This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with something that appears to have come from Facebook! [

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something really strange going on, here, with my laptop. I noticed it was running slow and I kept getting script errors on Facebook. I decided to run Spy-bot last night and found 13
viruses or malware on my computer and removed them. I had previously downloaded some sort of viewer to view movies, online, and it sent off about 20 forced downloads of all kinds of things, including something which changed my google chrome home page to a gaming type search engine. I could not find anything to change my home page on there and I don't use chrome very often. I normally use Firefox. I went into add/delete and deleted everything I could locate that had just downloaded. This was about a month ago.

Tonight, I ran SpyBot, again. Malwarebytes was not finding anything and Avira does not want to finish running and hasn't for quite a while. I know, my bad. I should have done something right away but I am very careful not to download things I don't know for sure what they are, except that movie viewer that my friend, a person who was in training to be a
computer repair person, told me to go to (the website where this was located). I don't click links to things I am unsure of and this is what is puzzling me. I have no clue how I got this problem.

I decided I just did not like the way things were running so I ran spy bot, again, and when I was done, it said everything was ok but I looked and noticed one of my desktop icons was
renamed to one of my Facebook friend's names, instead, and had the google chrome icon instead of what it was supposed to be. That made me freak and I decided to go ahead and uninstall chrome. After the computer was done uninstalling, I looked at the desktop and even more icons had appeared with other Facebook friends as the names of the icons. I ran Spybot, again, and it comes out clean.

I rebooted again and checked and sure enough, all chrome looking icons are still there. I clicked each one and each one takes me to a different page on Facebook.

Whatever is going on here is obviously not good!

Here is a new copy of Hijackthis plus the OTL log (there was only one!) and the DDS logs. Please advise me what to do!

Thanks!

OTL logfile created on: 11/17/2011 3:05:54 AM - Run 5
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Ratopia\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.93 Gb Total Physical Memory | 2.24 Gb Available Physical Memory | 57.12% Memory free
8.05 Gb Paging File | 6.07 Gb Available in Paging File | 75.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 143.04 Gb Total Space | 70.35 Gb Free Space | 49.18% Space Free | Partition Type: NTFS
Drive D: | 139.50 Gb Total Space | 97.21 Gb Free Space | 69.68% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: ARWEN | User Name: Ratopia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Ratopia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe (Egis inc.)
PRC - C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\aol\1242688622\ee\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe (AOL LLC)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll ()
MOD - C:\Windows\PLFSetI.exe ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:64bit: - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV:64bit: - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV:64bit: - (ETService) – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FreeAgentGoNext Service) – C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (eDataSecurity Service) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CLHNService) – C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (MobilityService) – C:\Acer\Mobility Center\MobilityService.exe ()
SRV - (AOL ACS) – C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)


========== Driver Services (SafeList) ==========

DRV:64bit: - (avipbb) – C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\AVGIDSFilter.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\AVGIDSDriver.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (L1E) – C:\Windows\SysNative\DRIVERS\L1E60x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (psdvdisk) – C:\Windows\SysNative\DRIVERS\PSDVdisk.sys (Egis Incorporated)
DRV:64bit: - (PSDNServ) – C:\Windows\SysNative\DRIVERS\PSDNServ.sys (Egis Incorporated)
DRV:64bit: - (PSDFilter) – C:\Windows\SysNative\DRIVERS\psdfilter.sys (Egis Incorporated)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (TcUsb) – C:\Windows\SysNative\Drivers\tcusb.sys (UPEK Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\DRIVERS\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\Drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (HSFHWAZL) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (winbondcir) – C:\Windows\SysNative\DRIVERS\winbondcir.sys (Winbond Electronics Corporation)
DRV:64bit: - (wanatw) WAN Miniport (ATW) – C:\Windows\SysNative\DRIVERS\wanatw64.sys (America Online, Inc.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) – C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl (Cyberlink Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80647
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tb…0647&lng;=en
IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL LLC)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher…d&%language
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cbe35ad&v;=6.010.006.004&i;=23&tp;=ab&iy;=&ychte;=us&lng;=en-US&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Ratopia\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG10\Firefox\ [2010/10/22 12:20:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/10/22 12:20:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/09 01:39:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/09 01:39:28 | 000,000,000 | —D | M]

[2011/09/28 03:54:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Ratopia\AppData\Roaming\mozilla\Extensions
[2011/10/28 22:01:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Ratopia\AppData\Roaming\mozilla\Firefox\Profiles\yas9n9so.default\extensions
[2010/08/09 21:49:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Ratopia\AppData\Roaming\mozilla\Firefox\Profiles\yas9n9so.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/29 23:01:39 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Ratopia\AppData\Roaming\mozilla\Firefox\Profiles\yas9n9so.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}(53)
[2011/03/24 01:09:34 | 000,000,000 | —D | M] (GamePlayLabs Plugin) – C:\Users\Ratopia\AppData\Roaming\mozilla\Firefox\Profiles\yas9n9so.default\extensions\[removed]
[2010/12/13 03:33:40 | 000,005,529 | —- | M] () – C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchplugins\SearchquWebSearch.xml
[2011/09/28 04:38:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/28 15:17:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 23:27:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/04 01:45:28 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/31 17:06:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/21 01:01:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2009/10/13 17:21:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2010/10/22 12:20:21 | 000,000,000 | —D | M] ("urn:mozilla:install-manifest" em:id="avg@igeared" em:name="AVG Security Toolbar" em:version="6.010.006.004" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) – C:\PROGRAM FILES (X86)\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED
[2011/03/04 18:39:16 | 000,000,000 | —D | M] ("Savevid.com Easy Video Downloader") – C:\PROGRAM FILES (X86)\SAVEVID\[removed]
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/05/25 10:09:48 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010/11/22 17:04:00 | 000,865,632 | —- | M] (Medical Informatics Engineering, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npzzatif.dll
[2010/12/13 03:33:40 | 000,005,529 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchquWebSearch.xml
[2011/10/28 21:32:07 | 000,001,456 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\WebSearchober24026852.xml
[2011/09/27 22:02:34 | 000,001,456 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\WebSearchober8747444.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdivx32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Users\Ratopia\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: AlternaTIFF (QuickTime compatible) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npzzatif.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Ratopia\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2006/09/18 15:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\Update\1.3.21.57\%ProgramW6432%\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll File not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL LLC)
O4:64bit: - HKLM..\Run: [eDataSecurity Loader] C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
O4:64bit: - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe (AOL LLC)
O4 - HKLM..\Run: [Info Center] C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8:64bit: - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper20073151.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} http://utilities.pcpitstop.com/Nirvana/con…DiskMD3Ctrl.dll (diskhealth Class)
O16 - DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} http://utilities.pcpitstop.com/Nirvana/con…opAntiVirus.dll (PCPitstop AntiVirus)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{405C5A07-D13D-4CBB-8F90-C179872E14CA}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\avgsecuritytoolbar - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/17 02:52:41 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Ratopia\Desktop\HiJackThis.exe
[2011/11/17 02:52:13 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Ratopia\Desktop\OTL.exe
[2011/11/17 02:41:55 | 000,000,000 | —D | C] – C:\Users\Ratopia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/17 01:58:23 | 000,000,000 | —D | C] – C:\Users\Ratopia\AppData\Local\Acer Arcade Deluxe
[2011/11/14 04:27:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/08 20:57:43 | 000,000,000 | —D | C] – C:\Users\Ratopia\Desktop\Misc Photos from camera
[2011/11/01 20:52:31 | 000,000,000 | —D | C] – C:\Users\Ratopia\Desktop\Gabie Schpanski_057-3
[2011/10/30 02:52:59 | 000,000,000 | —D | C] – C:\Users\Ratopia\Desktop\NECKLACES
[2011/10/28 21:35:00 | 000,000,000 | —D | C] – C:\Users\Ratopia\AppData\Local\WeatherBug
[2011/10/28 21:34:57 | 000,000,000 | —D | C] – C:\Users\Ratopia\AppData\Roaming\WeatherBug
[2011/10/28 21:33:01 | 000,000,000 | —D | C] – C:\Users\Ratopia\AppData\Roaming\Fighters
[2011/10/28 21:32:31 | 000,000,000 | —D | C] – C:\ProgramData\Fighters
[2011/10/28 21:32:07 | 000,000,000 | —D | C] – C:\ProgramData\Oberon Media
[2011/10/27 23:32:47 | 000,000,000 | —D | C] – C:\Users\Ratopia\Desktop\Pome
[2011/10/22 18:13:50 | 000,000,000 | —D | C] – C:\Users\Ratopia\Desktop\Jibjab
[2011/10/19 14:08:36 | 000,000,000 | —D | C] – C:\Users\Ratopia\Desktop\Kestrel
[2008/12/17 23:13:36 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Users\Ratopia\Desktop\*.tmp files -> C:\Users\Ratopia\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/17 02:53:19 | 000,625,664 | —- | M] () – C:\Users\Ratopia\Desktop\dds.scr
[2011/11/17 02:52:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Ratopia\Desktop\HiJackThis.exe
[2011/11/17 02:52:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Ratopia\Desktop\OTL.exe
[2011/11/17 02:50:17 | 000,002,563 | —- | M] () – C:\Users\Ratopia\Desktop\HiJackThis.lnk
[2011/11/17 02:28:21 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/17 02:28:21 | 000,604,502 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/17 02:28:21 | 000,104,170 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/17 02:26:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/17 02:21:17 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/17 02:21:16 | 000,000,414 | —- | M] () – C:\Windows\tasks\PC Optimizer Pro64 startups.job
[2011/11/17 02:21:08 | 000,000,000 | —- | M] () – C:\Windows\SysNative\LogConfigTemp.xml
[2011/11/17 02:20:56 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/17 02:20:56 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/17 02:20:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/17 02:20:45 | 4220,379,136 | -HS- | M] () – C:\hiberfil.sys
[2011/11/17 02:19:09 | 000,000,680 | —- | M] () – C:\Users\Ratopia\AppData\Local\d3d9caps.dat
[2011/11/16 19:53:50 | 000,327,051 | —- | M] () – C:\Users\Ratopia\Desktop\5542412236_be4efe7a23_b[1].jpg
[2011/11/16 06:27:30 | 000,040,960 | —- | M] () – C:\Users\Ratopia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/16 06:13:37 | 000,002,224 | —- | M] () – C:\Windows\wininit.ini
[2011/11/15 19:49:03 | 000,039,538 | —- | M] () – C:\Users\Ratopia\Desktop\Schiap neck;ace - look at that final.jpg
[2011/11/15 19:42:01 | 000,048,873 | —- | M] () – C:\Users\Ratopia\Desktop\Lisner necklace - similar to final on so called Selro blue set with spirals.jpg
[2011/11/15 18:46:58 | 000,030,063 | —- | M] () – C:\Users\Ratopia\Desktop\$(KGrHqJ,!l4E5(pWzGcdBOZ!NheBeQ~~60_1.jpg
[2011/11/15 04:16:13 | 000,610,794 | —- | M] () – C:\Users\Ratopia\Desktop\2010-12-30_19-07-14_812.jpg
[2011/11/14 18:25:23 | 000,008,583 | —- | M] () – C:\Users\Ratopia\Desktop\tyto barn owl.jpg
[2011/11/13 22:04:38 | 000,061,298 | —- | M] () – C:\Users\Ratopia\Desktop\Possible D&E; brooch.jpg
[2011/11/13 21:36:18 | 000,042,014 | —- | M] () – C:\Users\Ratopia\Desktop\Possible Juliana or D&E; Brooch.jpg
[2011/11/09 23:29:00 | 000,038,750 | —- | M] () – C:\Users\Ratopia\Desktop\Nov10.jpg
[2011/11/09 20:21:17 | 000,008,249 | —- | M] () – C:\Users\Ratopia\Desktop\authorization_form[1].pdf
[2011/11/07 02:23:55 | 000,031,238 | —- | M] () – C:\Users\Ratopia\Desktop\My Czech dragon brooch.jpg
[2011/11/06 05:26:31 | 000,060,500 | —- | M] () – C:\Users\Ratopia\Desktop\Judy Lee bracelet and earrings with book verification.JPG
[2011/11/05 02:11:16 | 000,016,279 | —- | M] () – C:\Users\Ratopia\Desktop\Grant woman problem.JPG
[2011/11/03 22:40:53 | 497,971,690 | —- | M] () – C:\Users\Ratopia\Desktop\Michael-Jackson-Life-of-an-Icon-2011[www.savevid.com].flv
[2011/11/02 00:49:56 | 000,027,017 | —- | M] () – C:\Users\Ratopia\Desktop\Robert us bank credit cqrd statement Oct 2011.pdf
[2011/10/31 16:57:47 | 000,035,360 | —- | M] () – C:\Users\Ratopia\Desktop\381059_289072164447300_100000335568227_1010692_773830117_n.jpg
[2011/10/30 22:07:00 | 000,075,040 | —- | M] () – C:\Users\Ratopia\Desktop\Zsir and Coco.jpg
[2011/10/30 22:05:21 | 000,026,257 | —- | M] () – C:\Users\Ratopia\Desktop\Zsir as a young kitty.JPG
[2011/10/30 16:05:37 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/28 22:13:36 | 000,013,873 | —- | M] () – C:\Users\Ratopia\Desktop\Cardinals 2011.jpg
[2011/10/26 15:36:23 | 000,061,569 | —- | M] () – C:\Users\Ratopia\Desktop\PhotoCaptionOct28.jpg
[2011/10/25 23:57:00 | 000,093,052 | —- | M] () – C:\Users\Ratopia\Desktop\My Son.jpg
[2011/10/25 20:34:58 | 000,000,438 | —- | M] () – C:\Users\Ratopia\Desktop\Harshad Sarode.URL
[2011/10/25 16:26:34 | 000,053,597 | —- | M] () – C:\Users\Ratopia\Desktop\335609_2238233152617_1151643217_32041701_1583424197_o.jpg
[2011/10/23 01:09:07 | 095,971,328 | —- | M] () – C:\Users\Ratopia\Desktop\JibJab_Order_3976910_Movie.mpg
[2011/10/22 17:53:17 | 000,087,446 | —- | M] () – C:\Users\Ratopia\Desktop\Robert in Tulsa with Lion and Tiger cubs.jpg
[2011/10/22 13:52:09 | 000,009,675 | —- | M] () – C:\Users\Ratopia\Desktop\WoodRive
[2011/10/19 23:13:55 | 000,040,365 | —- | M] () – C:\Users\Ratopia\Desktop\atheists.jpg
[2011/10/18 18:52:39 | 000,086,079 | —- | M] () – C:\Users\Ratopia\Desktop\Starr Ranch Owl 10-18-2011 7.51pm cst.jpg
[1 C:\Users\Ratopia\Desktop\*.tmp files -> C:\Users\Ratopia\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/17 02:53:14 | 000,625,664 | —- | C] () – C:\Users\Ratopia\Desktop\dds.scr
[2011/11/17 02:41:55 | 000,002,563 | —- | C] () – C:\Users\Ratopia\Desktop\HiJackThis.lnk
[2011/11/16 19:54:14 | 000,327,051 | —- | C] () – C:\Users\Ratopia\Desktop\5542412236_be4efe7a23_b[1].jpg
[2011/11/15 19:49:21 | 000,039,538 | —- | C] () – C:\Users\Ratopia\Desktop\Schiap neck;ace - look at that final.jpg
[2011/11/15 19:42:56 | 000,048,873 | —- | C] () – C:\Users\Ratopia\Desktop\Lisner necklace - similar to final on so called Selro blue set with spirals.jpg
[2011/11/15 18:46:57 | 000,030,063 | —- | C] () – C:\Users\Ratopia\Desktop\$(KGrHqJ,!l4E5(pWzGcdBOZ!NheBeQ~~60_1.jpg
[2011/11/15 04:01:47 | 000,610,794 | —- | C] () – C:\Users\Ratopia\Desktop\2010-12-30_19-07-14_812.jpg
[2011/11/14 18:25:40 | 000,008,583 | —- | C] () – C:\Users\Ratopia\Desktop\tyto barn owl.jpg
[2011/11/13 22:04:37 | 000,061,298 | —- | C] () – C:\Users\Ratopia\Desktop\Possible D&E; brooch.jpg
[2011/11/13 21:48:08 | 000,042,014 | —- | C] () – C:\Users\Ratopia\Desktop\Possible Juliana or D&E; Brooch.jpg
[2011/11/09 23:29:00 | 000,038,750 | —- | C] () – C:\Users\Ratopia\Desktop\Nov10.jpg
[2011/11/09 20:21:17 | 000,008,249 | —- | C] () – C:\Users\Ratopia\Desktop\authorization_form[1].pdf
[2011/11/07 02:24:21 | 000,031,238 | —- | C] () – C:\Users\Ratopia\Desktop\My Czech dragon brooch.jpg
[2011/11/06 05:26:28 | 000,060,500 | —- | C] () – C:\Users\Ratopia\Desktop\Judy Lee bracelet and earrings with book verification.JPG
[2011/11/05 02:11:14 | 000,016,279 | —- | C] () – C:\Users\Ratopia\Desktop\Grant woman problem.JPG
[2011/11/03 22:40:31 | 497,971,690 | —- | C] () – C:\Users\Ratopia\Desktop\Michael-Jackson-Life-of-an-Icon-2011[www.savevid.com].flv
[2011/11/02 00:49:56 | 000,027,017 | —- | C] () – C:\Users\Ratopia\Desktop\Robert us bank credit cqrd statement Oct 2011.pdf
[2011/10/31 16:57:46 | 000,035,360 | —- | C] () – C:\Users\Ratopia\Desktop\381059_289072164447300_100000335568227_1010692_773830117_n.jpg
[2011/10/30 22:07:00 | 000,075,040 | —- | C] () – C:\Users\Ratopia\Desktop\Zsir and Coco.jpg
[2011/10/30 22:05:19 | 000,026,257 | —- | C] () – C:\Users\Ratopia\Desktop\Zsir as a young kitty.JPG
[2011/10/28 22:13:36 | 000,013,873 | —- | C] () – C:\Users\Ratopia\Desktop\Cardinals 2011.jpg
[2011/10/26 15:36:21 | 000,061,569 | —- | C] () – C:\Users\Ratopia\Desktop\PhotoCaptionOct28.jpg
[2011/10/25 23:56:59 | 000,093,052 | —- | C] () – C:\Users\Ratopia\Desktop\My Son.jpg
[2011/10/25 20:34:58 | 000,000,438 | —- | C] () – C:\Users\Ratopia\Desktop\Harshad Sarode.URL
[2011/10/25 16:26:33 | 000,053,597 | —- | C] () – C:\Users\Ratopia\Desktop\335609_2238233152617_1151643217_32041701_1583424197_o.jpg
[2011/10/23 01:07:50 | 095,971,328 | —- | C] () – C:\Users\Ratopia\Desktop\JibJab_Order_3976910_Movie.mpg
[2011/10/22 17:53:16 | 000,087,446 | —- | C] () – C:\Users\Ratopia\Desktop\Robert in Tulsa with Lion and Tiger cubs.jpg
[2011/10/22 13:52:09 | 000,009,675 | —- | C] () – C:\Users\Ratopia\Desktop\WoodRive
[2011/10/19 23:14:11 | 000,040,365 | —- | C] () – C:\Users\Ratopia\Desktop\atheists.jpg
[2011/10/18 18:51:51 | 000,086,079 | —- | C] () – C:\Users\Ratopia\Desktop\Starr Ranch Owl 10-18-2011 7.51pm cst.jpg
[2011/09/24 22:52:12 | 000,937,320 | —- | C] () – C:\Users\Ratopia\AppData\Local\census.cache
[2011/09/24 22:51:26 | 000,174,679 | —- | C] () – C:\Users\Ratopia\AppData\Local\ars.cache
[2011/09/24 22:42:23 | 000,000,036 | —- | C] () – C:\Users\Ratopia\AppData\Local\housecall.guid.cache
[2010/08/25 19:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 19:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 19:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010/06/12 03:39:35 | 000,000,680 | —- | C] () – C:\Users\Ratopia\AppData\Local\d3d9caps.dat
[2010/02/12 15:15:53 | 000,000,732 | —- | C] () – C:\Users\Ratopia\AppData\Local\d3d9caps64.dat
[2009/10/04 15:01:22 | 000,000,302 | —- | C] () – C:\Users\Ratopia\AppData\Roaming\wklnhst.dat
[2009/09/13 14:44:31 | 000,454,656 | —- | C] () – C:\Windows\SysWow64\PaintX.dll
[2009/07/10 21:45:50 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/07/10 21:45:22 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/07/10 21:44:48 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/14 17:21:46 | 000,237,568 | —- | C] () – C:\Windows\SysWow64\rmc_rtspdl.dll
[2009/05/20 14:12:21 | 000,040,960 | —- | C] () – C:\Users\Ratopia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/18 16:44:54 | 000,000,335 | —- | C] () – C:\Windows\nsreg.dat
[2009/05/18 14:47:51 | 000,002,224 | —- | C] () – C:\Windows\wininit.ini
[2008/12/20 04:42:16 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2008/12/20 04:42:16 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2008/12/20 04:42:16 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2008/12/20 04:40:09 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/12/18 01:13:34 | 000,001,024 | RH– | C] () – C:\Windows\SysWow64\NTIOFM4.dll
[2008/12/18 01:13:34 | 000,001,024 | RH– | C] () – C:\Windows\SysWow64\NTIBUN5.dll
[2008/12/17 23:54:28 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/12/17 23:11:37 | 000,147,172 | —- | C] () – C:\Windows\SysWow64\igfcg550.bin
[2008/08/13 20:25:02 | 000,129,604 | —- | C] () – C:\Windows\Set_Resolution_2.0.exe
[2008/05/27 10:38:56 | 000,005,552 | R— | C] () – C:\Program Files (x86)\ReadMe.htm
[2008/01/20 20:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 20:47:32 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\pcadm.dll
[2006/11/02 09:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 06:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 06:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 03:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2001/12/26 18:12:30 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\multiplex_vcd.dll
[2001/09/04 01:46:38 | 000,110,592 | —- | C] () – C:\Windows\SysWow64\Hmpg12.dll
[2001/07/30 18:33:56 | 000,118,784 | —- | C] () – C:\Windows\SysWow64\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 000,118,784 | —- | C] () – C:\Windows\SysWow64\HMPV2_ENC_MMX.dll

========== LOP Check ==========

[2009/05/07 23:47:49 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\Acer
[2008/12/18 01:09:07 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\Acer GameZone Console
[2010/10/19 18:22:38 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\AVG10
[2011/09/19 18:54:39 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\DeepBurner
[2009/05/18 14:40:48 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\eSobi
[2011/10/28 21:33:01 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\Fighters
[2009/12/08 01:44:42 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\GlarySoft
[2009/05/07 23:47:49 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\Leadertech
[2009/10/04 15:01:24 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\Template
[2011/10/28 21:34:57 | 000,000,000 | —D | M] – C:\Users\Ratopia\AppData\Roaming\WeatherBug
[2011/11/17 02:21:16 | 000,000,414 | —- | M] () – C:\Windows\Tasks\PC Optimizer Pro64 startups.job
[2011/11/17 02:19:59 | 000,032,570 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/12/17 23:14:12 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/11/17 02:20:45 | 4220,379,136 | -HS- | M] () – C:\hiberfil.sys
[2008/12/20 04:53:09 | 000,000,020 | —- | M] () – C:\Medion.ini
[2011/11/17 02:20:44 | 239,005,695 | -HS- | M] () – C:\pagefile.sys
[2008/12/20 04:48:57 | 000,000,060 | —- | M] () – C:\Partition.txt
[2008/12/20 04:40:53 | 000,000,693 | —- | M] () – C:\RHDSetup.log

< %systemroot%\Fonts\*.com >
[2006/11/02 09:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 09:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 09:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/10 21:53:42 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2008/05/27 10:38:56 | 000,005,552 | R— | M] () – C:\Program Files (x86)\ReadMe.htm

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/01/29 19:20:45 | 000,000,281 | -HS- | M] () – C:\Users\Ratopia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/17 02:52:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Ratopia\Desktop\HiJackThis.exe
[2011/09/28 01:46:20 | 002,002,320 | —- | M] (Trend Micro Inc.) – C:\Users\Ratopia\Desktop\HousecallLauncher.exe
[2011/11/17 02:52:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Ratopia\Desktop\OTL.exe
[1 C:\Users\Ratopia\Desktop\*.tmp files -> C:\Users\Ratopia\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:01:24 AM, on 11/17/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE
C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Common Files\aol\1242688622\ee\aolsoftware.exe
C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngrUI.exe
C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Ratopia\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher…d&%language
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tb…0647&lng=en
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80647
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_6930
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tb…0647&lng=en
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80647
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll
O2 - BHO: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\PROGRA~2\WI084F~1\ToolBar\SearchquDx.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\PROGRA~2\WI084F~1\ToolBar\SearchquDx.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~2\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acer Assist Launcher] "C:\Program Files (x86)\Acer\Acer Assist\launcher.exe"
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [HostManager] "C:\Program Files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\WI084F~1\Datamngr\DATAMN~1.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Info Center] "C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} (diskhealth Class) - http://utilities.pcpitstop.com/Nirvana/con…DiskMD3Ctrl.dll
O16 - DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} (PCPitstop AntiVirus) - http://utilities.pcpitstop.com/Nirvana/con…opAntiVirus.dll
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\WI084F~1\Datamngr\datamngr.dll C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 15356 bytes
. DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 3:22:25.35 on Thu 11/17/2011 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_24 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4024.2098 [GMT -6:00] . AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe C:\Program Files\Acer\Empowering Technology\Service\ETService.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Acer\Mobility Center\MobilityService.exe C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio64.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\alg.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe C:\Windows\RAVCpl64.exe C:\Windows\PLFSetI.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe C:\Users\Ratopia\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Common Files\aol\1242688622\ee\aolsoftware.exe C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngrUI.exe C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe C:\Windows\system32\igfxext.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskeng.exe C:\Windows\System32\notepad.exe C:\Windows\notepad.exe C:\Windows\System32\notepad.exe C:\Windows\notepad.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Ratopia\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930 uSearch Bar = hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930 uInternet Settings,ProxyOverride = mSearchAssistant = hxxp://toolbar.inbox.com/search/ie.aspx?tbid=80647&lng=en mCustomizeSearch = hxxp://toolbar.inbox.com/help/sa_customize.aspx?tbid=80647 uURLSearchHooks: H - No File mURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: AOL Toolbar Loader: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll BHO: Searchqu Toolbar: {7ff99715-3016-4381-84ce-e4e4c9673020} - C:\PROGRA~2\WI084F~1\ToolBar\SearchquDx.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll BHO: UrlHelper Class: {a40dc6c5-79d0-4ca8-a185-8ff989af1115} - C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB: Searchqu Toolbar: {7ff99715-3016-4381-84ce-e4e4c9673020} - C:\PROGRA~2\WI084F~1\ToolBar\SearchquDx.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 mRun: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" mRun: [BkupTray] "C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" mRun: [LManager] C:\PROGRA~2\LAUNCH~1\QtZgAcer.EXE mRun: [eRecoveryService] mRun: [ArcadeDeluxeAgent] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" mRun: [CLMLServer] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" mRun: [Acer Assist Launcher] "C:\Program Files (x86)\Acer\Acer Assist\launcher.exe" mRun: [Acer Product Registration] "C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" /startup mRun: [HostManager] "C:\Program Files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe" mRun: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [DATAMNGR] C:\PROGRA~2\WI084F~1\Datamngr\DATAMN~1.EXE mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Info Center] "C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe" mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper20073151.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: C:\PROGRA~2\WI084F~1\Datamngr\datamngr.dll C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: ShowBarObj Class: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: UrlHelper Class: {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI084F~1\Datamngr\x64\IEBHO.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\Update\1.3.21.57\%ProgramW6432%\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: Acer eDataSecurity Management: {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll TB-X64: AOL Toolbar: {DE9C389F-3316-41A7-809B-AA305ED9D922} - TB-X64: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun-x64: [IAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" mRun-x64: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe mRun-x64: [eDataSecurity Loader] "C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" mRun-x64: [RtHDVCpl] RAVCpl64.exe mRun-x64: [Skytel] Skytel.exe mRun-x64: [PLFSetI] C:\Windows\PLFSetI.exe mRun-x64: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" AppInit_DLLs-X64: C:\PROGRA~2\WI084F~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI084F~1\Datamngr\x64\IEBHO.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cbe35ad&v=6.010.006.004&i=23&tp=ab&iy=&ychte=us&lng=en-US&q= FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll FF - plugin: C:\Program Files (x86)\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Reader\browser\nppdf32.dll FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Ratopia\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll FF - plugin: C:\Users\Ratopia\AppData\Roaming\Mozilla\plugins\np-mswmp.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: AVG Security Toolbar em:version=6.010.006.004 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-9-7 305232] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-9-7 381008] R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-12-20 32240] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-9-24 136360] R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-9-24 269480] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2011-9-24 88288] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-3-3 16384] R2 CLHNService;CLHNService;C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-12-20 81504] R2 ETService;Empowering Technology Service;C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-12-18 24576] R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648] R2 FreeAgentGoNext Service;Seagate Service;C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-9-25 189736] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-4-25 45056] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-4-25 131072] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-9-28 1153368] R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2008-12-17 294400] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2008-12-17 129536] R3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2008-11-17 4751360] R3 winbondcir;Winbond IR Transceiver;C:\Windows\System32\drivers\winbondcir.sys [2007-3-28 46592] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-15 135664] S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 133712] S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920] S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-15 135664] S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;C:\Program Files\Zune\WMZuneComm.exe [2011-8-5 306400] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S4 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-10-19 517448] S4 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-9-3 6104144] S4 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-9-10 265400] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-7-10 89920] . =============== Created Last 30 ================ . 2011-11-17 08:41:56 388096 —-a-r- C:\Users\Ratopia\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-17 08:20:48 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{FFA4A42E-4B99-4E2D-BEDD-2997E230F741}\offreg.dll 2011-11-17 07:58:23 ——– d—–w- C:\Users\Ratopia\AppData\Local\Acer Arcade Deluxe 2011-11-15 22:28:48 8570192 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{FFA4A42E-4B99-4E2D-BEDD-2997E230F741}\mpengine.dll 2011-11-08 22:55:18 1426304 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-11-08 22:55:15 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat 2011-11-08 22:55:15 2409784 —-a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat 2011-11-08 22:55:10 893440 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-08 22:55:10 707584 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-08 22:55:10 50688 —-a-w- C:\Program Files\Windows Mail\wabimp.dll 2011-10-29 03:35:00 ——– d—–w- C:\Users\Ratopia\AppData\Local\WeatherBug 2011-10-29 03:34:57 ——– d—–w- C:\Users\Ratopia\AppData\Roaming\WeatherBug 2011-10-29 03:34:56 18944 —-a-r- C:\Users\Ratopia\AppData\Roaming\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe 2011-10-29 03:33:01 ——– d—–w- C:\Users\Ratopia\AppData\Roaming\Fighters 2011-10-29 03:32:31 ——– d—–w- C:\PROGRA~3\Fighters 2011-10-29 03:32:07 ——– d—–w- C:\PROGRA~3\Oberon Media . ==================== Find3M ==================== . 2011-10-30 22:05:37 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-26 21:50:33 88288 —-a-w- C:\Windows\System32\drivers\avgntflt.sys 2011-09-06 13:56:50 2764288 —-a-w- C:\Windows\System32\win32k.sys 2011-09-02 14:15:02 1383424 —-a-w- C:\Windows\System32\mshtml.tlb 2011-09-02 13:39:07 1383424 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-31 22:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-08-25 16:20:38 735744 —-a-w- C:\Windows\System32\UIAutomationCore.dll 2011-08-25 16:19:32 847360 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-25 16:19:32 332288 —-a-w- C:\Windows\System32\oleacc.dll 2011-08-25 16:15:04 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll 2011-08-25 16:14:01 563712 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-25 16:14:01 238080 —-a-w- C:\Windows\SysWow64\oleacc.dll 2011-08-25 13:54:14 4096 —-a-w- C:\Windows\System32\oleaccrc.dll 2011-08-25 13:31:01 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll . ============= FINISH: 3:23:03.33 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 12/20/2008 4:36:05 AM System Uptime: 11/17/2011 2:20:24 AM (1 hours ago) . Motherboard: Acer | | Makalu Processor: Intel® Core™2 Duo CPU T6400 @ 2.00GHz | U2E1 | 2000/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 143 GiB total, 70.01 GiB free. D: is FIXED (NTFS) - 139 GiB total, 97.094 GiB free. F: is CDROM (CDFS) . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) AAC Decoder Acer Arcade Deluxe Acer Assist Acer Crystal Eye Webcam 2.0.8 Acer eAudio Management Acer eDataSecurity Management Acer Empowering Technology Acer ePower Management Acer eRecovery Management Acer eSettings Management Acer GameZone Console 2.0.1.1 Acer GridVista Acer Mobility Center Plug-In Acer Registration Acer ScreenSaver Acrobat.com Activation Assistant for the 2007 Microsoft Office suites Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.4.5 AOL Toolbar AOL Uninstaller (Choose which Products to Remove) Apple Application Support Apple Software Update AT&T Yahoo! Internet Mail Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver AutoUpdate Avira AntiVir Personal - Free Antivirus Azada Backspin Billiards Bing Bar Bookworm Deluxe Bricks of Egypt CCleaner (remove only) Chuzzle CyberLink PowerDirector D3DX10 DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Version Checker DivX Web Player Download Updater (AOL LLC) Easy CD-DA Extractor 15 eSobi v2 Flip Words 2 Google Earth Plug-in Google Toolbar for Internet Explorer Google Update Helper H.264 Decoder HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Info Center 1.0.0.6 InstallIQ Updater Java Auto Updater Java™ 6 Update 24 Jewel Quest Solitaire Kick N Rush Launch Manager LightScribe 1.4.142.1 Mahjong Escape Ancient China Mahjongg Artifacts Malwarebytes' Anti-Malware version 1.51.2.1300 Microsoft Default Manager Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft UI Engine Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works MKV Splitter Mozilla Firefox (3.6.24) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Mystery Case Files - Huntsville Mystery Solitaire - Secret Island NTI Backup Now 5 NTI Backup Now Standard NTI Media Maker 8 Octoshape add-in for Adobe Flash Player PhotoNow! QuickTime Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Replay Media Catcher 3.02 RTC Client API v1.2 SaveVid Plug-in Seagate Manager Installer Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553074) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft Office Excel 2007 (KB2553073) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Segoe UI Spybot - Search & Destroy Uninstall AOL Emergency Connect Utility 1.0 Update for 2007 Microsoft Office System (KB2284654) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) V - The File Viewer VC80CRTRedist - 8.0.50727.762 Viewpoint Media Player Visual C++ 8.0 Runtime Setup Package (x64) Visual Studio 2008 x64 Redistributables Winamp Winamp Detector Plug-in Winbond CIR Device Drivers Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Savevid MediaBar WinZip 12.1 Yahoo! BrowserPlus 2.9.8 Yahoo! Install Manager Yahoo! Messenger Yahoo! Toolbar Zuma Deluxe . ==== End Of File ===========================
Hi CoolCat,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
[2010/12/13 03:33:40 | 000,005,529 | —- | M] () – C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchplugins\SearchquWebSearch.xml
[2010/06/28 15:17:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 23:27:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/04 01:45:28 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/31 17:06:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/12/13 03:33:40 | 000,005,529 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchquWebSearch.xml
[2011/10/28 21:32:07 | 000,001,456 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\WebSearchober24026852.xml
[2011/09/27 22:02:34 | 000,001,456 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\WebSearchober8747444.xml
O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\IEBHO.dll (Discordia, LTD)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll ()
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngrUI.exe (Discordia, LTD)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\IEBHO.dll (Discordia, LTD)


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
OK, here is the scan as per your instructions. Thank you!! :) All processes killed ========== PROCESSES ========== ========== OTL ========== Prefs.js: "Web Search" removed from browser.search.defaultenginename Prefs.js: "Web Search" removed from browser.search.order.1 Prefs.js: "Web Search" removed from browser.search.selectedEngine Prefs.js: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 removed from extensions.enabledItems Prefs.js: avg@igeared:6.010.006.004 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchplugins\SearchquWebSearch.xml moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\WebSearchober24026852.xml moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\WebSearchober8747444.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FF99715-3016-4381-84CE-E4E4C9673020}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FF99715-3016-4381-84CE-E4E4C9673020}\ deleted successfully. C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\IEBHO.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FF99715-3016-4381-84CE-E4E4C9673020} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FF99715-3016-4381-84CE-E4E4C9673020}\ not found. File C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully. C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngrUI.exe moved successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI084F~1\Datamngr\x64\datamngr.dll deleted successfully. C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\datamngr.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI084F~1\Datamngr\x64\IEBHO.dll deleted successfully. C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\x64\IEBHO.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI084F~1\Datamngr\datamngr.dll deleted successfully. File pInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\datamngr.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll deleted successfully. File pInit_DLLs: (C:\PROGRA~2\WI084F~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows Savevid MediaBar\Datamngr\IEBHO.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Ratopia ->Temp folder emptied: 365657 bytes ->Temporary Internet Files folder emptied: 17517507 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 115456621 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 1855040 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 337084 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 327051 bytes Total Files Cleaned = 130.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 11192011_192053 Files\Folders moved on Reboot… C:\Users\Ratopia\AppData\Local\Temp\RtkBtMnt.exe moved successfully. Registry entries deleted on Reboot…
Good,

Now give this a go:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
OK, apparent;ly I have a Windows Defender running, somewhere. I wasn't aware of this until looking at this log. Here's the ComboFix log. Thanks!! ComboFix 11-11-19.04 - Ratopia 11/19/2011 21:01:10.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4024.2427 [GMT -6:00] Running from: C:\Users\[removed]\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\ProgramData\Tarma Installer C:\ProgramData\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setup.dll C:\ProgramData\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll C:\ProgramData\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\Setup.dat C:\ProgramData\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\Setup.exe C:\ProgramData\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\Setup.ico C:\Users\Ratopia\AppData\Local\Temp\RtkBtMnt.exe C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\games\00d2dfc64c07a4f32824abac1d6f735b C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\games\3e4265e00cbc4a9cf22a105046a46d8a C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\games\44a5d79f5451d3036ba3986425e234c8 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\games\GameCategories.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\games\GameTypes.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\guid.dat C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\preferences.dat C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\search\searchqutb-search-history.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\stats.dat C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\uninstallFF.dat C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\version.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weather\141fc2e6489f76f2e1272827143c4fda C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weather\361b7b5d79ecfba06724fad84f67beaf C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weather\72647ba3fb8f4442b6c947b02eb24949 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weather\9119f4973e06dd6bac220a659e30b45c C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weather\forecasts_cache.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weather\observations_cache.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\weatherbutton_prefs.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\123255b2b28c7d59e179f9d8f0563ec9 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\1fcf78eb82203c1c18b17d44a9cee667 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\5f97e3d93ca303d1e2354b2b89ba759e C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\84b70525cff6359fdeca553342c23e4c C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\9d01b5a215d7eaa18756160a8b232a78 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\adfc34adcc6d7d5506eb7e6246fae36d C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\bf5b6317ae07da699882fc948f22eda4 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\category_cache.xml C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\e1d2b5bf3daf0fb28de9d364e28de54f C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\f9677b9a97642062e20072fe40162600 C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\searchqutb\widgets_cache\widget_cache.xml C:\Users\Ratopia\avira_antivir_personal_en.exe ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_COMSysApp ((((((((((((((((((((((((( Files Created from 2011-10-20 to 2011-11-20 ))))))))))))))))))))))))))))))) 2011-11-20 03:18:59 . 2011-11-20 03:18:59 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B2E53EDC-3200-4832-BB11-50ED5E1FA059}\offreg.dll 2011-11-19 03:48:30 . 2011-11-19 03:48:30 ——– d—–w- C:\Users\Ratopia\AppData\Local\Adobe 2011-11-18 23:50:46 . 2011-10-07 04:16:03 8570192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B2E53EDC-3200-4832-BB11-50ED5E1FA059}\mpengine.dll 2011-11-18 02:59:23 . 2011-11-18 02:59:23 ——– d—–w- C:\Users\Ratopia\AppData\Local\Acer Arcade Deluxe 2011-11-17 08:41:56 . 2011-11-17 08:41:56 388096 —-a-r- C:\Users\Ratopia\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-08 22:55:18 . 2011-09-20 21:06:18 1426304 —-a-w- C:\Windows\system32\drivers\tcpip.sys 2011-11-08 22:55:15 . 2011-10-17 11:41:35 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat 2011-11-08 22:55:15 . 2011-10-17 11:41:10 2409784 —-a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat 2011-11-08 22:55:10 . 2011-09-30 16:16:23 893440 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-08 22:55:10 . 2011-09-30 16:16:23 50688 —-a-w- C:\Program Files\Windows Mail\wabimp.dll 2011-11-08 22:55:10 . 2011-09-30 15:57:08 707584 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-10-29 03:35:00 . 2011-10-29 03:36:00 ——– d—–w- C:\Users\Ratopia\AppData\Local\WeatherBug 2011-10-29 03:34:57 . 2011-10-29 03:34:57 ——– d—–w- C:\Users\Ratopia\AppData\Roaming\WeatherBug 2011-10-29 03:34:56 . 2011-10-29 03:34:56 18944 —-a-r- C:\Users\Ratopia\AppData\Roaming\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe 2011-10-29 03:33:01 . 2011-10-29 03:33:01 ——– d—–w- C:\Users\Ratopia\AppData\Roaming\Fighters 2011-10-29 03:32:31 . 2011-10-29 04:18:11 ——– d—–w- C:\ProgramData\Fighters 2011-10-29 03:32:07 . 2011-10-29 03:32:07 ——– d—–w- C:\ProgramData\Oberon Media . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2011-10-30 22:05:37 . 2011-05-15 23:58:52 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-26 21:50:33 . 2011-09-25 03:42:42 88288 —-a-w- C:\Windows\system32\drivers\avgntflt.sys 2011-09-26 21:50:33 . 2011-09-25 03:42:42 123784 —-a-w- C:\Windows\system32\drivers\avipbb.sys 2011-09-06 13:56:50 . 2011-10-13 21:39:13 2764288 —-a-w- C:\Windows\system32\win32k.sys 2011-09-02 14:15:02 . 2011-10-13 21:39:02 1383424 —-a-w- C:\Windows\system32\mshtml.tlb 2011-09-02 13:39:07 . 2011-10-13 21:39:02 1383424 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-31 22:00:50 . 2009-05-26 22:53:04 25416 —-a-w- C:\Windows\system32\drivers\mbam.sys 2011-08-25 16:20:38 . 2011-10-13 21:38:33 735744 —-a-w- C:\Windows\system32\UIAutomationCore.dll 2011-08-25 16:19:32 . 2011-10-13 21:38:34 332288 —-a-w- C:\Windows\system32\oleacc.dll 2011-08-25 16:19:32 . 2011-10-13 21:38:33 847360 —-a-w- C:\Windows\system32\oleaut32.dll 2011-08-25 16:15:04 . 2011-10-13 21:38:33 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll 2011-08-25 16:14:01 . 2011-10-13 21:38:33 563712 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-25 16:14:01 . 2011-10-13 21:38:33 238080 —-a-w- C:\Windows\SysWow64\oleacc.dll 2011-08-25 13:54:14 . 2011-10-13 21:38:32 4096 —-a-w- C:\Windows\system32\oleaccrc.dll 2011-08-25 13:31:01 . 2011-10-13 21:38:32 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2010-10-06 16:31:46 2475336 —-a-w- C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2010-10-06 16:31:46 2475336] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:52:34 121392 —-a-w- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 21:07:20 2260480] "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-08 05:45:33 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "eAudio"="C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-09-12 06:46:24 781824] "BkupTray"="C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 05:36:20 28672] "LManager"="C:\PROGRA~2\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 12:03:36 817672] "ArcadeDeluxeAgent"="C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 23:54:10 147456] "CLMLServer"="C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 23:54:18 167936] "Acer Assist Launcher"="C:\Program Files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 22:17:40 1261568] "Acer Product Registration"="C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 18:21:22 3387392] "HostManager"="C:\Program Files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe" [2008-06-24 18:34:50 41824] "MaxMenuMgr"="C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 05:31:32 185640] "Microsoft Default Manager"="C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 16:12:14 288080] "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" [2010-11-29 23:38:18 421888] "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Reader\Reader_sl.exe" [2011-06-08 04:02:26 37296] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 04:59:06 937920] "Info Center"="C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 17:16:48 24216] "avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 12:53:33 281768] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 18:16:28 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 19:27:14 138576] R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46:11 135664] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-26 05:36:02 131072] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [x] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [x] R3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 23:44:14 183560] R3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46:11 135664] R3 WMZuneComm;Zune Windows Mobile Connectivity Service;C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 17:53:12 306400] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 19:27:14 1020768] R4 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-10-06 16:31:48 517448] R4 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-09-03 15:35:50 6104144] R4 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-09-10 06:45:22 265400] S0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys [x] S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys [x] S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-07-19 00:05:12 32240] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 12:53:48 136360] S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 21:11:14 16384] S2 CLHNService;CLHNService;C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-17 02:35:02 81504] S2 ETService;Empowering Technology Service;C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 22:27:22 24576] S2 FreeAgentGoNext Service;Seagate Service;C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-26 05:32:18 189736] S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-26 05:36:20 45056] S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 20:31:10 1153368] S3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys [x] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys [x] S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETw5v64.sys [x] S3 winbondcir;Winbond IR Transceiver;C:\Windows\system32\DRIVERS\winbondcir.sys [x] Contents of the 'Scheduled Tasks' folder 2011-11-20 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46:24 . 2010-07-15 19:46:11] 2011-11-20 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46:24 . 2010-07-15 19:46:11] ——— x86-64 ———– [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:53:36 50736 —-a-w- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 09:45:06 182808] "ePower_DMC"="C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 18:03:50 481792] "eDataSecurity Loader"="C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 01:53:44 561200] "RtHDVCpl"="RAVCpl64.exe" [2008-09-18 11:02:14 6495264] "Skytel"="Skytel.exe" [2008-09-18 11:02:52 1833504] "PLFSetI"="C:\Windows\PLFSetI.exe" [2007-10-23 18:56:18 200704] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 02:08:44 1237288] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2011-02-12 00:25:56 162328] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2011-02-12 00:25:38 386584] "Persistence"="C:\Windows\system32\igfxpers.exe" [2011-02-12 00:25:46 417304] "Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2011-08-05 17:53:06 163552] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 ——- Supplementary Scan ——- uLocal Page = C:\Windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930 mLocal Page = %SystemRoot%\system32\blank.htm uInternet Settings,ProxyOverride = IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm TCP: DhcpNameServer = [removed] [removed] Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll FF - ProfilePath - C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cbe35ad&v=6.010.006.004&i=23&tp=ab&iy=&ychte=us&lng=en-US&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: AVG Security Toolbar em:version=6.010.006.004 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} - - - - ORPHANS REMOVED - - - - Toolbar-10 - (no file) Wow6432Node-HKCU-Run-Weather - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe Wow6432Node-HKLM-Run-eRecoveryService - (no file) Wow6432Node-HKLM-Run-SunJavaUpdateSched - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe BHO-{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI084F~1\Datamngr\x64\IEBHO.dll WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKLM-Run-Windows Defender - C:\Program Files (x86)\Windows Defender\MSASCui.exe AddRemove-Yahoo! Mail - C:\Windows\system32\regsvr32 AddRemove-YInstHelper - C:\Windows\system32\regsvr32 AddRemove-Octoshape add-in for Adobe Flash Player - C:\Users\Ratopia\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
CoolCat,

You've got two anti-virus programs running. Avira and AVG. That's a bad idea. Two AV's running will cause conflicts and actually make them less effective. Please uninstall one of them. Personally, of the two, I prefer Avira but it is your choice.

After you have done that, let's get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
That's weird because I went into add/remove programs and uninstalled AVG over 6 months ago. I'll do it again then run the scans you suggest. Thank you!!
OK, trying to run this scanner and I am getting the warning that AVG is active. I had just gone into the control panel, again, and attempted to uninstall it and I get the message after I click to uninstall, that there is nothing to uninstall. Yet it is showing around 135mb for that file. Plus it also says I have Windows Defender running plus Avira which I shut off in the system tray. What do I do, now? Thanks
This script should take care of AVG.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
    C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
    C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
    C:\Windows\system32\DRIVERS\avgrkx64.sys
    C:\Windows\system32\DRIVERS\avgldx64.sys
    C:\Windows\system32\DRIVERS\avgmfx64.sys
    C:\Windows\system32\DRIVERS\avgtdia.sys
    
    Folder::
    C:\Program Files (x86)\AVG
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"=-
    
    Driver::
    AVGIDSDriver
    AVGIDSFilter
    AVG Security Toolbar Service
    AVGIDSAgent
    avgwd
    AVGIDSEH
    Avgrkx64
    Avgldx64
    Avgmfx64
    Avgtdia
    
    DDS::
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Here is directions for shutting off windows defender: http://windows.microsoft.com/en-US/windows…ender-on-or-off
Ok, I just finished the scan - before I saw your reply. So here is that log, then I will go back and do the rest that you just posted. Thanks!! C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquTb.dll Win32/Adware.Bandoo application C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\searchqutb.js Win32/Adware.Bandoo application C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.htm Win32/Adware.Bandoo application C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.xul Win32/Adware.Bandoo application C:\ProgramData\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res Win32/Adware.Bandoo application C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res Win32/Adware.Bandoo application C:\Users\Ratopia\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\7841c717-10a04874 multiple threats C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\[removed]\chrome\content\overlay.js Win32/Adware.GamePlayLabs application C:\Users\Ratopia\Desktop\Antivirus\VideoCodecPlugin.exe a variant of Win32/Adware.GamePlayLabs application C:\Users\Ratopia\Downloads\cnet_DeepBurner1_exe.exe a variant of Win32/InstallCore.D application C:\Users\Ratopia\Downloads\winamp5581_full_emusic-7plus_en-us.exe Win32/OpenCandy application C:\_OTL\MovedFiles\11192011_192053\C_Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquDx.dll Win32/Adware.Bandoo application
OK, hopefully everything worked! B) ComboFix 11-11-19.04 - Ratopia 11/20/2011 3:07.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4024.2160 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Ratopia\Desktop\CFScript.txt AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\windows\system32\DRIVERS\AVGIDSDriver.Sys" "c:\windows\system32\DRIVERS\AVGIDSEH.Sys" "c:\windows\system32\DRIVERS\AVGIDSFilter.Sys" "c:\windows\system32\DRIVERS\avgldx64.sys" "c:\windows\system32\DRIVERS\avgmfx64.sys" "c:\windows\system32\DRIVERS\avgrkx64.sys" "c:\windows\system32\DRIVERS\avgtdia.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\AVG c:\program files (x86)\AVG\AVG10\3rd_party\licenses\ace.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\arabica.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\boost.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\bsdiff.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\bzip.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\carp.html c:\program files (x86)\AVG\AVG10\3rd_party\licenses\cryptopp.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\curl.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\dazukofs.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\expat.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\imagemagick.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\infozip.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\lua.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\md4_md5_license.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\milter.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\minizip.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\openssl_license.html c:\program files (x86)\AVG\AVG10\3rd_party\licenses\sasl.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\tinyxml.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\unrar.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\untar.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\xalan_xerces.txt c:\program files (x86)\AVG\AVG10\3rd_party\licenses\zlib.txt c:\program files (x86)\AVG\AVG10\3rd_party\readme.txt c:\program files (x86)\AVG\AVG10\avg.snu c:\program files (x86)\AVG\AVG10\avg_us.chm c:\program files (x86)\AVG\AVG10\avg_us.lng c:\program files (x86)\AVG\AVG10\avgabout.dll c:\program files (x86)\AVG\AVG10\avgamnot.dll c:\program files (x86)\AVG\AVG10\avgapia.dll c:\program files (x86)\AVG\AVG10\avgapix.dll c:\program files (x86)\AVG\AVG10\avgar_us.chm c:\program files (x86)\AVG\AVG10\avgatend.stp c:\program files (x86)\AVG\AVG10\avgatupd.stp c:\program files (x86)\AVG\AVG10\avgcclia.dll c:\program files (x86)\AVG\AVG10\avgcclix.dll c:\program files (x86)\AVG\AVG10\avgcerta.dll c:\program files (x86)\AVG\AVG10\avgcertx.dll c:\program files (x86)\AVG\AVG10\avgcfga.dll c:\program files (x86)\AVG\AVG10\avgcfgex.exe c:\program files (x86)\AVG\AVG10\avgcfgx.dll c:\program files (x86)\AVG\AVG10\avgcfgx.dll.old c:\program files (x86)\AVG\AVG10\avgchcla.dll c:\program files (x86)\AVG\AVG10\avgchclx.dll c:\program files (x86)\AVG\AVG10\avgchjwa.dll c:\program files (x86)\AVG\AVG10\avgchsva.exe c:\program files (x86)\AVG\AVG10\avgclita.dll c:\program files (x86)\AVG\AVG10\avgclitx.dll c:\program files (x86)\AVG\AVG10\avgcmgr.exe c:\program files (x86)\AVG\AVG10\avgcsla.dll c:\program files (x86)\AVG\AVG10\avgcslx.dll c:\program files (x86)\AVG\AVG10\avgcslx.dll.old c:\program files (x86)\AVG\AVG10\avgcsrva.exe c:\program files (x86)\AVG\AVG10\avgcsrvx.exe c:\program files (x86)\AVG\AVG10\avgdg_us.chm c:\program files (x86)\AVG\AVG10\avgdiagex.exe c:\program files (x86)\AVG\AVG10\avgdumpa.exe c:\program files (x86)\AVG\AVG10\avgdumpx.exe c:\program files (x86)\AVG\AVG10\avgemca.exe c:\program files (x86)\AVG\AVG10\avgf_us.chm c:\program files (x86)\AVG\AVG10\avgfree_us.mht c:\program files (x86)\AVG\AVG10\avgidp_us.chm c:\program files (x86)\AVG\AVG10\avgidpsdkx.dll c:\program files (x86)\AVG\AVG10\avgidpsdkx.dll.old c:\program files (x86)\AVG\AVG10\avglnga.dll c:\program files (x86)\AVG\AVG10\avglngx.dll c:\program files (x86)\AVG\AVG10\avgloga.dll c:\program files (x86)\AVG\AVG10\avglogx.dll c:\program files (x86)\AVG\AVG10\avglogx.dll.old c:\program files (x86)\AVG\AVG10\avglscanx.exe c:\program files (x86)\AVG\AVG10\avgmfapx.exe c:\program files (x86)\AVG\AVG10\avgmfapx.exe.old c:\program files (x86)\AVG\AVG10\avgmfarx.dll c:\program files (x86)\AVG\AVG10\avgmfarx.dll.old c:\program files (x86)\AVG\AVG10\avgmtrapx.dll c:\program files (x86)\AVG\AVG10\avgmvfla.dll c:\program files (x86)\AVG\AVG10\avgmvflx.dll c:\program files (x86)\AVG\AVG10\avgmwdef_us.mht c:\program files (x86)\AVG\AVG10\avgnsa.exe c:\program files (x86)\AVG\AVG10\avgntdumpa.exe c:\program files (x86)\AVG\AVG10\avgntdumpx.exe c:\program files (x86)\AVG\AVG10\avgpostinstx.dll c:\program files (x86)\AVG\AVG10\avgpp.dll c:\program files (x86)\AVG\AVG10\avgppa.dll c:\program files (x86)\AVG\AVG10\avgresf.dll c:\program files (x86)\AVG\AVG10\avgrkta.dll c:\program files (x86)\AVG\AVG10\avgrsa.exe c:\program files (x86)\AVG\AVG10\avgsals_us.mht c:\program files (x86)\AVG\AVG10\avgsbfree_us.mht c:\program files (x86)\AVG\AVG10\avgsbga.dll c:\program files (x86)\AVG\AVG10\avgscana.dll c:\program files (x86)\AVG\AVG10\avgscana.exe c:\program files (x86)\AVG\AVG10\avgscanx.dll c:\program files (x86)\AVG\AVG10\avgscanx.exe c:\program files (x86)\AVG\AVG10\avgsched.dll c:\program files (x86)\AVG\AVG10\avgse.dll c:\program files (x86)\AVG\AVG10\avgsea.dll c:\program files (x86)\AVG\AVG10\avgsrma.dll c:\program files (x86)\AVG\AVG10\avgsrmaa.exe c:\program files (x86)\AVG\AVG10\avgsrmax.exe c:\program files (x86)\AVG\AVG10\avgsrmx.dll c:\program files (x86)\AVG\AVG10\avgssie.dll c:\program files (x86)\AVG\AVG10\avgssiea.dll c:\program files (x86)\AVG\AVG10\avgtbapi.dll c:\program files (x86)\AVG\AVG10\AVGToolbarInstall.exe c:\program files (x86)\AVG\AVG10\avgtrial_us.mht c:\program files (x86)\AVG\AVG10\avgui.exe c:\program files (x86)\AVG\AVG10\avguiadv.dll c:\program files (x86)\AVG\AVG10\avguires.dll c:\program files (x86)\AVG\AVG10\avgupd.sig c:\program files (x86)\AVG\AVG10\avgupdx.dll c:\program files (x86)\AVG\AVG10\avgvva.dll c:\program files (x86)\AVG\AVG10\avgvvx.dll c:\program files (x86)\AVG\AVG10\avgwd.dll c:\program files (x86)\AVG\AVG10\avgwd.dll.old c:\program files (x86)\AVG\AVG10\avgwdsvc.exe c:\program files (x86)\AVG\AVG10\avgwdsvc.exe.old c:\program files (x86)\AVG\AVG10\avgwdwsc.dll c:\program files (x86)\AVG\AVG10\avgwdwsc.dll.old c:\program files (x86)\AVG\AVG10\avgwebui.dll c:\program files (x86)\AVG\AVG10\avgwsc.exe c:\program files (x86)\AVG\AVG10\avgxpl.dll c:\program files (x86)\AVG\AVG10\avgxpla.dll c:\program files (x86)\AVG\AVG10\axioo.dll c:\program files (x86)\AVG\AVG10\cf.dat c:\program files (x86)\AVG\AVG10\contacts_us.html c:\program files (x86)\AVG\AVG10\dfncfg.dat c:\program files (x86)\AVG\AVG10\Drivers\avgld.cat c:\program files (x86)\AVG\AVG10\Drivers\avgld.inf c:\program files (x86)\AVG\AVG10\Drivers\avgldx64.sys c:\program files (x86)\AVG\AVG10\Drivers\avgldx86.sys c:\program files (x86)\AVG\AVG10\Drivers\avgmf.cat c:\program files (x86)\AVG\AVG10\Drivers\avgmf.inf c:\program files (x86)\AVG\AVG10\Drivers\avgmfx64.sys c:\program files (x86)\AVG\AVG10\Drivers\avgmfx86.sys c:\program files (x86)\AVG\AVG10\Drivers\avgrk.cat c:\program files (x86)\AVG\AVG10\Drivers\avgrk.inf c:\program files (x86)\AVG\AVG10\Drivers\avgrkx64.sys c:\program files (x86)\AVG\AVG10\Drivers\avgrkx86.sys c:\program files (x86)\AVG\AVG10\Drivers\avgtdi.cat c:\program files (x86)\AVG\AVG10\Drivers\avgtdi.inf c:\program files (x86)\AVG\AVG10\Drivers\avgtdia.sys c:\program files (x86)\AVG\AVG10\Drivers\avgtdix.sys c:\program files (x86)\AVG\AVG10\Drivers\ErHrVx64\AVGIDSEH.cat c:\program files (x86)\AVG\AVG10\Drivers\ErHrVx64\AVGIDSEH.inf c:\program files (x86)\AVG\AVG10\Drivers\ErHrVx64\AVGIDSEH.sys c:\program files (x86)\AVG\AVG10\Drivers\Vista\AVGIDSDriver.cat c:\program files (x86)\AVG\AVG10\Drivers\Vista\AVGIDSDriver.inf c:\program files (x86)\AVG\AVG10\Drivers\Vista\AVGIDSDriver.sys c:\program files (x86)\AVG\AVG10\Drivers\Vista\AVGIDSFilter.cat c:\program files (x86)\AVG\AVG10\Drivers\Vista\AVGIDSFilter.inf c:\program files (x86)\AVG\AVG10\Drivers\Vista\AVGIDSFilter.sys c:\program files (x86)\AVG\AVG10\Firefox\chrome.manifest c:\program files (x86)\AVG\AVG10\Firefox\Chrome\searchshield.jar c:\program files (x86)\AVG\AVG10\Firefox\Components\avgssff.dll c:\program files (x86)\AVG\AVG10\Firefox\Components\ISearchShield.xpt c:\program files (x86)\AVG\AVG10\Firefox\install.rdf c:\program files (x86)\AVG\AVG10\fixcfg.exe c:\program files (x86)\AVG\AVG10\HtmLayout.dll c:\program files (x86)\AVG\AVG10\HtmLayout.dll.old c:\program files (x86)\AVG\AVG10\Icons\alert_mask.png c:\program files (x86)\AVG\AVG10\Icons\background_middle_gray.gif c:\program files (x86)\AVG\AVG10\Icons\background_middle_green.gif c:\program files (x86)\AVG\AVG10\Icons\background_middle_orange.gif c:\program files (x86)\AVG\AVG10\Icons\background_middle_red.gif c:\program files (x86)\AVG\AVG10\Icons\background_middle_yellow.gif c:\program files (x86)\AVG\AVG10\Icons\background_top_gray.gif c:\program files (x86)\AVG\AVG10\Icons\background_top_green.gif c:\program files (x86)\AVG\AVG10\Icons\background_top_orange.gif c:\program files (x86)\AVG\AVG10\Icons\background_top_red.gif c:\program files (x86)\AVG\AVG10\Icons\background_top_yellow.gif c:\program files (x86)\AVG\AVG10\Icons\block-doc.gif c:\program files (x86)\AVG\AVG10\Icons\blocked.gif c:\program files (x86)\AVG\AVG10\Icons\blocked12.png c:\program files (x86)\AVG\AVG10\Icons\border_bottom_gray.gif c:\program files (x86)\AVG\AVG10\Icons\border_bottom_green.gif c:\program files (x86)\AVG\AVG10\Icons\border_bottom_orange.gif c:\program files (x86)\AVG\AVG10\Icons\border_bottom_red.gif c:\program files (x86)\AVG\AVG10\Icons\border_bottom_yellow.gif c:\program files (x86)\AVG\AVG10\Icons\border_top_gray.gif c:\program files (x86)\AVG\AVG10\Icons\border_top_green.gif c:\program files (x86)\AVG\AVG10\Icons\border_top_orange.gif c:\program files (x86)\AVG\AVG10\Icons\border_top_red.gif c:\program files (x86)\AVG\AVG10\Icons\border_top_yellow.gif c:\program files (x86)\AVG\AVG10\Icons\box_bottom_red.gif c:\program files (x86)\AVG\AVG10\Icons\box_top_red.gif c:\program files (x86)\AVG\AVG10\Icons\caution.gif c:\program files (x86)\AVG\AVG10\Icons\caution12.png c:\program files (x86)\AVG\AVG10\Icons\click_here_gray.gif c:\program files (x86)\AVG\AVG10\Icons\click_here_green.gif c:\program files (x86)\AVG\AVG10\Icons\click_here_orange.gif c:\program files (x86)\AVG\AVG10\Icons\click_here_red.gif c:\program files (x86)\AVG\AVG10\Icons\click_here_yellow.gif c:\program files (x86)\AVG\AVG10\Icons\clock.gif c:\program files (x86)\AVG\AVG10\Icons\clock12.png c:\program files (x86)\AVG\AVG10\Icons\close.gif c:\program files (x86)\AVG\AVG10\Icons\icons_blocked.gif c:\program files (x86)\AVG\AVG10\Icons\icons_caution.gif c:\program files (x86)\AVG\AVG10\Icons\icons_close.gif c:\program files (x86)\AVG\AVG10\Icons\icons_safe.gif c:\program files (x86)\AVG\AVG10\Icons\icons_unknown.gif c:\program files (x86)\AVG\AVG10\Icons\icons_warning.gif c:\program files (x86)\AVG\AVG10\Icons\LS_Logo_Results.gif c:\program files (x86)\AVG\AVG10\Icons\safe.gif c:\program files (x86)\AVG\AVG10\Icons\safe12.png c:\program files (x86)\AVG\AVG10\Icons\unknown.gif c:\program files (x86)\AVG\AVG10\Icons\vrsn-secured-lsfo.gif c:\program files (x86)\AVG\AVG10\Icons\warning.gif c:\program files (x86)\AVG\AVG10\Icons\warning12.png c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\avgcslex.dll c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\driver\platform_VISTA\UniversalDD.sys c:\program files (x86)\AVG\AVG10\imsdk64.dll c:\program files (x86)\AVG\AVG10\js.dat c:\program files (x86)\AVG\AVG10\license_us.htm c:\program files (x86)\AVG\AVG10\lscanlog.cfg c:\program files (x86)\AVG\AVG10\mfaus.lns c:\program files (x86)\AVG\AVG10\mfavera.txt c:\program files (x86)\AVG\AVG10\mfaverx.txt c:\program files (x86)\AVG\AVG10\PCTuneup\AxBrowsers.dll c:\program files (x86)\AVG\AVG10\PCTuneup\DiskCleanerHelper.dll c:\program files (x86)\AVG\AVG10\PCTuneup\DiskDefragHelper.dll c:\program files (x86)\AVG\AVG10\PCTuneup\helper.dll c:\program files (x86)\AVG\AVG10\PCTuneup\localizer.dll c:\program files (x86)\AVG\AVG10\PCTuneup\MicroScanner.exe c:\program files (x86)\AVG\AVG10\PCTuneup\PerlRegExp.bpl c:\program files (x86)\AVG\AVG10\PCTuneup\RegistryCleanerHelper.dll c:\program files (x86)\AVG\AVG10\PCTuneup\RescueCenterHelper.dll c:\program files (x86)\AVG\AVG10\PCTuneup\rtl120.bpl c:\program files (x86)\AVG\AVG10\PCTuneup\vcl120.bpl c:\program files (x86)\AVG\AVG10\ph.dat c:\program files (x86)\AVG\AVG10\sb.dat c:\program files (x86)\AVG\AVG10\sb.dat.xcd c:\program files (x86)\AVG\AVG10\sb2.dat c:\program files (x86)\AVG\AVG10\sc.dat c:\program files (x86)\AVG\AVG10\sc.dat.xcd c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\23_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\26_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\27_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\29_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\38_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\39_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\40_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\41_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\42_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\43_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\44_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\45_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\46_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\48_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\49_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\50_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\56_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\57_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\58_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\59_sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\channels.dat c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome.manifest c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\26_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\27_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\29_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\38_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\39_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\40_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\41_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\42_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\43_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\44_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\45_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\46_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\48_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\49_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\50_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\56_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\57_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\58_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\59_config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\autocomplete-popup.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\config.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\contexthtml.xul c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\custom.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\26_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\27_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\29_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\38_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\41_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\42_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\43_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\44_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\45_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\46_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\49_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\50_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\56_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\58_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\59_tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\about.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bg_arr.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bg_body.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bg_main-heading.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bg_rule-overlay.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bg_rule.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bg_tab.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_AB.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_ABSearch.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_arrow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_bottom_shadow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirm.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmAVGSafe.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmEmail.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmFacebook.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmIco_fb.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmIco_notifier.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmIco_weather.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmTbr.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmWeather.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_egs.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_general.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_IDV1.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_IDV2.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_logo.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_protection.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_search.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_searchSearchBox.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_searchSearchBoxBaidu.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_searchSearchBoxBlank.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_SPupdate.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_SPupdateSearchBox.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_style.css c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_top_shadow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_update.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\deletehistory_processing.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_config.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifier.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierBackground.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierBullet.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierClose.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierDown.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierDownActive.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierDownDisabled.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierIco.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierNext.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierNextActive.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierNextDisabled.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierPrevious.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierPreviousActive.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierPreviousDisabled.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierScrollbar.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierSettings.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierUp.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierUpActive.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\emailchecker_notifierUpDisabled.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\Facebook_config.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\Facebook_error.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\facebook_logo.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\Facebook_notifier.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\Facebook_notifierIco.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\Facebook_status.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\facebook_style.css c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\facebook_textbox.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\Facebook_user.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBAccess.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBCalc.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBExcel.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBExplorer.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBMediaPlayer.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBNotepad.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBOutlook.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBOutlookExpress.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBPaint.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBPowerPoint.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBSkype.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBWord.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!backgroundGrey.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!backgroundRed.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!bullet.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!close.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoiDNES.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoRead.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoRSS.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoSimple.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoUnread.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!logo.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!settings.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!tabHilighted.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_advanced.css c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_advanced.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_bullet-1.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_config.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_simple.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_askdialog.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_background.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_checkboxdialog.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_closedialog.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_closedialog.htm.old c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_closedialog_bg1.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_closedialog_bg2.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icohelp.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icohelp.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoQuest.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoRisk.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoSafe.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoUnkn.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_loading.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_logo.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_main.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu1.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu2.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu3.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu4.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_style.css c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_arrow_gray.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_arrow_green.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_arrow_orange.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_arrow_red.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_arrow_yellow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_middle_gray.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_middle_green.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_middle_orange.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_middle_red.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_middle_yellow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_top_gray.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_top_green.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_top_orange.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_top_red.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_background_top_yellow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_blocked.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_bottom_gray.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_bottom_green.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_bottom_orange.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_bottom_red.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_bottom_yellow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_top_gray.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_top_green.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_top_orange.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_top_red.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_border_top_yellow.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_caution.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_dangerous.html c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_icons_blocked.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_icons_caution.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_icons_close.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_icons_safe.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_icons_unknown.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_icons_warning.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_LS_Logo_Results.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_questionable.html c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_risky.html c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_safe.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_safe.html c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_unknown.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_unknown.html c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_waiting.html c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\ssb_warning.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_button.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_button_hilight.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_buttonHilight.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_ie7footer.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_ie7header.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_poweredByBlank.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_poweredByYahoo.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\tbapi.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\toolbarprotector_window.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\updater_error.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\updater_ok.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\updater_processing.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\weather_bg.gif c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\weather_error.htm c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\weather_img.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\html\weather_x.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\htmlwindow.xul c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\imageButton.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\26_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\38_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\39_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\40_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\41_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\42_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\43_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\44_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\45_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\46_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\48_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\49_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\50_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\56_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\57_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\58_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\59_en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\en.ini c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\Languages\languages.cfg c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\libs\include.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\libs\include_lite.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\marquee.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\overlay.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\overlay.xul c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\content\searchProviders.xml c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\icons\default\htmlwindow.ico c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\38_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\38_spBaidu.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\39_spGeneralSearch.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\40_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\40_spYandex.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\41_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\41_spYandex.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\42_spGeneralSearch.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\43_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\43_spYandex.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\44_spGeneralSearch.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\45_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\45_spYandex.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\46_spGeneralSearch.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\48_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\48_spBaidu.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\49_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\49_spBaidu.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\50_searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\50_spBaidu.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\56_spYahoo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\57_spYahoo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\58_spYahoo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\59_spYahoo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\chevron.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\contexthtml.css c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\dragdrop.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\emailchecker_icoEmail.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\emailchecker_icoEmailNew.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\gripper.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoAbout.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoAVGInfo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoFacebook_facebook.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoFacebook_FriendReq.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoFacebook_messages.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoFacebook_pokes.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoGoButtonBG.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoHomepage.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoIdentityGuard.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoOptions.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoProtection.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoProtectionLimited.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSS.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSSBlue.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSSGray.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSSGreen.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoShieldButtonBG_D.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoShieldButtonBG_Q.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoShieldButtonBG_R.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoShieldButtonBG_S.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoShieldButtonBG_U.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoShieldButtonBG_W.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoTrash.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBAccess.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBCalc.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBExcel.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBExplorer.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBMediaPlayer.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBNotepad.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBOutlook.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBOutlookExpress.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBPaint.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBPowerPoint.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBSkype.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBWord.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoUpdate.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\icoWeather.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\logo.ico c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\logo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\overlay.css c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\rssreader_!icoRead.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\rssreader_!icoUnread.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\Search_provider_drop.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\searchProvider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\settings_icon.ico c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\slider.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spImages.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spLocal.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spSearch.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spShopping.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spVideo.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spWiki.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spYahooBG.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\spYahooBG_small.png c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\chrome\skin\toolbarprotector_icon.ico c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\autocomplete.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\avgapi.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\facebook.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils.xpt c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\notifications.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\sp.js c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgdatabaseversion.xpt c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgprogramversion.xpt c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgsearchratingsconfig.xpt c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.xpt c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgverdicts.xpt c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\install.rdf c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\xpfunc.dll c:\program files (x86)\AVG\AVG10\Toolbar\Firefox\sp.xml c:\program files (x86)\AVG\AVG10\Toolbar\IE8Lib.dll c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe c:\program files (x86)\AVG\AVG10\updatecomps.bak c:\users\Ratopia\AppData\Local\Temp\RtkBtMnt.exe c:\windows\system32\DRIVERS\AVGIDSDriver.Sys c:\windows\system32\DRIVERS\AVGIDSEH.Sys c:\windows\system32\DRIVERS\AVGIDSFilter.Sys c:\windows\system32\DRIVERS\avgldx64.sys c:\windows\system32\DRIVERS\avgmfx64.sys c:\windows\system32\DRIVERS\avgrkx64.sys c:\windows\system32\DRIVERS\avgtdia.sys . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Legacy_AVGIDSDRIVER ——-\Legacy_AVGIDSEH ——-\Legacy_AVGIDSFILTER ——-\Legacy_AVGLDX64 ——-\Legacy_AVGMFX64 ——-\Legacy_AVGRKX64 ——-\Legacy_AVGTDIA ——-\Service_AVG Security Toolbar Service ——-\Service_AVGIDSAgent ——-\Service_AVGIDSDriver ——-\Service_AVGIDSEH ——-\Service_AVGIDSFilter ——-\Service_Avgldx64 ——-\Service_Avgmfx64 ——-\Service_Avgrkx64 ——-\Service_Avgtdia ——-\Service_avgwd ——-\Service_COMSysApp . . ((((((((((((((((((((((((( Files Created from 2011-10-20 to 2011-11-20 ))))))))))))))))))))))))))))))) . . 2011-11-20 09:22 . 2011-11-20 09:22 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-20 04:38 . 2011-11-20 04:38 ——– d—–w- c:\program files (x86)\ESET 2011-11-20 03:38 . 2011-11-20 09:29 ——– d—–w- c:\users\Ratopia\AppData\Local\temp 2011-11-19 03:48 . 2011-11-19 03:48 ——– d—–w- c:\users\Ratopia\AppData\Local\Adobe 2011-11-18 23:50 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2E53EDC-3200-4832-BB11-50ED5E1FA059}\mpengine.dll 2011-11-18 02:59 . 2011-11-18 02:59 ——– d—–w- c:\users\Ratopia\AppData\Local\Acer Arcade Deluxe 2011-11-17 08:41 . 2011-11-17 08:41 388096 —-a-r- c:\users\Ratopia\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-08 22:55 . 2011-09-20 21:06 1426304 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-08 22:55 . 2011-10-17 11:41 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-11-08 22:55 . 2011-10-17 11:41 2409784 —-a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat 2011-11-08 22:55 . 2011-09-30 16:16 893440 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-08 22:55 . 2011-09-30 16:16 50688 —-a-w- c:\program files\Windows Mail\wabimp.dll 2011-11-08 22:55 . 2011-09-30 15:57 707584 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-10-29 03:35 . 2011-10-29 03:36 ——– d—–w- c:\users\Ratopia\AppData\Local\WeatherBug 2011-10-29 03:34 . 2011-10-29 03:34 ——– d—–w- c:\users\Ratopia\AppData\Roaming\WeatherBug 2011-10-29 03:34 . 2011-10-29 03:34 18944 —-a-r- c:\users\Ratopia\AppData\Roaming\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe 2011-10-29 03:33 . 2011-10-29 03:33 ——– d—–w- c:\users\Ratopia\AppData\Roaming\Fighters 2011-10-29 03:32 . 2011-10-29 04:18 ——– d—–w- c:\programdata\Fighters 2011-10-29 03:32 . 2011-10-29 03:32 ——– d—–w- c:\programdata\Oberon Media . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-30 22:05 . 2011-05-15 23:58 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-26 21:50 . 2011-09-25 03:42 88288 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2011-09-26 21:50 . 2011-09-25 03:42 123784 —-a-w- c:\windows\system32\drivers\avipbb.sys 2011-09-06 13:56 . 2011-10-13 21:39 2764288 —-a-w- c:\windows\system32\win32k.sys 2011-09-02 14:15 . 2011-10-13 21:39 1383424 —-a-w- c:\windows\system32\mshtml.tlb 2011-09-02 13:39 . 2011-10-13 21:39 1383424 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-08-31 22:00 . 2009-05-26 22:53 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-25 16:20 . 2011-10-13 21:38 735744 —-a-w- c:\windows\system32\UIAutomationCore.dll 2011-08-25 16:19 . 2011-10-13 21:38 332288 —-a-w- c:\windows\system32\oleacc.dll 2011-08-25 16:19 . 2011-10-13 21:38 847360 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-25 16:15 . 2011-10-13 21:38 555520 —-a-w- c:\windows\SysWow64\UIAutomationCore.dll 2011-08-25 16:14 . 2011-10-13 21:38 563712 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-25 16:14 . 2011-10-13 21:38 238080 —-a-w- c:\windows\SysWow64\oleacc.dll 2011-08-25 13:54 . 2011-10-13 21:38 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2011-08-25 13:31 . 2011-10-13 21:38 4096 —-a-w- c:\windows\SysWow64\oleaccrc.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-08 68856] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-09-12 781824] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "LManager"="c:\progra~2\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672] "ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 147456] "CLMLServer"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 167936] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "HostManager"="c:\program files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe" [2008-06-24 41824] "MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "Adobe Reader Speed Launcher"="c:\program files (x86)\Reader\Reader_sl.exe" [2011-06-08 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Info Center"="c:\program files (x86)\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 24216] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 135664] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-26 131072] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 135664] R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2011-08-05 306400] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768] S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-07-19 32240] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360] S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384] S2 CLHNService;CLHNService;c:\program files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-17 81504] S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576] S2 FreeAgentGoNext Service;Seagate Service;c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-26 189736] S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-26 45056] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x] S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys [x] S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . 2011-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808] "ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 481792] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 561200] "RtHDVCpl"="RAVCpl64.exe" [2008-09-18 6495264] "Skytel"="Skytel.exe" [2008-09-18 1833504] "PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1237288] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&s;=2&o;=vp64&d;=1208&m;=aspire_6930 mLocal Page = %SystemRoot%\system32\blank.htm uInternet Settings,ProxyOverride = IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Save video on Savevid.com - c:\program files (x86)\Savevid\redirect.htm TCP: DhcpNameServer = [removed] [removed] DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll FF - ProfilePath - c:\users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;= FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cbe35ad&v;=6.010.006.004&i;=23&tp;=ab&iy;=&ychte;=us&lng;=en-US&q;= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}] "ImagePath"="\??\c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\AOL\ACS\AOLAcsd.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Launch Manager\QtZgAcer.EXE c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe . ************************************************************************** . Completion time: 2011-11-20 03:45:38 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-20 09:45 ComboFix2.txt 2011-11-20 03:37 . Pre-Run: 72,581,894,144 bytes free Post-Run: 72,345,325,568 bytes free . - - End Of File - - 465398074F4023686B68C9B8E7466BC4
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\SearchquTb.dll 
    C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\searchqutb.js 
    C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.htm 
    C:\Program Files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.xul 
    C:\ProgramData\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res 
    C:\Users\All Users\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res 
    C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\[removed]\chrome\content\overlay.js 
    C:\Users\Ratopia\Desktop\Antivirus\VideoCodecPlugin.exe 
    C:\Users\Ratopia\Downloads\cnet_DeepBurner1_exe.exe 
    C:\Users\Ratopia\Downloads\winamp5581_full_emusic-7plus_en-us.exe 
    
    Folder::
    C:\Users\Ratopia\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\7841c717-10a04874
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Then let me know how things seem to be running now.
ComboFix 11-11-19.04 - Ratopia 11/20/2011 17:55:06.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4024.2630 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Ratopia\Desktop\CFScript.txt AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\searchqutb.js" "c:\program files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.htm" "c:\program files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.xul" "c:\program files (x86)\Windows Savevid MediaBar\ToolBar\SearchquTb.dll" "c:\programdata\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res" "c:\users\All Users\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res" "c:\users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\[removed]\chrome\content\overlay.js" "c:\users\Ratopia\Desktop\Antivirus\VideoCodecPlugin.exe" "c:\users\Ratopia\Downloads\cnet_DeepBurner1_exe.exe" "c:\users\Ratopia\Downloads\winamp5581_full_emusic-7plus_en-us.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\searchqutb.js c:\program files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.htm c:\program files (x86)\Windows Savevid MediaBar\ToolBar\chrome\content\toolbar.xul c:\program files (x86)\Windows Savevid MediaBar\ToolBar\SearchquTb.dll c:\programdata\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res c:\users\All Users\{E18E22CC-D778-4926-A9ED-F0A132BFBD3C}\SavevidSetupV2.res c:\users\Ratopia\AppData\Local\Temp\RtkBtMnt.exe c:\users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\[removed]\chrome\content\overlay.js c:\users\Ratopia\Desktop\Antivirus\VideoCodecPlugin.exe c:\users\Ratopia\Downloads\cnet_DeepBurner1_exe.exe c:\users\Ratopia\Downloads\winamp5581_full_emusic-7plus_en-us.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_COMSysApp . . ((((((((((((((((((((((((( Files Created from 2011-10-21 to 2011-11-21 ))))))))))))))))))))))))))))))) . . 2011-11-21 00:08 . 2011-11-21 00:14 ——– d—–w- c:\users\Ratopia\AppData\Local\temp 2011-11-19 03:48 . 2011-11-19 03:48 ——– d—–w- c:\users\Ratopia\AppData\Local\Adobe 2011-11-18 23:50 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2E53EDC-3200-4832-BB11-50ED5E1FA059}\mpengine.dll 2011-11-18 02:59 . 2011-11-18 02:59 ——– d—–w- c:\users\Ratopia\AppData\Local\Acer Arcade Deluxe 2011-11-17 08:41 . 2011-11-17 08:41 388096 —-a-r- c:\users\Ratopia\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-08 22:55 . 2011-09-20 21:06 1426304 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-08 22:55 . 2011-10-17 11:41 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-11-08 22:55 . 2011-10-17 11:41 2409784 —-a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat 2011-11-08 22:55 . 2011-09-30 16:16 893440 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-08 22:55 . 2011-09-30 16:16 50688 —-a-w- c:\program files\Windows Mail\wabimp.dll 2011-11-08 22:55 . 2011-09-30 15:57 707584 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-10-29 03:35 . 2011-10-29 03:36 ——– d—–w- c:\users\Ratopia\AppData\Local\WeatherBug 2011-10-29 03:34 . 2011-10-29 03:34 ——– d—–w- c:\users\Ratopia\AppData\Roaming\WeatherBug 2011-10-29 03:34 . 2011-10-29 03:34 18944 —-a-r- c:\users\Ratopia\AppData\Roaming\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe 2011-10-29 03:33 . 2011-10-29 03:33 ——– d—–w- c:\users\Ratopia\AppData\Roaming\Fighters 2011-10-29 03:32 . 2011-10-29 04:18 ——– d—–w- c:\programdata\Fighters 2011-10-29 03:32 . 2011-10-29 03:32 ——– d—–w- c:\programdata\Oberon Media . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-30 22:05 . 2011-05-15 23:58 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-26 21:50 . 2011-09-25 03:42 88288 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2011-09-26 21:50 . 2011-09-25 03:42 123784 —-a-w- c:\windows\system32\drivers\avipbb.sys 2011-09-06 13:56 . 2011-10-13 21:39 2764288 —-a-w- c:\windows\system32\win32k.sys 2011-09-02 14:15 . 2011-10-13 21:39 1383424 —-a-w- c:\windows\system32\mshtml.tlb 2011-09-02 13:39 . 2011-10-13 21:39 1383424 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-08-31 22:00 . 2009-05-26 22:53 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-25 16:20 . 2011-10-13 21:38 735744 —-a-w- c:\windows\system32\UIAutomationCore.dll 2011-08-25 16:19 . 2011-10-13 21:38 332288 —-a-w- c:\windows\system32\oleacc.dll 2011-08-25 16:19 . 2011-10-13 21:38 847360 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-25 16:15 . 2011-10-13 21:38 555520 —-a-w- c:\windows\SysWow64\UIAutomationCore.dll 2011-08-25 16:14 . 2011-10-13 21:38 563712 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-25 16:14 . 2011-10-13 21:38 238080 —-a-w- c:\windows\SysWow64\oleacc.dll 2011-08-25 13:54 . 2011-10-13 21:38 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2011-08-25 13:31 . 2011-10-13 21:38 4096 —-a-w- c:\windows\SysWow64\oleaccrc.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-08 68856] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-09-12 781824] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "LManager"="c:\progra~2\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672] "ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 147456] "CLMLServer"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 167936] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "HostManager"="c:\program files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe" [2008-06-24 41824] "MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "Adobe Reader Speed Launcher"="c:\program files (x86)\Reader\Reader_sl.exe" [2011-06-08 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Info Center"="c:\program files (x86)\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 24216] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 135664] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-26 131072] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 135664] R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2011-08-05 306400] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768] S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-07-19 32240] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360] S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384] S2 CLHNService;CLHNService;c:\program files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-17 81504] S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576] S2 FreeAgentGoNext Service;Seagate Service;c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-26 189736] S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-26 45056] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x] S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys [x] S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . 2011-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808] "ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 481792] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 561200] "RtHDVCpl"="RAVCpl64.exe" [2008-09-18 6495264] "Skytel"="Skytel.exe" [2008-09-18 1833504] "PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1237288] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930 mLocal Page = %SystemRoot%\system32\blank.htm uInternet Settings,ProxyOverride = IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Save video on Savevid.com - c:\program files (x86)\Savevid\redirect.htm TCP: DhcpNameServer = [removed] [removed] DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll FF - ProfilePath - c:\users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cbe35ad&v=6.010.006.004&i=23&tp=ab&iy=&ychte=us&lng=en-US&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}] "ImagePath"="\??\c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\AOL\ACS\AOLAcsd.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Launch Manager\QtZgAcer.EXE c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe . ************************************************************************** . Completion time: 2011-11-20 18:30:41 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-21 00:30 ComboFix2.txt 2011-11-20 09:45 ComboFix3.txt 2011-11-20 03:37 . Pre-Run: 72,287,358,976 bytes free Post-Run: 72,172,359,680 bytes free . - - End Of File - - DA126689C5F79E6E9B3068B360A20A05

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI