This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 11/14/2011 12:06:31 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:UsersOwnerDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 41.33% Memory free
5.86 Gb Paging File | 3.88 Gb Available in Paging File | 66.15% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 285.98 Gb Total Space | 223.00 Gb Free Space | 77.98% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 2.01 Gb Free Space | 16.84% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersOwnerDownloadsOTL (1).exe (OldTimer Tools)
PRC - C:UsersOwnerAppDataLocalGoogleUpdate1.3.21.79GoogleCrashHandler.exe (Google Inc.)
PRC - C:Program Files (x86)SophosSophos Anti-VirusSAVAdminService.exe (Sophos Limited)
PRC - C:Program Files (x86)SophosSophos Anti-VirusWeb Intelligenceswi_service.exe (Sophos Limited)
PRC - C:Program Files (x86)Malwarebytes' Anti-Malwarembam.exe (Malwarebytes Corporation)
PRC - C:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
PRC - C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
PRC - C:Program Files (x86)RealRealPlayerUpdaterealsched.exe (RealNetworks, Inc.)
PRC - C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (Adobe Systems Incorporated)
PRC - C:Program Files (x86)SophosAutoUpdateALMon.exe (Sophos Limited)
PRC - C:Program Files (x86)SophosAutoUpdateALsvc.exe (Sophos Limited)
PRC - C:Program Files (x86)SophosSophos Anti-VirusSavService.exe (Sophos Limited)
PRC - C:Program Files (x86)BitTorrentBitTorrent.exe (BitTorrent, Inc.)
PRC - C:Program Files (x86)DivXDivX UpdateDivXUpdate.exe ()
PRC - C:Program Files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:Program Files (x86)McAfee Security Scan2.1.121SSScheduler.exe (McAfee, Inc.)
PRC - C:Program Files (x86)CiscoCisco NAC AgentNACAgentUI.exe (Cisco Systems, Inc.)
PRC - C:Program Files (x86)CiscoCisco NAC AgentNACAgent.exe (Cisco Systems, Inc.)
PRC - C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:Program Files (x86)Yahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)
PRC - C:Program Files (x86)Common FilesEPSONEBAPIeEBSvc.exe (SEIKO EPSON CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Management1049a76b3de293d
f726d380932215c91System.Management.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32PresentationFramewo#\07cdef1a740151932dcf161f3306bd9cPresentationFramework.Aero.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Runtime.Remo#b2622080e047
040fa044dd21a04ff10dSystem.Runtime.Remoting.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Dataf8196c3588c2229e84516
af4b6a0ee60System.Data.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32PresentationFramewo#70e2ca33ffa5
2c743285dc5b4910a229PresentationFramework.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Drawing3b2cfd85528a27eb71
dc41d8067359a1System.Drawing.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32UIAutomationTypes93df5ea9646ad11
a21517e4ab1d803d9UIAutomationTypes.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32UIAutomationProviderbb1d36ae26e7
cadf563061596682e747UIAutomationProvider.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32Accessibility31fce331fded94dd066
27603f6fe4562Accessibility.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32PresentationCore7c94a121334aeca7
553c7f01290740f0PresentationCore.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32WindowsBased7a64c28cf0c90e6c48af
4f7d6f9ed41WindowsBase.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Xml130ad4d9719e566ca933ac
7158a04203System.Xml.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Configuration2d5bcbeb9475
ef62189f605bcca1cec6System.Configuration.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32Systemabab08afa60a6f06bdde0fcc96
49c379System.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32mscorliba1a82db68b3badc7c27ea1f6
579d22c5mscorlib.ni.dll ()
MOD - C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202ppgooglenacl
pluginchrome.dll ()
MOD - C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202pdf.dll ()
MOD - C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202avutil-51.dll ()
MOD - C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202avformat-53.dll ()
MOD - C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202avcodec-53.dll ()
MOD - C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202gcswf32.dll ()
MOD - C:WindowsassemblyGAC_MSILHP.ActiveSupportLibrary2.0.0.1__01a974bc1760f423H
P.ActiveSupportLibrary.dll ()
MOD - C:Program Files (x86)DivXDivX UpdateDivXUpdateCheck.dll ()
MOD - C:Program Files (x86)DivXDivX UpdateDivXUpdate.exe ()
MOD - C:WindowsassemblyGAC_32System.Data2.0.0.0__b77a5c561934e089System.Data.dll ()
MOD - C:Program Files (x86)Yahoo!Messengeryui.dll ()
MOD - C:Program Files (x86)Common FilesLightScribeQtGui4.dll ()
MOD - C:Program Files (x86)Common FilesLightScribeQtCore4.dll ()
MOD - C:Program Files (x86)Common FilesLightScribepluginsimageformatsqjpeg4.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorPillarsPCAlertsPCAlertsPillar.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorPillarsECenterECLibrary.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorMessagingServer.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorMessagingClients.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorRemotingClient.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorMessagingInterface.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorMessagingMessages.dll ()
MOD - C:Program Files (x86)Hewlett-PackardHP AdvisorMicrosoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:Program FilesWindows LiveMeshwlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV - (SAVAdminService) – C:Program Files (x86)SophosSophos Anti-VirusSAVAdminService.exe (Sophos Limited)
SRV - (swi_service) – C:Program Files (x86)SophosSophos Anti-VirusWeb Intelligenceswi_service.exe (Sophos Limited)
SRV - (MBAMService) – C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (Adobe Systems Incorporated)
SRV - (Sophos AutoUpdate Service) – C:Program Files (x86)SophosAutoUpdateALsvc.exe (Sophos Limited)
SRV - (SAVService) – C:Program Files (x86)SophosSophos Anti-VirusSavService.exe (Sophos Limited)
SRV - (HPDrvMntSvc.exe) – C:Program Files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (McComponentHostService) – C:Program Files (x86)McAfee Security Scan2.1.121McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (Microsoft Corporation)
SRV - (NACAgent) – C:Program Files (x86)CiscoCisco NAC AgentNACAgent.exe (Cisco Systems, Inc.)
SRV - (HsfXAudioService) – C:WindowsSysWOW64XAudio64.dll (Conexant Systems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:WindowsMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:Program Files (x86)HP GamesHP Game ConsoleGameConsoleService.exe (WildTangent, Inc.)
SRV - (YahooAUService) – C:Program Files (x86)Yahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)
SRV - (EpsonBidirectionalService) – C:Program Files (x86)Common FilesEPSONEBAPIeEBSvc.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SAVOnAccess) – C:WindowsSysNativedriverssavonaccess.sys (Sophos Limited)
DRV:64bit: - (MBAMProtector) – C:WindowsSysNativedriversmbam.sys (Malwarebytes Corporation)
DRV:64bit: - (sdcfilter) – C:WindowsSysNativedriverssdcfilter.sys (Sophos Plc)
DRV:64bit: - (amdsata) – C:WindowsSysNativedriversamdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:WindowsSysNativedriversamdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:WindowsSysNativedriversHpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:WindowsSysNativedriversTsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:WindowsSysNativedriverssdbus.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:WindowsSysNativedriversathrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (fssfltr) – C:WindowsSysNativedriversfssfltr.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:WindowsSysNativedriversigdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:WindowsSysNativedriversIntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (CnxtHdAudService) – C:WindowsSysNativedriversCHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsbs) – C:WindowsSysNativedriversamdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:WindowsSysNativedriverslsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:WindowsSysNativedriversstexstor.sys (Promise Technology)
DRV:64bit: - (XAudio) – C:WindowsSysNativedriversXAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) – C:WindowsSysNativedriversCAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (mdmxsdk) – C:WindowsSysNativedriversmdmxsdk.sys (Conexant)
DRV:64bit: - (winachsf) – C:WindowsSysNativedriversCAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:WindowsSysNativedriversCAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (SynTP) – C:WindowsSysNativedriversSynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SrvHsfV92) – C:WindowsSysNativedriversVSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:WindowsSysNativedriversVSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:WindowsSysNativedriversVSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:WindowsSysNativedriversyk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:WindowsSysNativedriversnetw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:WindowsSysNativedriversevbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:WindowsSysNativedriversbxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:WindowsSysNativedriversb57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:WindowsSysNativedrivershcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:WindowsSysNativedriversRtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:WindowsSysNativedriversRt64win7.sys (Realtek )
DRV:64bit: - (HpqKbFiltr) – C:WindowsSysNativedriversHpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (SophosBootDriver) – C:WindowsSysNativedriversSophosBootDriver.sys (Sophos Plc)
DRV - (WIMMount) – C:WindowsSysWOW64driverswimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = file://c:windowssyswow64blank.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.yahoo.com
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com
IE - HKLM..URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:Program Files (x86)BitTorrentBartbBit1.dll (Conduit Ltd.)

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cnnb
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache = http://www.msn.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache_TIMESTAMP = 4B 09 14 E5 45 DB CA 01 [binary data]
IE - HKCU..URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:Program Files (x86)BitTorrentBartbBit1.dll (Conduit Ltd.)
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0


FF:64bit: - [removed]/DivX VOD Helper,version=1.0.0: C:Program FilesDivXDivX OVS Helpernpovshelper.dll (DivX, LLC.)
FF:64bit: - [removed]/GENUINE: disabled File not found
FF:64bit: - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~2Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/FlashPlayer: C:Windowssystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/ShockwavePlayer: C:Windowssystem32AdobeDirectornp32dsw.dll (Adobe Systems, Inc.)
FF - [removed]/DivX Browser Plugin,version=1.0.0: C:Program Files (x86)DivXDivX Plus Web Playernpdivx32.dll (DivX,Inc.)
FF - [removed]/DivX VOD Helper,version=1.0.0: C:Program Files (x86)DivXDivX OVS Helpernpovshelper.dll (DivX, LLC.)
FF - [removed]/JavaPlugin: C:Program Files (x86)Javajre6binnew_pluginnpjp2.dll (Sun Microsystems, Inc.)
FF - [removed]/YahooMessengerStatePlugin;version=1.0.0.6: C:Program Files (x86)Yahoo!SharednpYState.dll (Yahoo! Inc.)
FF - [removed]/GENUINE: disabled File not found
FF - [removed]/NpCtrl,version=1.0: c:Program Files (x86)Microsoft Silverlight4.0.60831.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~2MICROS~4Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/OfficeLive,version=1.5: C:Program Files (x86)MicrosoftOffice LivenpOLW.dll (Microsoft Corp.)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~2MICROS~4Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3502.0922: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3508.1109: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/nppl3260;version=12.0.1.647: C:Program Files (x86)RealRealPlayerNetscape6nppl3260.dll (RealNetworks, Inc.)
FF - [removed]/nprjplug;version=12.0.1.647: C:Program Files (x86)RealRealPlayerNetscape6nprjplug.dll (RealNetworks, Inc.)
FF - [removed]/nprpchromebrowserrecordext;version=12.0.1.652: C:ProgramDataRealRealPlayerBrowserRecordPluginMozillaPluginsnprpchromebrow
serrecordext.dll (RealNetworks, Inc.)
FF - [removed]/nprphtml5videoshim;version=12.0.1.652: C:ProgramDataRealRealPlayerBrowserRecordPluginMozillaPluginsnprphtml5video
shim.dll (RealNetworks, Inc.)
FF - [removed]/nprpjplug;version=12.0.1.647: C:Program Files (x86)RealRealPlayerNetscape6nprpjplug.dll (RealNetworks, Inc.)
FF - [removed]/nsJSRealPlayerPlugin;version=: File not found
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program Files (x86)AdobeReader 10.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - HKCUSoftwareMozillaPlugins@Skype Limited.com/Facebook Video Calling Plugin: C:UsersOwnerAppDataLocalFacebookVideoSkypenpFacebookVideoCalling.dll (Skype Limited)
FF - [removed]/Google Update;version=3: C:UsersOwnerAppDataLocalGoogleUpdate1.3.21.79npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:UsersOwnerAppDataLocalGoogleUpdate1.3.21.79npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/BrowserPlus,version=2.9.8: C:UsersOwnerAppDataLocalYahoo!BrowserPlus2.9.8Pluginsnpybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:ProgramDataRealRealPlayerBrowserRecordPluginFirefoxExt [2011/11/14 01:49:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 6.0.2extensionsComponents: C:Program Files (x86)Mozilla Firefoxcomponents [2011/11/14 01:48:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 6.0.2extensionsPlugins: C:Program Files (x86)Mozilla Firefoxplugins

[2011/11/13 15:57:08 | 000,000,000 | —D | M] (No name found) – C:UsersOwnerAppDataRoamingMozillaExtensions
[2011/11/14 01:08:39 | 000,000,000 | —D | M] (No name found) – C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles9f3t3tei.defaultextensi
ons
[2011/08/17 23:12:00 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles9f3t3tei.defaultextensi
ons{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/14 01:45:41 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles9f3t3tei.defaultextensi
ons{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/11/13 15:56:53 | 000,002,519 | —- | M] () – C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles9f3t3tei.defaultsearchp
luginsSearch_Results.xml
[2011/11/14 11:09:21 | 000,000,000 | —D | M] (No name found) – C:Program Files (x86)Mozilla Firefoxextensions
[2011/08/14 16:56:22 | 000,000,000 | —D | M] (Java Console) – C:Program Files (x86)Mozilla Firefoxextensions{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/14 11:09:21 | 000,000,000 | —D | M] (Java Console) – C:Program Files (x86)Mozilla Firefoxextensions{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/10/12 21:26:00 | 000,134,104 | —- | M] (Mozilla Foundation) – C:Program Files (x86)mozilla firefoxcomponentsbrowsercomps.dll
[2011/10/12 21:25:57 | 000,002,252 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsbing.xml
[2011/11/13 15:56:53 | 000,002,519 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsSearch_Results.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:Windowssystem32MacromedFlashNPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:Program Files (x86)Javajre6binnew_pluginnpjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:Program Files (x86)AdobeReader 10.0ReaderBrowsernppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:Program Files (x86)Microsoft Silverlight4.0.60531.0npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:Windowssystem32AdobeDirectornp32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:Program Files (x86)DivXDivX Plus Web Playernpdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:Program Files (x86)RealRealPlayerNetscape6nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:Program Files (x86)RealRealPlayerNetscape6nprpjplug.dll
CHR - plugin: RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:ProgramDataRealRealPlayerBrowserRecordPluginMozillaPluginsnprpchromebrow
serrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:ProgramDataRealRealPlayerBrowserRecordPluginMozillaPluginsnprphtml5video
shim.dll
CHR - plugin: Microsoftu00AE Windows Media Player Firefox Plugin (Enabled) = C:PFilesPluginsnp-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:PROGRA~2MICROS~4Office14NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:PROGRA~2MICROS~4Office14NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:Program Files (x86)MicrosoftOffice LivenpOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202ppGoogleNaCl
PluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:UsersOwnerAppDataLocalGoogleChromeApplication14.0.835.202pdf.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:Program Files (x86)DivXDivX OVS Helpernpovshelper.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:Program Files (x86)RealRealPlayerNetscape6nprjplug.dll
CHR - plugin: Windows Liveu0099 Photo Gallery (Enabled) = C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:UsersOwnerAppDataLocalFacebookVideoSkypenpFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:UsersOwnerAppDataLocalGoogleUpdate1.3.21.65npGoogleUpdate3.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:UsersOwnerAppDataLocalYahoo!BrowserPlus2.9.8Pluginsnpybrowserplus_2.9.8.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chromeu2122 (Beta) = C:UsersOwnerAppDataLocalGoogleChromeUser DataDefaultExtensionscfhdojbkjhnklbpkdaibdccddilifddb1.1.4_0
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:UsersOwnerAppDataLocalGoogleChromeUser DataDefaultExtensionsjfmjfhklogoienhpfnppmbcbjfjnkonk1.4_0

O1 HOSTS File: ([2010/09/10 14:09:01 | 000,000,824 | —- | M]) - C:WindowsSysNativedriversetchosts
O2:64bit: - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:Program Files (x86)SophosSophos Anti-VirusSophosBHOX64.dll (Sophos Limited)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll File not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program Files (x86)Yahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:ProgramDataRealRealPlayerBrowserRecordPluginIErpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:Program Files (x86)ConduitEngineConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:Program Files (x86)SophosSophos Anti-VirusSophosBHO.dll (Sophos Limited)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:Program Files (x86)BitTorrentBartbBit1.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program Files (x86)Yahoo!CompanionInstallscpnYTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
O3 - HKLM..Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:Program Files (x86)ConduitEngineConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM..Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:Program Files (x86)BitTorrentBartbBit1.dll (Conduit Ltd.)
O3 - HKLM..Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program Files (x86)Yahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O3 - HKCU..ToolbarWebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU..ToolbarWebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:Program Files (x86)ConduitEngineConduitEngin0.dll (Conduit Ltd.)
O3 - HKCU..ToolbarWebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:Program Files (x86)BitTorrentBartbBit1.dll (Conduit Ltd.)
O4:64bit: - HKLM..Run: [cAudioFilterAgent] C:Program FilesConexantcAudioFilterAgentcAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..Run: [HotKeysCmds] C:WindowsSysNativehkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [IgfxTray] C:WindowsSysNativeigfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [Persistence] C:WindowsSysNativeigfxpers.exe (Intel Corporation)
O4 - HKLM..Run: [DivXUpdate] C:Program Files (x86)DivXDivX UpdateDivXUpdate.exe ()
O4 - HKLM..Run: [EEventManager] C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..Run: [Malwarebytes' Anti-Malware] C:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
O4 - HKLM..Run: [NACAgentUI] C:Program Files (x86)CiscoCisco NAC AgentNACAgentUI.exe (Cisco Systems, Inc.)
O4 - HKLM..Run: [Sophos AutoUpdate Monitor] C:Program Files (x86)SophosAutoUpdateALMon.exe (Sophos Limited)
O4 - HKLM..Run: [TkBellExe] C:Program Files (x86)RealRealPlayerupdaterealsched.exe (RealNetworks, Inc.)
O4 - HKLM..Run: [UpdatePRCShortCut] C:Program Files (x86)Hewlett-PackardRecoveryMUITransferMUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..Run: [BitTorrent] C:Program Files (x86)BitTorrentBitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..Run: [Epson Stylus NX420(Network)] C:Windowssystem32spoolDRIVERSx643E_IATIGCA.EXE /FU "C:WindowsTEMPE_SC20.tmp" /EF "HKCU" File not found
O4 - HKCU..Run: [Facebook Update] C:UsersOwnerAppDataLocalFacebookUpdateFacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..Run: [Messenger (Yahoo!)] C:Program Files (x86)Yahoo!MessengerYahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..Run: [SmartAudio] C:Program FilesCONEXANTSAIISAIICpl.exe ()
O4 - HKLM..RunOnce: [Malwarebytes' Anti-Malware] C:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:UsersOwnerAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupZooskMessenger.lnk = File not found
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktop = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktopChanges = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: EnableLUA = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: PromptOnSecureDesktop = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDesktopCleanupWizard = 1
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: WallpaperStyle = 2
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~2MICROS~4Office14EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~2MICROS~4Office14EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.2.1
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{B4799569-2BB8-4929-AE4A-AD632244A142}: DhcpNameServer = 192.168.2.1
O18:64bit: - ProtocolHandlergrooveLocalGWS - No CLSID value found
O18:64bit: - ProtocolHandlerlivecall - No CLSID value found
O18:64bit: - ProtocolHandlerms-help - No CLSID value found
O18:64bit: - ProtocolHandlerms-itss - No CLSID value found
O18:64bit: - ProtocolHandlermsnim - No CLSID value found
O18:64bit: - ProtocolHandlerwlmailhtml - No CLSID value found
O18:64bit: - ProtocolHandlerwlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:PROGRA~2SophosSOPHOS~1SOPHOS~2.DLL) - C:Program Files (x86)SophosSophos Anti-Virussophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:PROGRA~2SophosSOPHOS~1SOPHOS~1.DLL) -C:Program Files (x86)SophosSophos Anti-Virussophos_detoured.dll (Sophos Limited)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSysNativeuserinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:WindowsSysNativeSystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:WindowsSysWow64explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:WindowsSysWow64userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - WinlogonNotifyigfxcui: DllName - (igfxdev.dll) - C:WindowsSysNativeigfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30:64bit: - LSA: Authentication Packages - (owsw) - File not found
O30 - LSA: Authentication Packages - (owsw) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM..comfile [open] – "%1" %*
O35:64bit: - HKLM..exefile [open] – "%1" %*
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37:64bit: - HKLM…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM…exe [@ = exefile] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:WindowsSysWOW64l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:WindowsSysWow64l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:WindowsSysWow64iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:WindowsSysWow64DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:WindowsSysWow64DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/14 11:22:06 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:WindowsSysWow64driversmbamswissarmy.sys
[2011/11/14 11:21:50 | 000,000,000 | —D | C] – C:UsersOwnerAppDataRoamingMalwarebytes
[2011/11/14 11:21:44 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsMalwarebytes' Anti-Malware
[2011/11/14 11:21:43 | 000,000,000 | —D | C] – C:ProgramDataMalwarebytes
[2011/11/14 11:21:40 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:WindowsSysNativedriversmbam.sys
[2011/11/14 11:21:39 | 000,000,000 | —D | C] – C:Program Files (x86)Malwarebytes' Anti-Malware
[2011/11/14 11:09:35 | 000,000,000 | —D | C] – C:Program Files (x86)Common FilesJava
[2011/11/14 11:09:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSysWow64javaws.exe
[2011/11/14 11:09:17 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSysWow64javaw.exe
[2011/11/14 11:09:17 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSysWow64java.exe
[2011/11/14 03:28:54 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{0F87A5AC-C5E4-48BB-924E-C84302E4311E}
[2011/11/14 03:28:40 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{4AD7ECE2-E777-452F-A004-BB3F3F0AFA18}
[2011/11/14 01:00:29 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{1895F8DA-7219-4776-9604-32D87DB3DBE5}
[2011/11/14 01:00:15 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{968A952E-E97D-4E08-AAB8-F0C3C937A56E}
[2011/11/14 00:39:58 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{476F6690-5E1B-47F6-8FCB-C3FAA1C2F49E}
[2011/11/14 00:39:43 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{3088BEFD-ED1C-4EAE-AD3D-2DA37D865858}
[2011/11/13 16:06:04 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocalIlivid Player
[2011/11/13 15:57:39 | 000,000,000 | -H-D | C] – C:ProgramData{08E30618-5D06-461B-BBD3-4ADFB0810824}
[2011/11/13 15:57:23 | 000,000,000 | —D | C] – C:Program Files (x86)iLivid
[2011/11/13 15:56:54 | 000,000,000 | —D | C] – C:ProgramDataboost_interprocess
[2011/11/13 15:56:53 | 000,000,000 | —D | C] – C:Program Files (x86)Windows iLivid Toolbar
[2011/11/13 15:56:38 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocalPackageAware
[2011/11/11 22:05:34 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{57217CE1-C773-42D4-ADAB-C7D391A8254F}
[2011/11/11 22:05:17 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{FE285BF3-C8C3-40BE-969E-0268EFECA4DF}
[2011/11/11 14:27:39 | 000,000,000 | —D | C] – C:Program Files (x86)Common FilesSymantec Shared
[2011/11/10 23:01:26 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{CFEA29EB-32A3-4BAF-A084-53B0D6622F4F}
[2011/11/10 23:01:13 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{B59005EC-35D3-4CA8-BEC7-8A6801F6FB8F}
[2011/11/04 21:43:50 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{BEF73D07-3FD4-4739-9A1E-DF5B45899236}
[2011/11/04 21:43:34 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{22D926D9-12EB-4689-AC99-D81B402D0FE1}
[2011/11/01 10:57:26 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{E5978AE6-045E-4093-8487-E690E67B8BCD}
[2011/11/01 10:57:10 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{9963872E-530C-4076-BEB0-4D7965936D2E}
[2011/10/26 11:21:32 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{D355D776-D85B-4C57-B920-199293E2943A}
[2011/10/26 11:21:18 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{C2B05C8C-943D-4E3F-88CE-01EE4900DEF5}
[2011/10/23 00:34:53 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{D3A39CC2-05C5-47E4-94BA-82C69ED32B55}
[2011/10/23 00:34:36 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{5BE9980A-F51A-4D4F-8E6D-FB9BF18D6F2D}
[2011/10/19 17:56:26 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{91C98B85-0BDA-42BC-BE8E-CB0943C1DCA0}
[2011/10/19 17:56:09 | 000,000,000 | —D | C] – C:UsersOwnerAppDataLocal{CFA8734A-321A-4476-9E67-238E13E6C931}
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]
[1 C:UsersOwnerDesktop*.tmp files -> C:UsersOwnerDesktop*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/14 12:07:04 | 000,000,908 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-3572206792-2987823953-3148424483-1000UA.job
[2011/11/14 11:38:05 | 000,000,928 | —- | M] () – C:WindowstasksFacebookUpdateTaskUserS-1-5-21-3572206792-2987823953-3148424483-1000UA.job
[2011/11/14 11:22:13 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:WindowsSysWow64driversmbamswissarmy.sys
[2011/11/14 11:21:44 | 000,001,113 | —- | M] () – C:UsersPublicDesktopMalwarebytes' Anti-Malware.lnk
[2011/11/14 08:58:08 | 000,000,402 | -H– | M] () – C:WindowstasksNorton Security Scan for Owner.job
[2011/11/14 03:34:04 | 000,023,248 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 03:34:04 | 000,023,248 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 03:31:43 | 000,726,316 | —- | M] () – C:WindowsSysNativePerfStringBackup.INI
[2011/11/14 03:31:43 | 000,624,178 | —- | M] () – C:WindowsSysNativeperfh009.dat
[2011/11/14 03:31:43 | 000,106,522 | —- | M] () – C:WindowsSysNativeperfc009.dat
[2011/11/14 03:26:15 | 000,000,332 | —- | M] () – C:WindowstasksHPCeeScheduleForOwner.job
[2011/11/14 03:25:43 | 000,431,848 | —- | M] () – C:WindowsSysNativeFNTCACHE.DAT
[2011/11/14 03:25:43 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2011/11/14 03:24:50 | 2361,802,752 | -HS- | M] () – C:hiberfil.sys
[2011/11/14 01:07:00 | 000,000,856 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-3572206792-2987823953-3148424483-1000Core.job
[2011/10/17 16:38:00 | 000,000,906 | —- | M] () – C:WindowstasksFacebookUpdateTaskUserS-1-5-21-3572206792-2987823953-3148424483-1000Core.job
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]
[1 C:UsersOwnerDesktop*.tmp files -> C:UsersOwnerDesktop*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/14 11:21:44 | 000,001,113 | —- | C] () – C:UsersPublicDesktopMalwarebytes' Anti-Malware.lnk
[2011/08/12 15:15:29 | 000,000,000 | —- | C] () – C:WindowsEEventManager.INI
[2011/07/28 14:41:24 | 000,000,097 | —- | C] () – C:WindowsSysWow64PICSDK.ini
[2011/07/28 14:41:23 | 000,073,220 | —- | C] () – C:WindowsSysWow64EPPICPrinterDB.dat
[2011/07/28 14:41:23 | 000,031,053 | —- | C] () – C:WindowsSysWow64EPPICPattern131.dat
[2011/07/28 14:41:23 | 000,029,114 | —- | C] () – C:WindowsSysWow64EPPICPattern1.dat
[2011/07/28 14:41:23 | 000,027,417 | —- | C] () – C:WindowsSysWow64EPPICPattern121.dat
[2011/07/28 14:41:23 | 000,021,021 | —- | C] () – C:WindowsSysWow64EPPICPattern3.dat
[2011/07/28 14:41:23 | 000,015,670 | —- | C] () – C:WindowsSysWow64EPPICPattern5.dat
[2011/07/28 14:41:23 | 000,013,280 | —- | C] () – C:WindowsSysWow64EPPICPattern2.dat
[2011/07/28 14:41:23 | 000,010,673 | —- | C] () – C:WindowsSysWow64EPPICPattern4.dat
[2011/07/28 14:41:23 | 000,004,943 | —- | C] () – C:WindowsSysWow64EPPICPattern6.dat
[2011/07/28 14:41:23 | 000,001,140 | —- | C] () – C:WindowsSysWow64EPPICPresetData_PT.dat
[2011/07/28 14:41:23 | 000,001,140 | —- | C] () – C:WindowsSysWow64EPPICPresetData_BP.dat
[2011/07/28 14:41:23 | 000,001,137 | —- | C] () – C:WindowsSysWow64EPPICPresetData_ES.dat
[2011/07/28 14:41:23 | 000,001,130 | —- | C] () – C:WindowsSysWow64EPPICPresetData_FR.dat
[2011/07/28 14:41:23 | 000,001,130 | —- | C] () – C:WindowsSysWow64EPPICPresetData_CF.dat
[2011/07/28 14:41:23 | 000,001,104 | —- | C] () – C:WindowsSysWow64EPPICPresetData_EN.dat
[2011/07/28 14:34:07 | 000,000,071 | —- | C] () – C:WindowsENX420.ini
[2011/06/21 20:03:47 | 000,000,000 | —- | C] () – C:Windowsnsreg.dat
[2011/01/12 20:43:22 | 000,001,854 | —- | C] () – C:UsersOwnerAppDataRoamingGhostObjGAFix.xml
[2010/12/15 09:37:41 | 000,000,000 | —- | C] () – C:WindowsHMHud.INI
[2010/10/27 01:06:46 | 000,004,157 | —- | C] () – C:ProgramDatabltofzsb.qlf
[2010/08/25 19:34:30 | 000,982,240 | —- | C] () – C:WindowsSysWow64igkrng500.bin
[2010/08/25 19:34:30 | 000,439,308 | —- | C] () – C:WindowsSysWow64igcompkrng500.bin
[2010/08/25 19:34:30 | 000,092,356 | —- | C] () – C:WindowsSysWow64igfcg500m.bin
[2010/08/25 18:52:00 | 000,208,896 | —- | C] () – C:WindowsSysWow64iglhsip32.dll
[2010/08/25 18:52:00 | 000,143,360 | —- | C] () – C:WindowsSysWow64iglhcp32.dll
[2010/03/24 21:16:29 | 000,000,056 | -H– | C] () – C:ProgramDataezsidmv.dat
[2009/11/27 22:59:08 | 000,000,290 | —- | C] () – C:ProgramDatahpqp.ini
[2009/10/25 21:27:20 | 000,013,312 | —- | C] () – C:WindowsLPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:Windowsbootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:WindowsSysWow64NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:WindowsSysWow64dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:Windowsmib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:WindowsSysWow64BWContextHandler.dll
[2009/07/13 16:59:36 | 001,498,564 | —- | C] () – C:WindowsSysWow64igkrng400.bin
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:WindowsSysWow64msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:WindowsSysWow64mlang.dat
[2009/06/03 14:14:52 | 000,134,592 | —- | C] () – C:WindowsSysWow64igfcg500.bin

========== LOP Check ==========

[2011/11/14 12:32:25 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingBitTorrent
[2010/02/03 16:09:30 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingCiscoCAA
[2010/05/26 18:51:12 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingcom.zoosk.Desktop.096E6A67431258A508A2446A847B240
591D2C99B.1
[2011/07/30 11:26:53 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingEpson
[2011/01/01 14:36:48 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingHEM Data
[2011/07/28 14:57:12 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingLeadertech
[2010/12/24 22:17:06 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingSecondLife
[2010/01/30 20:49:46 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingWildTangent
[2011/04/04 16:15:20 | 000,000,000 | —D | M] – C:UsersOwnerAppDataRoamingWindows Live Writer
[2011/10/17 16:38:00 | 000,000,906 | —- | M] () – C:WindowsTasksFacebookUpdateTaskUserS-1-5-21-3572206792-2987823953-3148424483-1000Core.job
[2011/11/14 11:38:05 | 000,000,928 | —- | M] () – C:WindowsTasksFacebookUpdateTaskUserS-1-5-21-3572206792-2987823953-3148424483-1000UA.job
[2011/02/04 04:24:53 | 000,032,616 | —- | M] () – C:WindowsTasksSCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:bootmgr
[2010/01/02 22:28:26 | 000,000,000 | —- | M] () – C:detestfrag.txt
[2011/06/22 19:46:43 | 000,001,854 | —- | M] () – C:GhostObjGAFix.xml
[2011/11/14 03:24:50 | 2361,802,752 | -HS- | M] () – C:hiberfil.sys
[2010/06/04 06:59:58 | 000,000,186 | —- | M] () – C:hpqlb.log
[2010/06/09 12:03:33 | 000,348,074 | —- | M] () – C:intel_chipset.log
[2011/11/14 03:24:53 | 3149,074,432 | -HS- | M] () – C:pagefile.sys
[2010/09/10 14:09:01 | 000,000,000 | -HS- | M] () – C:ProgramData.LOG1
[2010/09/10 14:09:01 | 000,000,000 | -HS- | M] () – C:ProgramData.LOG2
[2011/03/12 01:34:07 | 000,000,184 | —- | M] () – C:setup.log
[2011/09/13 16:03:52 | 000,001,335 | —- | M] () – C:SoftUpdate.log

< %systemroot%Fonts*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/06/10 15:49:50 | 000,000,065 | -H– | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:WindowsWLXPGSS.SCR
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >
[2010/10/31 12:36:38 | 000,001,718 | -HS- | M] () – C:UsersOwnerAppDataRoamingMicrosoftLastFlashConfig.wfc

< %PROGRAMFILES%*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:Program Files (x86)desktop.ini
[2010/12/15 09:36:34 | 000,068,694 | —- | M] () – C:Program Files (x86)hminstalllog.txt

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2011/07/28 14:27:41 | 000,000,221 | -HS- | M] () – C:UsersOwnerAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >

< End of report >

OTL Extras logfile created on: 11/14/2011 12:06:31 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:UsersOwnerDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 41.33% Memory free
5.86 Gb Paging File | 3.88 Gb Available in Paging File | 66.15% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 285.98 Gb Total Space | 223.00 Gb Free Space | 77.98% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 2.01 Gb Free Space | 16.84% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClasses]
.url[@ = InternetShortcut] – C:WindowsSysNativerundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSysWow64control.exe (Microsoft Corporation)

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = FirefoxHTML] – C:Program Files (x86)Mozilla Firefoxfirefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcVol]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]
"" =
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"EPSON NX420 Series" = EPSON NX420 Series Printer Uninstall
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 29
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E432692-A736-4F77-AF77-F9078CF88D31}" = HP Wireless Assistant
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{62AD5F7F-9CFC-4523-AF83-C58F02836635}" = Geek Squad 24 Hour Computer Support
"{64A7418C-6BD4-48BE-A2E3-CAEC3BCD9E81}" = HP User Guides 0156
"{6632ABC5-9AEE-4243-9086-FB358DB58147}" = Cisco NAC Agent
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}" = HP Advisor
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE626616-D7C4-4F00-7E0B-EAF26FA65749}" = muvee Reveal
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E92D47A1-D27D-430A-8368-0BAFD956507D}" = HP Support Assistant
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED721ABC-423D-4F7D-AEBB-E1E39C388E84}" = Facebook Video Calling 1.0.0.8714
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FA8BFB25-BF48-4F8B-8859-B30810745190}" = LightScribe System Software
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"BetOnline Poker" = BetOnline Poker
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"ClubWPT" = ClubWPT
"conduitEngine" = Conduit Engine
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Scanner" = EPSON Scan
"Homepage Protection" = Homepage Protection
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"NSS" = Norton Security Scan
"Office14.SingleImage" = Microsoft Office Professional 2010
"RealPlayer 12.0" = RealPlayer
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Google Chrome" = Google Chrome
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
:welcome:

This is how you most likely infected this system. File Sharing is very dangerous, your downloading that file from an unknown source and not all but most contain malware of one sort or another, its a tool malware writers use to infect you. If you dont uninstall them and use them after we clean you up I am kind of wasting my time as you will become infected over and over again.

"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
conduitEngine" = Conduit Engine



You have Malwarebytes installed, open it, check for updates and run a Quick scan and post the log.


Then run both these programs and post the logs

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI