This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Bad Image OLEACC.dll virus?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

2 days ago I could not log on to my PC except in safe mode (although safe mode with netwroking was selected, no network icons were displayed). Everytime I tried, I got a message saying the file C:\windows\system32\oleacc.dll was not designed to run on windows, and a message saying bad image. From using a different PC I came to the conclusion that it could be due to Malware, especially when Norton failed to run. I managed to run RKill and Malware Bytes. This removed a long list of errors and since then I have been able to log on again. I have now completed a scan using OTL and was wondering if anyone would be kind enough to look at the files and see if all looks ok.
Thanks for your time.

Stu.

OTL logfile created on: 29/10/2011 21:48:03 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Newells\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.96 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 46.86% Memory free
6.14 Gb Paging File | 4.76 Gb Available in Paging File | 77.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.08 Gb Total Space | 140.37 Gb Free Space | 62.92% Space Free | Partition Type: NTFS
Drive E: | 9.77 Gb Total Space | 4.78 Gb Free Space | 49.00% Space Free | Partition Type: NTFS
Drive F: | 4.38 Gb Total Space | 4.20 Gb Free Space | 95.80% Space Free | Partition Type: UDF

Computer Name: NEWELLS-PC | User Name: Newells | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Newells\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_85b55258\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_85b55258\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe ()
PRC - C:\Program Files\Lexmark 5600-6600 Series\lxdumsdmon.exe ()
PRC - C:\Windows\System32\lxducoms.exe ( )
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
PRC - C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MenuSkinning\6328431763ab322e8901cf681d9fcda0\MenuSkinning.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\ad53176332c9cf83ffe257a4d6d45b6e\VistaBridgeLibrary.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DellDock\c372ceb9ec74a680c1cc2868f9c42626\DellDock.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\5f33d978c771d038171869203ce3c080\MyDock.Util.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Google\Quick Search Box\bin\1.2.1151.245\rlz.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VPrintOnline.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SpiffyExt.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VPrintOnlineHelper40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCom.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\KFx.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\Atlas.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\kpries40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocAcqMod.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\keml40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocCamBack.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocUpdateCheck.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaAdapter.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\AppCore.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaControls.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\IStorageMediaStore.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaCDBackup.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\UpdateChecker.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESSkin.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCliWicMDRW.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESEmail.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxXML2V.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxImV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxProcV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxZipV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxCmpV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxCommonV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxFFV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxBaseV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\KPCDInterface.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\areaifdll.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\DibLibIP.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaPrintOnline.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\Pcd.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\DXRawFormatHandler.esx ()
MOD - C:\Program Files\Lexmark Toolbar\resource.dll ()
MOD - C:\Program Files\Lexmark Toolbar\toolband.dll ()
MOD - C:\Windows\System32\bcmwlrmt.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\lxdumsdmon.exe ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\lxducaps.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\lxduscw.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\lxdudrs.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\lxducnv4.dll ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\lxdudatr.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\app4r.monitor.core.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\app4r.monitor.common.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files\Lexmark 5600-6600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files\CyberLink\Power2Go\P2GRC.dll ()
MOD - C:\Program Files\CyberLink\Power2Go\CLVistaAudioMixer.dll ()
MOD - C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe ()


========== Win32 Services (SafeList) ==========

SRV - (DeviceMonitorService) – C:\Program Files\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (N360) – C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_85b55258\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_85b55258\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (lxdu_device) – C:\Windows\System32\lxducoms.exe ( )
SRV - (lxduCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe ()
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111014.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111028.030\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111028.034\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111028.034\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (PCDSRVC{E9D79540-57D5953E-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (motusbdevice) – C:\Windows\System32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (Motousbnet) – C:\Windows\System32\drivers\Motousbnet.sys (Motorola)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (BTCFilterService) – C:\Windows\System32\drivers\motfilt.sys (Motorola Inc)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (seehcri) – C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (MotoSwitchService) – C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=2081118
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Guffins.com/Plugin: C:\Program Files\Guffins\bar\1.bin\NPu4Stub.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/09/28 07:14:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_2_3 [2011/10/29 20:08:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/09/26 20:28:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Guffins\bar\1.bin [2011/10/28 06:44:32 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Newells\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\Guffins\bar\1.bin\NPu4Stub.dll
CHR - plugin: My Web Search Plugin Stub (Enabled) = C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Newells\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2_0\
CHR - Extension: SiteAdvisor = C:\Users\Newells\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Guffins) - {de2fdf7c-2637-4ba3-b427-3fce2d331db5} - C:\Program Files\Guffins\bar\1.bin\u4bar.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter File not found
O4 - HKLM..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe File not found
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Lexmark 5600-6600 Series Fax Server] C:\Program Files\Lexmark 5600-6600 Series\fm3032.exe ()
O4 - HKLM..\Run: [lxduamon] C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe ()
O4 - HKLM..\Run: [lxdumon.exe] C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Boots Insert Detect] C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe ()
O4 - HKCU..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - Startup: C:\Users\Newells\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = File not found
O4 - Startup: C:\Users\Newells\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {76392179-60A8-462D-8961-B95C14DAADF4} https://billcentre.vodafone.co.uk/bpa/conte…printengine.cab (PrintEngine ActiveX Control v4.2)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1176E70E-1768-4414-8844-7570BF2D40C6}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{153CF26D-8156-449D-8013-C226750FA89A}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Newells\Pictures\2009-2010\100_0964.JPG
O24 - Desktop BackupWallPaper: C:\Users\Newells\Pictures\2009-2010\100_0964.JPG
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{b5916971-6403-11e0-84cb-0023ae03b552}\Shell - "" = AutoRun
O33 - MountPoints2\{b5916971-6403-11e0-84cb-0023ae03b552}\Shell\AutoRun\command - "" = D:\setup.exe -a
O33 - MountPoints2\{d0b271f9-6fc5-11df-b1f1-0023ae03b552}\Shell\AutoRun\command - "" = D:\Get_Started_for_Win.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.clmp3enc - C:\Program Files\CyberLink\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/27 23:01:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/27 23:01:00 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/10/27 23:01:00 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/27 22:18:42 | 000,000,000 | —D | C] – C:\Users\Newells\AppData\Roaming\Malwarebytes
[2011/10/27 22:18:42 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/27 21:03:08 | 000,000,000 | —D | C] – C:\Windows\pss
[2011/10/26 21:31:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/10/26 21:30:59 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/10/26 21:24:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/26 21:23:25 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/26 21:23:23 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/26 21:14:34 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/24 14:29:02 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2011/10/24 14:29:02 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2011/10/20 15:21:54 | 000,000,000 | —D | C] – C:\Users\Newells\AppData\Roaming\motorola
[2011/10/20 15:21:40 | 000,000,000 | —D | C] – C:\Users\Newells\Documents\MotorolaMediaLink
[2011/10/20 14:57:53 | 000,000,000 | —D | C] – C:\Users\Newells\Documents\Podcast
[2011/10/20 14:57:49 | 000,000,000 | —D | C] – C:\ProgramData\Motorola Media Link
[2011/10/20 14:48:03 | 000,000,000 | —D | C] – C:\Users\Newells\AppData\Local\Motorola
[2011/10/20 14:47:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Motorola Media Link
[2011/10/20 14:47:22 | 000,000,000 | —D | C] – C:\Binaries
[2011/10/20 14:47:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nero
[2011/10/20 14:47:02 | 000,000,000 | —D | C] – C:\ProgramData\Nero
[2011/10/20 14:47:02 | 000,000,000 | —D | C] – C:\Program Files\Motorola Media Link
[2011/10/20 14:46:59 | 000,000,000 | —D | C] – C:\ProgramData\Motorola
[2011/10/20 14:41:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Motorola
[2011/10/20 14:39:41 | 000,000,000 | —D | C] – C:\Users\Newells\AppData\Local\Downloaded Installations
[2011/10/14 22:40:18 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/10/14 22:40:17 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/10/14 22:40:16 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/10/14 22:40:16 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/10/14 22:40:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/10/13 08:36:00 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/10/13 08:35:59 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/10/13 08:35:59 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/10/13 08:35:59 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/10/13 08:35:58 | 002,043,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/10/13 08:35:47 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/10/13 08:35:47 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2008/12/29 23:04:38 | 000,438,272 | —- | C] ( ) – C:\Windows\System32\LXDUhcp.dll
[2008/12/29 23:04:37 | 000,851,968 | —- | C] ( ) – C:\Windows\System32\lxduusb1.dll
[2008/12/29 23:04:37 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxduinpa.dll
[2008/12/29 23:04:37 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxduiesc.dll
[2008/12/29 23:04:36 | 001,069,056 | —- | C] ( ) – C:\Windows\System32\lxduserv.dll
[2008/12/29 23:04:36 | 000,651,264 | —- | C] ( ) – C:\Windows\System32\lxdupmui.dll
[2008/12/29 23:04:36 | 000,577,536 | —- | C] ( ) – C:\Windows\System32\lxdulmpm.dll
[2008/12/29 23:04:35 | 000,679,936 | —- | C] ( ) – C:\Windows\System32\lxduhbn3.dll
[2008/12/29 23:04:35 | 000,328,360 | —- | C] ( ) – C:\Windows\System32\lxduih.exe
[2008/12/29 23:04:33 | 000,765,952 | —- | C] ( ) – C:\Windows\System32\lxducomc.dll
[2008/12/29 23:04:33 | 000,594,600 | —- | C] ( ) – C:\Windows\System32\lxducoms.exe
[2008/12/29 23:04:33 | 000,376,832 | —- | C] ( ) – C:\Windows\System32\lxducomm.dll
[2008/12/29 23:04:33 | 000,369,320 | —- | C] ( ) – C:\Windows\System32\lxducfg.exe
[150 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[150 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/29 21:53:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2011/10/29 21:46:59 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/10/29 21:29:15 | 000,000,019 | —- | M] () – C:\Windows\SoundConverter.INI
[2011/10/29 21:27:04 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/29 20:13:09 | 000,617,480 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/10/29 20:13:09 | 000,112,560 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/10/29 20:09:10 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/29 20:08:06 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/29 20:08:06 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/29 20:08:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/29 20:08:00 | 3181,760,512 | -HS- | M] () – C:\hiberfil.sys
[2011/10/27 23:01:03 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/27 21:56:19 | 000,005,386 | —- | M] () – C:\Users\Newells\AppData\Roaming\wklnhst.dat
[2011/10/27 21:04:01 | 000,295,832 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/10/27 13:02:05 | 000,002,627 | —- | M] () – C:\Users\Newells\Desktop\Microsoft Office Word 2007.lnk
[2011/10/26 21:59:25 | 000,001,245 | —- | M] () – C:\Windows\System32\mapisvc.inf
[2011/10/26 21:31:15 | 000,001,728 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/10/26 21:24:14 | 000,001,666 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/24 14:29:02 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2011/10/24 14:29:02 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2011/10/20 14:47:31 | 000,001,961 | —- | M] () – C:\Users\Public\Desktop\MOTOROLA MEDIA LINK.lnk
[2011/10/17 09:23:21 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/15 18:00:55 | 000,000,404 | —- | M] () – C:\Windows\tasks\EasyShare Registration Task.job
[2011/10/13 17:09:17 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2011/10/13 17:09:17 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2011/10/13 17:08:45 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01007.Wdf
[2011/10/13 17:08:35 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[150 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[150 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/29 21:29:15 | 000,000,019 | —- | C] () – C:\Windows\SoundConverter.INI
[2011/10/27 23:34:21 | 3181,760,512 | -HS- | C] () – C:\hiberfil.sys
[2011/10/27 23:01:03 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/27 13:01:59 | 000,002,627 | —- | C] () – C:\Users\Newells\Desktop\Microsoft Office Word 2007.lnk
[2011/10/26 21:31:14 | 000,001,728 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/10/26 21:24:14 | 000,001,666 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/20 14:47:30 | 000,001,961 | —- | C] () – C:\Users\Public\Desktop\MOTOROLA MEDIA LINK.lnk
[2011/10/13 17:09:17 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2011/10/13 17:09:17 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2011/10/13 17:08:45 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01007.Wdf
[2011/10/13 17:08:35 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2011/05/12 20:26:27 | 000,001,940 | —- | C] () – C:\Users\Newells\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/04/05 19:51:31 | 000,106,496 | —- | C] () – C:\Windows\System32\PixText.dll
[2009/10/21 16:47:12 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/10/21 16:47:12 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/01/15 22:01:14 | 000,005,972 | —- | C] () – C:\Users\Newells\AppData\Local\d3d9caps.dat
[2009/01/01 14:13:56 | 000,029,239 | —- | C] () – C:\Users\Newells\AppData\Roaming\UserTile.png
[2008/12/29 23:14:14 | 000,360,448 | —- | C] () – C:\Windows\System32\lxducoin.dll
[2008/12/29 23:10:47 | 000,040,960 | —- | C] () – C:\Windows\System32\lxduvs.dll
[2008/12/29 23:09:02 | 000,081,920 | —- | C] () – C:\Windows\System32\lxducaps.dll
[2008/12/29 23:09:01 | 001,036,288 | —- | C] () – C:\Windows\System32\lxdudrs.dll
[2008/12/29 23:09:01 | 000,069,632 | —- | C] () – C:\Windows\System32\lxducnv4.dll
[2008/12/29 23:08:45 | 000,045,056 | —- | C] () – C:\Windows\System32\LXDUPMON.DLL
[2008/12/29 23:08:45 | 000,032,768 | —- | C] () – C:\Windows\System32\LXDUFXPU.DLL
[2008/12/29 23:08:25 | 000,086,016 | —- | C] () – C:\Windows\System32\lxduoem.dll
[2008/12/29 23:06:44 | 000,000,044 | —- | C] () – C:\Windows\System32\lxdurwrd.ini
[2008/12/29 23:04:38 | 000,389,120 | —- | C] () – C:\Windows\System32\LXDUinst.dll
[2008/12/29 23:04:34 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdugrd.dll
[2008/12/29 22:54:15 | 000,086,016 | —- | C] () – C:\Users\Newells\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/29 22:42:47 | 000,005,386 | —- | C] () – C:\Users\Newells\AppData\Roaming\wklnhst.dat
[2008/11/18 14:00:16 | 002,192,024 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2008/11/18 14:00:16 | 000,492,496 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2008/11/18 14:00:16 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1489.dll
[2008/11/18 14:00:16 | 000,146,596 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/11/18 13:58:16 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/11/18 12:19:45 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2008/11/18 12:19:45 | 000,024,064 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2008/02/04 00:11:25 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,295,832 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,617,480 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,112,560 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2009/05/19 20:10:21 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\5600-6600 Series
[2009/09/07 14:47:58 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/09/19 16:11:29 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\GARMIN
[2011/04/06 11:09:57 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\HMRC
[2008/12/29 23:21:35 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\Lexmark Productivity Studio
[2011/10/20 15:21:54 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\motorola
[2011/09/10 16:14:11 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\Nokia
[2011/01/25 15:44:03 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\PCDr
[2009/06/10 18:42:03 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\Skinux
[2008/12/29 22:42:48 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\Template
[2011/05/19 08:45:59 | 000,000,000 | —D | M] – C:\Users\Newells\AppData\Roaming\Tific
[2011/10/15 18:00:55 | 000,000,404 | —- | M] () – C:\Windows\Tasks\EasyShare Registration Task.job
[2011/09/12 22:50:00 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/10/29 16:43:07 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/10/29 21:46:59 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/11/18 14:00:27 | 000,003,200 | RH– | M] () – C:\dell.sdr
[2011/10/29 20:08:00 | 3181,760,512 | -HS- | M] () – C:\hiberfil.sys
[2011/10/29 20:07:59 | 3495,571,456 | -HS- | M] () – C:\pagefile.sys
[2011/10/27 23:44:47 | 000,000,412 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/27 09:08:48 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2008/05/24 01:17:14 | 000,121,856 | —- | M] () – C:\Windows\system32\spool\prtprocs\w32x86\lxdudrpp.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 04:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/14 09:48:26 | 000,000,574 | -HS- | M] () – C:\Users\Newells\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/03 10:34:24 | 000,000,269 | —- | M] () – C:\Users\Newells\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Superdry.url

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-15 21:02:32

< End of report >


OTL Extras logfile created on: 29/10/2011 21:48:06 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Newells\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.96 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 46.86% Memory free
6.14 Gb Paging File | 4.76 Gb Available in Paging File | 77.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.08 Gb Total Space | 140.37 Gb Free Space | 62.92% Space Free | Partition Type: NTFS
Drive E: | 9.77 Gb Total Space | 4.78 Gb Free Space | 49.00% Space Free | Partition Type: NTFS
Drive F: | 4.38 Gb Total Space | 4.20 Gb Free Space | 95.80% Space Free | Partition Type: UDF

Computer Name: NEWELLS-PC | User Name: Newells | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1D789E49-B51E-4B02-BFE6-6ABB04DFC554}" = lport=445 | protocol=6 | dir=in | app=system |
"{21C45D5E-58D3-43DC-87ED-F08119418844}" = rport=445 | protocol=6 | dir=out | app=system |
"{3E6A0419-4520-4991-8913-016163BCC152}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4029A955-281A-4563-8F47-28CCE22F8AEE}" = rport=138 | protocol=17 | dir=out | app=system |
"{8FCD7E39-2F89-4DAC-A3E9-C4CD606B2782}" = lport=137 | protocol=17 | dir=in | app=system |
"{95748779-C214-4B11-A95F-735ADD85E6B5}" = rport=137 | protocol=17 | dir=out | app=system |
"{A9474692-8333-4C80-9B78-B7473409882E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AFB00193-8E18-48E3-ABE9-85D83FC8E9F8}" = rport=139 | protocol=6 | dir=out | app=system |
"{CC048812-04A9-4C91-A23F-5455336970DB}" = lport=138 | protocol=17 | dir=in | app=system |
"{D97413E0-9744-4085-BF7C-FC22B73F8DD3}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09893284-1A49-4AC4-8809-646DA135983F}" = protocol=17 | dir=in | app=c:\program files\lexmark 5600-6600 series\frun.exe |
"{1784ADBA-ADEE-4498-9181-A6F4EC8E26A9}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{1D23475B-B33C-482D-B834-FF51441FC272}" = protocol=6 | dir=in | app=c:\windows\system32\lxducoms.exe |
"{21CD9BF5-C320-4758-8E49-C9122158E4A2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{28DB27DD-2609-480A-BDD6-12A720AF56ED}" = protocol=6 | dir=in | app=c:\program files\lexmark 5600-6600 series\lxduamon.exe |
"{40E13CC6-F7C9-468F-9663-3ACFBBAB8076}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5BD4EC3A-B8C1-497C-9D39-2EAE9B07E8E2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{5E0A7460-6754-4DBA-8426-718621526429}" = protocol=17 | dir=in | app=c:\windows\system32\lxducoms.exe |
"{69DEDE5E-D49B-429A-8D38-385385C12785}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6FC26417-D187-4541-940A-6569322D3DF9}" = protocol=6 | dir=in | app=c:\program files\lexmark 5600-6600 series\frun.exe |
"{72DBBDEC-23C4-4692-8951-8A5E395B44E0}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{754A93A8-E00E-40F6-984B-CF0DA95CAFDE}" = protocol=6 | dir=in | app=c:\program files\lexmark 5600-6600 series\lxdufax.exe |
"{86618B7A-9627-4420-AA93-D9954D28B779}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{8845A1B4-283F-4B42-9B2A-2A95B481D5EC}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{8D9B4714-C426-4D35-BBE6-046686779E60}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8EC65198-18B8-4E12-8413-67809B3F3008}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{A6CCCB13-D04F-47AF-8440-BF18E422242A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A86DBD83-8958-4281-BAAA-888448A22CAD}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{C4385E5B-66FF-4AD2-AF0E-F88B0B09C311}" = protocol=17 | dir=in | app=c:\program files\lexmark 5600-6600 series\lxduamon.exe |
"{EEB18CDB-3980-431E-8EF7-93B649957A09}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{EFBCF2BA-1173-492D-9C17-7C62E7545FD1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{F1C07705-B27A-4146-9B61-6E82D1EB1BD6}" = protocol=17 | dir=in | app=c:\program files\lexmark 5600-6600 series\lxdufax.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0E5FDD1D-DCE8-4F9D-9BFD-4E4CF89811E2}" = iCloud
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D76A52C-87A6-4AB0-A7B0-08C8D5DF1D75}" = Motorola Mobile Drivers Installation 5.2.0
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{378397D6-FD32-4092-A854-6A75CB7EDA46}" = MOTOROLA MEDIA LINK
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}" = EDocs
"{6D3963B0-E13B-4FC3-B0FF-506A304BB043}" = Cisco EAP-FAST Module
"{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}" = MotoHelper MergeModules
"{6FFB40A5-7F7D-4A32-8905-3CDF962EE1E4}" = Internet From BT
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}" = MobileMe Control Panel
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{C39A4E1F-9AF1-4FE1-A80E-A5B867FABB42}" = Dell Best of Web
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F413B69D-4AD6-42AB-AEA5-0548989FAD50}" = Norton 360
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Basic PAYE Tools" = Basic PAYE Tools
"Boots F2CD Picture Suite" = Boots F2CD Picture Suite
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card Utility
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Support Center" = Dell Support Center
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"HMRC Employer CD-ROM 2009 " = HMRC Employer CD-ROM 2009
"HMRC Employer CD-ROM 2010 " = HMRC Employer CD-ROM 2010 - Updated Edition 2.1.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Lexmark 5600-6600 Series" = Lexmark 5600-6600 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MotoHelper" = MotoHelper 2.0.53 Driver 5.2.0
"N360" = Norton 360 Premier Edition

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 29/10/2011 06:41:21 | Computer Name = Newells-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 29/10/2011 06:41:21 | Computer Name = Newells-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2137089

Error - 29/10/2011 06:41:21 | Computer Name = Newells-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2137089

Error - 29/10/2011 06:41:28 | Computer Name = Newells-PC | Source = EventSystem | ID = 4621
Description =

Error - 29/10/2011 11:23:28 | Computer Name = Newells-PC | Source = WinMgmt | ID = 10
Description =

Error - 29/10/2011 11:43:02 | Computer Name = Newells-PC | Source = EventSystem | ID = 4621
Description =

Error - 29/10/2011 15:09:21 | Computer Name = Newells-PC | Source = WinMgmt | ID = 10
Description =

Error - 29/10/2011 16:25:03 | Computer Name = Newells-PC | Source = Application Error | ID = 1000
Description = Faulting application setup.exe_InstallShield, version 14.0.0.162,
time stamp 0x4626b2f4, faulting module unknown, version 0.0.0.0, time stamp 0x00000000,
exception code 0xc0000005, fault offset 0x6dfb1e60, process id 0xdd8, application
start time 0x01cc9678c8d418b4.

Error - 29/10/2011 16:28:40 | Computer Name = Newells-PC | Source = VSS | ID = 8194
Description =

Error - 29/10/2011 16:31:52 | Computer Name = Newells-PC | Source = VSS | ID = 8194
Description =

[ Broadcom Wireless LAN Events ]
Error - 07/10/2011 12:42:17 | Computer Name = Newells-PC | Source = WLAN-Tray | ID = 0
Description = 17:42:17, Fri, Oct 07, 11 Error - Unable to gain access to user store


Error - 09/10/2011 15:51:57 | Computer Name = Newells-PC | Source = WLAN-Tray | ID = 0
Description = 20:51:57, Sun, Oct 09, 11 Error - Unable to gain access to user store


Error - 18/10/2011 09:00:26 | Computer Name = Newells-PC | Source = WLAN-Tray | ID = 0
Description = 14:00:26, Tue, Oct 18, 11 Error - Unable to gain access to user store


[ System Events ]
Error - 29/10/2011 11:23:36 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2011 11:23:36 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 29/10/2011 11:23:36 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2011 11:23:36 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 29/10/2011 15:09:24 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2011 15:09:24 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2011 15:09:24 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2011 15:09:24 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 29/10/2011 15:09:24 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2011 15:09:24 | Computer Name = Newells-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Hello swn and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again swn

There are a few leftovers but nothing too malicious so we’ll deal with those first and then run some other scans.

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKLM\Software\MozillaPlugins\@Guffins.com/Plugin: C:\Program Files\Guffins\bar\1.bin\NPu4Stub.dll File not found
    FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll File not found
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\1.bin
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Guffins\bar\1.bin [2011/10/28 06:44:32 | 000,000,000 | —D | M]
    CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\Guffins\bar\1.bin\NPu4Stub.dll
    CHR - plugin: My Web Search Plugin Stub (Enabled) = C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll
    O3 - HKLM\..\Toolbar: (Guffins) - {de2fdf7c-2637-4ba3-b427-3fce2d331db5} - C:\Program Files\Guffins\bar\1.bin\u4bar.dll File not found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

================================================

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done, click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include in next post:

OTL fix log
New OTL log
Gmer.txt


Thanks

Satchfan
Hello Satchfan, Here is the OTL log. I ran OTL twice as I accidently closed the first report. I cannot run GMER - tried twice and both times I get a message saying it has stopped working. First time I got the blue screen as well. I'll await your advise. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Guffins.com/Plugin\ not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@mywebsearch.com/Plugin\ not found. File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\1.bin not found. File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Guffins\bar\1.bin not found. File C:\Program Files\Guffins\bar\1.bin\NPu4Stub.dll not found. File C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{de2fdf7c-2637-4ba3-b427-3fce2d331db5} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{de2fdf7c-2637-4ba3-b427-3fce2d331db5}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Newells ->Temp folder emptied: 81833 bytes ->Temporary Internet Files folder emptied: 7816994 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 615 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 8.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 11022011_213529 Files\Folders moved on Reboot… C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAU3OF0R\Messenger[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAU3OF0R\WebIMPop[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAU3OF0R\xmlProxy[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAU3OF0R\xmlProxy[2].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9CI5ZNCX\adloader[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9CI5ZNCX\iframe[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92E2L2KT\AjaxHistoryFrame[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92E2L2KT\default[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92E2L2KT\EditMessageLight[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92E2L2KT\InboxLight[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92E2L2KT\index[9].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92E2L2KT\resourcespreload[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TR1XC4F\display[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TR1XC4F\LocalStorage[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TR1XC4F\resourcespreload[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TR1XC4F\RteFrame_16.0.1877.0920[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TR1XC4F\tt[1].htm moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Newells\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. Registry entries deleted on Reboot…
Please run OTL again and send a new log as I only received the "Fix" log

NEXT

Please run GMER again, but this time uncheck everything EXCEPT "Sections" and "C:\" .

If it still doesn’t work, try it in safe mode.

Boot to Safe mode with Networking and see if you can then run it

To Enter Safemode• Go to Start> Shut off your Computer> Restart
• As the computer starts to boot-up, Tap the F8 KEY - this will bring up a menu.
• Use the Up and Down Arrow Keys to scroll up to Safemode
• Then press Enter on your keyboard
Satchfan
Hello swn It has been several days since I posted instructions to help with your computer problem. Please let me know if you are having problems and still need help. Thanks Satchfan
Hi swn
  • open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • post the OTL.txt log it produces in your next reply.
=======================================================

I'd also like to be sure there are no rootkits present so please also try running Gmer in safe mode as I previously asked.

Thanks

Satchfan
Hi Satchfan, I can't get OTL to run now. Each time I hit quick scan, the boxes check themselves and it hangs on "SCANNING MODULES". GMER - did it in normal mode and have attached the log. Stu

Attachments:

Hi swn

As there was some evidence of remaining malware, I'd still like another scan.

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please don't attach it, copy and paste it in your reply.

Thanks

Satchfan
Hello swn It has been several days since I posted instructions to help with your computer problem. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI