This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

need review of hijackthis log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
not sure if i'm infected or not… been noticing a lot of things cropping up with my system and was just wondering if someone could review the attached hijack this log.

be much appreciated.

thanks.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:38:06 AM, on 13/11/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\My Documents\Downloads\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.msn.com/?lang=en-ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll
O3 - Toolbar: FrostWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE /FU "C:\WINDOWS\TEMP\E_S221.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1295222014093
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} (diskhealth Class) - http://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} (Photo Upload Plugin Class) - http://costco.pnimedia.com/upload/activex/…veX_Control.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s…el_4.3.16.0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} (Photo Upload Plugin Class) - http://costco.pnimedia.com/upload/activex/…veX_Control.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

–
End of file - 8868 bytes
Hello stmayhem and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

• disable any script blocking protection (How to Disable your Security Programs)
• double click DDS icon to run the tool (may take up to 3 minutes to run)
• when done, DDS.txt will open.
• after a few moments, attach.txt will open in a second window.
• save both reports to your desktop.
• Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

DDS.txt
Attach.txt
aswMBR log


Thanks

Satchfan
as requested: DDS log: . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 17:05:20 on 2011-11-14 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1444 [GMT -5:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Winamp\winamp.exe C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1312.0\msneshellx.dll BHO: Ask Toolbar BHO: {d4027c7f-154a-4066-a1ad-4243d8127440} - FrostWire Toolbar BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1312.0\msneshellx.dll TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [EPSON Artisan 50 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiffa.exe /fu "c:\windows\temp\E_S221.tmp" /EF "HKCU" mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1295222014093 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://costco.pnimedia.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.16.0.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} - hxxp://costco.pnimedia.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{9512CBCA-D924-4335-85D9-3C24D6ACC0C2} : DhcpNameServer = 192.168.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-3 371544] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-5 301528] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-10-1 116608] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-5 19544] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-5 42184] R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2010-12-28 583640] S2 NIHardwareService;NIHardwareService;c:\program files\common files\native instruments\hardware\NIHardwareService.exe [2009-7-17 3576320] S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872] S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys –> c:\windows\system32\vsdatant.sys [?] . =============== Created Last 30 ================ . 2011-11-13 14:19:49 ——– d—–w- c:\documents and settings\owner\application data\Unity 2011-11-13 14:17:21 ——– d—–w- c:\documents and settings\owner\local settings\application data\Unity 2011-10-19 22:41:36 ——– dc-h–w- c:\documents and settings\all users\application data\{BAF9AC5D-AA3E-4138-92BE-340E0F0D21EA} 2011-10-18 19:55:18 ——– d—–w- c:\program files\IK Multimedia 2011-10-18 18:36:18 ——– d—–w- c:\program files\ASIO4ALL v2 2011-10-18 18:30:51 ——– dc-h–w- c:\documents and settings\all users\application data\{D69A48BF-7653-4AA8-94BC-5847522A4573} 2011-10-18 18:25:56 ——– d—–w- c:\program files\common files\Digidesign 2011-10-18 18:24:44 ——– dc-h–w- c:\documents and settings\all users\application data\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222} 2011-10-18 18:23:52 ——– dc-h–w- c:\documents and settings\all users\application data\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2} 2011-10-18 18:23:42 ——– d—–w- c:\program files\Native Instruments . ==================== Find3M ==================== . 2011-10-18 19:57:47 16 —-a-w- c:\windows\system32\msvcsv60.dll 2011-10-17 16:34:37 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-03 10:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-10-03 07:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-08-31 21:00:50 22216 —-a-w- c:\windows\system32\drivers\mbam.sys . ============= FINISH: 17:11:08.81 =============== Attach log: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 05/04/2010 2:15:22 PM System Uptime: 13/11/2011 10:30:58 AM (31 hours ago) . Motherboard: Dell Computer Corp. | | 0WF887 Processor: Intel® Celeron® CPU 2.66GHz | Microprocessor | 2660/533mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 74 GiB total, 34.856 GiB free. D: is CDROM () E: is CDROM () F: is FIXED (NTFS) - 932 GiB total, 788.265 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP605: 09/11/2011 10:24:19 AM - System Checkpoint RP606: 09/11/2011 9:16:28 PM - Software Distribution Service 3.0 RP607: 10/11/2011 10:14:25 PM - System Checkpoint RP608: 11/11/2011 6:31:09 PM - Installed Java™ 6 Update 29 RP609: 12/11/2011 7:25:45 PM - System Checkpoint RP610: 13/11/2011 7:35:57 PM - System Checkpoint . ==== Installed Programs ====================== . µTorrent 32 Bit HP CIO Components Installer 7-Zip 9.20 Adobe AIR Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 10 Plugin Adobe Flash Player 11 ActiveX Adobe Help Center 1.0 Adobe Illustrator CS2 Adobe Photoshop CS2 Adobe Reader X (10.1.1) Adobe Shockwave Player 11.6 Adobe Stock Photos 1.0 Adobe SVG Viewer 3.0 AndreaMosaic 3.32.3 Any Video Converter 3.2.2 Apple Application Support Apple Software Update Ashampoo Burning Studio 6 FREE ASIO4ALL Auslogics Disk Defrag avast! Free Antivirus BufferChm CCleaner ConvertXtoDVD 2.2.0.251 ConvertXtoDVD 3.3.4.106e Copy CyberLink PhotoNow CyberLink PowerDirector Destinations DeviceDiscovery Digital Photo Navigator 1.5 DJ_AIO_05_F4400_Software_Min EPSON Artisan 50 Series Printer Uninstall Everio MediaBrowser F4400 Facebook Plug-In GoldWave v5.55 Google Chrome GPBaseService2 Guitar Pro 5.0 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB942288-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB981793) HP Deskjet F4400 Printer Driver Software 13.0 Rel .5 HP Imaging Device Functions 13.0 HP Print Projects 1.0 HP Smart Web Printing 4.60 HP Solution Center 13.0 HP Update hpPrintProjects HPProductAssistant hpWLPGInstaller HyperLoad - Wiffle Baseball Intel® Extreme Graphics 2 Driver Intel® Network Connections 14.2.100.0 Java Auto Updater Java™ 6 Update 29 K-Lite Mega Codec Pack 7.6.0 LWS Help_main Malwarebytes' Anti-Malware version 1.51.2.1300 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 MSN MSN Toolbar MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) Native Instruments Controller Editor Native Instruments Guitar Rig 4 Native Instruments Rammfire Native Instruments Service Center OpenOffice.org 3.3 Philips Songbird Photodex Presenter ProShow Gold QuickTime Registry Mechanic 9.0 Scan Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Segoe UI Simply Accounting by Sage 2007 Skype Toolbars Skype™ 4.2 SmartSound Quicktracks Plugin SmartWebPrinting SolutionCenter Spelling Dictionaries Support For Adobe Reader 9 Status SUPERAntiSpyware Free Edition swMSM System Requirements Lab for Intel Toolbox TrayApp Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Vector Magic VST Bridge 1.1 WebEx Record and Playback WebFldrs XP WebReg Winamp Winamp Detector Plug-in Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows PowerShell™ 1.0 Windows XP Service Pack 3 WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 08/11/2011 6:15:59 PM, error: Service Control Manager [7034] - The NIHardwareService service terminated unexpectedly. It has done this 1 time(s). 08/11/2011 6:10:38 PM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting. . ==== End Of File =========================== MBR log: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-14 17:25:06 —————————– 17:25:06.062 OS Version: Windows 5.1.2600 Service Pack 3 17:25:06.062 Number of processors: 1 586 0x409 17:25:06.062 ComputerName: USER-A6148CA035 UserName: Owner 17:25:06.453 Initialize success 17:25:06.781 AVAST engine defs: 11111400 17:25:09.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 17:25:09.000 Disk 0 Vendor: HDS728080PLAT20 PF2OA27A Size: 76293MB BusType: 3 17:25:11.015 Disk 0 MBR read successfully 17:25:11.015 Disk 0 MBR scan 17:25:11.015 Disk 0 Windows XP default MBR code 17:25:11.031 Disk 0 scanning sectors +156232125 17:25:11.187 Disk 0 scanning C:\WINDOWS\system32\drivers 17:25:29.109 Service scanning 17:25:30.203 Modules scanning 17:25:56.796 Disk 0 trace - called modules: 17:25:56.812 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS 17:25:56.812 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a600ab8] 17:25:56.812 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a5bdd98] 17:25:57.515 AVAST engine scan C:\WINDOWS 17:26:09.812 AVAST engine scan C:\WINDOWS\system32 17:29:54.953 AVAST engine scan C:\WINDOWS\system32\drivers 17:30:26.875 AVAST engine scan C:\Documents and Settings\Owner 18:23:44.015 AVAST engine scan C:\Documents and Settings\All Users 18:29:29.015 Scan finished successfully 18:35:04.234 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 18:35:04.250 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt" thanks for taking the time to review this info.
Hi stmayhem

There’s nothing showing up in those logs except some remnants.

One thing showing up is vsdatant.sys which is a ZoneAlarm file. Did you have ZoneAlarm installed previously?

Let’s try another scan

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Logs to include with next post:

OTL.txt
Extras.txt


Thanks

Satchfan
i'm not sure that I ever had zone alarm installed on this system. I originally bought it off a friend… they have had it installed prior to me purchasing it…

as requested:

OTL.txt:


OTL logfile created on: 15/11/2011 10:33:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.51% Memory free
5.85 Gb Paging File | 5.49 Gb Available in Paging File | 93.88% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 33.83 Gb Free Space | 45.41% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 789.34 Gb Free Space | 84.74% Space Free | Partition Type: NTFS

Computer Name: USER-A6148CA035 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Alwil Software\Avast5\defs\11111501\algo.dll ()
MOD - C:\Program Files\Alwil Software\Avast5\defs\11111501\aswRep.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\pdf.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\avutil-51.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\avformat-53.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\avcodec-53.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\gcswf32.dll ()
MOD - C:\Program Files\Alwil Software\Avast5\aswDld.dll ()
MOD - C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (NIHardwareService) – C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (LVUVC) Logitech Webcam 120(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.msn.com/?lang=en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.8.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.5.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.1002
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.19.1667
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2202
FF - prefs.js..extensions.enabledItems: [removed]:5.0.0.2417
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2200
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2207
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2203
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7.1667

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 23:15:34 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 23:15:34 | 000,000,000 | —D | M]

[2011/09/26 09:40:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/12/29 19:27:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/12/29 19:30:19 | 000,000,530 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Philips-Songbird\Profiles\zuwulc4y.default\searchplugins\e6e50a4b-2416-4c43-925e-dd78043fe347.xml
[2011/01/15 12:14:00 | 000,000,000 | —D | M] (Philips Branding) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:29:47 | 000,000,000 | —D | M] (QuickTime Playback) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:29:48 | 000,000,000 | —D | M] (Windows Media Playback) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:27:20 | 000,000,000 | —D | M] (7digital Music Store) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (Artwork Extras) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:13 | 000,000,000 | —D | M] (CD Rip Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:20 | 000,000,000 | —D | M] (Concerts) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:15 | 000,000,000 | —D | M] (AAC Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:17 | 000,000,000 | —D | M] (H.264 Video Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:15 | 000,000,000 | —D | M] (MP3 Encoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:16 | 000,000,000 | —D | M] (MPEG-4 Video Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (File association) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (Philips GoGear Device Manager) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (gonzo) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:13 | 000,000,000 | —D | M] (Gracenote Metadata Lookup Provider) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:19 | 000,000,000 | —D | M] (mashTape) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:11 | 000,000,000 | —D | M] (MSC Device Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:12 | 000,000,000 | —D | M] (MTP Device Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:14 | 000,000,000 | —D | M] (Philips addon manager) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (Philips auto msc-mtp switch) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:08 | 000,000,000 | —D | M] (Philips Skin) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:08 | 000,000,000 | —D | M] (Philips UI) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (Purple Rain) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: Photodex Presenter Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npPxPlay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2006/02/28 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKCU..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11c_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1295222014093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} http://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll (diskhealth Class)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://costco.pnimedia.com/upload/activex/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s…el_4.3.16.0.cab (SysInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://costco.pnimedia.com/upload/activex/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9512CBCA-D924-4335-85D9-3C24D6ACC0C2}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\crypt32chain: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cryptnet: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cscdll: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\Schedule: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\sclgntfy: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\SensLogn: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\termsrv: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/05 13:13:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/03/06 06:54:34 | 000,000,000 | RH-D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 07:56:50 | 000,000,036 | RH– | M] () - F:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{110886aa-40f3-11df-bcc7-001320e7d5ea}\Shell - "" = AutoRun
O33 - MountPoints2\{110886aa-40f3-11df-bcc7-001320e7d5ea}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f2e80ca9-12fb-11e0-bd36-001320e7d5ea}\Shell\AutoRun\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/15 08:09:55 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/14 17:05:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\Administrative Tools
[2011/11/14 17:04:26 | 000,607,017 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.pif
[2011/11/13 09:19:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Unity
[2011/11/13 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Unity
[2011/11/11 18:32:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/11/11 18:31:45 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/11/11 18:31:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/11/11 18:31:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/11/07 08:17:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\misfits show
[2011/10/19 17:41:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BAF9AC5D-AA3E-4138-92BE-340E0F0D21EA}
[2011/10/19 09:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Kevin Powe Portfolio
[2011/10/18 14:55:18 | 000,000,000 | —D | C] – C:\Program Files\IK Multimedia
[2011/10/18 13:36:18 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2011/10/18 13:36:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\ASIO4ALL v2
[2011/10/18 13:30:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{D69A48BF-7653-4AA8-94BC-5847522A4573}
[2011/10/18 13:25:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Digidesign
[2011/10/18 13:24:44 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}
[2011/10/18 13:23:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}
[2011/10/18 13:23:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Native Instruments
[2011/10/18 13:23:42 | 000,000,000 | —D | C] – C:\Program Files\Native Instruments
[2010/04/05 17:47:28 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Owner\Application Data\pcouffin.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/15 22:35:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-515967899-682003330-1003UA.job
[2011/11/15 22:28:08 | 000,000,671 | —- | M] () – C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2011/11/15 20:01:40 | 000,000,664 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\d3d9caps.dat
[2011/11/15 08:10:04 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/15 02:35:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-515967899-682003330-1003Core.job
[2011/11/14 18:35:04 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2011/11/14 17:04:31 | 000,607,017 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.pif
[2011/11/13 14:07:44 | 000,012,378 | —- | M] () – C:\Documents and Settings\Owner\Desktop\new song titles.odt
[2011/11/13 10:32:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/13 10:24:10 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/12 13:05:04 | 000,228,352 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/09 21:08:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/08 22:54:14 | 000,444,106 | —- | M] () – C:\Documents and Settings\Owner\Desktop\2009311_16742_logo.jpg
[2011/11/08 18:12:37 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/08 18:12:37 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/08 18:07:15 | 001,299,416 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/05 08:59:32 | 000,101,272 | —- | M] () – C:\Documents and Settings\Owner\Desktop\450978_700b.jpg
[2011/10/31 13:51:34 | 000,019,834 | —- | M] () – C:\Documents and Settings\Owner\Desktop\idea for printing.odt
[2011/10/30 10:12:11 | 000,053,079 | —- | M] () – C:\Documents and Settings\Owner\Desktop\420615_460s.jpg
[2011/10/26 11:35:06 | 003,118,701 | —- | M] () – C:\Documents and Settings\Owner\Desktop\P1030175.JPG
[2011/10/20 09:08:12 | 000,014,238 | —- | M] () – C:\Documents and Settings\Owner\My Documents\rick solar logix ad.odt
[2011/10/19 11:35:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/10/18 14:57:47 | 000,000,016 | —- | M] () – C:\WINDOWS\System32\w3data.vss
[2011/10/18 14:57:47 | 000,000,016 | —- | M] () – C:\WINDOWS\System32\msvcsv60.dll
[2011/10/18 14:57:47 | 000,000,016 | —- | M] () – C:\WINDOWS\msocreg32.dat
[2011/10/18 13:36:18 | 000,000,813 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2011/10/18 13:30:23 | 000,000,811 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Guitar Rig 4.lnk
[2011/10/17 11:34:37 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/14 18:35:04 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2011/11/08 22:54:17 | 000,444,106 | —- | C] () – C:\Documents and Settings\Owner\Desktop\2009311_16742_logo.jpg
[2011/11/07 08:23:54 | 003,118,701 | —- | C] () – C:\Documents and Settings\Owner\Desktop\P1030175.JPG
[2011/11/05 08:59:37 | 000,101,272 | —- | C] () – C:\Documents and Settings\Owner\Desktop\450978_700b.jpg
[2011/11/03 13:31:12 | 000,000,664 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\d3d9caps.dat
[2011/10/31 13:51:32 | 000,019,834 | —- | C] () – C:\Documents and Settings\Owner\Desktop\idea for printing.odt
[2011/10/30 10:12:15 | 000,053,079 | —- | C] () – C:\Documents and Settings\Owner\Desktop\420615_460s.jpg
[2011/10/25 13:21:26 | 003,149,585 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Death Eater Mask #8 - Full Size.pdf
[2011/10/20 09:59:49 | 000,012,378 | —- | C] () – C:\Documents and Settings\Owner\Desktop\new song titles.odt
[2011/10/20 09:08:12 | 000,014,238 | —- | C] () – C:\Documents and Settings\Owner\My Documents\rick solar logix ad.odt
[2011/10/18 13:36:18 | 000,000,813 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2011/10/18 13:30:23 | 000,000,811 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Guitar Rig 4.lnk
[2011/10/10 13:51:08 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2011/10/10 13:51:08 | 000,000,016 | —- | C] () – C:\WINDOWS\msocreg32.dat
[2011/08/23 09:16:44 | 000,000,671 | —- | C] () – C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2011/08/20 20:49:42 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2011/08/20 20:49:34 | 000,650,752 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/08/20 20:49:34 | 000,243,200 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/08/20 20:49:33 | 000,074,752 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/07/17 12:25:25 | 000,000,022 | —- | C] () – C:\WINDOWS\cmm.dat
[2011/04/18 19:16:34 | 000,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2011/04/12 17:52:55 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\AVERM.dll
[2011/04/12 17:52:55 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2011/02/15 17:25:29 | 000,000,078 | —- | C] () – C:\WINDOWS\Simply.ini
[2011/01/28 21:32:16 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2011/01/27 18:01:44 | 000,830,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/27 17:36:44 | 000,000,193 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/01/20 18:25:02 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/10/12 20:20:09 | 000,228,352 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/01 21:37:01 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/07/27 03:03:20 | 010,829,656 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/07/27 03:03:20 | 000,102,744 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/07/27 03:03:18 | 000,290,648 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/07/27 02:56:04 | 000,090,411 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/04/27 21:06:13 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/22 23:13:45 | 000,023,110 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2010/04/21 21:18:05 | 000,168,057 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2010/04/21 21:18:05 | 000,000,632 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2010/04/06 12:10:00 | 000,000,873 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/04/05 20:30:37 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\AISAWFileMap.dll
[2010/04/05 20:29:53 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\Implode.dll
[2010/04/05 18:25:55 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/05 17:47:28 | 000,087,608 | —- | C] () – C:\Documents and Settings\Owner\Application Data\inst.exe
[2010/04/05 17:47:28 | 000,007,887 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.cat
[2010/04/05 17:47:27 | 000,001,144 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.inf
[2010/04/05 13:15:27 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/04/05 13:10:46 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/04/05 08:58:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/05 08:57:31 | 001,299,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/20 12:44:46 | 000,051,392 | —- | C] () – C:\WINDOWS\System32\drivers\atnt40k.sys
[2006/02/28 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 07:00:00 | 000,432,356 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 07:00:00 | 000,067,312 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/09/03 16:04:16 | 000,139,280 | —- | C] () – C:\WINDOWS\System32\CSGina.dll

========== LOP Check ==========

[2010/04/05 13:49:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/04/05 17:44:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/09/19 19:39:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/09/15 18:14:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\crack-pavka77-GP6.0.1-7840
[2010/11/23 15:25:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2010/05/02 20:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoldWave
[2010/09/15 18:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Guitar Pro 6
[2011/01/16 20:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2011/02/10 21:03:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/10/10 14:41:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Native Instruments
[2010/11/26 13:03:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Particles
[2010/09/08 14:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/05/09 10:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PIXELA
[2010/04/05 20:44:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sage Software
[2010/09/28 18:36:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/01/27 18:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soluto
[2010/09/17 17:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonoma Wire Works
[2011/10/19 11:30:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/30 19:43:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/02/10 20:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/10/18 13:24:46 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}
[2011/10/19 17:58:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BAF9AC5D-AA3E-4138-92BE-340E0F0D21EA}
[2011/10/18 13:30:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{D69A48BF-7653-4AA8-94BC-5847522A4573}
[2011/10/18 13:23:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}
[2011/03/18 12:49:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2010/04/05 17:44:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ashampoo
[2011/07/16 10:58:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Audacity
[2010/04/19 20:41:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2010/05/15 19:56:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Facebook
[2011/08/09 09:24:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2010/07/10 17:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2011/08/08 12:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Guitar Pro 6
[2011/08/25 15:13:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2010/10/02 16:40:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/04/05 21:14:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Netscape
[2011/08/16 14:23:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nullsoft
[2010/04/05 17:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/01/26 18:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2010/12/29 19:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Philips
[2010/12/29 19:27:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Philips-Songbird
[2010/04/05 21:13:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Photodex
[2011/01/16 20:41:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Registry Mechanic
[2010/11/26 13:02:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Specialbit
[2011/11/11 18:22:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/11/13 09:19:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Unity
[2011/11/15 21:41:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2011/11/15 22:28:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso
[2010/09/08 14:43:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/05 16:37:33 | 001,434,405 | —- | M] () – C:\2108FP.TXT
[2010/04/05 13:13:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/03/09 18:30:42 | 000,748,354 | —- | M] () – C:\Backupjune15a1.CAB
[2011/04/07 10:40:34 | 000,750,694 | —- | M] () – C:\Backupmarch22.21.CAB
[2011/03/22 20:02:14 | 000,750,661 | —- | M] () – C:\Backupmarch221.CAB
[2011/10/19 11:35:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/04/05 13:13:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/18 10:50:45 | 000,017,250 | —- | M] () – C:\hpfr3320.log
[2010/04/18 10:50:45 | 000,000,522 | —- | M] () – C:\hpfr3320.xml
[2010/04/05 13:13:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/05 13:13:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/08 14:42:21 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/13 10:32:13 | 4290,772,992 | -HS- | M] () – C:\pagefile.sys
[2010/04/05 21:14:48 | 000,001,761 | —- | M] () – C:\photodex-presenter-install.log
[2011/02/24 13:44:35 | 001,875,200 | —- | M] () – C:\pshow-burn-debug-spti.log
[2011/02/24 13:44:35 | 000,002,541 | —- | M] () – C:\pshow-burn-debug.log
[2010/04/19 10:04:06 | 000,396,800 | -HS- | M] () – C:\Thumbs.db

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/04/05 13:13:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/10/06 14:37:30 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/23 09:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/04/05 08:56:35 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/04/05 08:56:35 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/04/05 08:56:35 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2010/06/21 22:32:45 | 000,001,778 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Adobe Stock Photos.lnk
[2010/09/08 14:49:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2010/04/21 21:32:21 | 000,001,018 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\HP Solution Center.lnk
[2010/09/08 14:49:14 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2010/04/05 13:13:33 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2011/01/16 18:53:12 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2010/04/07 19:09:15 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\µTorrent.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-11 07:02:05

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >


< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006/02/28 07:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2011/11/15 22:23:52 | 000,067,026 | —- | M] () MD5=88CE8AE42504042447A6B3F40E73E09B – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2006/02/28 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2006/02/28 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2006/02/28 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie8\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2011/11/15 17:42:54 | 000,109,644 | —- | M] () MD5=3AC7423B52D0B32F6C8F311B17C73F76 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2006/02/28 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2006/02/28 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1BFE92CC
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF0C5444
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EE323A4

< End of report >


and extrax.txt:

OTL Extras logfile created on: 15/11/2011 10:33:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.51% Memory free
5.85 Gb Paging File | 5.49 Gb Available in Paging File | 93.88% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 33.83 Gb Free Space | 45.41% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 789.34 Gb Free Space | 84.74% Space Free | Partition Type: NTFS

Computer Name: USER-A6148CA035 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire
"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp – (Nullsoft, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{1D243F00-1389-4C63-A7E9-B17E967D1901}" = WebEx Record and Playback
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{497072FE-0A75-4E5C-A5B7-EB1FA67F66F1}" = DJ_AIO_05_F4400_Software_Min
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{51A79BE3-6AF4-4405-AC9A-E5F74FE20299}" = Simply Accounting by Sage 2007
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AEBB4A3-6878-4CEE-AD34-0F6958A983F0}" = HP Deskjet F4400 Printer Driver Software 13.0 Rel .5
"{5CA03ECF-B4A6-464B-9F5D-64D8B61B083F}" = Everio MediaBrowser
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{67F69C6C-8F2F-4C18-AAA8-9BD64BA1B7FB}" = HyperLoad - Wiffle Baseball
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.4.106e
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8EAD600D-1912-4DEF-92B5-0C7525E17ED2}" = F4400
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9C661DEF-3F08-468D-B5CE-B37E4771B5D2}" = MSN Toolbar
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD [removed]
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C7FAFC98-5ECC-40FC-B440-A5D5FE3A6A6E}" = Native Instruments Guitar Rig 4
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"{D597935A-5F0E-44F8-A028-A0EF9C647D95}" = Native Instruments Rammfire
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA8C7558-D8F9-4D36-9487-C835B26A618B}" = Simply Accounting by Sage 2007
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EEEFE7A9-293E-4F5F-A114-81731A9C3826}" = Intel® Network Connections [removed]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFE32BFA-0F26-45BA-9209-4A6B11F74179}" = System Requirements Lab for Intel
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator CS2" = Adobe Illustrator CS2
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AndreaMosaic" = AndreaMosaic 3.32.3
"Any Video Converter_is1" = Any Video Converter 3.2.2
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"ASIO4ALL" = ASIO4ALL
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"EPSON Artisan 50 Series" = EPSON Artisan 50 Series Printer Uninstall
"GoldWave v5.55" = GoldWave v5.55
"Guitar Pro 5_is1" = Guitar Pro 5.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.6.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Guitar Rig 4" = Native Instruments Guitar Rig 4
"Native Instruments Rammfire" = Native Instruments Rammfire
"Native Instruments Service Center" = Native Instruments Service Center
"Philips Songbird" = Philips Songbird
"Photodex Presenter" = Photodex Presenter
"ProShow Gold" = ProShow Gold
"Registry Mechanic_is1" = Registry Mechanic 9.0
"uTorrent" = µTorrent
"Vector Magic" = Vector Magic
"VST Bridge_is1" = VST Bridge 1.1
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 04/04/2011 12:52:39 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application mplayerc.exe, version 6.4.9.1, faulting module
quicktime.qts, version 7.69.80.9, fault address 0x00009c3f.

Error - 07/04/2011 1:55:52 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application vmde.exe, version 0.0.0.0, faulting module vmde.exe,
version 0.0.0.0, fault address 0x000f45b7.

Error - 07/04/2011 3:58:43 PM | Computer Name = USER-A6148CA035 | Source = MsiInstaller | ID = 11500
Description =

Error - 07/04/2011 3:58:45 PM | Computer Name = USER-A6148CA035 | Source = MsiInstaller | ID = 11500
Description =

Error - 11/04/2011 10:02:39 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
gcswf32.dll, version 10.2.154.26, fault address 0x000c7a3f.

Error - 26/04/2011 4:05:12 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.7.2830, faulting module
pmp_p4s.dll, version 0.0.0.0, fault address 0x000017d3.

Error - 18/05/2011 11:51:18 AM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 12.0.725.0, fault address 0x00962453.

Error - 19/05/2011 10:18:32 AM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.7.2830, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0001b21a.

Error - 30/05/2011 8:54:44 AM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.7.2830, faulting module
ml_bookmarks.dll, version 0.0.0.0, fault address 0x0000128b.

Error - 27/06/2011 8:59:13 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application vmde.exe, version 0.0.0.0, faulting module vmde.exe,
version 0.0.0.0, fault address 0x000f45b7.

[ System Events ]
Error - 06/11/2011 9:02:19 PM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 08/11/2011 7:10:38 PM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.

Error - 08/11/2011 7:15:59 PM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7034
Description = The NIHardwareService service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/11/2011 4:13:22 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.

Error - 10/11/2011 9:24:10 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7034
Description = The NIHardwareService service terminated unexpectedly. It has done
this 1 time(s).

Error - 13/11/2011 11:26:26 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.

Error - 13/11/2011 11:35:21 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.

Error - 13/11/2011 11:35:21 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7034
Description = The NIHardwareService service terminated unexpectedly. It has done
this 1 time(s).

Error - 15/11/2011 12:30:49 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 15/11/2011 12:30:49 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053


< End of report >
Hi stmayhem

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\crypt32chain: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\cryptnet: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\cscdll: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\ScCertProp: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\Schedule: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\sclgntfy: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\SensLogn: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\termsrv: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\wlballoon: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
    @Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1BFE92CC
    @Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
    @Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF0C5444
    @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EE323A4
    
    :Services
    vsdatant
    
    :Files
    c:\windows\system32\vsdatant.sys
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
==============================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include in next post:

OTL fix log
New OTL log
Mbam.txt


How is your computer running?

Thanks

Satchfan
Hello stmayhem It has been several days since I posted instructions to help with your computer problem. Please let me know if you are having problems and still need help. Thanks Satchfan
sorry…just noticed that there was a reply from you to this thread. for some reason i didn't get the email notification that there was a reply. am following instructions right now, will post results when scan is finished.
ok…so here are the new logs:

this is the OTL fix log:


All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon\ deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:1BFE92CC deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:EF0C5444 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:4EE323A4 deleted successfully.
========== SERVICES/DRIVERS ==========
Service vsdatant stopped successfully!
Service vsdatant deleted successfully!
========== FILES ==========
File\Folder c:\windows\system32\vsdatant.sys not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56468 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1737058 bytes

User: Owner
->Temp folder emptied: 2366762282 bytes
->Temporary Internet Files folder emptied: 323827723 bytes
->Java cache emptied: 2141493 bytes
->Google Chrome cache emptied: 301996461 bytes
->Flash cache emptied: 95611 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2157287 bytes
%systemroot%\System32 .tmp files removed: 99840 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5163027 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 77090286 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 3154120428 bytes

Total Files Cleaned = 5,947.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11202011_145512

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…


this is the OTL log after rebooting and rerunning the program:


OTL logfile created on: 20/11/2011 3:25:46 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\My Documents\Downloads\desktop psd files
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 73.31% Memory free
5.85 Gb Paging File | 5.50 Gb Available in Paging File | 93.98% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 37.84 Gb Free Space | 50.79% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 789.24 Gb Free Space | 84.73% Space Free | Partition Type: NTFS

Computer Name: USER-A6148CA035 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\desktop psd files\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH)
PRC - C:\Program Files\VSO\ConvertX\3\ConvertXtoDvd.exe (VSO Software SARL)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Alwil Software\Avast5\defs\11112001\algo.dll ()
MOD - C:\Program Files\Alwil Software\Avast5\defs\11112001\aswRep.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files\Alwil Software\Avast5\aswDld.dll ()
MOD - C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (NIHardwareService) – C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (LVUVC) Logitech Webcam 120(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.msn.com/?lang=en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.8.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.5.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.1002
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.19.1667
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2202
FF - prefs.js..extensions.enabledItems: [removed]:5.0.0.2417
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2200
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2207
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2203
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7.1667

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 23:15:34 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 23:15:34 | 000,000,000 | —D | M]

[2011/09/26 09:40:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/12/29 19:27:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/12/29 19:30:19 | 000,000,530 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Philips-Songbird\Profiles\zuwulc4y.default\searchplugins\e6e50a4b-2416-4c43-925e-dd78043fe347.xml
[2011/01/15 12:14:00 | 000,000,000 | —D | M] (Philips Branding) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:29:47 | 000,000,000 | —D | M] (QuickTime Playback) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:29:48 | 000,000,000 | —D | M] (Windows Media Playback) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:27:20 | 000,000,000 | —D | M] (7digital Music Store) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (Artwork Extras) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:13 | 000,000,000 | —D | M] (CD Rip Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:20 | 000,000,000 | —D | M] (Concerts) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:15 | 000,000,000 | —D | M] (AAC Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:17 | 000,000,000 | —D | M] (H.264 Video Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:15 | 000,000,000 | —D | M] (MP3 Encoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:16 | 000,000,000 | —D | M] (MPEG-4 Video Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (File association) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (Philips GoGear Device Manager) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (gonzo) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:13 | 000,000,000 | —D | M] (Gracenote Metadata Lookup Provider) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:19 | 000,000,000 | —D | M] (mashTape) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:11 | 000,000,000 | —D | M] (MSC Device Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:12 | 000,000,000 | —D | M] (MTP Device Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:14 | 000,000,000 | —D | M] (Philips addon manager) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (Philips auto msc-mtp switch) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:08 | 000,000,000 | —D | M] (Philips Skin) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:08 | 000,000,000 | —D | M] (Philips UI) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (Purple Rain) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Photodex Presenter Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npPxPlay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2006/02/28 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKCU..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE (SEIKO EPSON CORPORATION)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1295222014093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} http://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll (diskhealth Class)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://costco.pnimedia.com/upload/activex/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s…el_4.3.16.0.cab (SysInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://costco.pnimedia.com/upload/activex/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9512CBCA-D924-4335-85D9-3C24D6ACC0C2}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/05 13:13:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/03/06 06:54:34 | 000,000,000 | RH-D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 07:56:50 | 000,000,036 | RH– | M] () - F:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{110886aa-40f3-11df-bcc7-001320e7d5ea}\Shell - "" = AutoRun
O33 - MountPoints2\{110886aa-40f3-11df-bcc7-001320e7d5ea}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f2e80ca9-12fb-11e0-bd36-001320e7d5ea}\Shell\AutoRun\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 15:26:40 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/11/20 14:55:12 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/19 11:54:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\tanya resumes
[2011/11/14 17:05:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\Administrative Tools
[2011/11/13 09:19:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Unity
[2011/11/13 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Unity
[2011/11/11 18:32:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/11/11 18:31:45 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/11/11 18:31:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/11/11 18:31:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/05 17:47:28 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Owner\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/11/20 15:40:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-515967899-682003330-1003UA.job
[2011/11/20 15:38:52 | 000,000,664 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\d3d9caps.dat
[2011/11/20 15:29:14 | 000,000,671 | —- | M] () – C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2011/11/20 15:19:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/20 14:50:25 | 000,230,400 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/19 21:41:35 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-515967899-682003330-1003Core.job
[2011/11/19 17:56:38 | 000,017,852 | —- | M] () – C:\Documents and Settings\Owner\My Documents\STAINED GLASS JELLO RECIPE.odt
[2011/11/19 11:46:41 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/16 21:08:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/16 20:38:28 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/13 14:07:44 | 000,012,378 | —- | M] () – C:\Documents and Settings\Owner\Desktop\new song titles.odt
[2011/11/08 18:12:37 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/08 18:12:37 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/08 18:07:15 | 001,299,416 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/31 13:51:34 | 000,019,834 | —- | M] () – C:\Documents and Settings\Owner\Desktop\idea for printing.odt

========== Files Created - No Company Name ==========

[2011/11/19 17:56:38 | 000,017,852 | —- | C] () – C:\Documents and Settings\Owner\My Documents\STAINED GLASS JELLO RECIPE.odt
[2011/11/03 13:31:12 | 000,000,664 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\d3d9caps.dat
[2011/10/31 13:51:32 | 000,019,834 | —- | C] () – C:\Documents and Settings\Owner\Desktop\idea for printing.odt
[2011/10/10 13:51:08 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2011/10/10 13:51:08 | 000,000,016 | —- | C] () – C:\WINDOWS\msocreg32.dat
[2011/08/23 09:16:44 | 000,000,671 | —- | C] () – C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2011/08/20 20:49:42 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2011/08/20 20:49:34 | 000,650,752 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/08/20 20:49:34 | 000,243,200 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/08/20 20:49:33 | 000,074,752 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/07/17 12:25:25 | 000,000,022 | —- | C] () – C:\WINDOWS\cmm.dat
[2011/04/18 19:16:34 | 000,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2011/04/12 17:52:55 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\AVERM.dll
[2011/04/12 17:52:55 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2011/02/15 17:25:29 | 000,000,078 | —- | C] () – C:\WINDOWS\Simply.ini
[2011/01/28 21:32:16 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2011/01/27 18:01:44 | 000,830,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/27 17:36:44 | 000,000,193 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/01/20 18:25:02 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/10/12 20:20:09 | 000,230,400 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/01 21:37:01 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/07/27 03:03:20 | 010,829,656 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/07/27 03:03:20 | 000,102,744 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/07/27 03:03:18 | 000,290,648 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/07/27 02:56:04 | 000,090,411 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/04/27 21:06:13 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/22 23:13:45 | 000,023,110 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2010/04/21 21:18:05 | 000,168,057 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2010/04/21 21:18:05 | 000,000,632 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2010/04/06 12:10:00 | 000,000,873 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/04/05 20:30:37 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\AISAWFileMap.dll
[2010/04/05 20:29:53 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\Implode.dll
[2010/04/05 18:25:55 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/05 17:47:28 | 000,087,608 | —- | C] () – C:\Documents and Settings\Owner\Application Data\inst.exe
[2010/04/05 17:47:28 | 000,007,887 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.cat
[2010/04/05 17:47:27 | 000,001,144 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.inf
[2010/04/05 13:15:27 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/04/05 13:10:46 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/04/05 08:58:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/05 08:57:31 | 001,299,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/20 12:44:46 | 000,051,392 | —- | C] () – C:\WINDOWS\System32\drivers\atnt40k.sys
[2006/02/28 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 07:00:00 | 000,432,356 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 07:00:00 | 000,067,312 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/09/03 16:04:16 | 000,139,280 | —- | C] () – C:\WINDOWS\System32\CSGina.dll

< End of report >

and this is my Mbam log after running quick scan:


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8201

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20/11/2011 3:39:03 PM
mbam-log-2011-11-20 (15-39-03).txt

Scan type: Quick scan
Objects scanned: 176086
Time elapsed: 12 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Everything seems to be fine.

Let’s run a final scan before we give the all-clear and tidy up.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
hi Satchfan, here is a copy of the log that esat produced. C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache(2)\f_00218b HTML/ScrInject.B.Gen virus C:\Documents and Settings\Owner\My Documents\My Music\tanya music\white deer photography files from f drive\AutoFX Software [4-in-1] [vertigo173]\Auto.FX.Software.Mystical.Lighting.v1.0.zip probably a variant of Win32/VB.FDEFQJJ trojan F:\programs\Adobe Illustrator CS2 + Keygen.zip a variant of Win32/Keygen.AO application F:\programs\ConvertXtoDVD 3.3.4.106e And Keygen [1337x]\Keygen.exe a variant of Win32/Keygen.AS application F:\programs\Cyberlink POWER DIRECTOR Ultra v7.00.1628(NEW-with serial keys)\Cyberlink PowerDirector Ultra v7.00.1628.rar probably a variant of Win32/Agent.JAMZZKT trojan i'm aware that the 3 on the f drive (and the autofx software zip) are keygens and can sometimes be flagged as trojans… but the scrinject.b.gen virus is new to me…
Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

Satchfan
here's the ckscanner log: CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\all users\favorites\data\documents and settings\administrator\favorites\tanya\new\plant tycoon 1 01 crack torrent downloads.url c:\documents and settings\owner\my documents\data\documents and settings\administrator\favorites\tanya\new\plant tycoon 1 01 crack torrent downloads.url c:\documents and settings\owner\my documents\downloads\guitar_pro_v6_0_7_soundbanks_keygen_registered____kk__.torrent c:\documents and settings\owner\my documents\downloads\ik_multimedia_amplitube_v3_0_1_vst_rtas_keygen_dynamics_spy.torrent c:\documents and settings\owner\my documents\downloads\movies\guitar rig 4.0.7\crack\guitar rig 4.dll c:\documents and settings\owner\my documents\downloads\movies\guitar rig 4.0.7\crack\guitar rig 4.exe c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\plug-ins\mystical\surfacelight\objects\nutcracker.thm c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\brushes\today\anodyne-stock_cracks.abr c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\brushes\today\cracksbrushes_by_ephedrina-stock\cracks_by_ephedrina_stock.abr c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\brushes\today\cracksbrushes_by_ephedrina-stock\read first please!.txt c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\brushes\today\cracksbrushes_by_ephedrina-stock\crack_imagepack\thumbs.db c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\photoshop actions\today\cracksbrushes_by_ephedrina-stock\cracks_by_ephedrina_stock.abr c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\photoshop actions\today\cracksbrushes_by_ephedrina-stock\read first please!.txt c:\documents and settings\owner\my documents\my music\tanya music\white deer photography files from f drive\tanyas photoshop presets\presets\photoshop actions\today\cracksbrushes_by_ephedrina-stock\crack_imagepack\thumbs.db c:\program files\adobe\adobe photoshop cs2\presets\brushes\today\anodyne-stock_cracks.abr c:\program files\adobe\adobe photoshop cs2\presets\brushes\today\cracksbrushes_by_ephedrina-stock\cracks_by_ephedrina_stock.abr c:\program files\adobe\adobe photoshop cs2\presets\brushes\today\cracksbrushes_by_ephedrina-stock\read first please!.txt c:\program files\adobe\adobe photoshop cs2\presets\brushes\today\cracksbrushes_by_ephedrina-stock\crack_imagepack\thumbs.db c:\program files\adobe\adobe photoshop cs2\presets\photoshop actions\december 16th actions\adobe photoshop actions for photographers\atomic cupcake actions\ac-crackedaction072705cktr.zip c:\program files\adobe\adobe photoshop cs2\presets\photoshop actions\feb 2009 cover action pro\adobe photoshop actions for photographers\atomic cupcake actions\ac-crackedaction072705cktr.zip c:\program files\adobe\adobe photoshop cs2\presets\photoshop actions\today\cracksbrushes_by_ephedrina-stock\cracks_by_ephedrina_stock.abr c:\program files\adobe\adobe photoshop cs2\presets\photoshop actions\today\cracksbrushes_by_ephedrina-stock\read first please!.txt c:\program files\adobe\adobe photoshop cs2\presets\photoshop actions\today\cracksbrushes_by_ephedrina-stock\crack_imagepack\thumbs.db scanner sequence 3.ZZ.11.HUAPLA —– EOF —–
You have a collection of illegal software on your system, which is how your computer became infected. Besides being illegal, cracks/keygens are the most certain means of infecting your system, as ALL illegal software contains some form of malicious code.

This forum, as well as all the other malware removal forums, does not condone the use of illegal software and does not offer support unless it is for the removal.of it.

Continuing to help you could be viewed as supporting/condoning this therefore. If you require further help I need you to uninstall all the illegal software that you have downloaded and installed. When you have done thus, run CKScanner again and post a new log. If I don’t hear back from you in 24 hours this thread will be closed and no more help will be offered.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI