This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu.com, D.D.S & HiiJack data help

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

D.D.S data
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 12:44:34 on 2011-11-12
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3326.2171 [GMT -6:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}
SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com/406
uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
BHO: UrlHelper Class: {a40dc6c5-79d0-4ca8-a185-8ff989af1115} - c:\progra~1\wi371a~1\datamngr\IEBHO.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No File
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: HyperCam Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\hypercam toolbar\tbcore3.dll
TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
uRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Skytel] Skytel.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [DATAMNGR] c:\progra~1\wi371a~1\datamngr\DATAMN~1.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.27.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{13F3D2D0-E325-4AAC-8AE1-B42EBDC03ED9} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{28CF4636-CBBB-4EB3-A4E3-E1D721F555D9} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{890BF7B0-6A3F-4888-9078-86DA6FC15A00} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{90D864C0-144B-4A02-9217-4A2D1E6BE5A9} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{DB57FC0B-5A33-4D01-AC80-6B0DFEF8F265} : DhcpNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: c:\progra~1\wi371a~1\datamngr\datamngr.dll c:\progra~1\wi371a~1\datamngr\IEBHO.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\seth\appdata\roaming\mozilla\firefox\profiles\mbibxhlj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=101&systemid=406&q=
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\Shim.dll
FF - component: c:\users\seth\appdata\roaming\mozilla\firefox\profiles\mbibxhlj.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-20 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-20 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-20 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-20 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-20 297752]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2009-3-20 68136]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-4-15 1153368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-8 24652]
R3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2009-3-22 13225]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2011-1-12 125672]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [2011-4-3 17792]
S2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.9.24\symcpcculaunchsvc.exe /s –> c:\program files\norton pc checkup\engine\2.0.9.24\SymcPCCULaunchSvc.exe [?]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-11-5 2214504]
S2 PCCUJobMgr;Common Client Job Manager Service;"c:\program files\norton pc checkup\engine\2.0.9.24\ccsvchst.exe" /s "pccujobmgr" /m "c:\program files\norton pc checkup\engine\2.0.9.24\dimaster.dll" /prefetch:1 –> c:\program files\norton pc checkup\engine\2.0.9.24\ccSvcHst.exe [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-1 34384]
.
=============== Created Last 30 ================
.
2011-11-09 13:06:31 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 13:06:30 707584 —-a-w- c:\program files\common files\system\wab32.dll
2011-11-05 20:49:20 66664 —-a-w- c:\windows\system32\nvshext.dll
2011-11-05 20:49:20 2560616 —-a-w- c:\windows\system32\nvsvcr.dll
2011-11-05 20:49:19 543336 —-a-w- c:\windows\system32\easyupdatusapiu.dll
2011-11-05 20:48:13 ——– d—–w- c:\programdata\NVIDIA Corporation
2011-11-05 20:23:06 98816 —-a-w- c:\windows\system32\mfps.dll
2011-11-05 20:11:38 713560 —-a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2011-10-17 05:10:05 ——– d—–w- C:\.jagex_cache_32
.
==================== Find3M ====================
.
2011-11-12 16:42:43 16608 —-a-w- c:\windows\gdrv.sys
2011-11-05 20:23:06 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-09-12 03:44:09 139080 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-09-12 03:43:55 270240 —-a-w- c:\windows\system32\PnkBstrB.xtr
2011-09-12 03:43:55 270240 —-a-w- c:\windows\system32\PnkBstrB.exe
2011-09-11 21:54:30 270240 —-a-w- c:\windows\system32\PnkBstrB.ex0
2011-09-11 17:36:34 138056 —-a-w- c:\users\seth\appdata\roaming\PnkBstrK.sys
2011-09-11 17:36:14 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2011-09-06 13:30:12 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-08-25 16:15:04 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-08-25 16:14:01 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-08-25 16:14:01 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-08-25 13:31:01 4096 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 12:45:03.77 ===============


Hiijack data

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:23:22 PM, on 11/12/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Seth\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)
O3 - Toolbar: HyperCam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll (file missing)
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (file missing)
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (file missing)
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.27.0.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton PC Checkup Application Launcher - Unknown owner - C:\Program Files\Norton PC Checkup\Engine\2.0.9.24\SymcPCCULaunchSvc.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Unknown owner - C:\Program Files\Norton PC Checkup\Engine\2.0.9.24\ccSvcHst.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8281 bytes
OTL Report

OTL logfile created on: 11/12/2011 1:12:05 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Seth\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 59.95% Memory free
6.72 Gb Paging File | 5.33 Gb Available in Paging File | 79.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 105.23 Gb Free Space | 45.19% Space Free | Partition Type: NTFS

Computer Name: THEJACKAL | User Name: Seth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Seth\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (PCCUJobMgr) – File not found
SRV - (Norton PC Checkup Application Launcher) – File not found
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (nTuneService) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Driver Services (SafeList) ==========

DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (SCREAMINGBDRIVER) – C:\Windows\System32\drivers\ScreamingBAudio.sys (Screaming Bee LLC)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) – C:\Windows\System32\drivers\vcsvad.sys (Avnex)
DRV - (NVR0Dev) – C:\Windows\nvoclock.sys (NVidia Corp.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (pgfilter) – C:\Program Files\PeerGuardian2\pgfilter.sys ()
DRV - (Razerlow) – C:\Windows\System32\drivers\Razerlow.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (FVNETusb) – C:\Windows\System32\drivers\vnet58lx.sys (Cisco-Linksys LLC.)
DRV - (TIEHDUSB) – C:\Windows\System32\drivers\tiehdusb.sys (Texas Instruments Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\InprocServer32 File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll (DeviceVM Inc.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\InprocServer32 File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.14908
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@fileplanet.com/fpdlm: C:\Program Files\Download Manager\npfpdlm.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Seth\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\Seth\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll File not found
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 14:12:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/12 00:08:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/05 13:39:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Seth\Program Files\DNA

[2011/07/24 00:34:55 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Extensions
[2009/06/25 22:09:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Extensions\[removed]
[2009/07/27 06:40:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Extensions\[removed]
[2011/11/05 15:17:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions
[2010/07/04 01:59:42 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/24 00:34:46 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2010/05/10 21:04:03 | 000,000,000 | —D | M] (Battlefield Heroes Updater) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions\[removed]
[2011/02/09 20:03:43 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions\[removed]
[2010/01/01 00:18:14 | 000,004,554 | —- | M] () – C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\mbibxhlj.default\searchplugins\aim-search.xml
[2011/07/24 00:34:42 | 000,002,501 | —- | M] () – C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\mbibxhlj.default\searchplugins\SearchResults.xml
[2011/11/05 14:11:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/05 08:29:38 | 000,000,000 | —D | M] (The Browser Highlighter) – C:\Program Files\Mozilla Firefox\extensions\[removed]
() (No name found) – C:\USERS\SETH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MBIBXHLJ.DEFAULT\EXTENSIONS\[removed]
[2011/11/12 00:08:12 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2011/11/12 00:08:11 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 00:08:11 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: EA Battlefield Heroes Updater (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.122.0_0\npBFHUpdater.dll
CHR - plugin: EA Battlefield Heroes Updater (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.122.0_0\BFHUpdater.exe
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npLegitCheckPlugin.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npViewpoint.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Seth\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Battlefield Heroes = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.122.0_0\
CHR - Extension: Poppit = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll File not found
O3 - HKLM\..\Toolbar: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll File not found
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.27.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{13F3D2D0-E325-4AAC-8AE1-B42EBDC03ED9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{28CF4636-CBBB-4EB3-A4E3-E1D721F555D9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{890BF7B0-6A3F-4888-9078-86DA6FC15A00}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{90D864C0-144B-4A02-9217-4A2D1E6BE5A9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB57FC0B-5A33-4D01-AC80-6B0DFEF8F265}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Seth\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Seth\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{5d464e82-795d-11df-8646-000f66156043}\Shell\AutoRun\command - "" = D:\setupSNK.exe
O33 - MountPoints2\{b7f95884-61ad-11df-95a7-000f66156043}\Shell\AutoRun\command - "" = E:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ROX.exe
O33 - MountPoints2\{b7f95884-61ad-11df-95a7-000f66156043}\Shell\open\command - "" = E:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ROX.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.bdmpeg - C:\Windows\System32\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.mpeg - C:\Windows\System32\bdmpegv.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/12 12:18:12 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Seth\Desktop\OTL.exe
[2011/11/12 12:17:29 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Seth\Desktop\HiJackThis.exe
[2011/11/12 12:15:35 | 000,607,260 | R— | C] (Swearware) – C:\Users\Seth\Desktop\dds.scr
[2011/11/09 17:20:49 | 005,610,638 | —- | C] (Adobe Systems, Inc.) – C:\Users\Seth\Desktop\Transformice.exe
[2011/11/05 14:50:54 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/11/05 14:49:20 | 002,560,616 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvsvcr.dll
[2011/11/05 14:49:20 | 000,066,664 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvshext.dll
[2011/11/05 14:49:19 | 000,543,336 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\easyupdatusapiu.dll
[2011/11/05 14:48:13 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2011/11/05 14:24:17 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/11/05 14:24:17 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/11/05 14:24:17 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/11/05 14:24:17 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/11/05 14:24:17 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/11/05 14:24:17 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/11/05 14:24:16 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/11/05 14:24:16 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/11/05 14:24:16 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/11/05 14:24:16 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/11/05 14:24:16 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/11/05 14:24:16 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/11/05 14:24:16 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/11/05 14:24:16 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/11/05 14:24:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/11/05 14:24:16 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/11/05 14:24:16 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/11/05 14:24:16 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/11/05 14:24:16 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/11/05 14:24:15 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/11/05 14:24:15 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/11/05 14:24:15 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/11/05 14:24:15 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/11/05 14:24:15 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/11/05 14:24:15 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/11/05 14:24:15 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/11/05 14:24:15 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/11/05 14:24:15 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/11/05 14:24:15 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/11/05 14:24:15 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/11/05 14:24:15 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/11/05 14:24:15 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/11/05 14:24:14 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/11/05 14:24:14 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/11/05 14:24:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/11/05 14:24:14 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/11/05 14:24:14 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/11/05 14:23:06 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/11/05 14:23:06 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/11/05 14:23:06 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/11/05 14:23:06 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/11/05 14:23:06 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/11/05 14:23:06 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/11/05 14:23:06 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/11/05 14:23:04 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/11/05 14:23:04 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/11/05 14:23:04 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/11/05 14:23:03 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/11/05 14:23:03 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/11/05 14:23:02 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/11/05 14:23:02 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/11/05 14:23:02 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/11/05 14:23:02 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/11/05 14:23:02 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/11/05 14:23:02 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/11/05 14:23:01 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/11/05 14:23:01 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/11/05 14:23:01 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/11/05 14:23:01 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/11/05 14:23:01 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/11/05 14:23:01 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/10/16 23:10:05 | 000,000,000 | —D | C] – C:\.jagex_cache_32
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/12 12:42:42 | 000,006,560 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/12 12:42:42 | 000,006,560 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/12 12:18:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Seth\Desktop\OTL.exe
[2011/11/12 12:17:32 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Seth\Desktop\HiJackThis.exe
[2011/11/12 12:15:41 | 000,607,260 | R— | M] (Swearware) – C:\Users\Seth\Desktop\dds.scr
[2011/11/12 12:01:11 | 000,000,491 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Transformice - Shortcut.lnk
[2011/11/12 12:01:04 | 000,000,215 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Call of Duty Black Ops - Multiplayer.url
[2011/11/12 12:01:02 | 000,000,667 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Rappelz.lnk
[2011/11/12 12:00:46 | 000,001,668 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Play League of Legends.lnk
[2011/11/12 10:49:00 | 000,598,350 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/11/12 10:49:00 | 000,101,988 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/11/12 10:44:52 | 086,184,203 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/11/12 10:42:43 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\Windows\gdrv.sys
[2011/11/12 10:42:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/11 18:00:00 | 000,000,406 | —- | M] () – C:\Windows\tasks\Norton Security Scan for Seth.job
[2011/11/09 20:22:51 | 000,045,010 | —- | M] () – C:\Users\Seth\Desktop\379706_272527072790861_100001007104949_811707_2112067813_n.jpg
[2011/11/09 17:21:10 | 005,610,638 | —- | M] (Adobe Systems, Inc.) – C:\Users\Seth\Desktop\Transformice.exe
[2011/11/07 15:15:00 | 000,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/05 14:24:22 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/11/05 14:24:22 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/11/05 14:24:17 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/11/05 14:24:17 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/11/05 14:24:17 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/11/05 14:24:17 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/11/05 14:24:17 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/11/05 14:24:17 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/11/05 14:24:16 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/11/05 14:24:16 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/11/05 14:24:16 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/11/05 14:24:16 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/11/05 14:24:16 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/11/05 14:24:16 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/11/05 14:24:16 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/11/05 14:24:16 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/11/05 14:24:16 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/11/05 14:24:16 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/11/05 14:24:16 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/11/05 14:24:16 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/11/05 14:24:16 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/11/05 14:24:16 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/11/05 14:24:15 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/11/05 14:24:15 | 001,798,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/11/05 14:24:15 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/11/05 14:24:15 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/11/05 14:24:15 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/11/05 14:24:15 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/11/05 14:24:15 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/11/05 14:24:15 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/11/05 14:24:15 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/11/05 14:24:15 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/11/05 14:24:15 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/11/05 14:24:15 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/11/05 14:24:15 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/11/05 14:24:14 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/11/05 14:24:14 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/11/05 14:24:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/11/05 14:24:14 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/11/05 14:24:14 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/11/05 14:23:06 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/11/05 14:23:06 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/11/05 14:23:06 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/11/05 14:23:06 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/11/05 14:23:06 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/11/05 14:23:06 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/11/05 14:23:06 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/11/05 14:23:04 | 000,683,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/11/05 14:23:04 | 000,288,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/11/05 14:23:04 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/11/05 14:23:03 | 001,068,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/11/05 14:23:03 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/11/05 14:23:02 | 001,172,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/11/05 14:23:02 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/11/05 14:23:02 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/11/05 14:23:02 | 000,219,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/11/05 14:23:02 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/11/05 14:23:02 | 000,160,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/11/05 14:23:01 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/11/05 14:23:01 | 000,876,032 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/11/05 14:23:01 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/11/05 14:23:01 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/11/05 14:23:01 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/11/05 14:23:01 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/11/05 14:11:42 | 000,000,830 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/05 14:11:42 | 000,000,806 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/14 05:57:58 | 000,385,672 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/12 12:01:11 | 000,000,491 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Transformice - Shortcut.lnk
[2011/11/12 12:01:04 | 000,000,215 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Call of Duty Black Ops - Multiplayer.url
[2011/11/12 12:01:02 | 000,000,667 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Rappelz.lnk
[2011/11/12 12:00:46 | 000,001,668 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Play League of Legends.lnk
[2011/11/09 20:22:50 | 000,045,010 | —- | C] () – C:\Users\Seth\Desktop\379706_272527072790861_100001007104949_811707_2112067813_n.jpg
[2011/11/05 14:24:16 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/11/05 14:11:42 | 000,000,830 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/05 14:11:42 | 000,000,818 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/05 14:11:42 | 000,000,806 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/29 14:58:15 | 000,009,550 | -HS- | C] () – C:\Users\Seth\AppData\Local\61x36458x38t121clu4y2
[2011/06/29 12:48:42 | 000,009,550 | -HS- | C] () – C:\ProgramData\61x36458x38t121clu4y2
[2011/01/26 22:44:40 | 000,230,752 | —- | C] () – C:\Windows\patchw32.dll
[2011/01/26 22:44:40 | 000,118,176 | —- | C] () – C:\Windows\patchw.dll
[2010/07/23 01:32:19 | 001,970,176 | —- | C] () – C:\Windows\System32\d3dx9.dll
[2010/03/12 18:41:50 | 000,002,688 | —- | C] () – C:\Windows\Sandboxie.ini
[2009/12/17 16:46:27 | 000,139,080 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2009/12/17 16:46:27 | 000,138,056 | —- | C] () – C:\Users\Seth\AppData\Roaming\PnkBstrK.sys
[2009/12/17 16:46:12 | 000,270,240 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/12/17 16:46:11 | 002,427,248 | —- | C] () – C:\Windows\System32\pbsvc_heroes.exe
[2009/12/17 16:46:11 | 000,075,136 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/11/21 15:22:41 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/11/21 15:22:41 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/11/21 15:22:09 | 000,062,976 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/06/26 18:38:36 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/04/09 14:20:59 | 000,000,552 | —- | C] () – C:\Users\Seth\AppData\Local\d3d8caps.dat
[2009/03/23 12:53:11 | 000,053,760 | —- | C] () – C:\Users\Seth\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/20 20:41:25 | 000,131,072 | —- | C] () – C:\Windows\System32\SpoonUninstall.exe
[2009/03/20 20:41:25 | 000,036,104 | —- | C] () – C:\Windows\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
[2009/03/20 19:14:57 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/20 06:35:38 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2009/03/20 06:33:28 | 000,000,680 | —- | C] () – C:\Users\Seth\AppData\Local\d3d9caps.dat
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2007/06/21 00:34:08 | 000,203,328 | R— | C] () – C:\Windows\GSetup.exe
[2007/03/12 11:01:30 | 000,217,088 | —- | C] () – C:\Windows\NVGfxOgl.dll
[2006/11/02 06:56:48 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:47:43 | 000,385,672 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 04:33:01 | 000,598,350 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,101,988 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/04/30 00:34:04 | 000,049,152 | —- | C] () – C:\Windows\System32\WbxRMenu.dll
[2006/04/13 23:18:24 | 000,196,608 | —- | C] () – C:\Windows\System32\atonres.dll
[2006/04/13 23:18:24 | 000,131,072 | —- | C] () – C:\Windows\System32\WbxMSAI.dll
[2006/04/13 23:18:24 | 000,098,304 | —- | C] () – C:\Windows\System32\atonecli.dll

========== LOP Check ==========

[2009/05/08 23:24:19 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\acccore
[2010/01/02 21:04:48 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\AIM
[2010/05/15 22:24:06 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\AnvSoft
[2011/04/03 01:12:13 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Avnex
[2011/03/06 20:37:28 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\BitTorrent
[2009/07/31 16:23:48 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Blackberry Desktop
[2010/01/04 02:10:56 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\DNA
[2009/12/16 16:49:52 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\FOG Downloader
[2011/01/29 23:49:40 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\GetRightToGo
[2011/05/24 08:06:11 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\GSC 2.00
[2011/08/12 17:54:21 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\gtk-2.0
[2010/07/23 17:13:55 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\iWin
[2009/07/21 06:33:26 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\LimeWire
[2011/01/15 17:21:53 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\LolClient
[2010/09/19 10:16:58 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Oberon Media
[2009/07/08 19:53:28 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Research In Motion
[2011/04/03 01:25:20 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Screaming Bee
[2010/04/05 21:18:52 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\SecondLife
[2009/07/27 06:39:54 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Songbird2
[2011/02/09 21:20:40 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Tific
[2011/02/02 15:40:17 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\TS3Client
[2011/11/12 12:07:11 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\uTorrent
[2010/05/15 22:43:02 | 000,000,000 | —D | M] – C:\Users\Seth\AppData\Roaming\Xilisoft Corporation
[2011/11/07 15:15:00 | 000,000,472 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/11/12 01:52:28 | 000,032,592 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/03/21 10:24:17 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/03/20 06:42:02 | 000,000,200 | —- | M] () – C:\csb.log
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/03/27 12:32:33 | 000,001,087 | -H– | M] () – C:\IPH.PH
[2010/05/31 11:12:05 | 000,000,078 | —- | M] () – C:\lxbt.log
[2011/11/12 10:42:14 | 3801,694,208 | -HS- | M] () – C:\pagefile.sys
[2009/03/20 06:40:03 | 000,000,426 | —- | M] () – C:\RHDSetup.log
[2011/11/12 12:44:36 | 000,000,321 | —- | M] () – C:\service.log
[2011/06/30 14:47:39 | 000,060,478 | —- | M] () – C:\TDSSKiller.2.5.8.0_30.06.2011_15.46.39_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:19 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:19 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:19 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/11/21 15:35:59 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 06:36:30 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/10/11 19:28:13 | 000,001,674 | -H– | M] () – C:\Users\Seth\AppData\Roaming\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2008/01/20 20:43:58 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 21:20:25 | 017,223,680 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:20:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:20:25 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/11/12 12:01:04 | 000,000,215 | —- | M] () – C:\Users\Seth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Call of Duty Black Ops - Multiplayer.url
[2011/11/05 14:27:18 | 000,000,286 | -HS- | M] () – C:\Users\Seth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/12 12:17:32 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Seth\Desktop\HiJackThis.exe
[2011/11/12 12:18:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Seth\Desktop\OTL.exe
[2011/11/09 17:21:10 | 005,610,638 | —- | M] (Adobe Systems, Inc.) – C:\Users\Seth\Desktop\Transformice.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-12 07:52:15

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:52B72A7C
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:CC174F28
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:FB1B13D8
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
Hello SethE1 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again SethE1

P2P - I see you have P2P software, (BitTorrent, BitTorrent, LimeWire), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall them now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep them, please don’t use them until we have finished up here.

===================================================

The ASK toolbar comes bundled with many third-party applications, is considered as Spyware and comes with vulnerabilities.

See the following links and decide yourself whether or not you want to keep it.:

http://secunia.com/advisories/product/15810/
http://www.benedelman.org/spyware/ask-toolbars/

===================================================

Disable Spybot’s TeaTimer and Windows Defender

Spybot’s TeaTimer and Windows Defender can sometimes prevent some things from being fixed.

Please disable TeaTimer and Windows Defender for now until you are clean. TeaTimer and Windows Defender can be re-activated once your log is clean.
  • open Spybot Search & Destroy
  • in the Mode menu click "Advanced mode" if not already selected
  • choose "Yes" at the Warning prompt
  • expand the "Tools" menu
  • click "Resident"
  • uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box
  • in the File menu click "Exit" to exit Spybot Search & Destroy.
To disable Windows Defender:
  • open Windows Defender
  • click on Tools, General Settings
  • scroll down and uncheck Turn on real-time protection (recommended)
  • after you uncheck this, click on the Save button and close Windows Defender.
===================================================

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    SRV - (Norton PC Checkup Application Launcher) – File not found
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
    FF - HKLM\Software\MozillaPlugins\@fileplanet.com/fpdlm: C:\Program Files\Download Manager\npfpdlm.dll File not found
    FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Seth\Program Files\DNA\plugins\npbtdna.dll File not found
    FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\Seth\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll File not found
    [2011/07/24 00:34:46 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions\{99079a25-328f-4bd4-be04-
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
    O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
    O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll File not found
    O3 - HKLM\..\Toolbar: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll File not found
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O33 - MountPoints2\{5d464e82-795d-11df-8646-000f66156043}\Shell\AutoRun\command - "" = D:\setupSNK.exe
    O33 - MountPoints2\{b7f95884-61ad-11df-95a7-000f66156043}\Shell\AutoRun\command - "" = E:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ROX.exe
    O33 - MountPoints2\{b7f95884-61ad-11df-95a7-000f66156043}\Shell\open\command - "" = E:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ROX.exe
    @Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:52B72A7C
    @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:CC174F28
    @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D1B5B4F1
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:FB1B13D8
    @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Other logs to include:

OTL fix log
New OTL log
Extras.txt


Note: Extras.txt should be on your desktop from the first run of OTL. If it is not, when you do the new OTL scan, do the following:

Under Extra Registry put a check in Use SafeList:

🖼Click to load external image (Posted Image)

Click Run Scan

Satchfan
First OTL

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named datamngrUI.exe was found!
Service Norton PC Checkup Application Launcher stopped successfully!
Service Norton PC Checkup Application Launcher deleted successfully!
File File not found not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@fileplanet.com/fpdlm\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1\ deleted successfully.
Folder C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions\{99079a25-328f-4bd4-be04-\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{338B4DFE-2E2C-4338-9E41-E176D497299E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
File C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll deleted successfully.
File pInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll deleted successfully.
File pInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d464e82-795d-11df-8646-000f66156043}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d464e82-795d-11df-8646-000f66156043}\ not found.
File D:\setupSNK.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7f95884-61ad-11df-95a7-000f66156043}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7f95884-61ad-11df-95a7-000f66156043}\ not found.
File E:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ROX.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7f95884-61ad-11df-95a7-000f66156043}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7f95884-61ad-11df-95a7-000f66156043}\ not found.
File E:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ROX.exe not found.
ADS C:\ProgramData\TEMP:52B72A7C deleted successfully.
ADS C:\ProgramData\TEMP:CC174F28 deleted successfully.
ADS C:\ProgramData\TEMP:D1B5B4F1 deleted successfully.
ADS C:\ProgramData\TEMP:FB1B13D8 deleted successfully.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Seth\Desktop\cmd.bat deleted successfully.
C:\Users\Seth\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Seth
->Flash cache emptied: 5183 bytes

User: UpdatusUser

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Seth
->Temp folder emptied: 6109922 bytes
->Temporary Internet Files folder emptied: 3385838 bytes
->Java cache emptied: 33926032 bytes
->FireFox cache emptied: 120670514 bytes
->Google Chrome cache emptied: 84553827 bytes
->Flash cache emptied: 0 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2356 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 394837 bytes

Total Files Cleaned = 238.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11132011_132345

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

—————————————————————————————————————————————–
Combo Fix log

ComboFix 11-11-13.02 - Seth 11/13/2011 13:37:36.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3326.2178 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}
SP: AVG Anti-Virus Free *Disabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\users\Seth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tool
c:\windows\system32\orange-install.ico
c:\windows\system32\socklink.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-10-13 to 2011-11-13 )))))))))))))))))))))))))))))))
.
.
2011-11-13 19:42 . 2011-11-13 19:42 ——– d—–w- c:\users\Seth\AppData\Local\temp
2011-11-13 19:42 . 2011-11-13 19:42 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-13 19:23 . 2011-11-13 19:23 ——– d—–w- C:\_OTL
2011-11-09 13:06 . 2011-09-20 21:02 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 13:06 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2011-11-05 20:49 . 2011-11-05 20:49 ——– d—–w- c:\users\UpdatusUser
2011-11-05 20:49 . 2011-05-21 11:01 66664 —-a-w- c:\windows\system32\nvshext.dll
2011-11-05 20:49 . 2011-05-21 11:01 2560616 —-a-w- c:\windows\system32\nvsvcr.dll
2011-11-05 20:49 . 2011-05-21 11:01 543336 —-a-w- c:\windows\system32\easyupdatusapiu.dll
2011-11-05 20:48 . 2011-11-05 20:48 ——– d—–w- c:\programdata\NVIDIA Corporation
2011-11-05 20:23 . 2011-11-05 20:23 98816 —-a-w- c:\windows\system32\mfps.dll
2011-11-05 20:11 . 2011-11-12 06:08 134104 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-10-17 05:10 . 2011-10-17 05:10 ——– d—–w- C:\.jagex_cache_32
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-13 19:25 . 2009-03-20 12:35 16608 —-a-w- c:\windows\gdrv.sys
2011-09-12 03:44 . 2009-12-17 22:46 139080 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-09-12 03:43 . 2010-05-11 03:31 270240 —-a-w- c:\windows\system32\PnkBstrB.xtr
2011-09-12 03:43 . 2009-12-17 22:46 270240 —-a-w- c:\windows\system32\PnkBstrB.exe
2011-09-11 21:54 . 2009-12-17 22:46 270240 —-a-w- c:\windows\system32\PnkBstrB.ex0
2011-09-11 17:36 . 2009-12-17 22:46 138056 —-a-w- c:\users\Seth\AppData\Roaming\PnkBstrK.sys
2011-09-11 17:36 . 2009-12-17 22:46 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2011-09-06 13:30 . 2011-10-13 15:06 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-08-25 16:15 . 2011-10-13 15:06 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-08-25 16:14 . 2011-10-13 15:06 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-08-25 16:14 . 2011-10-13 15:06 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-08-25 13:31 . 2011-10-13 15:06 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-11-12 06:08 . 2011-11-05 20:11 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-05 81920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2011-10-17 2042208]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Skytel"="Skytel.exe" [2008-07-24 1833504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 22:10 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 23:36 30040 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-02-16 21:15 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-02-16 21:15 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2010-12-21 00:08 963976 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-05-21 11:01 3693672 —-a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
2007-09-05 00:25 81920 —-a-w- c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-05-21 11:01 111208 —-a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 22:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-07-24 10:16 6265376 —-a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2011-01-12 14:35 405736 —-a-w- c:\program files\Sandboxie\SbieCtrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-26 22:05 16945032 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-09-04 22:06 1242448 —-a-w- c:\program files\Steam\Steam.exe
.
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\Norton PC Checkup\Engine\2.0.9.24\ccSvcHst.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-12-16 3453712]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-01 34384]
R3 XDva359;XDva359;c:\windows\system32\XDva359.sys [x]
R3 XDva375;XDva375;c:\windows\system32\XDva375.sys [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-08-20 335240]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-05-03 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-08-20 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-08-20 297752]
S2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2008-09-24 68136]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\Drivers\Razerlow.sys [2005-04-25 13225]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page =
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\mbibxhlj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&q;=
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.ytff.general.dontshowhpoffer, true);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
BHO-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
MSConfigStartUp-Adware_ProMFCT - c:\program files\Adware_Pro\Adware_Pro.exe
MSConfigStartUp-AIMPro - c:\program files\AIM\AIM Pro\aimpro.exe
MSConfigStartUp-BitTorrent DNA - c:\users\Seth\Program Files\DNA\btdna.exe
MSConfigStartUp-BlackBerryAutoUpdate - c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
MSConfigStartUp-EzPrint - c:\program files\Lexmark 5200 Series\ezprint.exe
MSConfigStartUp-igndlm - c:\program files\Download Manager\DLM.exe
MSConfigStartUp-lxbtmon - c:\program files\Lexmark 5200 Series\lxbtmon.exe
MSConfigStartUp-Messenger (Yahoo!) - c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
MSConfigStartUp-PeerGuardian - c:\program files\PeerGuardian2\pg2.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe
AddRemove-BandiMPEG1 - c:\program files\BandiMPEG1\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-13 13:42
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.9.24\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.9.24\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-11-13 13:44:00
ComboFix-quarantined-files.txt 2011-11-13 19:43
.
Pre-Run: 147,716,182,016 bytes free
Post-Run: 147,639,533,568 bytes free
.
- - End Of File - - 852E427ACC600BBA744E09BC0E78C885
2nd OTL

OTL logfile created on: 11/13/2011 1:46:26 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Seth\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 60.72% Memory free
6.73 Gb Paging File | 5.60 Gb Available in Paging File | 83.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 137.54 Gb Free Space | 59.06% Space Free | Partition Type: NTFS

Computer Name: THEJACKAL | User Name: Seth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Seth\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PCCUJobMgr) – File not found
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (nTuneService) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Driver Services (SafeList) ==========

DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (SCREAMINGBDRIVER) – C:\Windows\System32\drivers\ScreamingBAudio.sys (Screaming Bee LLC)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) – C:\Windows\System32\drivers\vcsvad.sys (Avnex)
DRV - (NVR0Dev) – C:\Windows\nvoclock.sys (NVidia Corp.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (Razerlow) – C:\Windows\System32\drivers\Razerlow.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (FVNETusb) – C:\Windows\System32\drivers\vnet58lx.sys (Cisco-Linksys LLC.)
DRV - (TIEHDUSB) – C:\Windows\System32\drivers\tiehdusb.sys (Texas Instruments Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll (DeviceVM Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.14908
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 14:12:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/12 00:08:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/05 13:39:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Seth\Program Files\DNA

[2011/07/24 00:34:55 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Extensions
[2009/06/25 22:09:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Extensions\[removed]
[2009/07/27 06:40:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Extensions\[removed]
[2011/11/13 13:16:50 | 000,000,000 | —D | M] (No name found) – C:\Users\Seth\AppData\Roaming\mozilla\Firefox\Profiles\mbibxhlj.default\extensions
[2010/01/01 00:18:14 | 000,004,554 | —- | M] () – C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\mbibxhlj.default\searchplugins\aim-search.xml
[2011/07/24 00:34:42 | 000,002,501 | —- | M] () – C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\mbibxhlj.default\searchplugins\SearchResults.xml
[2011/11/05 14:11:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/05 08:29:38 | 000,000,000 | —D | M] (The Browser Highlighter) – C:\Program Files\Mozilla Firefox\extensions\[removed]
() (No name found) – C:\USERS\SETH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MBIBXHLJ.DEFAULT\EXTENSIONS\[removed]
[2011/11/12 00:08:12 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2011/11/12 00:08:11 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/12 00:08:11 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.2 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: EA Battlefield Heroes Updater (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.122.0_0\npBFHUpdater.dll
CHR - plugin: EA Battlefield Heroes Updater (Enabled) = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.122.0_0\BFHUpdater.exe
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npLegitCheckPlugin.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npViewpoint.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Seth\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Battlefield Heroes = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.122.0_0\
CHR - Extension: Poppit = C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2011/11/13 13:42:16 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.27.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{13F3D2D0-E325-4AAC-8AE1-B42EBDC03ED9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{28CF4636-CBBB-4EB3-A4E3-E1D721F555D9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{890BF7B0-6A3F-4888-9078-86DA6FC15A00}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{90D864C0-144B-4A02-9217-4A2D1E6BE5A9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB57FC0B-5A33-4D01-AC80-6B0DFEF8F265}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Seth\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Seth\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/13 13:44:02 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/13 13:44:02 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/13 13:44:02 | 000,000,000 | —D | C] – C:\Users\Seth\AppData\Local\temp
[2011/11/13 13:35:37 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/13 13:35:37 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/13 13:35:37 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/13 13:35:33 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/13 13:35:32 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/13 13:23:45 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/13 13:21:45 | 004,292,869 | R— | C] (Swearware) – C:\Users\Seth\Desktop\ComboFix.exe
[2011/11/12 12:18:12 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Seth\Desktop\OTL.exe
[2011/11/12 12:17:29 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Seth\Desktop\HiJackThis.exe
[2011/11/12 12:15:35 | 000,607,260 | R— | C] (Swearware) – C:\Users\Seth\Desktop\dds.scr
[2011/11/09 17:20:49 | 005,610,638 | —- | C] (Adobe Systems, Inc.) – C:\Users\Seth\Desktop\Transformice.exe
[2011/11/05 14:50:54 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/11/05 14:49:20 | 002,560,616 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvsvcr.dll
[2011/11/05 14:49:20 | 000,066,664 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvshext.dll
[2011/11/05 14:49:19 | 000,543,336 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\easyupdatusapiu.dll
[2011/11/05 14:48:13 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2011/11/05 14:24:17 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/11/05 14:24:17 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/11/05 14:24:17 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/11/05 14:24:17 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/11/05 14:24:17 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/11/05 14:24:17 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/11/05 14:24:16 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/11/05 14:24:16 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/11/05 14:24:16 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/11/05 14:24:16 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/11/05 14:24:16 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/11/05 14:24:16 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/11/05 14:24:16 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/11/05 14:24:16 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/11/05 14:24:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/11/05 14:24:16 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/11/05 14:24:16 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/11/05 14:24:16 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/11/05 14:24:16 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/11/05 14:24:15 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/11/05 14:24:15 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/11/05 14:24:15 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/11/05 14:24:15 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/11/05 14:24:15 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/11/05 14:24:15 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/11/05 14:24:15 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/11/05 14:24:15 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/11/05 14:24:15 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/11/05 14:24:15 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/11/05 14:24:15 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/11/05 14:24:15 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/11/05 14:24:15 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/11/05 14:24:14 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/11/05 14:24:14 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/11/05 14:24:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/11/05 14:24:14 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/11/05 14:24:14 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/11/05 14:23:06 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/11/05 14:23:06 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/11/05 14:23:06 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/11/05 14:23:06 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/11/05 14:23:06 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/11/05 14:23:06 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/11/05 14:23:06 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/11/05 14:23:04 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/11/05 14:23:04 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/11/05 14:23:04 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/11/05 14:23:03 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/11/05 14:23:03 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/11/05 14:23:02 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/11/05 14:23:02 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/11/05 14:23:02 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/11/05 14:23:02 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/11/05 14:23:02 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/11/05 14:23:02 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/11/05 14:23:01 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/11/05 14:23:01 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/11/05 14:23:01 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/11/05 14:23:01 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/11/05 14:23:01 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/11/05 14:23:01 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/10/16 23:10:05 | 000,000,000 | —D | C] – C:\.jagex_cache_32

========== Files - Modified Within 30 Days ==========

[2011/11/13 13:43:18 | 000,006,560 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/13 13:43:18 | 000,006,560 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/13 13:42:16 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/11/13 13:30:09 | 000,598,350 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/11/13 13:30:09 | 000,101,988 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/11/13 13:25:24 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\Windows\gdrv.sys
[2011/11/13 13:25:21 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/13 13:21:58 | 004,292,869 | R— | M] (Swearware) – C:\Users\Seth\Desktop\ComboFix.exe
[2011/11/13 13:03:36 | 086,237,003 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/11/12 13:24:37 | 000,001,662 | —- | M] () – C:\Users\Public\Desktop\Defraggler.lnk
[2011/11/12 12:18:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Seth\Desktop\OTL.exe
[2011/11/12 12:17:32 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Seth\Desktop\HiJackThis.exe
[2011/11/12 12:15:41 | 000,607,260 | R— | M] (Swearware) – C:\Users\Seth\Desktop\dds.scr
[2011/11/12 12:01:11 | 000,000,491 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Transformice - Shortcut.lnk
[2011/11/12 12:01:04 | 000,000,215 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Call of Duty Black Ops - Multiplayer.url
[2011/11/12 12:01:02 | 000,000,667 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Rappelz.lnk
[2011/11/12 12:00:46 | 000,001,668 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Play League of Legends.lnk
[2011/11/09 20:22:51 | 000,045,010 | —- | M] () – C:\Users\Seth\Desktop\379706_272527072790861_100001007104949_811707_2112067813_n.jpg
[2011/11/09 17:21:10 | 005,610,638 | —- | M] (Adobe Systems, Inc.) – C:\Users\Seth\Desktop\Transformice.exe
[2011/11/05 14:24:22 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/11/05 14:24:22 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/11/05 14:24:17 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/11/05 14:24:17 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/11/05 14:24:17 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/11/05 14:24:17 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/11/05 14:24:17 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/11/05 14:24:17 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/11/05 14:24:16 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/11/05 14:24:16 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/11/05 14:24:16 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/11/05 14:24:16 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/11/05 14:24:16 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/11/05 14:24:16 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/11/05 14:24:16 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/11/05 14:24:16 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/11/05 14:24:16 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/11/05 14:24:16 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/11/05 14:24:16 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/11/05 14:24:16 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/11/05 14:24:16 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/11/05 14:24:16 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/11/05 14:24:15 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/11/05 14:24:15 | 001,798,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/11/05 14:24:15 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/11/05 14:24:15 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/11/05 14:24:15 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/11/05 14:24:15 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/11/05 14:24:15 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/11/05 14:24:15 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/11/05 14:24:15 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/11/05 14:24:15 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/11/05 14:24:15 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/11/05 14:24:15 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/11/05 14:24:15 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/11/05 14:24:14 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/11/05 14:24:14 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/11/05 14:24:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/11/05 14:24:14 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/11/05 14:24:14 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/11/05 14:23:06 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/11/05 14:23:06 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/11/05 14:23:06 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/11/05 14:23:06 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/11/05 14:23:06 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/11/05 14:23:06 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/11/05 14:23:06 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/11/05 14:23:04 | 000,683,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/11/05 14:23:04 | 000,288,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/11/05 14:23:04 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/11/05 14:23:03 | 001,068,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/11/05 14:23:03 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/11/05 14:23:02 | 001,172,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/11/05 14:23:02 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/11/05 14:23:02 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/11/05 14:23:02 | 000,219,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/11/05 14:23:02 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/11/05 14:23:02 | 000,160,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/11/05 14:23:01 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/11/05 14:23:01 | 000,876,032 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/11/05 14:23:01 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/11/05 14:23:01 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/11/05 14:23:01 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/11/05 14:23:01 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/11/05 14:11:42 | 000,000,830 | —- | M] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/05 14:11:42 | 000,000,806 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk

========== Files Created - No Company Name ==========

[2011/11/13 13:35:37 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/13 13:35:37 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/13 13:35:37 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/13 13:35:37 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/13 13:35:37 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/12 12:01:11 | 000,000,491 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Transformice - Shortcut.lnk
[2011/11/12 12:01:04 | 000,000,215 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Call of Duty Black Ops - Multiplayer.url
[2011/11/12 12:01:02 | 000,000,667 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Rappelz.lnk
[2011/11/12 12:00:46 | 000,001,668 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Play League of Legends.lnk
[2011/11/09 20:22:50 | 000,045,010 | —- | C] () – C:\Users\Seth\Desktop\379706_272527072790861_100001007104949_811707_2112067813_n.jpg
[2011/11/05 14:24:16 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/11/05 14:11:42 | 000,000,830 | —- | C] () – C:\Users\Seth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/05 14:11:42 | 000,000,818 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/05 14:11:42 | 000,000,806 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/29 14:58:15 | 000,009,550 | -HS- | C] () – C:\Users\Seth\AppData\Local\61x36458x38t121clu4y2
[2011/06/29 12:48:42 | 000,009,550 | -HS- | C] () – C:\ProgramData\61x36458x38t121clu4y2
[2011/01/26 22:44:40 | 000,230,752 | —- | C] () – C:\Windows\patchw32.dll
[2011/01/26 22:44:40 | 000,118,176 | —- | C] () – C:\Windows\patchw.dll
[2010/07/23 01:32:19 | 001,970,176 | —- | C] () – C:\Windows\System32\d3dx9.dll
[2010/03/12 18:41:50 | 000,002,688 | —- | C] () – C:\Windows\Sandboxie.ini
[2009/12/17 16:46:27 | 000,139,080 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2009/12/17 16:46:27 | 000,138,056 | —- | C] () – C:\Users\Seth\AppData\Roaming\PnkBstrK.sys
[2009/12/17 16:46:12 | 000,270,240 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/12/17 16:46:11 | 002,427,248 | —- | C] () – C:\Windows\System32\pbsvc_heroes.exe
[2009/12/17 16:46:11 | 000,075,136 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/11/21 15:22:41 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/11/21 15:22:41 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/11/21 15:22:09 | 000,062,976 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/06/26 18:38:36 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/04/09 14:20:59 | 000,000,552 | —- | C] () – C:\Users\Seth\AppData\Local\d3d8caps.dat
[2009/03/23 12:53:11 | 000,053,760 | —- | C] () – C:\Users\Seth\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/20 20:41:25 | 000,131,072 | —- | C] () – C:\Windows\System32\SpoonUninstall.exe
[2009/03/20 20:41:25 | 000,036,104 | —- | C] () – C:\Windows\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
[2009/03/20 19:14:57 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/20 06:35:38 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2009/03/20 06:33:28 | 000,000,680 | —- | C] () – C:\Users\Seth\AppData\Local\d3d9caps.dat
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2007/06/21 00:34:08 | 000,203,328 | R— | C] () – C:\Windows\GSetup.exe
[2007/03/12 11:01:30 | 000,217,088 | —- | C] () – C:\Windows\NVGfxOgl.dll
[2006/11/02 06:56:48 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:47:43 | 000,385,672 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 04:33:01 | 000,598,350 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,101,988 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/04/30 00:34:04 | 000,049,152 | —- | C] () – C:\Windows\System32\WbxRMenu.dll
[2006/04/13 23:18:24 | 000,196,608 | —- | C] () – C:\Windows\System32\atonres.dll
[2006/04/13 23:18:24 | 000,131,072 | —- | C] () – C:\Windows\System32\WbxMSAI.dll
[2006/04/13 23:18:24 | 000,098,304 | —- | C] () – C:\Windows\System32\atonecli.dll

< End of report >
———————————————————————————–

Extras

OTL Extras logfile created on: 11/13/2011 1:46:26 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Seth\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 60.72% Memory free
6.73 Gb Paging File | 5.60 Gb Available in Paging File | 83.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 137.54 Gb Free Space | 59.06% Space Free | Partition Type: NTFS

Computer Name: THEJACKAL | User Name: Seth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Mozilla Firefox 3.1 Beta 3\firefox.exe" -requestPending -osint -url "%1"
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07BB9FAD-2E2B-41E8-9E91-E6276BF094FA}" = lport=56423 | protocol=6 | dir=in | name=pando media booster |
"{09107DF3-7FAA-4E31-8061-DD2DE6BF6E05}" = rport=138 | protocol=17 | dir=out | app=system |
"{11AF0459-0BC9-4DCB-BCF6-8086CFFD5FA8}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{11DA840B-B6E8-48EB-A7CC-BF2D22153368}" = lport=139 | protocol=6 | dir=in | app=system |
"{16825FB2-84A1-4300-B53E-5CC0282E0D39}" = lport=57271 | protocol=17 | dir=in | name=pando media booster |
"{1CB01F8D-34D8-402A-8AB7-F78860DC1FF8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2B306C9C-B892-421B-B5EA-BAB033756D17}" = lport=57271 | protocol=6 | dir=in | name=pando media booster |
"{34B45291-772A-4F04-8190-6F0822B53E7F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{387964D6-2DC0-4745-A57D-A648D19D0AB2}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3F6C615C-302A-4180-8C98-CABDCD96BB61}" = lport=59119 | protocol=6 | dir=in | name=pando media booster |
"{415CA19D-60D8-4524-8B62-3CAA2B65899B}" = lport=59119 | protocol=6 | dir=in | name=pando media booster |
"{52344CE3-9F8E-4F70-B090-695C0636C2A1}" = rport=137 | protocol=17 | dir=out | app=system |
"{56519451-1206-4AF1-B6D7-CFECAC0B7C98}" = lport=57735 | protocol=6 | dir=in | name=pando |
"{5DEC9E79-4732-45B5-BC65-8D4935B1D570}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5E30E0BB-1DC4-44DA-B5E9-5D6FCF7FB0BB}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{6253A7C4-0C44-4D8F-84DE-296C2116FA87}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6356188F-4606-4AA4-B9BB-0D835982BAF5}" = lport=49158 | protocol=6 | dir=in | name=akamai netsession interface |
"{66422E0F-E69B-488A-8429-BFCC47432F64}" = lport=56423 | protocol=17 | dir=in | name=pando media booster |
"{667D6983-9970-43B0-ADC7-B45D5DB5BB41}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{6896567E-0A35-4A31-921E-73E339B587D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{68BCED43-EFF2-448A-92DC-BCC02A78349F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{697C435C-3781-42B4-B11B-970E086D2E7F}" = rport=139 | protocol=6 | dir=out | app=system |
"{6E8961A6-7626-453A-A880-636681216D48}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{7A578ABE-F7CF-4147-B987-D5B9B707CA6D}" = lport=138 | protocol=17 | dir=in | app=system |
"{81677FD0-5611-4CB0-AC2E-6C2D034CD999}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{83FC981D-3BD1-4AF6-827E-2FAA3438A674}" = lport=59119 | protocol=17 | dir=in | name=pando media booster |
"{8C72099C-F25D-44B1-A9E3-BC6AD23AE3DD}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{9681BBC0-57A0-4AD6-8527-F5A79527C8B9}" = rport=445 | protocol=6 | dir=out | app=system |
"{96B6A60F-8FA2-4967-925C-E788739BCB68}" = lport=57271 | protocol=17 | dir=in | name=pando media booster |
"{A0DBA538-9FCD-42E3-A229-3AF45CE895BA}" = lport=56423 | protocol=17 | dir=in | name=pando media booster |
"{AA816254-1468-4916-9FF0-760129E54FC6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{AABA4FCE-AC45-4814-AF58-D3422698D98D}" = lport=137 | protocol=17 | dir=in | app=system |
"{B0B4F62A-FF56-40C0-B233-4952779D0FDA}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C4221EEF-D624-4FF9-89AB-331F35125DA6}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{D2D7A7B5-7710-4054-A556-B4D53963E850}" = lport=56423 | protocol=6 | dir=in | name=pando media booster |
"{D3AFCEDA-5561-45CE-9C5A-B77A73845F26}" = lport=57271 | protocol=6 | dir=in | name=pando media booster |
"{E5A70ED7-BDCA-43B6-A937-6DF4513938A9}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |
"{E8D82BD1-71DB-43B1-8BFC-D153533394BC}" = lport=57735 | protocol=17 | dir=in | name=pando |
"{E9FCAA00-DAA7-4D19-99DA-66AF915C9DAB}" = lport=59119 | protocol=17 | dir=in | name=pando media booster |
"{F124BEC3-8B41-425A-8D2F-2677FFB7A609}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |
"{F47B57DE-2561-4674-9244-DFF522FAA7F9}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{F5163952-784F-48E0-B33E-408D62694CA9}" = lport=445 | protocol=6 | dir=in | app=system |
"{FE7C1858-B998-402E-A55B-F0CA11B9008B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02E54593-223B-41B8-9768-9F2B486C851E}" = protocol=17 | dir=in | app=c:\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{0630567C-358F-4454-9B51-61E3007D5FE5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{08E5B1E7-7ED0-4470-9192-8DFA086FB4C8}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{0B7DD510-B0CD-424B-9925-B9607947FBA5}" = protocol=17 | dir=in | app=c:\users\therolex\documents\games\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{0D29F274-DEFF-400F-9446-B6062CB814FF}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{0FEFDE81-FA82-4381-BCDD-75118DFE226C}" = dir=in | app=c:\program files\pando networks\pando\pando.exe |
"{1891106B-8554-4461-9D5A-7E049C999E8A}" = protocol=6 | dir=in | app=c:\program files\aeriagames\project torque\projecttorque.bin |
"{240812B8-9B17-4A36-AEAE-DC1E050771D9}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbtpswx.exe |
"{28ABE416-079A-437D-BC09-CA0CE0D31755}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{2C130691-67AF-4CCB-A7EA-D2EEF0D4609B}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{2CAB1920-6615-46F6-AB06-F55E9ED23AFE}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.0.1-to-3.0.2-enus-win-update-downloader.exe |
"{2E269A3B-E378-4E34-B9EF-EF483B88E255}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{3192C014-FC5B-42FB-9BA6-3E956CC47597}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{32B06C0A-61E4-465F-B0B6-27C74BF293DD}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{350AE138-6777-459F-BD03-37096992B9A9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{3B872049-8E7D-4A27-A4CF-D099D01075ED}" = protocol=6 | dir=in | app=c:\windows\system32\lxbtcoms.exe |
"{40B8C4B4-25F1-4835-9A24-B058DE3EF698}" = protocol=6 | dir=in | app=c:\users\therolex\documents\games\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{42139526-3953-4B58-AE0E-073D70A44FF7}" = protocol=17 | dir=in | app=c:\program files\pando networks\pando\pando.exe |
"{43230428-810F-45D3-AC1F-9DC13C6295D0}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{4422AEFE-8B0F-4824-9F36-7064FC54FDD3}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{45F2EB0D-D053-46C1-B523-989A3260A2C3}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{46D40D47-8CA5-46B2-9686-BA19E7C7FE17}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike source\hl2.exe |
"{472F31CE-6C1C-4B1B-A3A4-04FF8A6ADED6}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{4B7515FD-2605-4EC0-B6E3-D7E62D55735D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{4DA3B394-B722-45E5-8B36-E42B54C99D9C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{4FA5EC2D-A6AC-4772-B1E8-481A0399C8B8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{500EEA5C-686E-4758-86C9-753DD80A1379}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{528B1BA9-0B2C-4877-8795-B10A2914708A}" = protocol=6 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe |
"{532C1409-A002-492A-8B6F-00460D1591F9}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbtpswx.exe |
"{54217D47-A7E7-4AE2-A606-901C265143D4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{569DEDBD-08B3-4778-A966-B5662236C6D1}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{578A39F4-BE1F-44BA-A448-97726EF3F74A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{5AF8A35D-98E0-49B8-8254-1DC6D12F6E4A}" = protocol=17 | dir=in | app=c:\world of warcraft\launcher.exe |
"{5B49E7BF-644D-456F-89BC-9CFD11946111}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{66C405CB-FD0E-464D-BAC5-3A59FC263822}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{66D2C0D5-5263-4D6E-B1F6-B2642D16573F}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe |
"{68A1E95B-E05D-4D6D-986B-F22C89A0680B}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{6A33A0B9-9FB9-4499-B011-4CA20148DC60}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.0.1-to-3.0.2-enus-win-update-downloader.exe |
"{6A63914D-908C-423F-AFB4-4B6C3765A518}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{6DA35D32-4910-472B-8BE9-AF7E698E1E28}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{6DEE477A-E8F4-40B2-A30C-45DEC7497A85}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{6FE13D50-6E07-48A7-9F77-0FE395F7B814}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{756233A6-A4A4-4C44-A022-E56361B6B176}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{75DB10C1-F35D-4DEA-8A56-D3BA7C1E241F}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{76C5D368-3705-4C88-B338-3DFFA07A6EDE}" = protocol=6 | dir=in | app=c:\program files\pando networks\pando\pando.exe |
"{7CF117A9-D4F4-4A59-B26C-D99BBAE2F599}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike\hl.exe |
"{7FF3AF57-1BDD-443C-B4F1-57DFB2DD5D68}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
"{80BC4883-6949-4C0A-AAF6-29BB863A74F1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{81331BBB-B68A-4750-B8FC-3E7C8176D9CD}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{83941E4D-5EC1-4E63-A29B-3DE034BB8E65}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{83B7AA66-CFF7-423F-B4ED-426F206CD5A8}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{8656E136-29AC-4FFA-9268-5E830BE7920B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{89B968A6-6030-4FAF-82B7-ECDF72628565}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{905E21B5-4259-40D7-BD94-0B1166D8A54A}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{97E7009C-FDC1-4176-9155-95769C42F822}" = protocol=6 | dir=in | app=c:\program files\aeriagames\project torque\projecttorque.bin |
"{9A2E295B-8AE6-46BD-A550-21122C3B2B63}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{9DC8D04A-C02B-4EE9-8F1F-AE8FC57F5400}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{9F568D3C-9D30-4CD5-B4CD-1B0D0618EBFD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike\hl.exe |
"{A07CEDFC-BB5C-4CCE-852A-329C3ACD8278}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{A3CCCAEC-881A-42E2-9675-81753446B094}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{ADC733D8-B10F-480D-91CA-B54E9EE30FFD}" = protocol=6 | dir=in | app=c:\world of warcraft\launcher.exe |
"{B4336C6D-F732-491D-9A02-6E8A7B326E1E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{B55E0EB3-B9EC-48FD-A956-D6CA4C6044A0}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{B6DA7C2A-21AA-450A-8CB6-8C0B3E0FD39D}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{B7A5B918-6C29-4999-BE7A-6788C8D84A1C}" = protocol=6 | dir=in | app=c:\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{B7CC24F4-3D0C-4572-953C-65CF092F9718}" = protocol=17 | dir=in | app=c:\program files\aeriagames\project torque\projecttorque.bin |
"{B835E0DE-F8EA-4A8F-B73E-D77A3E8FFEA0}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{BB12B8DC-DD84-4F8B-B6E8-59A7F090DD00}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BBF34C75-92A9-4F50-ABFB-6C2D44154C8A}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe |
"{BE4485CF-CAB2-421C-89C8-BCB1E8159C47}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C25ED59F-3CAA-49CF-BE4F-C5C8D572668D}" = protocol=6 | dir=in | app=c:\program files\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{C49FF6DF-5F86-4E46-9107-0EB184BAEA81}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C72FF1A7-477A-4D5E-AD4D-037CAD88B1E7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C8789C60-0BA0-4C03-82F8-035CEF50304F}" = protocol=17 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe |
"{CDA8D88B-47D9-4AB5-9120-DFE1DBE11243}" = protocol=17 | dir=in | app=c:\program files\aeriagames\project torque\projecttorque.bin |
"{CF1DB7C8-9821-4B9E-B473-5AE70CF8AEDB}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{D639D5AB-5B62-47E0-A861-99D9DD4809E3}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{D92F3A5F-8DB4-45E0-AD04-0E2507DA3276}" = protocol=17 | dir=in | app=c:\windows\system32\lxbtcoms.exe |
"{DA4E4F50-1ADD-4208-9821-CC81A4824D4C}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{DC225965-3297-48B1-95B7-7C506EBE08FA}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{DEBD606E-4F5A-4448-9FD6-A660782CB924}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{E0AE3E48-3D0F-45D6-A797-81EE0D1D6361}" = protocol=17 | dir=in | app=c:\program files\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{E0BB8DE6-AF8D-48CE-BA5D-930C902E763E}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{E16302B3-7196-4980-9169-E59082F0DFFB}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{E8EA1498-D61F-4DA7-849C-B095DF43E20A}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{EE88F05E-E2E6-4757-9620-B56A8584B565}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{F39D917D-3C6B-40C1-9AFE-63332E9E0F58}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{F6016B5D-C379-44BD-A372-081933D24E0A}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{FFBE9B32-3D65-4619-A473-72300C8327D0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike source\hl2.exe |
"TCP Query User{0C46B273-CC02-4ECD-9BB1-1E478D64AF12}C:\users\seth\downloads\wowclient-downloader.exe" = protocol=6 | dir=in | app=c:\users\seth\downloads\wowclient-downloader.exe |
"TCP Query User{1A888201-1EE6-433B-B1AE-C682F617E656}C:\program files\steam\steamapps\timex5\half-life\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\half-life\hl.exe |
"TCP Query User{362278FA-2FAA-4B44-91A1-8A2B9DFBF549}C:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe |
"TCP Query User{383946D1-FFE8-488E-A7F4-EC62611E5218}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"TCP Query User{3A6E72D4-B494-4F3C-A336-F1B33D5727E6}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{3B67DE89-FB59-4F90-85B3-EAD5363606E5}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{454635FF-C9B6-4504-B0CA-19C61BFD5AE7}C:\program files\steam\steamapps\timex5\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike source\hl2.exe |
"TCP Query User{4FCE3A28-4CFF-4859-BBFE-F71C0BD2A8FF}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{59D0892E-B736-4938-A8CF-D4CE6B3C1627}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=6 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"TCP Query User{5DFEED18-0B7E-441B-9FB3-833DF3F46783}C:\users\therolex\documents\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\therolex\documents\games\world of warcraft\launcher.exe |
"TCP Query User{623D8EC4-77F7-446F-9D75-7391280A4B10}C:\users\seth\desktop\fogdownloader-rom_3_0_1_2153.exe" = protocol=6 | dir=in | app=c:\users\seth\desktop\fogdownloader-rom_3_0_1_2153.exe |
"TCP Query User{662154E2-E9A4-4020-9B78-9CAEA19BF651}C:\users\seth\desktop\sro_l4_full_client_downloader.exe" = protocol=6 | dir=in | app=c:\users\seth\desktop\sro_l4_full_client_downloader.exe |
"TCP Query User{66A16B08-4FF9-4C63-B768-FB33472687CF}C:\program files\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"TCP Query User{68238170-25B7-4908-8494-BE31D78882C3}C:\program files\steam\steamapps\timex5\counter-strike\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike\hl.exe |
"TCP Query User{6CB19B10-E1FD-4DFA-B9A0-8BA41B87D6E4}C:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe |
"TCP Query User{8ED01080-942E-47EC-896B-52ED81F6C70F}C:\program files\gigabyte\@bios\gwflash.exe" = protocol=6 | dir=in | app=c:\program files\gigabyte\@bios\gwflash.exe |
"TCP Query User{A33824BF-10B9-412B-B6E7-21CB9FAF8FC1}C:\program files\steam\steamapps\copperhead07\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\copperhead07\counter-strike source\hl2.exe |
"TCP Query User{A84128EC-6D62-4607-8124-40732E21D31E}C:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"TCP Query User{A969F52A-4B2C-417F-9D22-C2A3C4D57BCA}C:\users\seth\desktop\srobot.exe" = protocol=6 | dir=in | app=c:\users\seth\desktop\srobot.exe |
"TCP Query User{AC5E30D2-FFCC-4ABE-8FEB-DFC550D2F75F}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{B4346408-2BC9-4626-9415-6FB3AF59986A}C:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe |
"TCP Query User{B8609507-054C-4B08-8AB3-7EF1071EA1EA}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{D2CD8441-9ADD-4EE6-87F0-7925CA3DF035}C:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"TCP Query User{D8B260D7-CF84-4D4F-A65A-B7AB99269B35}C:\program files\mozilla firefox 3.1 beta 3\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox 3.1 beta 3\firefox.exe |
"TCP Query User{DCE3321C-3C0C-4563-8649-DBB480B3DFB0}C:\users\seth\desktop\teamspeak3-server_win32-3.0.0-beta30\teamspeak3-server_win32\ts3server_win32.exe" = protocol=6 | dir=in | app=c:\users\seth\desktop\teamspeak3-server_win32-3.0.0-beta30\teamspeak3-server_win32\ts3server_win32.exe |
"TCP Query User{DDA4FDCF-8B86-4C2A-9721-35713561DD62}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{E1CEBD48-3BF9-419E-8A9E-F47B9A964A26}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"TCP Query User{E4645042-A72B-471D-8038-184DCE8F0671}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"TCP Query User{EAE9ED78-A71A-4DC1-92EF-7996B47F334F}C:\users\seth\appdata\local\temp\pt2_downloader.exe" = protocol=6 | dir=in | app=c:\users\seth\appdata\local\temp\pt2_downloader.exe |
"TCP Query User{F175D33A-4D88-4E82-A985-59437F46AFE6}C:\users\seth\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\seth\program files\dna\btdna.exe |
"TCP Query User{F556810A-E7A6-44C2-BC6F-294C8067CA2F}C:\users\seth\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\seth\program files\dna\btdna.exe |
"TCP Query User{F682C622-8B92-4E8F-AEEE-F086D9984ABF}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{F6EEE7EA-FF86-4047-828D-C285E0FF6B45}C:\program files\aim\aim pro\aimpro.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim pro\aimpro.exe |
"TCP Query User{FA0A2AD7-3753-47AA-ABB0-BB0EE02D4002}C:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe |
"TCP Query User{FB875F3F-A01A-4263-A247-F7B2F7A56D53}C:\program files\runes of magic\client.exe" = protocol=6 | dir=in | app=c:\program files\runes of magic\client.exe |
"TCP Query User{FBA6E936-CFBE-4D8C-8AF6-4FDB52347679}C:\users\seth\desktop\fogdownloader-rom_2_1_0_1871.exe" = protocol=6 | dir=in | app=c:\users\seth\desktop\fogdownloader-rom_2_1_0_1871.exe |
"TCP Query User{FD5BEE4D-F733-4982-8295-9F63271873E9}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{0D7321F4-4AEF-4B4F-8E29-609E3AF165BA}C:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe |
"UDP Query User{12CE3B4A-1C7E-4B4B-82D1-92C79A27C747}C:\program files\gigabyte\@bios\gwflash.exe" = protocol=17 | dir=in | app=c:\program files\gigabyte\@bios\gwflash.exe |
"UDP Query User{25393606-A7B1-447A-8DAE-24571BF0A678}C:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\half-life 2 deathmatch\hl2.exe |
"UDP Query User{2A71DD19-ECD6-4CA0-8E54-C585B2D00FCF}C:\users\seth\desktop\fogdownloader-rom_2_1_0_1871.exe" = protocol=17 | dir=in | app=c:\users\seth\desktop\fogdownloader-rom_2_1_0_1871.exe |
"UDP Query User{2E127A90-5027-4D5A-93B9-C6AB8CD6B345}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{2ED8D3BA-56C2-4ECA-AF5B-57E7CF2D7E9F}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{3008AE57-5D0D-4F85-90FB-CE2135FC4318}C:\users\seth\desktop\sro_l4_full_client_downloader.exe" = protocol=17 | dir=in | app=c:\users\seth\desktop\sro_l4_full_client_downloader.exe |
"UDP Query User{3AA19A03-3EAA-47B0-87DB-78FBE5FC2EC2}C:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe |
"UDP Query User{4006DA00-4C4A-4731-A648-A5FFBDC78447}C:\program files\steam\steamapps\timex5\counter-strike\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike\hl.exe |
"UDP Query User{42729292-CA8E-4231-ADCC-984DD6BAC788}C:\program files\steam\steamapps\timex5\half-life\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\half-life\hl.exe |
"UDP Query User{46425304-0880-4441-93B9-DE51752B7436}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{50196508-EBF4-4609-B646-893210B04ADD}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=17 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"UDP Query User{535E2313-21C6-43F4-83E0-93C26D2A1D5B}C:\users\therolex\documents\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\therolex\documents\games\world of warcraft\launcher.exe |
"UDP Query User{56F05080-E9F9-4200-B408-F9224129EEFD}C:\program files\mozilla firefox 3.1 beta 3\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox 3.1 beta 3\firefox.exe |
"UDP Query User{5AE47F8B-8804-4A7D-9F06-C81BF994B5B6}C:\users\seth\downloads\wowclient-downloader.exe" = protocol=17 | dir=in | app=c:\users\seth\downloads\wowclient-downloader.exe |
"UDP Query User{6F9FCD90-1FD5-4BA7-B870-BE87D031A2D2}C:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"UDP Query User{77AACEEA-DE23-458A-86B6-D1283F154679}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{7C9650B2-ABBB-4595-A360-141868EDFCA2}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{862ACAF6-174F-49E9-AC60-A87F06C985DD}C:\users\seth\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\seth\program files\dna\btdna.exe |
"UDP Query User{9808AC17-C02C-4175-9B37-EDAAE7C3F0A9}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{98A79715-E437-4AF4-9EE3-0945B4119043}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{9E1A6CDA-466D-4FA3-9BFB-F3D8501DFA86}C:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\rolex121\team fortress 2\hl2.exe |
"UDP Query User{AC61DDD3-71B0-4D84-825C-980173936186}C:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"UDP Query User{ADD3B6B3-CD62-4911-A693-77103F97FE88}C:\program files\steam\steamapps\copperhead07\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\copperhead07\counter-strike source\hl2.exe |
"UDP Query User{B1BC34F3-526D-426E-854B-1917483E326E}C:\users\seth\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\seth\program files\dna\btdna.exe |
"UDP Query User{C21FAA95-DD22-445A-BEDB-FC621378E6CF}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{C34A0950-48C1-411D-B190-2991C45CD18D}C:\program files\runes of magic\client.exe" = protocol=17 | dir=in | app=c:\program files\runes of magic\client.exe |
"UDP Query User{C3F65AED-EF61-4F0F-913F-BB13F4FE866F}C:\users\seth\desktop\srobot.exe" = protocol=17 | dir=in | app=c:\users\seth\desktop\srobot.exe |
"UDP Query User{CDD55B66-11FC-49CF-9217-459268193DDB}C:\program files\aim\aim pro\aimpro.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim pro\aimpro.exe |
"UDP Query User{D1737895-6B65-4984-B1E5-1746E4F83FDB}C:\program files\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"UDP Query User{D8E83C75-2FD6-4702-A48B-ED58BEF2F9C5}C:\users\seth\appdata\local\temp\pt2_downloader.exe" = protocol=17 | dir=in | app=c:\users\seth\appdata\local\temp\pt2_downloader.exe |
"UDP Query User{DC5EBBAF-4A1A-4ECA-907F-AAFD166A9C48}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{E413B6D9-AB16-4B25-B79D-1E0C4F6FB9E5}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{E7BA5653-607D-4F9A-8BE2-71A0CA154AD5}C:\users\seth\desktop\teamspeak3-server_win32-3.0.0-beta30\teamspeak3-server_win32\ts3server_win32.exe" = protocol=17 | dir=in | app=c:\users\seth\desktop\teamspeak3-server_win32-3.0.0-beta30\teamspeak3-server_win32\ts3server_win32.exe |
"UDP Query User{E8E01BE1-7088-4982-96E0-8A75E717AC6E}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{EEA340CB-D3D0-4F2B-A5C6-949623758D5B}C:\program files\steam\steamapps\timex5\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\timex5\counter-strike source\hl2.exe |
"UDP Query User{F9BADB4D-7B8A-4B60-A5AB-2B9B8C004FB6}C:\users\seth\desktop\fogdownloader-rom_3_0_1_2153.exe" = protocol=17 | dir=in | app=c:\users\seth\desktop\fogdownloader-rom_3_0_1_2153.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3A9D04F7-80CA-4755-97EC-6025B515A6B8}" = League of Legends
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B08.1027.1
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B8.1015.1
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C538746-C2DC-40FC-B1FB-D4EA7966ABEB}" = Skype™ 5.1
"{A1DD0268-4069-4D39-B6D2-E00DB50CA9C4}" = League of Legends
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.03
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DF2035BE-5820-4965-BD97-7FAF8D4A7879}" = Microsoft_VC90_CRT_x86
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{EAD475E8-14E5-4854-8AF5-CE6B4024237C}_is1" = Rappelz_US
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_7" = AIM 7
"AVG8Uninstall" = AVG 8.5
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"CCleaner" = CCleaner
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"Defraggler" = Defraggler
"ENTERPRISE" = Microsoft Office Enterprise 2007
"GoldWave v5.20" = GoldWave v5.20
"GSC 2.00" = GSC 2.00
"HyperCam 2" = HyperCam 2
"InstallShield_{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B08.1027.1
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"PunkBusterSvc" = PunkBuster Services
"Sandboxie" = Sandboxie 3.52
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Steam App 240" = Counter-Strike: Source
"Steam App 42700" = Call of Duty: Black Ops
"Steam App 42710" = Call of Duty: Black Ops - Multiplayer
"Steam App 440" = Team Fortress 2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.1.0
"WinAVI Video Converter 9.09.0" = WinAVI Video Converter 9.0
"WinGimp-2.0_is1" = GIMP 2.6.10
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/1/2011 4:56:04 PM | Computer Name = TheJackal | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module datamngr.dll, version 1.0.0.1, time stamp 0x4de6a459, exception
code 0xc0000005, fault offset 0x0003c98e, process id 0x9e0, application start time
0x01cc98d8a411bc45.

Error - 11/1/2011 5:08:11 PM | Computer Name = TheJackal | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module datamngr.dll, version 1.0.0.1, time stamp 0x4de6a459, exception
code 0xc0000005, fault offset 0x0003c98e, process id 0x4b8, application start time
0x01cc98d8a60cf005.

Error - 11/2/2011 7:54:30 AM | Computer Name = TheJackal | Source = WinMgmt | ID = 10
Description =

Error - 11/2/2011 7:57:35 AM | Computer Name = TheJackal | Source = Software Licensing Service | ID = 8198
Description = License Activation (SLUI.exe) failed with the following error code:
0x80070057

Error - 11/2/2011 8:14:35 AM | Computer Name = TheJackal | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 15.0.874.106, time stamp
0x4ea7969e, faulting module datamngr.dll, version 1.0.0.1, time stamp 0x4de6a459,
exception code 0xc0000005, fault offset 0x0005170e, process id 0x2bc, application
start time 0x01cc995638bd4fa2.

Error - 11/2/2011 8:22:33 AM | Computer Name = TheJackal | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 15.0.874.106, time stamp
0x4ea7969e, faulting module datamngr.dll, version 1.0.0.1, time stamp 0x4de6a459,
exception code 0xc0000005, fault offset 0x0005170e, process id 0x104c, application
start time 0x01cc9959b97d6d22.

Error - 11/2/2011 4:21:19 PM | Computer Name = TheJackal | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module datamngr.dll, version 1.0.0.1, time stamp 0x4de6a459, exception
code 0xc0000005, fault offset 0x0003c98e, process id 0x17ec, application start time
0x01cc999ce7c1ed32.

Error - 11/2/2011 4:25:35 PM | Computer Name = TheJackal | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module datamngr.dll, version 1.0.0.1, time stamp 0x4de6a459, exception
code 0xc0000005, fault offset 0x0003c98e, process id 0x484, application start time
0x01cc999cf02c2992.

Error - 11/2/2011 5:02:39 PM | Computer Name = THEJACKAL | Source = WinMgmt | ID = 10
Description =

Error - 11/2/2011 5:11:22 PM | Computer Name = TheJackal | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 11/12/2011 5:11:40 PM | Computer Name = TheJackal | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 11/13/2011 3:01:46 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7000
Description =

Error - 11/13/2011 3:01:46 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7000
Description =

Error - 11/13/2011 3:01:48 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7026
Description =

Error - 11/13/2011 3:23:46 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7034
Description =

Error - 11/13/2011 3:25:26 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7000
Description =

Error - 11/13/2011 3:25:28 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7026
Description =

Error - 11/13/2011 3:36:22 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7030
Description =

Error - 11/13/2011 3:40:20 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7030
Description =

Error - 11/13/2011 3:42:18 PM | Computer Name = TheJackal | Source = Service Control Manager | ID = 7030
Description =


< End of report >


I deleted the P2P all utorrents, bittorrents ect ect

I tried my best to delete all of ask tool bar as best I could as well

Thanks for the help you given so far looking forwards to the next reply
Hi SethE1

That’s looking better.

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Please let me know how the computer is running now and if there are any remaining problems.

Thanks

Satchfan
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8156 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 11/13/2011 6:34:59 PM mbam-log-2011-11-13 (18-34-59).txt Scan type: Full scan (C:\|) Objects scanned: 319488 Time elapsed: 51 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Computer does seem a bit faster, things are not going to instantly to not responding like they were, firefox, chrome, and explorer are stable now from what i see, ill monitor them next few days see if anything acts up. But so far so good, Thanks a TON for all the help i love that you helped.
Hi SethE1

• Hold down the Windows key and press R to open a run box
• type the following text into the run box

appwiz.cpl

• This will open your Programs and Features
• A list of installed programs will populate
• Remove the following program:

Searchqu 406 MediaBar


===================================================

Remove remnants of Norton
  • download the Norton Removal Tool from here and save it to your desktop.
  • double click on Norton_Removal_Tool.exe to run the tool.
  • follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

===================================================

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Let me know if there are any outstanding problems

Satchfan
Okay well im about to run that online scan,

But now my computer must have malware or a virus due to the fact the now the computer is slowish, TC/Ping has stopped working keeps popping up, and AVG pops up Infected file detected but cant remove 5 times a minute now, and when i open my internet it sends me to a site telling me my computer is infected do this free microsoft scan to find all your virus, (of course i dont click it) (link to the site i suggest no one click it incase it is a virus: http://www.windowslivetechsupport.com/sv/i…&p_id=1003) AVG the infected file is somewhere in my temp internet or win32

What can i do so you guys and help me figure out whats wrong now…
SethE1

Run RogueKiller

Note: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when prompted, type 1 and press Enter
  • the RKreport.txt will be generated next to the executable, (on the desktop).
    If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.

Remember: do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Satchfan
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Seth [Admin rights]
Mode: Scan – Date : 11/16/2011 15:14:40

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 2 ¤¤¤
[HJ] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤


Finished : << RKreport[1].txt >>
RKreport[1].txt

Ran MBA as well it found nothing also, then the ESET scan found 3 things but it left no log behind for me to post, it said it cured 2/3 so 1 of them didnt get fixed.
When i search on google and click a link it sends me to a different site

TCP/IP had stopped pops up alot now as well.
Please post the log found by the Eset scan so that I can see what was found.

The log created by the scan can be found here:

C:\Program Files\ESET\EsetOnlineScanner\log.txt

Satchfan
Hello SethE1 It has been several days since I posted instructions to help with your computer problem. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI