This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browsers are Very Slow to Load Pages if at all and Freezing

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Pages are taking forever to load in all browsers and browsers are freezing.

Appreciate any help! Thank you in advance.

OTL logfile created on: 10/23/2011 1:28:29 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Richie\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 1.77 Gb Available Physical Memory | 54.35% Memory free
6.68 Gb Paging File | 5.19 Gb Available in Paging File | 77.57% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 91.63 Gb Free Space | 30.74% Space Free | Partition Type: NTFS

Computer Name: THEFAMILYDEN | User Name: Richie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/23 01:25:50 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Richie\Desktop\OTL.exe
PRC - [2011/10/18 13:07:14 | 000,140,952 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
PRC - [2011/10/08 17:34:24 | 000,820,568 | —- | M] (IObit) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/10/05 06:12:54 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/09/09 07:51:24 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2011/09/05 13:04:56 | 001,489,304 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
PRC - [2011/07/28 19:08:12 | 001,259,376 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/07/06 09:39:58 | 000,045,056 | —- | M] (Intuit) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2011/06/30 13:25:52 | 001,248,256 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/04/27 15:39:26 | 000,208,944 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2011/04/14 18:08:52 | 000,352,144 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011/01/07 21:06:12 | 000,803,432 | —- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2011/01/07 19:48:56 | 000,378,984 | —- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/10/27 19:03:46 | 000,759,072 | —- | M] (ABBYY (BIT Software)) – C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
PRC - [2008/09/16 12:03:18 | 000,169,312 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
PRC - [2008/05/19 13:28:52 | 000,065,536 | —- | M] () – C:\Program Files\VService\VService.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
PRC - [2006/12/05 01:36:10 | 000,537,520 | —- | M] ( ) – C:\Windows\System32\lxcqcoms.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe


========== Modules (No Company Name) ==========

MOD - [2011/10/10 20:09:28 | 008,522,400 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/10/05 06:12:54 | 001,833,944 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/07/28 19:09:42 | 000,096,112 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 19:08:12 | 001,259,376 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/01/07 19:48:38 | 000,235,624 | —- | M] () – C:\Program Files\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2009/02/14 05:04:38 | 000,756,040 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL


========== Win32 Services (SafeList) ==========

SRV - [2011/10/10 05:53:18 | 003,552,856 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll – (Akamai)
SRV - [2011/10/08 17:34:24 | 000,820,568 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe – (IMFservice)
SRV - [2011/09/09 07:51:24 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2011/07/06 09:39:58 | 000,045,056 | —- | M] (Intuit) [Auto | Running] – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2011/06/30 13:25:52 | 001,248,256 | —- | M] (Intuit Inc.) [Auto | Running] – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe – (QBVSS)
SRV - [2011/06/06 12:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/04/27 15:39:26 | 000,208,944 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2011/04/14 18:08:52 | 000,352,144 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/01/07 19:48:56 | 000,378,984 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2010/02/19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009/11/02 14:17:00 | 001,098,968 | —- | M] (TiVo Inc.) [Disabled | Stopped] – C:\Program Files\TiVo\Desktop\TiVoBeacon.exe – (TivoBeacon2)
SRV - [2009/07/23 21:10:38 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2009/04/14 00:07:42 | 000,651,720 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/10/27 19:03:46 | 000,759,072 | —- | M] (ABBYY (BIT Software)) [Auto | Running] – C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Professional.9.0)
SRV - [2008/09/16 12:03:18 | 000,169,312 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor7.0)
SRV - [2008/05/19 13:28:52 | 000,065,536 | —- | M] () [Auto | Running] – C:\Program Files\VService\VService.exe – (VService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/19 15:28:38 | 000,181,784 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe – (GameConsoleService)
SRV - [2006/12/19 18:23:20 | 000,094,208 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe – (EpsonBidirectionalService)
SRV - [2006/12/05 01:36:10 | 000,537,520 | —- | M] ( ) [Auto | Running] – C:\Windows\System32\lxcqcoms.exe – (lxcq_device)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - [2011/10/22 23:47:58 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{137C3209-B436-4F72-B768-1FAC6A511533}\MpKsl58e2081b.sys – (MpKsl58e2081b)
DRV - [2011/10/08 17:04:26 | 000,018,768 | —- | M] () [File_System | Disabled | Stopped] – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys – (FileMonitor)
DRV - [2011/09/20 14:28:42 | 000,019,792 | —- | M] (IObit.com) [Kernel | On_Demand | Stopped] – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\UrlFilter.sys – (UrlFilter)
DRV - [2011/09/20 14:28:36 | 000,030,600 | —- | M] (IObit.com) [Kernel | On_Demand | Stopped] – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\RegFilter.sys – (RegFilter)
DRV - [2011/09/09 07:51:18 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2011/04/27 15:25:24 | 000,065,024 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2011/04/18 13:18:50 | 000,043,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\MpNWMon.sys – (MpNWMon)
DRV - [2011/03/24 23:31:06 | 000,023,456 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\DrvAgent32.sys – (DrvAgent32)
DRV - [2011/03/16 19:00:08 | 000,032,672 | —- | M] (IObit Information Technology) [File_System | Auto | Running] – C:\Program Files\IObit\Protected Folder\pffilter.sys – (PfFilter)
DRV - [2011/01/07 23:27:00 | 010,467,656 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/08/23 10:56:04 | 000,223,128 | —- | M] (Alcohol Soft Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\Drivers\vaxscsi.sys – (vaxscsi)
DRV - [2010/04/13 06:47:22 | 000,023,096 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\SndTAudio.sys – (SndTAudio)
DRV - [2010/02/19 11:36:05 | 000,012,872 | —- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2010/01/20 23:47:54 | 000,836,384 | —- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\netr28u.sys – (netr28u)
DRV - [2009/09/02 04:09:24 | 000,176,128 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2009/04/11 01:06:26 | 000,019,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSDScan.sys – (WSDScan)
DRV - [2009/02/24 18:42:14 | 000,116,736 | —- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mcdbus.sys – (mcdbus)
DRV - [2008/11/28 15:26:56 | 000,010,704 | —- | M] (Pixbyte Development SL) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\iTurnsDriver.sys – (iTurns)
DRV - [2008/11/07 10:35:54 | 000,455,168 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2008/11/07 10:35:52 | 000,561,536 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2008/03/13 03:18:34 | 000,932,864 | —- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\AVerBDA716x.sys – (AVerBDA6x)
DRV - [2008/02/29 12:38:36 | 000,131,712 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\etDevice.sys – (DCamUSBET)
DRV - [2008/01/20 22:23:21 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV - [2008/01/20 22:23:20 | 002,225,664 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NETw3v32.sys – (NETw3v32) Intel®
DRV - [2007/09/07 06:43:56 | 000,006,656 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\etScan.sys – (ScanUSBET)
DRV - [2007/07/17 06:29:44 | 000,020,504 | —- | M] (Hewlett Packard) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\hpfxfax.sys – (HPFXFAX)
DRV - [2007/07/17 06:29:34 | 000,017,432 | —- | M] (Hewlett Packard) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\hpfxbulk.sys – (HPFXBULK)
DRV - [2007/07/03 20:59:10 | 000,086,824 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd) SAMSUNG Mobile Modem Diagnostic Serial Port (WDM)
DRV - [2007/07/03 20:58:20 | 000,106,792 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2007/07/03 20:57:24 | 000,011,944 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)
DRV - [2007/07/03 20:54:24 | 000,080,552 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2007/06/21 07:51:28 | 002,222,080 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NETw4v32.sys – (NETw4v32) Intel®
DRV - [2007/01/05 12:54:30 | 000,183,168 | —- | M] (eMPIA Technology Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\etFilter.sys – (FiltUSBET)
DRV - [2006/11/29 18:24:57 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/ig?hl=en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========



FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010/06/12 20:52:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/12 07:26:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/12 07:26:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/05 06:12:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/18 15:11:12 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{9179CC56-54BE-440B-B5A7-01F26C940093}: C:\Users\Richie\AppData\Local\{9179CC56-54BE-440B-B5A7-01F26C940093}

[2010/10/03 15:03:32 | 000,001,919 | —- | M] () – \Users\Richie\AppData\Roaming\Mozilla\Firefox\Profiles\jad3mhtm.default\searchplugins\bing-zugo.xml
[2011/03/08 20:23:08 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/02/17 09:11:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/12 12:59:38 | 000,000,000 | —D | M] (Personas) – C:\USERS\RICHIE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JAD3MHTM.DEFAULT\EXTENSIONS\[removed]
[2011/10/05 06:12:55 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/17 09:11:35 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/05 06:12:53 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - Extension: DivX HiQ = C:\Users\Richie\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\

O1 HOSTS File: ([2011/08/27 19:53:24 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {35065594-9169-4A34-B167-FC4865038E53} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - No CLSID value found.
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\Windows\is-ALUS6.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: morganstanleyclientserv.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3CC27286-417C-430D-9F20-96EA12BD0B3D}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{88A9763F-2AFD-4150-9A59-374CA5F64041}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FF2AAF1F-BD49-4D72-AF7E-3FA68B18A59E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks 2011\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Filter\text/x-mrml {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\Common Files\A&W\MidRadio.ocx (YAMAHA CORPORATION)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Richie\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Richie\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/10/23 01:27:05 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Richie\Desktop\HiJackThis.exe
[2011/10/23 01:25:45 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Richie\Desktop\OTL.exe
[2011/10/22 23:47:32 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2011/10/22 17:42:09 | 000,000,000 | —D | C] – C:\Users\Richie\AppData\Local\{3200B103-746B-4717-B250-9BB887AD687D}
[2011/10/22 17:41:58 | 000,000,000 | —D | C] – C:\Users\Richie\Documents\My Weblog Posts
[2011/10/22 17:41:54 | 000,000,000 | —D | C] – C:\Users\Richie\AppData\Local\Windows Live Writer
[2011/10/16 08:20:23 | 000,000,000 | —D | C] – C:\Users\Richie\AppData\Local\Intuit
[2011/10/16 08:13:21 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Intuit
[2011/10/16 08:13:21 | 000,000,000 | —D | C] – C:\ProgramData\Intuit
[2011/10/16 08:13:21 | 000,000,000 | —D | C] – C:\Program Files\Intuit
[2011/10/16 08:13:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intuit
[2011/10/16 08:12:34 | 000,000,000 | —D | C] – C:\ProgramData\COMMON FILES
[2011/10/16 08:07:11 | 000,000,000 | —D | C] – C:\Windows\Intuit
[2011/10/16 07:10:58 | 567,708,432 | —- | C] (Intuit, Inc. ) – C:\Users\Richie\Desktop\QuickBooksPremier2011.exe
[2011/10/16 07:10:56 | 000,000,000 | —D | C] – C:\Windows\Download Manager
[2011/10/16 07:10:54 | 000,000,000 | —D | C] – C:\Program Files\Akamai
[2011/10/15 19:03:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Akamai
[2011/10/13 06:57:15 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/10/13 06:57:13 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/10/13 06:57:13 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/10/13 06:57:12 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/10/13 06:57:12 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/10/13 05:48:44 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/10/13 05:48:44 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/10/13 05:48:44 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/10/13 05:48:44 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/10/13 05:48:20 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/10/13 05:48:20 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2011/10/13 05:48:15 | 002,043,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/03/24 18:59:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Program Files\taskkill.exe
[2006/12/04 21:36:12 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxcqih.exe
[2006/12/04 21:36:10 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxcqcoms.exe
[2006/12/04 21:36:06 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxcqcfg.exe
[2006/11/06 04:37:46 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxcqpmui.dll
[2006/11/06 04:35:50 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxcqserv.dll
[2006/11/06 04:28:08 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxcqcomm.dll
[2006/11/06 04:26:14 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxcqlmpm.dll
[2006/11/06 04:24:44 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxcqiesc.dll
[2006/11/06 04:21:48 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxcqpplc.dll
[2006/11/06 04:20:48 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxcqcomc.dll
[2006/11/06 04:20:14 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxcqprox.dll
[2006/11/06 04:12:44 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxcqinpa.dll
[2006/11/06 04:11:58 | 000,991,232 | —- | C] ( ) – C:\Windows\System32\lxcqusb1.dll
[2006/11/06 04:07:04 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxcqhbn3.dll

========== Files - Modified Within 30 Days ==========

[2011/10/23 01:27:10 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Richie\Desktop\HiJackThis.exe
[2011/10/23 01:25:50 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Richie\Desktop\OTL.exe
[2011/10/23 01:12:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/22 23:50:03 | 003,811,640 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/10/22 23:49:32 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/22 23:49:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/22 23:47:44 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/22 23:47:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/22 21:23:51 | 000,000,926 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2011/10/21 22:46:10 | 000,025,120 | —- | M] () – C:\Users\Richie\Documents\cc_20111021_224605.reg
[2011/10/21 22:45:25 | 000,000,764 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/10/18 06:46:04 | 000,000,000 | —- | M] () – C:\Users\Richie\Documents\NEWSOFT
[2011/10/17 21:52:00 | 000,086,151 | —- | M] () – C:\Users\Richie\Desktop\fml.xml
[2011/10/17 20:44:00 | 000,008,967 | —- | M] () – C:\Users\Richie\Desktop\truestory.m3u
[2011/10/17 20:43:29 | 000,781,312 | -HS- | M] () – C:\Users\Richie\ehthumbs_vista.db
[2011/10/17 19:40:04 | 000,093,184 | —- | M] () – C:\Users\Richie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/16 08:17:24 | 000,000,095 | —- | M] () – C:\Windows\QBChanUtil_Trigger.ini
[2011/10/16 08:17:02 | 000,002,006 | —- | M] () – C:\Users\Public\Desktop\QuickBooks Premier - Contractor Edition 2011.lnk
[2011/10/16 08:11:53 | 000,001,915 | —- | M] () – C:\Users\Richie\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/16 08:05:56 | 567,708,432 | —- | M] (Intuit, Inc. ) – C:\Users\Richie\Desktop\QuickBooksPremier2011.exe
[2011/10/16 07:44:54 | 000,001,857 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2011/10/16 07:44:54 | 000,001,437 | —- | M] () – C:\Users\Richie\Desktop\DivX Movies.lnk
[2011/10/16 07:44:18 | 000,000,885 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2011/10/16 07:10:58 | 000,000,710 | —- | M] () – C:\Users\Richie\Desktop\Setup_QuickBooksPremier2011.lnk
[2011/10/13 06:52:18 | 000,728,632 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/10/13 06:52:17 | 000,148,558 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/10/12 05:57:42 | 000,000,805 | —- | M] () – C:\Users\Public\Desktop\DVDneXtCOPY Ultimate.lnk
[2011/10/10 20:09:29 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/01 03:02:27 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/09/30 03:00:59 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/09/23 23:45:52 | 000,709,968 | —- | M] () – C:\Windows\is-ALUS6.exe
[2011/09/23 23:45:52 | 000,010,498 | —- | M] () – C:\Windows\is-ALUS6.msg
[2011/09/23 23:45:52 | 000,000,890 | —- | M] () – C:\Users\Richie\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/09/23 23:45:52 | 000,000,381 | —- | M] () – C:\Windows\is-ALUS6.lst

========== Files Created - No Company Name ==========

[2011/10/22 23:47:10 | 003,811,640 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2011/10/22 21:23:51 | 000,000,926 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2011/10/21 22:46:07 | 000,025,120 | —- | C] () – C:\Users\Richie\Documents\cc_20111021_224605.reg
[2011/10/18 06:46:04 | 000,000,000 | —- | C] () – C:\Users\Richie\Documents\NEWSOFT
[2011/10/17 21:52:00 | 000,086,151 | —- | C] () – C:\Users\Richie\Desktop\fml.xml
[2011/10/17 20:44:00 | 000,008,967 | —- | C] () – C:\Users\Richie\Desktop\truestory.m3u
[2011/10/17 19:37:09 | 000,781,312 | -HS- | C] () – C:\Users\Richie\ehthumbs_vista.db
[2011/10/16 08:17:02 | 000,002,006 | —- | C] () – C:\Users\Public\Desktop\QuickBooks Premier - Contractor Edition 2011.lnk
[2011/10/16 08:12:35 | 000,000,095 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2011/10/16 08:11:53 | 000,001,915 | —- | C] () – C:\Users\Richie\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/16 07:44:18 | 000,000,885 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2011/10/16 07:10:56 | 000,000,710 | —- | C] () – C:\Users\Richie\Desktop\Setup_QuickBooksPremier2011.lnk
[2011/09/23 23:45:52 | 000,709,968 | —- | C] () – C:\Windows\is-ALUS6.exe
[2011/09/23 23:45:52 | 000,010,498 | —- | C] () – C:\Windows\is-ALUS6.msg
[2011/09/23 23:45:52 | 000,000,381 | —- | C] () – C:\Windows\is-ALUS6.lst
[2011/07/13 09:47:23 | 000,004,096 | -H– | C] () – C:\Users\Richie\AppData\Local\keyfile3.drm
[2011/05/22 09:07:27 | 000,073,220 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2011/05/22 09:07:27 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2011/05/22 09:07:27 | 000,029,114 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2011/05/22 09:07:27 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2011/05/22 09:07:27 | 000,021,021 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2011/05/22 09:07:27 | 000,015,670 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2011/05/22 09:07:27 | 000,013,280 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2011/05/22 09:07:27 | 000,010,673 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2011/05/22 09:07:27 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2011/05/22 09:07:27 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2011/05/22 09:07:27 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2011/05/22 09:07:27 | 000,001,137 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2011/05/22 09:07:27 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2011/05/22 09:07:27 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2011/05/22 09:07:27 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2011/05/22 09:07:27 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2011/05/22 09:01:23 | 000,000,090 | —- | C] () – C:\Windows\EPART810.ini
[2011/05/15 16:04:25 | 000,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2011/03/22 16:07:02 | 000,000,023 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/03/05 11:08:06 | 000,000,148 | —- | C] () – C:\Windows\Readiris.ini
[2011/02/19 23:17:13 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/02/19 23:17:13 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/02/19 23:17:13 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/02/19 23:17:13 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/02/19 23:17:13 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/02/17 17:08:38 | 000,000,608 | -HS- | C] () – C:\Windows\System32\winzvprt5.sys
[2011/02/17 17:03:07 | 000,153,528 | —- | C] () – C:\Windows\hppins07.dat
[2011/02/17 17:03:07 | 000,153,487 | —- | C] () – C:\Windows\System32\hppins07.dat
[2011/02/17 17:03:07 | 000,000,838 | —- | C] () – C:\Windows\hppmdl07.dat
[2011/02/02 20:39:12 | 000,016,968 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2011/01/14 16:48:18 | 000,000,200 | —- | C] () – C:\Windows\ulead32.ini
[2010/12/06 12:14:23 | 000,000,841 | —- | C] () – \COMODO GeekBuddy.lnk
[2010/10/11 09:27:53 | 000,559,135 | —- | C] () – C:\Windows\hpoins16.dat.temp
[2010/10/11 09:27:53 | 000,004,602 | —- | C] () – C:\Windows\hpomdl16.dat.temp
[2010/09/26 19:57:21 | 000,559,135 | —- | C] () – C:\Windows\hpoins16.dat
[2010/09/26 19:57:21 | 000,004,602 | —- | C] () – C:\Windows\hpomdl16.dat
[2010/09/14 07:46:30 | 000,000,120 | —- | C] () – C:\Users\Richie\AppData\Local\Wwiwanofowacehe.dat
[2010/09/14 07:46:30 | 000,000,000 | —- | C] () – C:\Users\Richie\AppData\Local\Bpovepova.bin
[2010/08/22 12:42:05 | 000,000,000 | —- | C] () – C:\Windows\PCFriend.INI
[2010/05/23 16:59:34 | 000,059,924 | —- | C] () – C:\Windows\System32\libdvdcss-2.dll
[2010/04/24 18:12:30 | 000,000,217 | —- | C] () – \WirelessDiagLog.csv
[2010/04/03 17:50:32 | 000,000,000 | —- | C] () – C:\Users\Richie\AppData\Local\prvlcl.dat
[2010/02/06 19:24:39 | 000,001,090 | -H– | C] () – \IPH.PH
[2009/12/20 15:05:52 | 000,086,016 | —- | C] () – C:\Windows\System32\Machinist2.dll
[2009/09/17 21:52:16 | 000,000,552 | —- | C] () – C:\Users\Richie\AppData\Local\d3d8caps.dat
[2009/07/30 21:21:07 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/07/30 21:21:06 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/20 01:03:33 | 000,000,021 | —- | C] () – C:\Windows\atid.ini
[2009/05/06 07:31:19 | 000,294,912 | —- | C] () – C:\Windows\System32\SP_encore.dll
[2009/05/06 07:31:18 | 000,131,072 | —- | C] () – C:\Windows\System32\3GP_CREATOR_DLL_FILES.dll
[2009/05/06 07:30:00 | 000,135,168 | —- | C] () – C:\Windows\System32\SP_decore.dll
[2009/05/06 07:30:00 | 000,098,304 | —- | C] () – C:\Windows\System32\ResampleRateDll.dll
[2009/05/06 07:29:59 | 000,180,224 | —- | C] () – C:\Windows\System32\AMRDecore_Dll.dll
[2009/05/06 07:29:59 | 000,167,936 | —- | C] () – C:\Windows\System32\AMREncore_Dll.dll
[2009/05/01 00:12:13 | 000,000,094 | —- | C] () – C:\Users\Richie\AppData\Local\fusioncache.dat
[2009/04/19 18:25:05 | 000,009,728 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2009/04/15 01:00:56 | 000,000,220 | -HS- | C] () – C:\Windows\WSYS049.SYS
[2009/03/12 07:36:54 | 000,000,335 | —- | C] () – C:\Windows\nsreg.dat
[2009/03/07 18:57:31 | 000,002,766 | —- | C] () – C:\Windows\wininit.ini
[2009/03/05 06:54:58 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/01/31 12:00:32 | 000,093,184 | —- | C] () – C:\Users\Richie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/26 23:45:07 | 000,028,672 | —- | C] () – C:\Windows\hookdllX.dll
[2009/01/26 23:44:48 | 000,011,776 | —- | C] () – C:\Windows\System32\pmsbfn32.dll
[2009/01/26 23:43:39 | 000,045,056 | —- | C] () – C:\Windows\System32\lxcqpmon.dll
[2009/01/26 23:43:39 | 000,032,768 | —- | C] () – C:\Windows\System32\LXCQFXPU.DLL
[2009/01/25 02:42:19 | 000,000,498 | —- | C] () – C:\Windows\ODBC.INI
[2009/01/18 16:21:18 | 000,001,356 | —- | C] () – C:\Users\Richie\AppData\Local\d3d9caps.dat
[2009/01/18 05:07:38 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/01/18 03:59:35 | 000,000,007 | —- | C] () – C:\Windows\System32\mkghj.dll
[2008/09/03 20:11:24 | 000,054,600 | —- | C] () – \npbittorrent.dll
[2008/06/18 23:05:52 | 000,000,000 | RHS- | C] () – \MSDOS.SYS
[2008/06/18 23:05:52 | 000,000,000 | RHS- | C] () – \IO.SYS
[2008/04/30 10:40:27 | 000,003,072 | —- | C] () – C:\Windows\System32\716xCoInstaller.dll
[2008/04/30 09:04:34 | 000,008,192 | R-S- | C] () – \BOOTSECT.BAK
[2008/04/30 09:04:33 | 000,333,257 | RHS- | C] () – \bootmgr
[2007/06/01 13:58:40 | 000,999,424 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2007/03/16 18:00:00 | 000,003,403 | —- | C] () – C:\Windows\System32\hptcpmon.ini
[2007/01/11 20:24:32 | 000,000,685 | —- | C] () – C:\Windows\System32\hppapr07.dat
[2006/11/12 21:30:54 | 000,204,800 | —- | C] () – C:\Windows\System32\lxcqgrd.dll
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,728,632 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,148,558 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 06:23:09 | 000,000,024 | —- | C] () – \autoexec.bat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/11/02 02:25:08 | 000,000,010 | —- | C] () – \config.sys
[2006/10/24 20:16:22 | 000,344,064 | —- | C] () – C:\Windows\System32\lxcqcoin.dll
[2006/09/18 14:37:50 | 000,000,530 | —- | C] () – C:\Windows\System32\tx12_ic.ini
[2006/09/18 14:37:48 | 000,667,280 | —- | C] () – C:\Windows\System32\tx12.dll
[2005/06/23 14:37:48 | 000,040,960 | —- | C] () – C:\Windows\System32\lxcqvs.dll
[2002/07/22 12:25:00 | 000,794,624 | —- | C] () – C:\Windows\System32\LTRTN13n.DLL
[1998/10/11 00:07:38 | 000,088,576 | —- | C] () – C:\Windows\System32\Iticheck.dll

< End of report >

Attachments:

:welcome:

Sorry for the delay but we get a bit busy around here, but i am linked to you now


Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-28 00:16:26 —————————– 00:16:26.937 OS Version: Windows 6.0.6002 Service Pack 2 00:16:26.937 Number of processors: 2 586 0xF0D 00:16:26.938 ComputerName: THEFAMILYDEN UserName: Richie 00:16:27.869 Initialize success 00:16:40.978 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 00:16:40.982 Disk 0 Vendor: ST3320820AS 3.AAD Size: 305245MB BusType: 3 00:16:43.022 Disk 0 MBR read successfully 00:16:43.025 Disk 0 MBR scan 00:16:43.028 Disk 0 Windows VISTA default MBR code 00:16:43.032 Disk 0 scanning sectors +625140400 00:16:43.101 Disk 0 scanning C:\Windows\system32\drivers 00:16:50.381 Service scanning 00:16:51.145 Service MpKsle9a404da c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8BC8B8BC-3BF4-46FD-BCE5-7D26C226F8AB}\MpKsle9a404da.sys **LOCKED** 32 00:16:51.154 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32 00:16:51.795 Modules scanning 00:16:58.414 Disk 0 trace - called modules: 00:16:58.439 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys 00:16:58.450 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x856da340] 00:16:58.457 3 CLASSPNP.SYS[8b5aa8b3] -> nt!IofCallDriver -> [0x8558f918] 00:16:58.464 5 acpi.sys[8ae3d6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x855768a0] 00:16:58.470 Scan finished successfully 00:17:36.937 Disk 0 MBR has been saved successfully to "C:\Users\Richie\Desktop\MBR.dat" 00:17:36.949 The log file has been saved successfully to "C:\Users\Richie\Desktop\aswMBR.txt" . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 0:18:07 on 2011-10-28 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3327.1683 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe C:\Windows\System32\svchost.exe -k Akamai C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\lxcqcoms.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files\VService\VService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\ehome\ehsched.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\ehome\ehRecvr.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File TB: {35065594-9169-4A34-B167-FC4865038E53} - No File TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File TB: {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - No File uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED uRun: [Advanced SystemCare 4] c:\program files\iobit\advanced systemcare 4\ASCTray.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [IObit Malware Fighter] "c:\program files\iobit\iobit malware fighter\IMF.exe" /autostart mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mRunOnce: [InnoSetupRegFile.0000000001] "c:\windows\is-ALUS6.exe" /REG /REGSVRMODE mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: morganstanleyclientserv.com\www Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{3CC27286-417C-430D-9F20-96EA12BD0B3D} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{88A9763F-2AFD-4150-9A59-374CA5F64041} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{FF2AAF1F-BD49-4D72-AF7E-3FA68B18A59E} : DhcpNameServer = 192.168.1.1 192.168.1.1 Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - c:\program files\common files\a&w\MidRadio.ocx Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks 2011\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\users\richie\appdata\roaming\mozilla\firefox\profiles\jad3mhtm.default\ FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll . —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 750000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 750000 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: nglayout.initialpaint.delay - 0 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true FF - user.js: network.protocol-handler.warn-external.dnupdate - false . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R1 MpKsle9a404da;MpKsle9a404da;c:\programdata\microsoft\microsoft antimalware\definition updates\{8bc8b8bc-3bf4-46fd-bce5-7d26c226f8ab}\MpKsle9a404da.sys [2011-10-27 28752] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-11-25 116608] R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\common files\abbyy\finereader\9.00\licensing\pe\NetworkLicenseServer.exe [2008-10-27 759072] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-4-15 328536] R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2011-10-22 820568] R2 lxcq_device;lxcq_device;c:\windows\system32\lxcqcoms.exe -service –> c:\windows\system32\lxcqcoms.exe -service [?] R2 msftesql$SQLEXPRESS;SQL Server FullText Search (SQLEXPRESS);c:\program files\microsoft sql server\mssql.1\mssql\binn\msftesql.exe [2010-3-26 91992] R2 PfFilter;PfFilter;c:\program files\iobit\protected folder\pffilter.sys [2011-4-15 32672] R2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2011-6-30 1248256] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-7-30 1153368] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-1-7 378984] R2 VService;ECS Button Volume Control Service;c:\program files\vservice\VService.exe [2008-5-19 65536] R3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\drivers\AVerBDA716x.sys [2008-4-30 932864] R3 DCamUSBET;ET USB 2751 Camera;c:\windows\system32\drivers\etDevice.sys [2008-2-29 131712] R3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\drivers\etFilter.sys [2008-5-13 183168] R3 iTurns;iTurns;c:\windows\system32\drivers\iTurnsDriver.sys [2008-11-28 10704] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944] R3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\drivers\etScan.sys [2007-9-7 6656] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-25 133104] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2011-3-24 23456] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-14 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-7-25 133104] S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2007-7-17 20504] S3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2011-3-20 836384] S3 RegFilter;RegFilter;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\RegFilter.sys [2011-10-22 30600] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 12872] S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2010-5-3 23096] S3 UrlFilter;UrlFilter;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\UrlFilter.sys [2011-10-22 19792] S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [2010-8-23 223128] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-20 16896] S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-7-30 19968] S4 FileMonitor;FileMonitor;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\FileMonitor.sys [2011-10-22 18768] S4 TivoBeacon2;TiVo Beacon Service;c:\program files\tivo\desktop\TiVoBeacon.exe [2009-11-2 1098968] . =============== Created Last 30 ================ . 2011-10-27 08:25:27 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8bc8b8bc-3bf4-46fd-bce5-7d26c226f8ab}\MpKsle9a404da.sys 2011-10-27 08:24:52 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8bc8b8bc-3bf4-46fd-bce5-7d26c226f8ab}\offreg.dll 2011-10-27 08:24:48 6668624 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8bc8b8bc-3bf4-46fd-bce5-7d26c226f8ab}\mpengine.dll 2011-10-26 04:12:01 ——– d—–w- c:\users\richie\appdata\local\temp 2011-10-26 04:10:59 ——– d-sh–w- C:\$RECYCLE.BIN 2011-10-26 03:52:42 ——– d—–w- C:\ComboFix 2011-10-25 11:27:29 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-24 02:59:06 ——– d—–w- c:\users\richie\appdata\local\{E407C073-2E7D-46EB-8B78-F6DC3D3113C9} 2011-10-24 02:51:16 ——– d—–w- c:\users\richie\appdata\local\iFreeTV 2011-10-24 02:51:14 ——– d—–w- c:\program files\iFreeTV 2011-10-24 02:47:45 11776 —-a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll 2011-10-24 02:47:25 ——– d—–w- c:\program files\common files\xing shared 2011-10-24 02:46:57 150696 —-a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll 2011-10-24 02:46:50 107008 —-a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll 2011-10-23 17:52:05 ——– d—–w- c:\programdata\Viewpoint 2011-10-23 15:02:35 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-10-22 21:42:09 ——– d—–w- c:\users\richie\appdata\local\{3200B103-746B-4717-B250-9BB887AD687D} 2011-10-22 21:41:57 ——– d—–w- c:\users\richie\appdata\roaming\Windows Live Writer 2011-10-22 21:41:54 ——– d—–w- c:\users\richie\appdata\local\Windows Live Writer 2011-10-16 12:20:23 ——– d—–w- c:\users\richie\appdata\local\Intuit 2011-10-16 12:13:21 ——– d—–w- c:\programdata\Intuit 2011-10-16 12:13:21 ——– d—–w- c:\program files\Intuit 2011-10-16 12:13:21 ——– d—–w- c:\program files\common files\Intuit 2011-10-16 12:12:34 ——– d—–w- c:\programdata\COMMON FILES 2011-10-16 12:07:11 ——– d—–w- c:\windows\Intuit 2011-10-16 11:10:56 ——– d—–w- c:\windows\Download Manager 2011-10-16 11:10:54 ——– d—–w- c:\program files\Akamai 2011-10-15 23:03:00 ——– d—–w- c:\program files\common files\Akamai 2011-10-13 09:48:44 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax 2011-10-13 09:48:44 57856 —-a-w- c:\windows\system32\MSDvbNP.ax 2011-10-13 09:48:44 293376 —-a-w- c:\windows\system32\psisdecd.dll 2011-10-13 09:48:44 217088 —-a-w- c:\windows\system32\psisrndr.ax 2011-10-13 09:48:36 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-10-13 09:48:20 563712 —-a-w- c:\windows\system32\oleaut32.dll 2011-10-13 09:48:20 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2011-10-13 09:48:20 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2011-10-13 09:48:20 238080 —-a-w- c:\windows\system32\oleacc.dll 2011-10-13 09:48:15 2043392 —-a-w- c:\windows\system32\win32k.sys 2011-10-11 15:21:05 703824 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{46068300-8d16-4520-ba18-f889a5314ee7}\gapaengine.dll 2011-10-01 07:01:55 7152464 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\updates\mpengine.dll . ==================== Find3M ==================== . 2011-10-24 02:46:17 499712 —-a-w- c:\windows\system32\msvcp71.dll 2011-10-24 02:46:17 348160 —-a-w- c:\windows\system32\msvcr71.dll 2011-09-24 03:45:52 709968 —-a-w- c:\windows\is-ALUS6.exe 2011-09-01 02:35:59 1798144 —-a-w- c:\windows\system32\jscript9.dll 2011-09-01 02:28:15 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-09-01 02:22:54 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-08-31 21:00:50 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-03-24 22:59:37 81408 —-a-w- c:\program files\taskkill.exe . ============= FINISH: 0:19:42.34 ===============

Attachments:

Hi,

You have uTorrent installed, using File Sharing is one of the best ways to infect your system, your downloading that file from an unknown source and not all but the greater percentage of it contains malware, its the latest way that malware writers infect your system, I strongly urge you to uninstall it and stay away from any form of File Sharing.


aswMBR Checks for Rootkit type of infections and it found none .


You have a lot of security software installed, you really dont need that many, I would uninstall SuperAntiSpyware and free up some resources.


IObit Malware This one used to have some issues but I believe they have cleaned up there act.


Microsoft Security Essentials This contains all that you may need so no need for the other programs you have installed, sometimes running to many security programs can slow you down.



Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces




You have Malwarebytes installed, one of the better tools, open it, check for updates and run a Quick Scan removing all it finds and post the log
All processes killed
========== PROCESSES ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Richie\Desktop\cmd.bat deleted successfully.
C:\Users\Richie\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users
-> No Temporary Internet Files cache folder defined!
->Flash cache emptied: 35 bytes

User: Default
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: Default User
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: Public
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: Richie
->Temp folder emptied: 658697266 bytes
-> No Temporary Internet Files cache folder defined!
->Java cache emptied: 90721460 bytes
->FireFox cache emptied: 171772734 bytes
->Google Chrome cache emptied: 6323524 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 57646 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
Error loading Shell32.dll! Cannot empty RecycleBin.
RecycleBin emptied: 1981114 bytes

Total Files Cleaned = 886.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 10282011_075024

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8040 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 10/29/2011 8:29:10 AM mbam-log-2011-10-29 (08-29-10).txt Scan type: Quick scan Objects scanned: 188063 Time elapsed: 5 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Are both Firefox and Internet Explorer giving you problems or is it just one of them ?



ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Thanks for all of your help Ken. There was nothing detected when I ran the scan you asked me to run above. For whatever reason, it didn't offer a log as suggested, but nothing was found regardless. Both browsers are slow and freeze quite a bit. Whether it's important or not, I am not sure… but the Windows calculator is gone and cannot even find with a search… other windows items seem to be missing as well. Kind regards, Rich
Lets try this

Did you lose only the shortcut to the program in Accessories, or did the program itself disappear? The program is called calc (calc.exe) and it's in c:\windows\system32.

Did you look in the recycle bin?

Does it run if you type calc in the start>run-box (+ OK)?


Lets run system file checker, this will replace any missing or corrupted system files

Open an elevated command prompt.
To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
Type the following command, and then press ENTER:
sfc /scannow
calc.exe worked. Just missing from accessories, like paint and a few others. As for the browsers… it's miserable. Mostly notice freezing in Foxfire (up to date version) Thank you…
Did you run System File Checker ?

I am looking over your logs and see a couple of questionable files, lets do this


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
yes, ran sfc…


ComboFix 11-10-30.03 - Richie 10/30/2011 21:51:01.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3327.2107 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-31 )))))))))))))))))))))))))))))))
.
.
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Richie\AppData\Local\temp
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-30 16:33 . 2011-10-30 16:33 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\MpKslcbfe7afd.sys ERROR(0x00000005)
2011-10-30 16:33 . 2011-10-30 16:33 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\offreg.dll ERROR(0x00000005)
2011-10-30 15:29 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\mpengine.dll ERROR(0x00000005)
2011-10-28 13:25 . 2011-10-28 13:25 ——– d—–w- c:\users\Richie\AppData\Local\WinZip Courier
2011-10-28 11:50 . 2011-10-28 11:50 ——– d—–w- C:\_OTL
2011-10-28 04:36 . 2011-10-28 04:36 ——– d—–w- c:\users\Richie\AppData\Local\WinZip
2011-10-28 04:36 . 2011-10-28 04:36 ——– d—–w- c:\program files\WinZip Courier
2011-10-25 11:27 . 2011-10-27 13:10 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 02:45 . 2011-10-30 16:17 ——– d—–w- c:\program files\Real
2011-10-22 21:41 . 2011-10-22 21:41 ——– d—–w- c:\users\Richie\AppData\Roaming\Windows Live Writer
2011-10-22 21:41 . 2011-10-22 21:42 ——– d—–w- c:\users\Richie\AppData\Local\Windows Live Writer
2011-10-21 07:05 . 2011-10-21 07:05 222536 —-a-r- c:\windows\tabctl32.ocx
2011-10-16 15:24 . 2011-10-16 15:24 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\Intuit
2011-10-16 12:20 . 2011-10-16 12:34 ——– d—–w- c:\users\Richie\AppData\Local\Intuit
2011-10-16 12:13 . 2011-10-16 12:14 ——– d—–w- c:\program files\Common Files\Intuit
2011-10-16 12:13 . 2011-10-16 12:13 ——– d—–w- c:\program files\Intuit
2011-10-16 12:07 . 2011-10-16 12:07 ——– d—–w- c:\windows\Intuit
2011-10-16 11:10 . 2011-10-16 11:10 ——– d—–w- c:\users\Richie\AppData\Roaming\Download Manager
2011-10-16 11:10 . 2011-10-16 12:06 ——– d—–w- c:\windows\Download Manager
2011-10-16 11:10 . 2011-10-16 11:10 ——– d—–w- c:\program files\Akamai
2011-10-15 23:03 . 2011-10-30 16:33 ——– d—–w- c:\program files\Common Files\Akamai
2011-10-13 09:48 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 09:48 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 09:48 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 09:48 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 09:48 . 2011-09-14 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-10-13 09:48 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 09:48 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 09:48 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 09:48 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 09:48 . 2011-09-06 13:30 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-10-11 15:21 . 2011-10-11 15:20 703824 ——w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46068300-8D16-4520-BA18-F889A5314EE7}\gapaengine.dll ERROR(0x00000005)
2011-10-01 07:01 . 2011-08-12 02:44 7152464 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll ERROR(0x00000005)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 02:46 . 2009-02-11 16:25 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-10-24 02:46 . 2009-02-11 16:25 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-10-07 03:48 . 2011-06-30 20:53 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)
2011-09-24 03:45 . 2011-09-24 03:45 709968 —-a-w- c:\windows\is-ALUS6.exe
2011-09-01 02:08 . 2011-09-01 02:08 53248 —-a-r- c:\users\Richie\AppData\Roaming\Microsoft\Installer\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}\ARPPRODUCTICON.exe
2011-08-31 21:00 . 2009-03-14 11:47 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-03-24 22:59 . 2009-03-24 22:59 81408 —-a-w- c:\program files\taskkill.exe
2011-10-05 10:12 . 2011-05-06 10:09 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-15 39408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-07-14 639352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"InnoSetupRegFile.0000000001"="c:\windows\is-ALUS6.exe" [2011-09-24 709968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-09-09 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan.lnk]
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^AutoBackup Launcher.lnk]
backup=c:\windows\pss\AutoBackup Launcher.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled
backup=c:\windows\pss\Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk.disabled]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk.disabled
backup=c:\windows\pss\Desktop Manager.lnk.disabled.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 16:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 07:44 500208 ——w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 4]
2011-08-09 20:56 417112 —-a-w- c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2009-02-11 16:25 50472 —-a-w- c:\program files\AOL 9.5\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Artisan 810]
2009-02-23 10:00 199680 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIFRA.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2009-01-12 13:54 669520 ——w- c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etMonitor]
2007-09-19 12:03 102400 —-a-w- c:\windows\etMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
2009-02-06 04:00 843776 —-a-w- c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 22:36 30040 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 01:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]
2011-06-14 09:18 1527128 —-a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
2011-10-08 21:34 4441944 —-a-w- c:\program files\IObit\IObit Malware Fighter\IMF.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 13:14 206112 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-14 15:32 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTurnsPro]
2009-05-04 22:19 3436544 —-a-w- c:\program files\iTurnsPro\iTurnsPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-09 02:17 52256 —-a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-06-17 16:13 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCQCATS]
2006-11-21 08:27 106496 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\lxcqtime.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-08-31 21:00 1047208 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-07-17 16:12 288080 —-a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 19:16 997920 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-01-08 01:06 3597416 —-a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-01-08 01:06 111208 —-a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-15 01:01 71216 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 15:47 79192 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StereoLinksInstall]
2011-01-07 23:49 751208 —-a-w- c:\program files\NVIDIA Corporation\3D Vision\nvstlink.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-10-29 02:43 4615552 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-02-15 06:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify]
2009-11-02 18:17 430808 —-a-w- c:\program files\TiVo\Desktop\TiVoNotify.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer]
2009-11-02 18:17 2195160 —-a-w- c:\program files\TiVo\Desktop\TiVoServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoTransfer]
2009-11-02 18:17 604888 —-a-w- c:\program files\TiVo\Desktop\TiVoTransfer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolBoxFX]
2008-01-10 16:13 53248 —-a-w- c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TranscodingService]
2009-11-02 18:17 856280 —-a-w- c:\program files\TiVo\Desktop\Plus\TranscodingService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-07-14 02:23 639352 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"uTorrent"="c:\program files\uTorrent\uTorrent.exe"
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" start
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3072224684-2609516342-2026002776-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3072224684-2609516342-2026002776-500]
"EnableNotificationsRef"=dword:00000001
.
R1 MpKsl3ce342d6;MpKsl3ce342d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9FBD1987-DCD4-4F82-BD5F-07981EFEAE7D}\MpKsl3ce342d6.sys [x]
R1 MpKsl58e472e6;MpKsl58e472e6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1ACAFC42-E1DB-4C4A-80DA-B407EB390205}\MpKsl58e472e6.sys [x]
R1 MpKsl6b8edaa0;MpKsl6b8edaa0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7FED05D4-2454-4700-B0AC-AE5DA6D32270}\MpKsl6b8edaa0.sys [x]
R1 MpKslb7e76aad;MpKslb7e76aad;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1E76E570-0D43-40C6-ABD6-F2030C3374DE}\MpKslb7e76aad.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2011-03-25 23456]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2007-07-17 20504]
R3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2010-01-21 836384]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys [2011-09-20 30600]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-19 12872]
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2010-04-13 23096]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wlh_x86\UrlFilter.sys [2011-09-20 19792]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2010-08-23 223128]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-04-11 19968]
R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-09-09 116608]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
R4 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys [2011-10-08 18768]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 133104]
R4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 133104]
R4 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-10-08 820568]
R4 lxcq_device;lxcq_device;c:\windows\system32\lxcqcoms.exe [2006-12-05 537520]
R4 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-06-30 1248256]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R4 TivoBeacon2;TiVo Beacon Service;c:\program files\TiVo\Desktop\TiVoBeacon.exe [2009-11-02 1098968]
R4 VService;ECS Button Volume Control Service;c:\program files\VService\VService.exe [2008-05-19 65536]
S1 MpKslcbfe7afd;MpKslcbfe7afd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\MpKslcbfe7afd.sys [2011-10-30 28752]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-09-09 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2011-09-09 67664]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 msftesql$SQLEXPRESS;SQL Server FullText Search (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [2010-03-26 91992]
S2 PfFilter;PfFilter;c:\program files\IObit\Protected Folder\pffilter.sys [2011-03-16 32672]
S3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\DRIVERS\AVerBDA716x.sys [2008-03-13 932864]
S3 DCamUSBET;ET USB 2751 Camera;c:\windows\system32\DRIVERS\etDevice.sys [2008-02-29 131712]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2007-01-05 183168]
S3 iTurns;iTurns;c:\windows\system32\DRIVERS\iTurnsDriver.sys [2008-11-28 10704]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2007-09-07 6656]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLCBFE7AFD
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
rsmsvcs REG_MULTI_SZ ntmssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 16:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 17:14]
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 17:14]
.
2009-10-02 c:\windows\Tasks\User_Feed_Synchronization-{62B76A38-41CF-4814-99F8-09384E6752E0}.job
- c:\windows\system32\msfeedssync.exe [2011-04-01 00:55]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: morganstanleyclientserv.com\www
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\Richie\AppData\Roaming\Mozilla\Firefox\Profiles\jad3mhtm.default\
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-30 21:59
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql$SQLEXPRESS]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:SQLEXPRESS"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{593DDEC6-7468-4CDD-90E1-42DADAA222E9}"=hex:51,66,7a,6c,4c,1d,38,12,a8,dd,2e,
5d,5a,3a,b3,09,ef,f7,01,9a,df,fc,66,fd
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}"=hex:51,66,7a,6c,4c,1d,38,12,2e,fd,ed,
e4,cb,b5,c0,07,c5,4e,3a,0c,a2,bd,bf,47
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,
36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:40,34,7f,32,20,91,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,5e,58,29,fe,a1,59,4a,8d,99,05,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,5e,58,29,fe,a1,59,4a,8d,99,05,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-10-30 22:02:44
ComboFix-quarantined-files.txt 2011-10-31 02:02
ComboFix2.txt 2011-10-26 04:11
ComboFix3.txt 2011-04-26 23:08
ComboFix4.txt 2011-03-06 14:02
ComboFix5.txt 2011-10-31 01:49
.
Pre-Run: 157,689,552,896 bytes free
Post-Run: 158,327,185,408 bytes free
.
- - End Of File - - B5862CC4813546402B8A64409B00FD48
yes, ran sfc…


ComboFix 11-10-30.03 - Richie 10/30/2011 21:51:01.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3327.2107 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-31 )))))))))))))))))))))))))))))))
.
.
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Richie\AppData\Local\temp
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-30 16:33 . 2011-10-30 16:33 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\MpKslcbfe7afd.sys ERROR(0x00000005)
2011-10-30 16:33 . 2011-10-30 16:33 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\offreg.dll ERROR(0x00000005)
2011-10-30 15:29 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\mpengine.dll ERROR(0x00000005)
2011-10-28 13:25 . 2011-10-28 13:25 ——– d—–w- c:\users\Richie\AppData\Local\WinZip Courier
2011-10-28 11:50 . 2011-10-28 11:50 ——– d—–w- C:\_OTL
2011-10-28 04:36 . 2011-10-28 04:36 ——– d—–w- c:\users\Richie\AppData\Local\WinZip
2011-10-28 04:36 . 2011-10-28 04:36 ——– d—–w- c:\program files\WinZip Courier
2011-10-25 11:27 . 2011-10-27 13:10 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 02:45 . 2011-10-30 16:17 ——– d—–w- c:\program files\Real
2011-10-22 21:41 . 2011-10-22 21:41 ——– d—–w- c:\users\Richie\AppData\Roaming\Windows Live Writer
2011-10-22 21:41 . 2011-10-22 21:42 ——– d—–w- c:\users\Richie\AppData\Local\Windows Live Writer
2011-10-21 07:05 . 2011-10-21 07:05 222536 —-a-r- c:\windows\tabctl32.ocx
2011-10-16 15:24 . 2011-10-16 15:24 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\Intuit
2011-10-16 12:20 . 2011-10-16 12:34 ——– d—–w- c:\users\Richie\AppData\Local\Intuit
2011-10-16 12:13 . 2011-10-16 12:14 ——– d—–w- c:\program files\Common Files\Intuit
2011-10-16 12:13 . 2011-10-16 12:13 ——– d—–w- c:\program files\Intuit
2011-10-16 12:07 . 2011-10-16 12:07 ——– d—–w- c:\windows\Intuit
2011-10-16 11:10 . 2011-10-16 11:10 ——– d—–w- c:\users\Richie\AppData\Roaming\Download Manager
2011-10-16 11:10 . 2011-10-16 12:06 ——– d—–w- c:\windows\Download Manager
2011-10-16 11:10 . 2011-10-16 11:10 ——– d—–w- c:\program files\Akamai
2011-10-15 23:03 . 2011-10-30 16:33 ——– d—–w- c:\program files\Common Files\Akamai
2011-10-13 09:48 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 09:48 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 09:48 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 09:48 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 09:48 . 2011-09-14 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-10-13 09:48 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 09:48 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 09:48 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 09:48 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 09:48 . 2011-09-06 13:30 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-10-11 15:21 . 2011-10-11 15:20 703824 ——w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46068300-8D16-4520-BA18-F889A5314EE7}\gapaengine.dll ERROR(0x00000005)
2011-10-01 07:01 . 2011-08-12 02:44 7152464 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll ERROR(0x00000005)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 02:46 . 2009-02-11 16:25 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-10-24 02:46 . 2009-02-11 16:25 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-10-07 03:48 . 2011-06-30 20:53 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)
2011-09-24 03:45 . 2011-09-24 03:45 709968 —-a-w- c:\windows\is-ALUS6.exe
2011-09-01 02:08 . 2011-09-01 02:08 53248 —-a-r- c:\users\Richie\AppData\Roaming\Microsoft\Installer\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}\ARPPRODUCTICON.exe
2011-08-31 21:00 . 2009-03-14 11:47 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-03-24 22:59 . 2009-03-24 22:59 81408 —-a-w- c:\program files\taskkill.exe
2011-10-05 10:12 . 2011-05-06 10:09 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-15 39408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-07-14 639352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"InnoSetupRegFile.0000000001"="c:\windows\is-ALUS6.exe" [2011-09-24 709968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-09-09 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan.lnk]
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^AutoBackup Launcher.lnk]
backup=c:\windows\pss\AutoBackup Launcher.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled
backup=c:\windows\pss\Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk.disabled]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk.disabled
backup=c:\windows\pss\Desktop Manager.lnk.disabled.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 16:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 07:44 500208 ——w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 4]
2011-08-09 20:56 417112 —-a-w- c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2009-02-11 16:25 50472 —-a-w- c:\program files\AOL 9.5\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Artisan 810]
2009-02-23 10:00 199680 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIFRA.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2009-01-12 13:54 669520 ——w- c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etMonitor]
2007-09-19 12:03 102400 —-a-w- c:\windows\etMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
2009-02-06 04:00 843776 —-a-w- c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 22:36 30040 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 01:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]
2011-06-14 09:18 1527128 —-a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
2011-10-08 21:34 4441944 —-a-w- c:\program files\IObit\IObit Malware Fighter\IMF.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 13:14 206112 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-14 15:32 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTurnsPro]
2009-05-04 22:19 3436544 —-a-w- c:\program files\iTurnsPro\iTurnsPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-09 02:17 52256 —-a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-06-17 16:13 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCQCATS]
2006-11-21 08:27 106496 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\lxcqtime.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-08-31 21:00 1047208 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-07-17 16:12 288080 —-a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 19:16 997920 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-01-08 01:06 3597416 —-a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-01-08 01:06 111208 —-a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-15 01:01 71216 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 15:47 79192 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StereoLinksInstall]
2011-01-07 23:49 751208 —-a-w- c:\program files\NVIDIA Corporation\3D Vision\nvstlink.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-10-29 02:43 4615552 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-02-15 06:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify]
2009-11-02 18:17 430808 —-a-w- c:\program files\TiVo\Desktop\TiVoNotify.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer]
2009-11-02 18:17 2195160 —-a-w- c:\program files\TiVo\Desktop\TiVoServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoTransfer]
2009-11-02 18:17 604888 —-a-w- c:\program files\TiVo\Desktop\TiVoTransfer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolBoxFX]
2008-01-10 16:13 53248 —-a-w- c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TranscodingService]
2009-11-02 18:17 856280 —-a-w- c:\program files\TiVo\Desktop\Plus\TranscodingService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-07-14 02:23 639352 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"uTorrent"="c:\program files\uTorrent\uTorrent.exe"
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" start
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3072224684-2609516342-2026002776-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3072224684-2609516342-2026002776-500]
"EnableNotificationsRef"=dword:00000001
.
R1 MpKsl3ce342d6;MpKsl3ce342d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9FBD1987-DCD4-4F82-BD5F-07981EFEAE7D}\MpKsl3ce342d6.sys [x]
R1 MpKsl58e472e6;MpKsl58e472e6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1ACAFC42-E1DB-4C4A-80DA-B407EB390205}\MpKsl58e472e6.sys [x]
R1 MpKsl6b8edaa0;MpKsl6b8edaa0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7FED05D4-2454-4700-B0AC-AE5DA6D32270}\MpKsl6b8edaa0.sys [x]
R1 MpKslb7e76aad;MpKslb7e76aad;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1E76E570-0D43-40C6-ABD6-F2030C3374DE}\MpKslb7e76aad.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2011-03-25 23456]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2007-07-17 20504]
R3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2010-01-21 836384]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys [2011-09-20 30600]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-19 12872]
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2010-04-13 23096]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wlh_x86\UrlFilter.sys [2011-09-20 19792]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2010-08-23 223128]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-04-11 19968]
R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-09-09 116608]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
R4 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys [2011-10-08 18768]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 133104]
R4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 133104]
R4 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-10-08 820568]
R4 lxcq_device;lxcq_device;c:\windows\system32\lxcqcoms.exe [2006-12-05 537520]
R4 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-06-30 1248256]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R4 TivoBeacon2;TiVo Beacon Service;c:\program files\TiVo\Desktop\TiVoBeacon.exe [2009-11-02 1098968]
R4 VService;ECS Button Volume Control Service;c:\program files\VService\VService.exe [2008-05-19 65536]
S1 MpKslcbfe7afd;MpKslcbfe7afd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\MpKslcbfe7afd.sys [2011-10-30 28752]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-09-09 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2011-09-09 67664]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 msftesql$SQLEXPRESS;SQL Server FullText Search (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [2010-03-26 91992]
S2 PfFilter;PfFilter;c:\program files\IObit\Protected Folder\pffilter.sys [2011-03-16 32672]
S3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\DRIVERS\AVerBDA716x.sys [2008-03-13 932864]
S3 DCamUSBET;ET USB 2751 Camera;c:\windows\system32\DRIVERS\etDevice.sys [2008-02-29 131712]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2007-01-05 183168]
S3 iTurns;iTurns;c:\windows\system32\DRIVERS\iTurnsDriver.sys [2008-11-28 10704]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2007-09-07 6656]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLCBFE7AFD
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
rsmsvcs REG_MULTI_SZ ntmssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 16:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 17:14]
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 17:14]
.
2009-10-02 c:\windows\Tasks\User_Feed_Synchronization-{62B76A38-41CF-4814-99F8-09384E6752E0}.job
- c:\windows\system32\msfeedssync.exe [2011-04-01 00:55]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: morganstanleyclientserv.com\www
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\Richie\AppData\Roaming\Mozilla\Firefox\Profiles\jad3mhtm.default\
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-30 21:59
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql$SQLEXPRESS]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:SQLEXPRESS"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{593DDEC6-7468-4CDD-90E1-42DADAA222E9}"=hex:51,66,7a,6c,4c,1d,38,12,a8,dd,2e,
5d,5a,3a,b3,09,ef,f7,01,9a,df,fc,66,fd
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}"=hex:51,66,7a,6c,4c,1d,38,12,2e,fd,ed,
e4,cb,b5,c0,07,c5,4e,3a,0c,a2,bd,bf,47
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,
36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:40,34,7f,32,20,91,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,5e,58,29,fe,a1,59,4a,8d,99,05,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,5e,58,29,fe,a1,59,4a,8d,99,05,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-10-30 22:02:44
ComboFix-quarantined-files.txt 2011-10-31 02:02
ComboFix2.txt 2011-10-26 04:11
ComboFix3.txt 2011-04-26 23:08
ComboFix4.txt 2011-03-06 14:02
ComboFix5.txt 2011-10-31 01:49
.
Pre-Run: 157,689,552,896 bytes free
Post-Run: 158,327,185,408 bytes free
.
- - End Of File - - B5862CC4813546402B8A64409B00FD48
yes, ran sfc…


ComboFix 11-10-30.03 - Richie 10/30/2011 21:51:01.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3327.2107 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-31 )))))))))))))))))))))))))))))))
.
.
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Richie\AppData\Local\temp
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-10-31 01:59 . 2011-10-31 01:59 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-30 16:33 . 2011-10-30 16:33 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\MpKslcbfe7afd.sys ERROR(0x00000005)
2011-10-30 16:33 . 2011-10-30 16:33 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\offreg.dll ERROR(0x00000005)
2011-10-30 15:29 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\mpengine.dll ERROR(0x00000005)
2011-10-28 13:25 . 2011-10-28 13:25 ——– d—–w- c:\users\Richie\AppData\Local\WinZip Courier
2011-10-28 11:50 . 2011-10-28 11:50 ——– d—–w- C:\_OTL
2011-10-28 04:36 . 2011-10-28 04:36 ——– d—–w- c:\users\Richie\AppData\Local\WinZip
2011-10-28 04:36 . 2011-10-28 04:36 ——– d—–w- c:\program files\WinZip Courier
2011-10-25 11:27 . 2011-10-27 13:10 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 02:45 . 2011-10-30 16:17 ——– d—–w- c:\program files\Real
2011-10-22 21:41 . 2011-10-22 21:41 ——– d—–w- c:\users\Richie\AppData\Roaming\Windows Live Writer
2011-10-22 21:41 . 2011-10-22 21:42 ——– d—–w- c:\users\Richie\AppData\Local\Windows Live Writer
2011-10-21 07:05 . 2011-10-21 07:05 222536 —-a-r- c:\windows\tabctl32.ocx
2011-10-16 15:24 . 2011-10-16 15:24 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\Intuit
2011-10-16 12:20 . 2011-10-16 12:34 ——– d—–w- c:\users\Richie\AppData\Local\Intuit
2011-10-16 12:13 . 2011-10-16 12:14 ——– d—–w- c:\program files\Common Files\Intuit
2011-10-16 12:13 . 2011-10-16 12:13 ——– d—–w- c:\program files\Intuit
2011-10-16 12:07 . 2011-10-16 12:07 ——– d—–w- c:\windows\Intuit
2011-10-16 11:10 . 2011-10-16 11:10 ——– d—–w- c:\users\Richie\AppData\Roaming\Download Manager
2011-10-16 11:10 . 2011-10-16 12:06 ——– d—–w- c:\windows\Download Manager
2011-10-16 11:10 . 2011-10-16 11:10 ——– d—–w- c:\program files\Akamai
2011-10-15 23:03 . 2011-10-30 16:33 ——– d—–w- c:\program files\Common Files\Akamai
2011-10-13 09:48 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 09:48 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 09:48 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 09:48 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 09:48 . 2011-09-14 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-10-13 09:48 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 09:48 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 09:48 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 09:48 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 09:48 . 2011-09-06 13:30 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-10-11 15:21 . 2011-10-11 15:20 703824 ——w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46068300-8D16-4520-BA18-F889A5314EE7}\gapaengine.dll ERROR(0x00000005)
2011-10-01 07:01 . 2011-08-12 02:44 7152464 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll ERROR(0x00000005)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 02:46 . 2009-02-11 16:25 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-10-24 02:46 . 2009-02-11 16:25 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-10-07 03:48 . 2011-06-30 20:53 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)
2011-09-24 03:45 . 2011-09-24 03:45 709968 —-a-w- c:\windows\is-ALUS6.exe
2011-09-01 02:08 . 2011-09-01 02:08 53248 —-a-r- c:\users\Richie\AppData\Roaming\Microsoft\Installer\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}\ARPPRODUCTICON.exe
2011-08-31 21:00 . 2009-03-14 11:47 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-03-24 22:59 . 2009-03-24 22:59 81408 —-a-w- c:\program files\taskkill.exe
2011-10-05 10:12 . 2011-05-06 10:09 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-15 39408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-07-14 639352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"InnoSetupRegFile.0000000001"="c:\windows\is-ALUS6.exe" [2011-09-24 709968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-09-09 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan.lnk]
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^AutoBackup Launcher.lnk]
backup=c:\windows\pss\AutoBackup Launcher.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled
backup=c:\windows\pss\Canon IJ Status Monitor Canon MX860 series Printer (Copy 2).lnk.disabled.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk.disabled]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk.disabled
backup=c:\windows\pss\Desktop Manager.lnk.disabled.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Richie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Richie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 16:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 07:44 500208 ——w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 4]
2011-08-09 20:56 417112 —-a-w- c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2009-02-11 16:25 50472 —-a-w- c:\program files\AOL 9.5\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Artisan 810]
2009-02-23 10:00 199680 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIFRA.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2009-01-12 13:54 669520 ——w- c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etMonitor]
2007-09-19 12:03 102400 —-a-w- c:\windows\etMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
2009-02-06 04:00 843776 —-a-w- c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 22:36 30040 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 01:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]
2011-06-14 09:18 1527128 —-a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
2011-10-08 21:34 4441944 —-a-w- c:\program files\IObit\IObit Malware Fighter\IMF.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 13:14 206112 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-14 15:32 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTurnsPro]
2009-05-04 22:19 3436544 —-a-w- c:\program files\iTurnsPro\iTurnsPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-09 02:17 52256 —-a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-06-17 16:13 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCQCATS]
2006-11-21 08:27 106496 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\lxcqtime.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-08-31 21:00 1047208 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-07-17 16:12 288080 —-a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 19:16 997920 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-01-08 01:06 3597416 —-a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-01-08 01:06 111208 —-a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-15 01:01 71216 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 15:47 79192 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StereoLinksInstall]
2011-01-07 23:49 751208 —-a-w- c:\program files\NVIDIA Corporation\3D Vision\nvstlink.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-10-29 02:43 4615552 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-02-15 06:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify]
2009-11-02 18:17 430808 —-a-w- c:\program files\TiVo\Desktop\TiVoNotify.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer]
2009-11-02 18:17 2195160 —-a-w- c:\program files\TiVo\Desktop\TiVoServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoTransfer]
2009-11-02 18:17 604888 —-a-w- c:\program files\TiVo\Desktop\TiVoTransfer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolBoxFX]
2008-01-10 16:13 53248 —-a-w- c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TranscodingService]
2009-11-02 18:17 856280 —-a-w- c:\program files\TiVo\Desktop\Plus\TranscodingService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-07-14 02:23 639352 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"uTorrent"="c:\program files\uTorrent\uTorrent.exe"
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" start
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3072224684-2609516342-2026002776-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3072224684-2609516342-2026002776-500]
"EnableNotificationsRef"=dword:00000001
.
R1 MpKsl3ce342d6;MpKsl3ce342d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9FBD1987-DCD4-4F82-BD5F-07981EFEAE7D}\MpKsl3ce342d6.sys [x]
R1 MpKsl58e472e6;MpKsl58e472e6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1ACAFC42-E1DB-4C4A-80DA-B407EB390205}\MpKsl58e472e6.sys [x]
R1 MpKsl6b8edaa0;MpKsl6b8edaa0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7FED05D4-2454-4700-B0AC-AE5DA6D32270}\MpKsl6b8edaa0.sys [x]
R1 MpKslb7e76aad;MpKslb7e76aad;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1E76E570-0D43-40C6-ABD6-F2030C3374DE}\MpKslb7e76aad.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2011-03-25 23456]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2007-07-17 20504]
R3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2010-01-21 836384]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys [2011-09-20 30600]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-19 12872]
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2010-04-13 23096]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wlh_x86\UrlFilter.sys [2011-09-20 19792]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2010-08-23 223128]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-04-11 19968]
R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-09-09 116608]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
R4 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys [2011-10-08 18768]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 133104]
R4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 133104]
R4 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-10-08 820568]
R4 lxcq_device;lxcq_device;c:\windows\system32\lxcqcoms.exe [2006-12-05 537520]
R4 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-06-30 1248256]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R4 TivoBeacon2;TiVo Beacon Service;c:\program files\TiVo\Desktop\TiVoBeacon.exe [2009-11-02 1098968]
R4 VService;ECS Button Volume Control Service;c:\program files\VService\VService.exe [2008-05-19 65536]
S1 MpKslcbfe7afd;MpKslcbfe7afd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{043CBDBB-F613-4C7F-8D01-4BEC96038ABE}\MpKslcbfe7afd.sys [2011-10-30 28752]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-09-09 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2011-09-09 67664]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 msftesql$SQLEXPRESS;SQL Server FullText Search (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [2010-03-26 91992]
S2 PfFilter;PfFilter;c:\program files\IObit\Protected Folder\pffilter.sys [2011-03-16 32672]
S3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\DRIVERS\AVerBDA716x.sys [2008-03-13 932864]
S3 DCamUSBET;ET USB 2751 Camera;c:\windows\system32\DRIVERS\etDevice.sys [2008-02-29 131712]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2007-01-05 183168]
S3 iTurns;iTurns;c:\windows\system32\DRIVERS\iTurnsDriver.sys [2008-11-28 10704]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2007-09-07 6656]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLCBFE7AFD
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
rsmsvcs REG_MULTI_SZ ntmssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 16:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 17:14]
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 17:14]
.
2009-10-02 c:\windows\Tasks\User_Feed_Synchronization-{62B76A38-41CF-4814-99F8-09384E6752E0}.job
- c:\windows\system32\msfeedssync.exe [2011-04-01 00:55]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: morganstanleyclientserv.com\www
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\Richie\AppData\Roaming\Mozilla\Firefox\Profiles\jad3mhtm.default\
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-30 21:59
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql$SQLEXPRESS]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:SQLEXPRESS"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{593DDEC6-7468-4CDD-90E1-42DADAA222E9}"=hex:51,66,7a,6c,4c,1d,38,12,a8,dd,2e,
5d,5a,3a,b3,09,ef,f7,01,9a,df,fc,66,fd
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}"=hex:51,66,7a,6c,4c,1d,38,12,2e,fd,ed,
e4,cb,b5,c0,07,c5,4e,3a,0c,a2,bd,bf,47
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,
36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:40,34,7f,32,20,91,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,5e,58,29,fe,a1,59,4a,8d,99,05,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,5e,58,29,fe,a1,59,4a,8d,99,05,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-10-30 22:02:44
ComboFix-quarantined-files.txt 2011-10-31 02:02
ComboFix2.txt 2011-10-26 04:11
ComboFix3.txt 2011-04-26 23:08
ComboFix4.txt 2011-03-06 14:02
ComboFix5.txt 2011-10-31 01:49
.
Pre-Run: 157,689,552,896 bytes free
Post-Run: 158,327,185,408 bytes free
.
- - End Of File - - B5862CC4813546402B8A64409B00FD48

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI