E0533C2D7D}" = Catalyst Control Center Localization French
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 26
"{26B29DE2-7759-F8BB-FB10-98142B343C8C}" = CCC Help Korean
"{28ABE740-47F3-441B-9437-852F6A64EFF8}" = Lenovo_Wireless_Driver
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2FB28284-51D3-C991-3940-694B1B629F2B}" = Catalyst Control Center Localization German
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3945F4B5-0FAD-38E3-B39B-2F497550C847}" = CCC Help French
"{3F6107B9-D211-EBCC-EA41-BD2FAC156A23}" = Catalyst Control Center Localization Japanese
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{3FD8C713-B1D5-D973-5351-50A918C02749}" = Catalyst Control Center Core Implementation
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{586DD9D2-09B2-D1DB-AD2A-95194A771C49}" = CCC Help Dutch
"{5AD839E7-BFA7-4796-B2CA-B1D824ECCDF7}" = Virgin Media Security
"{5AFBC2F3-D3F5-660A-A2AD-CAD3E8EDA1D7}" = CCC Help English
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63953BA4-7F92-98F7-B99D-FEB4B7BF6905}" = Catalyst Control Center Localization All
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6C16A05F-C202-578A-108C-AFA4D9167CCC}" = Catalyst Control Center Localization Spanish
"{6C6D7326-770A-812B-B104-442F71A826F8}" = Catalyst Control Center Localization Russian
"{6EA1C352-4D16-5A9F-7751-D7AE08AA7F63}" = Catalyst Control Center Localization Chinese Traditional
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{714048C6-7703-4059-A8EC-17B31AAB73A2}" = RPS RpsCore
"{72085899-3540-2F67-F5C7-46FF826A235F}" = CCC Help German
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{74622EDD-7879-3185-976D-A6098420D889}" = CCC Help Portuguese
"{7505BBE5-CB0C-5027-1228-15CC7C26C4C3}" = CCC Help English
"{7673108D-9DED-4454-9712-FB2771D94446}" = RPS PerfectDiskStub
"{76C4BA9A-BFA5-151D-8A39-AA0E74041F83}" = Catalyst Control Center Localization Danish
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7753A3B2-E858-F0B3-3DD9-C027B16CBB81}" = Catalyst Control Center InstallProxy
"{77A5C01F-E04C-9616-2E3D-D78CF889712B}" = Catalyst Control Center Graphics Full Existing
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79D34E3B-8826-170B-8B3D-A9CD9C2D28F5}" = ccc-core-static
"{7AD77B9A-C77D-4EB5-AAD9-A01D0AFAE1B1}" = SccallinTcp
"{7CDF0744-7A0D-961B-3695-49756E822FC4}" = Catalyst Control Center Localization Swedish
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{8247BD1D-C258-DBEE-3225-B9F0214763AB}" = CCC Help Japanese
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92491D2C-D9E9-5FDD-64CD-82D5688872A9}" = Catalyst Control Center Localization Italian
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9EF77B2D-FF26-9237-BBAB-127110FD65CC}" = Catalyst Control Center Localization Portuguese
"{A0B0BCE9-2994-36F2-BE66-D23C884372E8}" = Visual C++ 9.0 OpenMP (x86) WinSXS MSM
"{A4B9033B-D183-4A6C-9BCB-6BC8F80B939D}" = RPS CRT
"{A5D4E41C-2583-46FE-9B99-62496F85C5F3}" = RPS CRT
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA2EBBCC-4E3B-3442-865E-7BB3E9F45F0C}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACB08AF2-DFE9-C179-8BC9-E3209F3EBC28}" = CCC Help Chinese Traditional
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BB5F88FC-5D66-9316-0E48-E411941A8A74}" = Catalyst Control Center Graphics Previews Vista
"{C17280C4-8BF2-946A-9C51-EEB2CD216D89}" = Catalyst Control Center Graphics Previews Common
"{C5D85C24-A56B-6954-77F1-B25A4B4E7B52}" = CCC Help Spanish
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8C5CE76-860E-B5FA-27EA-C52C74DDBD2D}" = Catalyst Control Center Localization Finnish
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CDCFA0B9-06DA-C47E-2CF1-37C5F25DF753}" = Catalyst Control Center InstallProxy
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFCD2A80-EC16-11E0-A273-B8AC6F97B88E}" = Google Earth
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D071B7C5-07A2-D000-05B8-2DE6A63249D9}" = Catalyst Control Center Localization Norwegian
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D2D3882A-3624-2963-EA08-27589DBCEF8A}" = CCC Help Norwegian
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2616F7B-9E5B-7B21-EDB0-5659A5A4DDA1}" = Catalyst Control Center Graphics Previews Common
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E481DB0E-52F2-4EE0-9BDA-9EE173FA6EA2}" = Catalyst Control Center - Branding
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E8E8C42E-E817-C7DA-1A81-BFD8388B4014}" = CCC Help Swedish
"{EB5BA578-FF7F-3863-8E53-7A003222B7FC}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{EB6C11E5-449C-3BA3-9086-80B18BCFF947}" = Visual C++ 9.0 OpenMP (x86) WinSXS MSM
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EFD537AE-0530-8887-DC9C-433E113547D7}" = Catalyst Control Center Localization Chinese Standard
"{F081ED08-77AE-8019-D554-904EF4F88FC1}" = CCC Help Chinese Standard
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F133ACD4-CFCF-BADD-4AC5-9408E2E7FD74}" = Catalyst Control Center Localization Dutch
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5CC2EF8-20A4-4366-A681-3FE849E65809}" = RICOH Media Driver
"{FB56BF24-6AB9-AC55-5B7A-D3657D2F4A38}" = Skins
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Browser Defender_is1" = Browser Defender 3.0
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox 7.0.1 (x86 en-GB)" = Mozilla Firefox 7.0.1 (x86 en-GB)
"RadialpointClientGateway_is1" = Virgin Media Service Manager 3.7.47
"Rapport_msi" = Rapport
"Spyware Doctor" = Spyware Doctor
"SpywareBlaster_is1" = SpywareBlaster 4.4
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.1
"Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.3d
"WinLiveSuite" = Windows Live Essentials
"Xvid_is1" = Xvid 1.2.2 final uninstall

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13/01/2011 11:29:30 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3744

Error - 13/01/2011 11:29:32 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 13/01/2011 11:29:32 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4883

Error - 13/01/2011 11:29:32 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4883

Error - 13/01/2011 17:54:50 | Computer Name = KimJoi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 13/01/2011 17:54:51 | Computer Name = KimJoi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 13/01/2011 17:55:07 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = 456: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 13/01/2011 17:55:07 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = 460: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 13/01/2011 17:55:07 | Computer Name = KimJoi-PC | Source = Bonjour Service | ID = 100
Description = 464: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 13/01/2011 18:00:35 | Computer Name = KimJoi-PC | Source = WinMgmt | ID = 10
Description =

[ Broadcom Wireless LAN Events ]
Error - 19/07/2011 10:29:22 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 15:29:22, Tue, Jul 19, 11 Error - Adaptername ID is not available within
the connection manager

Error - 19/07/2011 10:29:22 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 15:29:22, Tue, Jul 19, 11 Error - Unable to initialize Connection Manager
for "Dell Wireless 1397 WLAN Mini-Card"

Error - 15/09/2011 13:00:27 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 18:00:21, Thu, Sep 15, 11 Error - Unable to gain access to user store


Error - 20/09/2011 18:24:32 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 23:24:31, Tue, Sep 20, 11 Error - Unable to gain access to user store


Error - 09/10/2011 15:35:55 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 20:35:53, Sun, Oct 09, 11 Error - Unable to gain access to user store


Error - 20/10/2011 14:55:26 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 19:55:03, Thu, Oct 20, 11 Error - Unable to gain access to user store


Error - 20/10/2011 17:44:19 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 22:44:00, Thu, Oct 20, 11 Error - Unable to gain access to user store


Error - 21/10/2011 03:39:34 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 08:37:21, Fri, Oct 21, 11 Error - Unable to gain access to user store


Error - 21/10/2011 03:49:25 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 08:49:21, Fri, Oct 21, 11 Error - Unable to gain access to user store


Error - 21/10/2011 04:27:37 | Computer Name = KimJoi-PC | Source = WLAN-Tray | ID = 0
Description = 09:26:16, Fri, Oct 21, 11 Error - Unable to gain access to user store


[ System Events ]
Error - 21/10/2011 16:04:00 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:04:00 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:04:00 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:04:00 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:15:45 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:15:45 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:15:45 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:33:45 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:33:45 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 21/10/2011 16:33:45 | Computer Name = KimJoi-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.


< End of report >

Thanks and hope to hear from you soon …

JazzBiondi
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi mowman … here's my ComboFix.txt report … ComboFix 11-10-21.06 - Kim Joi 22/10/2011 9:09.1.2 - x64 NETWORK Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.4090.2992 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} AV: Virgin Media Security Anti-Virus *Disabled/Updated* {A61154FD-4365-E00F-9A33-13A09AD54B56} FW: Virgin Media Security Firewall *Disabled* {9E2AD5D8-090A-E157-B16C-BA9564060C2D} SP: Spyware Doctor *Enabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Virgin Media Security Anti-Spyware *Disabled/Updated* {1D70B519-655F-EF81-A083-28D2E15201EB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\PCDr\5830\Downloads\0fc909b5-f105-4459-82f3-583c6ea5d734.dll c:\programdata\PCDr\5830\Downloads\482517d4-aaa6-47f8-a7ad-de5cf6021ac2.dll c:\programdata\PCDr\5830\Downloads\ca1d3e50-4692-4c3f-877c-4f9917ab37a5.dll c:\programdata\PCDr\5830\Downloads\f9dc840b-c6f7-42a5-acec-50cc7a2827fd.dll c:\windows\SysWow64\odbcad32.exe c:\windows\SysWow64\system c:\windows\system32\slwga.dll . . . . Failed to delete c:\windows\system32\systemcpl.dll . . . . Failed to delete . . ((((((((((((((((((((((((( Files Created from 2011-09-22 to 2011-10-22 ))))))))))))))))))))))))))))))) . . 2011-10-22 08:27 . 2011-10-22 08:37 ——– d—–w- c:\users\Kim Joi\AppData\Local\temp 2011-10-22 08:27 . 2011-10-22 08:27 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-10-18 12:53 . 2011-10-22 07:54 ——– d—–w- c:\programdata\PC Tools 2011-09-27 06:48 . 2011-09-27 06:48 ——– d—–w- c:\users\Default\AppData\Local\Trusteer 2011-09-23 21:51 . 2011-10-06 18:00 ——– d—–w- c:\program files (x86)\Google 2011-09-23 21:51 . 2011-09-23 21:53 ——– d—–w- c:\users\Kim Joi\AppData\Local\Google . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-22 08:34 . 2011-10-22 08:30 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5A2DF81B-EA5B-472E-A3D1-0A80438B55BD}\offreg.dll 2011-10-15 06:17 . 2011-05-25 06:03 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-25 18:00 . 2011-05-06 05:57 64272 —-a-w- c:\windows\system32\drivers\RapportKE64.sys 2011-09-13 00:26 . 2011-10-18 17:59 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5A2DF81B-EA5B-472E-A3D1-0A80438B55BD}\mpengine.dll 2011-08-13 09:39 . 2011-08-13 09:39 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440] "Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-04-09 1762032] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-11-11 442536] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584] "ServiceManager.exe"="c:\program files (x86)\Virgin Media\Service Manager\ServiceManager.exe" [2011-03-25 4371768] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-19 421736] . c:\users\Kim Joi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-6 1312096] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-6 1312096] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk * . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\bdfsfltr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\scan] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService] @="Service" . R0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [x] R1 RapportCerberus_32029;RapportCerberus_32029;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus64_32029.sys [2011-10-18 396816] R1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-09-25 55056] R1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-09-25 61712] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_310debf0\AESTSr64.exe [x] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 136176] R2 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe RadialpointIDSAgent [x] R2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-09-25 919352] R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 136176] R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;c:\windows\system32\DRIVERS\OA008Ufd.sys [x] R3 OA008Vid;Creative Camera OA008 Function Driver;c:\windows\system32\DRIVERS\OA008Vid.sys [x] R3 PCAMp60a64;PCAMp60a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp60a64.sys [x] R3 PCASp60a64;PCASp60a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp60a64.sys [x] R3 PCD5SRVC{048DBD20-445E8C82-05040104};PCD5SRVC{048DBD20-445E8C82-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~2\DELLSU~1\HWDiag\bin\PCD5SRVC_x64.pkms [x] R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072] R3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys [2009-11-02 132616] R3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSFilter.sys [2009-11-02 35848] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\SysWOW64\drivers\AVGIDSEH.sys [2009-11-02 27144] S2 Radialpoint Security Services;Virgin Media Security;c:\program files (x86)\Virgin Media\Security\RpsSecurityAwareR.exe [2010-01-04 165408] S2 ServicepointService;ServicepointService;c:\program files (x86)\Virgin Media\Service Manager\ServicepointService.exe [2011-03-25 689464] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 21:51] . 2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 21:51] . 2011-10-02 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09] . 2011-10-02 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09] . 2011-10-22 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-25 1657128] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-21 4119552] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2008-09-26 2041112] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://uk.yahoo.com/?p=us mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll FF - ProfilePath - c:\users\Kim Joi\AppData\Roaming\Mozilla\Firefox\Profiles\92zjqexr.default\ . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run-TaskTray - (no file) SharedTaskScheduler-{A69B197E-BF0D-4986-A0D1-FB5D9FEF0D37} - (no file) SafeBoot-mcmscsvc SafeBoot-MCODS HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{048DBD20-445E8C82-05040104}] "ImagePath"="\??\c:\progra~2\DELLSU~1\HWDiag\bin\PCD5SRVC_x64.pkms" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . Completion time: 2011-10-22 09:42:57 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-22 08:42 . Pre-Run: 31,504,203,776 bytes free Post-Run: 31,757,615,104 bytes free . - - End Of File - - 6C255A68D7F22EAC46BF307A2BD62FFD
Can you see if you can run combofix in normal mode yet.



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Dear mowman … i can't log in to normal mode yet at this stage. The moment everything is about to load and look normal, it'll restart itself again :wall: By the way, here is the report generated by MalwareBytes AntiMalware … Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8001 Windows 6.0.6002 Service Pack 2 (Safe Mode) Internet Explorer 9.0.8112.16421 22/10/2011 22:30:22 mbam-log-2011-10-22 (22-30-22).txt Scan type: Quick scan Objects scanned: 179536 Time elapsed: 34 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) As for the Eset Online Scanner … i tried 3x doing the scanning, and approximately after an hour of scanning … laptop start to restart itself AGAIN. This really test my patience … so unfortunately, i'm not able to produce you this log. Hope you can advice me on alternative methods to fix this problem. JazzBiondi

Drive C: | 218.20 Gb Total Space | 24.75 Gb Free Space | 11.34% Space Free | Partition Type: NTFS

You are a bit short of space on your hard drive,remove any unwanted programs etc to free up more space.

AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}
AV: Virgin Media Security Anti-Virus *Disabled/Updated* {A61154FD-4365-E00F-9A33-13A09AD54B56}

Are you running two antivirus,if so you need to remove one.




Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O22 - SharedTaskScheduler: {A69B197E-BF0D-4986-A0D1-FB5D9FEF0D37} - SccallinTcp - No CLSID value found.
    O33 - MountPoints2\{44690977-3777-11df-8235-002219f85526}\Shell - "" = AutoRun
    O33 - MountPoints2\{44690977-3777-11df-8235-002219f85526}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
    O33 - MountPoints2\{b67c296a-84db-11de-ad4f-002219f85526}\Shell - "" = AutoRun
    O33 - MountPoints2\{b67c296a-84db-11de-ad4f-002219f85526}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
    @Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )










  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply
Dear mowman … I had already free up my "C Drive" to 85 Gb … and uninstalled the Spyware Doctor with Anti Virus program. Here is the log generated by OTL … All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{A69B197E-BF0D-4986-A0D1-FB5D9FEF0D37} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A69B197E-BF0D-4986-A0D1-FB5D9FEF0D37}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44690977-3777-11df-8235-002219f85526}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44690977-3777-11df-8235-002219f85526}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44690977-3777-11df-8235-002219f85526}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44690977-3777-11df-8235-002219f85526}\ not found. File G:\LaunchU3.exe -a not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b67c296a-84db-11de-ad4f-002219f85526}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b67c296a-84db-11de-ad4f-002219f85526}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b67c296a-84db-11de-ad4f-002219f85526}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b67c296a-84db-11de-ad4f-002219f85526}\ not found. File F:\setup.exe AUTORUN=1 not found. ADS C:\ProgramData\TEMP:5C321E34 deleted successfully. ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully. ADS C:\ProgramData\TEMP:430C6D84 deleted successfully. ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Kim Joi ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 147456 bytes ->Java cache emptied: 1016638 bytes ->FireFox cache emptied: 80236208 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 485 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 527642 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 78.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 10242011_194526 After rebooting, the laptop restarted (again n again) 4-5 times before i decided to go for Safe Mode (with networking). ** I tried scanning with aswMBR.exe … BUT twice ended up with "Blue Screen of Death". JazzBiondi
We seem to be running out of options here,I am not seeing ant more signs of malware in the logs,we will try one more scan.This can take a very long time to complete.



Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download Dr.Web CureIt and save it to your desktop.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the anti-virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
Dear mowman … For your info, i am still using Safe Mode (with networking) …. I have to say it was a long scan using Dr.Web CureIt! … took more than 3 hours but ended up the same fate with Eset Scanner, it rebooted itself before a complete full scan had been done. However, when i was doing the "complete scan", Dr.Web CureIt! detected these viruses (3 of them of the same thing) … i wrote down manually on a piece of paper in case the laptop freeze, hang or reboot before completion. Object: decora-d3d.dll Status: Win32.HLLW.Autoruner1.178 When the scanning detected these viruses, they asked for CURE? I clicked Yes To All … and at the bottom of the report (right side) saying all 3 had been deleted. Hope this info helps .. JazzBiondi
I am not sure if this is malware or not,lets try running Chkdsk

Click Start orb,type CMD in the search box,right click on the cmd that appears and select run as administrator.


In the command box that opens type chkdsk /f

Answer Y when chkdsk asks you if you want to check the drive next time Vista boots then restart,let me know if it fixes anything.
Dear mowman … did as you instructed but still the same result, cannot access normal mode. The moment when it shows "welcome" with Window Vista then it will either hang or rebooted itself. JazzBiondi
Dear mowman …

Here's the log generated by OTL …

OTL logfile created on: 27/10/2011 23:37:42 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kim Joi\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.99 Gb Total Physical Memory | 3.20 Gb Available Physical Memory | 80.12% Memory free
8.16 Gb Paging File | 7.48 Gb Available in Paging File | 91.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 85.83 Gb Free Space | 39.34% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 6.88 Gb Free Space | 46.95% Space Free | Partition Type: NTFS

Computer Name: KIMJOI-PC | User Name: Kim Joi | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kim Joi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe (Radialpoint Inc.)
PRC - C:\Program Files (x86)\Virgin Media\Security\RpsSecurityAwareR.exe (Virgin Media)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_310debf0\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (PDEngine) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV:64bit: - (PDAgent) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_310debf0\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (wltrysvc) – C:\Windows\SysNative\WLTRYSVC.EXE ()
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (RapportMgmtService) – C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (ServicepointService) – C:\Program Files (x86)\Virgin Media\Service Manager\ServicepointService.exe (Radialpoint Inc.)
SRV - (scan) – C:\Program Files (x86)\Virgin Media\Security\BitDefender\scan.dll (S.C. BitDefender S.R.L)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Radialpoint Security Services) – C:\Program Files (x86)\Virgin Media\Security\RpsSecurityAwareR.exe (Virgin Media)
SRV - (RP_FWS) – C:\Program Files (x86)\Virgin Media\Security\Fws.exe (Virgin Media)
SRV - (RadialpointIDSAgent) – C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (RapportKE64) – C:\Windows\SysNative\Drivers\RapportKE64.sys (Trusteer Ltd.)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (R300) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\DRIVERS\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (RPSKT) Security Services Driver (x64) – C:\Windows\SysNative\DRIVERS\rp_skt64.sys (Radialpoint Inc.)
DRV:64bit: - (RPPKT) Radialpoint Filter (x64) – C:\Windows\SysNative\DRIVERS\rp_pkt64.sys (Radialpoint, Inc.)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (DefragFS) – C:\Windows\SysNative\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (OA008Vid) – C:\Windows\SysNative\DRIVERS\OA008Vid.sys (Creative Technology Ltd.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (OA008Ufd) – C:\Windows\SysNative\DRIVERS\OA008Ufd.sys (Creative Technology Ltd.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\BCM42RLY.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\DRIVERS\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (e1express) Intel® – C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV - (RapportCerberus_32029) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus64_32029.sys ()
DRV - (RapportPG64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (RapportEI64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RadialpointIDSDriver) – C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys (AVG Technologies )
DRV - (RadialpointIDSFilter) – C:\Program Files (x86)\Virgin Media\Security\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys (AVG Technologies )
DRV - (RadialpointIDSEH) – C:\Windows\SysWOW64\drivers\AVGIDSEH.sys (AVG Technologies )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?p=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF:64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Virgin Media\Service Manager\nprpspa.dll (Virgin Media)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Virgin Media\Service Manager\nprpspa.dll (Virgin Media)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/03 12:45:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/17 07:26:53 | 000,000,000 | —D | M]

[2010/02/03 11:21:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Kim Joi\AppData\Roaming\mozilla\Extensions
[2011/06/30 22:45:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Kim Joi\AppData\Roaming\mozilla\Firefox\Profiles\92zjqexr.default\extensions
[2010/04/28 07:01:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Kim Joi\AppData\Roaming\mozilla\Firefox\Profiles\92zjqexr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/14 20:19:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/19 21:14:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 18:56:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/09 19:42:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/13 22:56:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/28 21:34:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/14 20:19:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/03 12:45:48 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/03 12:45:46 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/10/03 12:45:46 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/10/03 12:45:46 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/10/03 12:45:46 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/03 12:45:46 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/10/22 09:36:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\SysNative\WLTRAY.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ServiceManager.exe] C:\Program Files (x86)\Virgin Media\Service Manager\ServiceManager.exe (Virgin Media)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Kim Joi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E8CDE203-D99D-4C02-9E23-577802E6DF54}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/25 20:33:41 | 000,000,000 | —D | C] – C:\Users\Kim Joi\DoctorWeb
[2011/10/24 22:10:11 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Kim Joi\Desktop\aswMBR.exe
[2011/10/24 19:45:26 | 000,000,000 | —D | C] – C:\_OTL
[2011/10/22 22:39:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/10/22 09:42:59 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\temp
[2011/10/22 09:36:51 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/10/22 09:07:41 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/10/22 09:07:41 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/10/22 09:07:41 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/10/22 08:55:00 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/10/22 08:49:54 | 000,000,000 | —D | C] – C:\Qoobox
[2011/10/22 08:48:07 | 004,269,227 | R— | C] (Swearware) – C:\Users\Kim Joi\Desktop\ComboFix.exe
[2011/10/21 21:19:54 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Kim Joi\Desktop\OTL.exe
[2011/10/21 21:14:19 | 000,000,000 | —D | C] – C:\Users\Kim Joi\Desktop\tdsskiller
[2011/10/21 11:24:50 | 001,561,392 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Kim Joi\Desktop\TDSSKiller.exe
[2011/10/20 21:05:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2011/10/18 13:53:01 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/10/18 09:51:59 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{2C50EFE8-8E1F-431A-9E5C-FE1E0FA3C99D}
[2011/10/18 09:50:48 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{DD01CAF2-6DE4-4A34-9958-5A4F2E6E7671}
[2011/10/16 09:29:39 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{00F3442F-8DBB-4DC4-9895-159D32B52582}
[2011/10/16 09:29:28 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{4DF39974-8A62-440E-8E67-08B2EC51F5BD}
[2011/10/15 21:28:59 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{E6AED512-DAD0-460C-B4DE-150AADBA4D05}
[2011/10/15 21:28:48 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{4CD6D7CB-8D51-4230-A323-5D1A0C1B7591}
[2011/10/15 09:28:20 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{FA0E5ABC-CFF7-49E8-8773-72259FE06DCB}
[2011/10/15 09:28:08 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{B950077C-2132-4DDC-BF64-CCF76DCCA389}
[2011/10/14 10:02:09 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{3D8F6D0B-DAE0-4444-8EC9-2DB06AD7A101}
[2011/10/14 10:01:58 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{05ECCA1C-ED11-4343-88FF-9528CE04C291}
[2011/10/13 09:01:29 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{4950077F-6F1E-4B1D-A388-2081C753A3E5}
[2011/10/13 09:01:18 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{179F4CB6-9D80-4F6F-9BE0-7E547B25A046}
[2011/10/13 07:32:13 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/13 07:32:12 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/13 07:32:09 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/13 07:32:08 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/13 07:32:07 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/13 07:32:07 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/13 07:32:07 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/13 07:32:06 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/13 07:32:05 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/12 23:56:21 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 23:56:20 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 23:56:20 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 23:56:20 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 23:56:20 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 23:56:20 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 23:56:02 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 23:56:02 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 23:56:02 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 23:56:02 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 23:56:02 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 23:56:02 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 23:56:01 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 23:56:01 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/12 07:53:19 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{E789ED02-97F5-4201-B1DA-6AD98304AFBE}
[2011/10/12 07:53:07 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{051E9BBE-2E73-4F2B-AF32-DAFD24666049}
[2011/10/11 09:23:11 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{591A0A93-2436-43B4-A4F3-D619CF26202B}
[2011/10/11 09:23:00 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{6E5005B8-C65D-402A-BC82-DB163DBF4297}
[2011/10/10 10:23:16 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{5C8543C3-BFDF-4242-A71D-4173221DE786}
[2011/10/10 10:23:04 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{3A4C55F1-A40A-4E3A-B827-2A662367C407}
[2011/10/09 18:50:43 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{B695F8D5-D1A8-41C4-8272-8A17266E9E49}
[2011/10/09 18:50:32 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{DEAAF780-BEC3-4FC7-ADD3-3AB4BBAB2D17}
[2011/10/07 21:53:20 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{B8CCBA75-6627-49AF-BEEA-D84CB8DFB3BE}
[2011/10/07 21:53:08 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{A9F308A0-ED67-4680-A9D1-AB373C5AE701}
[2011/10/06 19:00:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/10/06 18:28:01 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{8F2278AB-9B6D-4959-B016-401520A28BD2}
[2011/10/06 18:27:50 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{2077E4BD-2228-42BD-8958-4CB3751C0B2C}
[2011/10/05 17:53:38 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{D4AA1EFA-88A9-4588-9436-B8C835FF68A6}
[2011/10/05 17:53:23 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{43B40FF3-B3F9-481B-AB71-A6B581D354BE}
[2011/10/04 08:02:49 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{0B120D13-00B9-40CD-88ED-70B1BE4B7616}
[2011/10/04 08:02:38 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{04D00421-BA7C-4CDE-91E3-ACECDECEAACC}
[2011/10/03 08:03:04 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{623D98E2-0645-4371-A948-66532E4DC304}
[2011/10/03 08:02:53 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{AD29AFFB-7D3D-4668-A1BC-DEE0D5616295}
[2011/09/30 21:18:37 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{998F4C08-BFE3-49EA-8000-3DBC94874DDD}
[2011/09/30 21:18:26 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{801B6427-7779-4620-9D57-6C425305DB73}
[2011/09/29 22:24:35 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{79719E62-5577-4791-A1FC-D910F9638441}
[2011/09/29 22:24:20 | 000,000,000 | —D | C] – C:\Users\Kim Joi\AppData\Local\{507B6DCC-7559-4228-A088-6F5718494F04}
[2009/08/28 18:07:54 | 008,270,752 | —- | C] (Dell, Inc. ) – C:\Users\Kim Joi\AppData\Roaming\DataSafeDotNet.exe

========== Files - Modified Within 30 Days ==========

[2011/10/27 23:34:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/27 18:57:27 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/27 18:57:26 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/27 18:51:15 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/10/27 18:44:33 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/26 21:57:11 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/25 20:31:28 | 079,686,160 | —- | M] () – C:\Users\Kim Joi\Desktop\26j9tynj.exe
[2011/10/25 20:17:43 | 471,699,742 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/10/25 19:41:48 | 000,381,176 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/24 22:33:48 | 000,000,732 | —- | M] () – C:\Users\Kim Joi\AppData\Local\d3d9caps64.dat
[2011/10/24 22:10:13 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Kim Joi\Desktop\aswMBR.exe
[2011/10/22 21:27:35 | 000,000,950 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/22 09:36:29 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/10/22 08:48:30 | 004,269,227 | R— | M] (Swearware) – C:\Users\Kim Joi\Desktop\ComboFix.exe
[2011/10/21 21:19:55 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Kim Joi\Desktop\OTL.exe
[2011/10/21 21:14:19 | 001,561,392 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Kim Joi\Desktop\TDSSKiller.exe
[2011/10/21 21:10:05 | 001,542,471 | —- | M] () – C:\Users\Kim Joi\Desktop\tdsskiller.zip
[2011/10/21 07:55:30 | 000,097,280 | —- | M] () – C:\Users\Kim Joi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/21 07:46:48 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/21 07:46:48 | 000,607,600 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/21 07:46:48 | 000,107,478 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/20 21:05:37 | 000,000,844 | —- | M] () – C:\Users\Kim Joi\Desktop\SpywareBlaster.lnk
[2011/10/20 20:15:31 | 000,002,243 | —- | M] () – C:\Windows\epplauncher.mif
[2011/10/18 19:06:44 | 002,908,726 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/10/15 07:17:06 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/06 19:00:23 | 000,002,117 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/02 07:05:52 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011/10/02 07:05:52 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job

========== Files Created - No Company Name ==========

[2011/10/25 20:28:59 | 079,686,160 | —- | C] () – C:\Users\Kim Joi\Desktop\26j9tynj.exe
[2011/10/24 21:17:42 | 471,699,742 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/10/22 09:07:41 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/10/22 09:07:41 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/10/22 09:07:41 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/10/22 09:07:41 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/10/22 09:07:41 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/10/21 21:10:02 | 001,542,471 | —- | C] () – C:\Users\Kim Joi\Desktop\tdsskiller.zip
[2011/10/20 21:05:37 | 000,000,844 | —- | C] () – C:\Users\Kim Joi\Desktop\SpywareBlaster.lnk
[2011/10/20 20:15:31 | 000,002,243 | —- | C] () – C:\Windows\epplauncher.mif
[2011/10/18 21:24:09 | 000,000,732 | —- | C] () – C:\Users\Kim Joi\AppData\Local\d3d9caps64.dat
[2011/10/18 18:58:40 | 002,908,726 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/10/06 19:00:23 | 000,002,117 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/10/01 23:25:10 | 000,000,564 | —- | C] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011/04/19 22:10:32 | 000,059,904 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/03/17 18:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/01/30 10:25:09 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/01/30 10:25:09 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/05/23 21:14:24 | 000,001,025 | —- | C] () – C:\Windows\SysWow64\sysprs7.dll
[2010/05/23 21:14:24 | 000,000,205 | —- | C] () – C:\Windows\SysWow64\lsprst7.dll
[2009/12/07 20:05:54 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/07 20:05:15 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/12/07 20:04:34 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/14 10:15:19 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/11 22:12:42 | 000,097,280 | —- | C] () – C:\Users\Kim Joi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/10 19:15:21 | 000,006,836 | —- | C] () – C:\Users\Kim Joi\AppData\Local\d3d9caps.dat
[2009/07/09 12:49:52 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2009/07/09 10:49:13 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/07/09 10:18:22 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/04/25 04:58:05 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/01/21 03:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 16:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 13:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 13:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 10:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin

========== Files - Unicode (All) ==========
[2009/09/09 09:20:26 | 000,000,036 | —- | M] ()(C:\Windows\SysWow64\???????????????????????????????????????g) – C:\Windows\SysWow64\㩃停潲牧浡䘠汩獥⠠㡸⤶噜物楧牂慯扤湡層䍐畧牡層慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
[2009/09/09 09:20:26 | 000,000,036 | —- | C] ()(C:\Windows\SysWow64\???????????????????????????????????????g) – C:\Windows\SysWow64\㩃停潲牧浡䘠汩獥⠠㡸⤶噜物楧牂慯扤湡層䍐畧牡層慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI