This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow data transfer rate [Closed]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Windows Xp
Asus F3JP
Firefox Browser

Loading up web pages and searching has all of a sudden slowed down dramatically. Using bookmarks i now often get server not found.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:53:20 AM, on 23/11/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17103)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\HPSIsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ASUS\PowerForPhone\PowerForPhone.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\Competition\My Documents\Downloads\HiJackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.asus.com/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: MediaBar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SearchCore for Browsers - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~1\SEARCH~1\SEARCH~1\BROWSE~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: MediaBar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\ASUS\PowerForPhone\PowerForPhone.exe
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 4] "C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Secunia PSI Tray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191532247943
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191532195505
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll APSHook.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O20 - Winlogon Notify: OneCard - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\WINDOWS\system32\HPSIsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files\Secunia\PSI\sua.exe

–
End of file - 12689 bytes
Hi TTGSC,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

============
NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.


Summary of the logs I need from you in your next post:
OTL.Txt and Extras.Txt
aswMBR log
OTL logfile created on: 24/11/2011 7:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Competition\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1023.20 Mb Total Physical Memory | 430.32 Mb Available Physical Memory | 42.06% Memory free
2.40 Gb Paging File | 1.49 Gb Available in Paging File | 61.91% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44.70 Gb Total Space | 26.28 Gb Free Space | 58.80% Space Free | Partition Type: FAT32
Drive D: | 27.94 Gb Total Space | 27.91 Gb Free Space | 99.89% Space Free | Partition Type: FAT32

Computer Name: TTGSC | User Name: Competition | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Competition\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\datamngrUI.exe (iMesh, Inc)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe (Apple Inc.)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\CFM\Cashflow7\Bin\CFM7.exe (Cashflow Manager Pty Ltd)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\HPSIsvc.exe (HP)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Wireless Console 2\wcourier.exe ()
PRC - C:\Program Files\Asus\WLAN Card Utilities\Center.exe (ASUSTeK COMPUTER INC.)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\Asus\PowerForPhone\PowerForPhone.exe ()
PRC - C:\Program Files\Asus\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
PRC - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe (Cognizance Corporation)
PRC - C:\WINDOWS\ATK0100\HControl.exe ()
PRC - C:\WINDOWS\ATK0100\ATKOSD.exe ()
PRC - C:\Program Files\Asus\Power4 Gear\BatteryLife.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe (Cyberlink Corp.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\hp1100su.dll ()
MOD - C:\WINDOWS\system32\HP1100LM.DLL ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1100GC.DLL ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe\9.0.242.0__89845dcd8080cc91\System.Data.SqlServerCe.dll ()
MOD - C:\Program Files\CFM\Cashflow7\Bin\CashflowEmail.dll ()
MOD - C:\Program Files\Wireless Console 2\wcourier.exe ()
MOD - C:\Program Files\Asus\WLAN Card Utilities\AsAuthen.dll ()
MOD - C:\Program Files\Asus\PowerForPhone\PowerForPhone.exe ()
MOD - C:\WINDOWS\ATK0100\HControl.exe ()
MOD - C:\WINDOWS\ATK0100\ATKOSD.exe ()
MOD - C:\WINDOWS\system32\LXPRMON.DLL ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCRPP5C.DLL ()
MOD - C:\WINDOWS\system32\TosBtHcrpAPI.dll ()
MOD - C:\WINDOWS\ATK0100\CMSSC.dll ()


========== Win32 Services (SafeList) ==========

SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (HPSIService) – C:\WINDOWS\system32\HPSIsvc.exe (HP)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\BIN\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (HP LaserJet Service) – C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (ASChannel) – c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll (Cognizance Corporation)
SRV - (lxcr_device) – C:\WINDOWS\System32\lxcrcoms.exe ( )
SRV - (ASWLSVC) – C:\WINDOWS\system32\ASWLSVC.exe ()


========== Driver Services (SafeList) ==========

DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (FileMonitor) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys ()
DRV - (UrlFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys (IObit.com)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (NETwLx32) Intel® – C:\WINDOWS\system32\drivers\NETwLx32.sys (Intel Corporation)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (mvusbews) – C:\WINDOWS\system32\drivers\mvusbews.sys (Marvell Semiconductor, Inc.)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (kqemu) – C:\WINDOWS\system32\drivers\kqemu.sys ()
DRV - (SynMini) – C:\WINDOWS\system32\drivers\SynMini.sys ()
DRV - (SynScan) – C:\WINDOWS\system32\drivers\SynScan.sys ()
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (ItSDisk) – C:\WINDOWS\system32\drivers\itsdisk.sys (Cognizance Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TosRfSnd) Bluetooth Audio Device (WDM) – C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)
DRV - (ipswuio) – C:\WINDOWS\system32\drivers\ipswuio.sys (Windows ® 2000 DDK provider)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (toshidpt) – C:\WINDOWS\system32\drivers\toshidpt.sys (TOSHIBA Corporation.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ATKACPI.sys ()
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (odysseyIM3) – C:\WINDOWS\system32\drivers\odysseyIM3.sys (Funk Software, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\system32\PCANDIS5.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (ASNDIS5) – C:\WINDOWS\system32\ASNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "iMesh Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "iMesh Web Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=685749"
FF - prefs.js..browser.search.selectedEngine: "iMesh Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..keyword.URL: "http://search.imesh.com/web?src=ffb&appid=20&systemid=1&sr=0&q="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Yahoo"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.imesh.com/web?src=ffb&appid=20&systemid=1&sr=0&q="

FF - HKLM\Software\MozillaPlugins\@abr.gov.au/KeyMgmtPlugin: C:\Program Files\ABR\Plug-In\bin\npAUSkeyPlugin.dll (Commonwealth Government of Australia)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/30 17:11:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010/08/29 09:40:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Competition\Application Data\Mozilla\Extensions
[2010/08/29 09:40:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Competition\Application Data\Mozilla\Firefox\Profiles\0fngczbi.default\extensions
[2011/05/04 10:59:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Competition\Application Data\Mozilla\Firefox\Profiles\0fngczbi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/22 20:35:26 | 000,000,000 | —D | M] (MediaBar) – C:\Documents and Settings\Competition\Application Data\Mozilla\Firefox\Profiles\0fngczbi.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0}
[2011/06/09 08:26:08 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/10 12:45:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/24 09:05:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\COMPETITION\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0FNGCZBI.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011/10/11 10:17:36 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/11/22 20:39:56 | 000,000,000 | —D | M] (No name found) – C:\PROGRAM FILES\SEARCHCORE FOR BROWSERS\SEARCHCORE FOR BROWSERS\FIREFOXEXTENSION
[2011/10/13 12:52:02 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/13 12:51:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/10/22 20:35:16 | 000,002,512 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml

O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - Reg Error: Value error. File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SearchCore for Browsers) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\BrowserConnection.dll (SearchCore for Browsers)
O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Infineon Technologies AG)
O3 - HKLM\..\Toolbar: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.EXE (ASYSTeK Computer INC.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\Asus\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CognizanceTS] c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASTSVCC.dll (Cognizance Corporation)
O4 - HKLM..\Run: [Control Center] C:\Program Files\Asus\WLAN Card Utilities\Center.exe (ASUSTeK COMPUTER INC.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\datamngrUI.exe (iMesh, Inc)
O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe ()
O4 - HKLM..\Run: [HPUsageTrackingLEDM] C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [PowerForPhone] C:\Program Files\Asus\PowerForPhone\PowerForPhone.exe ()
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe ()
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1191532247943 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1191532195505 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DE8FEEF-015B-40FC-8421-F05F32E9386A}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll) -C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\DATAMNGR.DLL (iMesh, Inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll) -C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\IEBHO.DLL (iMesh, Inc)
O20 - AppInit_DLLs: (APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\OneCard: DllName - (c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Competition\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Competition\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (nwprovau) -C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/03/21 14:08:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\Shell - "" = AutoRun
O33 - MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\Shell - "" = AutoRun
O33 - MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\Shell\AutoRun\command - "" = F:\SISetup.exe
O33 - MountPoints2\{dee612c5-6072-11df-816d-0019d2bd5c91}\Shell\AutoRun\command - "" = F:\CA-SCool-Cricket.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/24 18:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Competition\Desktop\index.php_files
[2011/11/22 20:39:54 | 000,000,000 | —D | C] – C:\Program Files\SearchCore for Browsers
[2011/11/22 20:39:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Game Booster
[2011/11/22 20:39:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Garmin
[2011/11/22 20:39:07 | 000,000,000 | —D | C] – C:\Program Files\etax2011
[2011/11/22 20:39:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Competition\Start Menu\Programs\e-tax 2011
[2011/11/22 20:39:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/22 20:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EPSON PRINT Image Framer
[2011/11/22 20:39:02 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/17 08:47:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Optus Mobile Broadband
[2011/11/17 08:45:24 | 000,000,000 | —D | C] – C:\Program Files\Optus Mobile Broadband
[2011/11/17 08:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DatacardService
[2006/02/21 05:14:44 | 001,183,744 | —- | C] ( ) – C:\WINDOWS\System32\LXCRSERV.DLL
[2006/02/21 05:06:06 | 000,421,888 | —- | C] ( ) – C:\WINDOWS\System32\lxcrcomm.dll
[2006/02/21 04:54:42 | 000,380,928 | —- | C] ( ) – C:\WINDOWS\System32\lxcrih.exe
[2006/02/21 04:54:30 | 000,536,576 | —- | C] ( ) – C:\WINDOWS\System32\LXCRLMPM.DLL
[2006/02/21 04:53:16 | 000,114,688 | —- | C] ( ) – C:\WINDOWS\System32\LXCRPPLC.DLL
[2006/02/21 04:53:08 | 000,495,616 | —- | C] ( ) – C:\WINDOWS\System32\LXCRCOMS.EXE
[2006/02/21 04:52:16 | 000,610,304 | —- | C] ( ) – C:\WINDOWS\System32\LXCRCOMC.DLL
[2006/02/21 04:51:22 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\LXCRPROX.DLL
[2006/02/21 04:45:16 | 000,995,328 | —- | C] ( ) – C:\WINDOWS\System32\LXCRUSB1.DLL
[2006/02/21 04:36:52 | 000,393,216 | —- | C] ( ) – C:\WINDOWS\System32\LXCRIESC.DLL
[2006/02/21 04:33:02 | 000,409,600 | —- | C] ( ) – C:\WINDOWS\System32\LXCRINPA.DLL
[1996/11/17 16:00:00 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\IMPLODE.DLL
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/24 18:19:22 | 000,080,712 | —- | M] () – C:\Documents and Settings\Competition\Desktop\index.php.htm
[2011/11/24 17:53:34 | 000,002,369 | —- | M] () – C:\Documents and Settings\Competition\Application Data\Microsoft\Internet Explorer\Quick Launch\Cashflow Manager 7.7.lnk
[2011/11/24 17:49:20 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/24 17:40:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/24 17:39:56 | 1072,975,872 | -HS- | M] () – C:\hiberfil.sys
[2011/11/24 17:10:48 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/23 15:30:58 | 000,001,852 | —- | M] () – C:\Documents and Settings\Competition\My Documents\Firefox Sync Key.html
[2011/11/23 15:25:14 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/11/23 15:08:02 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/11/23 11:45:50 | 000,001,408 | —- | M] () – C:\Documents and Settings\Competition\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator.lnk
[2011/11/17 08:47:14 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
[2011/11/11 14:19:40 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/06 18:20:10 | 000,056,532 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/10/30 13:47:36 | 000,002,012 | —- | M] () – C:\TTG-Entries-Broken Hill 2 Day Swimming Carnival-19Nov2011-001.ZIP
[2011/10/30 09:14:22 | 000,000,197 | —- | M] () – C:\Documents and Settings\Competition\My Documents\Local Disk ©.lnk
[2011/10/27 19:45:56 | 000,002,309 | —- | M] () – C:\Documents and Settings\Competition\Application Data\Microsoft\Internet Explorer\Quick Launch\TM 6.0.lnk
[2011/10/26 20:30:06 | 000,002,291 | —- | M] () – C:\Documents and Settings\Competition\Desktop\TM 6.0.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/24 18:19:17 | 000,080,712 | —- | C] () – C:\Documents and Settings\Competition\Desktop\index.php.htm
[2011/11/24 17:10:44 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/23 15:30:39 | 000,001,852 | —- | C] () – C:\Documents and Settings\Competition\My Documents\Firefox Sync Key.html
[2011/11/17 08:47:12 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
[2011/11/06 18:20:08 | 000,056,532 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/10/30 09:14:20 | 000,000,197 | —- | C] () – C:\Documents and Settings\Competition\My Documents\Local Disk ©.lnk
[2011/08/26 18:38:39 | 001,511,424 | —- | C] () – C:\WINDOWS\System32\HP1100SM.EXE
[2011/08/26 18:38:38 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\HP1100LM.DLL
[2011/07/01 11:35:51 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\mvusbews.dll
[2011/07/01 11:33:35 | 000,284,160 | —- | C] () – C:\WINDOWS\System32\mvhlewsi.DLL
[2011/07/01 11:33:30 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\HP1100SMs.dll
[2011/06/29 20:22:17 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/06/26 12:05:09 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2011/06/26 12:05:09 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2011/06/26 12:05:09 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2011/06/26 12:05:09 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2011/06/26 12:05:09 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2011/06/26 12:05:09 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2011/06/26 12:05:09 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2011/06/26 12:05:09 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2011/06/26 12:05:09 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2011/06/26 12:05:09 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2011/06/26 12:05:09 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2011/06/26 12:05:09 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2011/06/26 12:05:09 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2011/06/26 12:05:09 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2011/06/26 12:05:09 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2011/06/26 12:05:09 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2011/06/26 12:05:09 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2011/06/26 12:05:09 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2011/06/26 12:05:09 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2011/06/26 12:03:42 | 000,000,027 | —- | C] () – C:\WINDOWS\CDE RX650EC.ini
[2011/06/09 08:27:29 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/06/09 08:27:28 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/05/18 07:38:42 | 000,038,403 | —- | C] () – C:\Documents and Settings\Competition\Application Data\Comma Separated Values (Windows).ADR
[2010/08/29 09:39:34 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/10/10 13:37:34 | 000,157,361 | —- | C] () – C:\WINDOWS\hpoins27.dat.temp
[2009/10/10 13:37:33 | 000,000,932 | —- | C] () – C:\WINDOWS\hpomdl27.dat.temp
[2009/10/09 22:14:42 | 000,157,415 | —- | C] () – C:\WINDOWS\hpoins27.dat
[2009/10/09 22:14:42 | 000,000,932 | —- | C] () – C:\WINDOWS\hpomdl27.dat
[2009/09/24 11:54:22 | 000,084,644 | —- | C] () – C:\WINDOWS\System32\drivers\FwRad17.bin
[2009/09/19 15:48:40 | 000,038,442 | —- | C] () – C:\Documents and Settings\Competition\Application Data\Comma Separated Values (DOS).ADR
[2009/09/19 15:48:27 | 000,024,899 | —- | C] () – C:\Documents and Settings\Competition\Application Data\Comma Separated Values (DOS).CAL
[2009/05/13 10:28:44 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/05/13 10:28:44 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/04/01 10:48:16 | 000,053,478 | —- | C] () – C:\WINDOWS\mvtcpui.ini
[2008/10/15 17:18:52 | 000,000,255 | —- | C] () – C:\WINDOWS\lexstat.ini
[2008/08/23 17:44:37 | 000,159,827 | —- | C] () – C:\WINDOWS\System32\RemSvc.exe
[2008/08/23 17:44:36 | 000,537,600 | —- | C] () – C:\WINDOWS\System32\ASWL2K.exe
[2008/08/23 17:44:36 | 000,496,640 | —- | C] () – C:\WINDOWS\System32\ASWLSVC.exe
[2008/06/29 16:19:58 | 000,000,024 | —- | C] () – C:\WINDOWS\ATKPF.ini
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/15 09:44:08 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2008/04/10 20:30:18 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/03/01 11:55:12 | 000,076,800 | —- | C] () – C:\WINDOWS\System32\ExpP.dll
[2008/02/26 12:28:17 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2008/02/05 16:09:19 | 000,005,119 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ywasvxup.hvs
[2007/11/03 12:07:16 | 000,000,128 | —- | C] () – C:\WINDOWS\LIBENMP3.INI
[2007/11/03 12:07:16 | 000,000,075 | —- | C] () – C:\WINDOWS\LIBENACM.INI
[2007/11/03 12:07:16 | 000,000,048 | —- | C] () – C:\WINDOWS\LIBENVRS.INI
[2007/11/03 12:07:16 | 000,000,029 | —- | C] () – C:\WINDOWS\LIBENWMA.INI
[2007/11/03 12:01:09 | 000,001,758 | —- | C] () – C:\WINDOWS\smp3m45j.ini
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/09/02 09:26:58 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\LXPRMON.DLL
[2007/09/02 09:26:58 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXPMONUI.DLL
[2007/09/02 09:24:45 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\LXCRinst.dll
[2007/09/02 09:24:05 | 000,303,104 | R— | C] () – C:\WINDOWS\System32\lxcrcoin.dll
[2007/08/04 07:19:01 | 000,000,098 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2007/05/27 12:07:27 | 000,029,696 | —- | C] () – C:\Documents and Settings\Competition\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/21 20:37:57 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/05/11 09:45:33 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2007/05/11 09:23:56 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\ABF3JP.DAT
[2007/03/21 14:43:53 | 001,116,544 | R— | C] () – C:\WINDOWS\System32\drivers\SynMini.sys
[2007/03/21 14:43:53 | 000,498,688 | R— | C] () – C:\WINDOWS\System32\drivers\SynPin.sys
[2007/03/21 14:43:53 | 000,045,056 | R— | C] () – C:\WINDOWS\StkUnist.exe
[2007/03/21 14:43:53 | 000,028,800 | R— | C] () – C:\WINDOWS\System32\drivers\SynCamd.sys
[2007/03/21 14:43:53 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\SynSvc_.exe
[2007/03/21 14:43:53 | 000,014,848 | R— | C] () – C:\WINDOWS\System32\drivers\SynSam.sys
[2007/03/21 14:43:53 | 000,007,808 | R— | C] () – C:\WINDOWS\System32\drivers\SynScan.sys
[2007/03/21 14:30:51 | 000,987,136 | —- | C] () – C:\WINDOWS\System32\wcourier.exe
[2007/03/21 14:22:27 | 000,143,360 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/03/21 14:22:27 | 000,040,960 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/03/21 14:15:38 | 000,133,246 | R— | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2007/03/21 14:12:29 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2007/03/21 14:11:37 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2007/03/21 14:06:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2007/03/21 14:03:02 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/03/21 14:02:29 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/03/20 22:59:50 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/02/07 06:32:00 | 000,123,939 | —- | C] () – C:\WINDOWS\System32\drivers\kqemu.sys
[2006/01/02 21:16:32 | 000,000,010 | —- | C] () – C:\WINDOWS\System32\ABLKSR.ini
[2005/09/02 14:44:08 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:20 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2005/07/08 17:41:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxcrvs.dll
[2005/04/03 10:30:00 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\scardsyn.dll
[2005/02/17 10:07:48 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\ATKACPI.sys
[2004/08/20 15:18:51 | 000,007,424 | —- | C] () – C:\WINDOWS\System32\drivers\MMIOPORT.SYS
[2004/08/20 15:18:51 | 000,002,538 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/20 15:18:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/20 15:18:19 | 000,488,774 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/20 15:18:19 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/20 15:18:19 | 000,089,284 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/20 15:18:19 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/20 15:18:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/20 15:18:17 | 000,004,487 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/20 15:18:15 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/20 15:18:10 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/20 15:18:10 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/20 15:18:03 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/20 15:17:54 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/07/20 17:04:02 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TBTMonUI.dll
[1998/05/06 15:10:00 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\ODMA32.dll

========== LOP Check ==========

[2007/03/21 14:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Infineon
[2008/01/27 10:15:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/12/29 18:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/05/23 12:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/05/29 17:31:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/03 11:38:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Mender
[2011/06/09 08:26:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/06/26 12:08:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2011/07/08 10:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/10/17 13:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2011/10/22 19:38:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/10/22 19:38:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Premium
[2011/10/23 08:24:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/11/17 08:45:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DatacardService
[2011/11/17 08:47:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Optus Mobile Broadband
[2007/03/21 14:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\Infineon
[2007/05/13 11:36:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\Toshiba
[2009/09/10 16:59:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\Asus
[2009/09/10 18:05:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\Windows Desktop Search
[2009/09/10 18:08:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\Windows Search
[2011/05/19 16:54:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\MSNInstaller
[2011/05/31 08:44:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\ASUS Security Protect Manager
[2011/06/01 12:30:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\AUSkey
[2011/06/09 14:17:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\IObit
[2011/06/26 12:20:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\EPSON
[2011/10/11 10:18:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\SystemRequirementsLab
[2011/10/22 19:59:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\uTorrent
[2011/10/22 20:35:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\mediabarim
[2011/11/23 15:25:14 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/11/23 15:08:02 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 20:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/11/09 20:06:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 20:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/11/09 20:06:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 05:06:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 05:06:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 20:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/11/09 20:06:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 20:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/11/09 20:06:52 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 05:10:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 05:10:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 20:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 10:41:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 10:41:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 20:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 10:42:02 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 10:42:02 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 20:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 20:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 10:42:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 10:42:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2007/03/21 14:02:00 | 000,901,120 | —- | M] () – C:\WINDOWS\System32\config\system.sav
[2007/03/21 14:02:00 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2007/03/21 14:02:00 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav

< End of report >


OTL Extras logfile created on: 24/11/2011 7:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Competition\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1023.20 Mb Total Physical Memory | 430.32 Mb Available Physical Memory | 42.06% Memory free
2.40 Gb Paging File | 1.49 Gb Available in Paging File | 61.91% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44.70 Gb Total Space | 26.28 Gb Free Space | 58.80% Space Free | Partition Type: FAT32
Drive D: | 27.94 Gb Total Space | 27.91 Gb Free Space | 99.89% Space Free | Partition Type: FAT32

Computer Name: TTGSC | User Name: Competition | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"9100:TCP" = 9100:TCP:*:Enabled:Advanced TCP/IP Printer Port
"427:TCP" = 427:TCP:*:Enabled:Advanced TCP/IP SLP Port
"161:TCP" = 161:TCP:*:Enabled:Advanced TCP/IP SNMP Port

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" = C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe:*:Enabled:Windows Live Messenger
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\hp\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\hp\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
"C:\Program Files\hp\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\hp\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
"C:\Program Files\hp\Digital Imaging\bin\hposid01.exe" = C:\Program Files\hp\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\hp\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\hp\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\HP\HP LaserJet P1100 Series\wificonfig.exe" = C:\Program Files\HP\HP LaserJet P1100 Series\wificonfig.exe:*:Enabled:Advanced TCP/IP Port Installer – (Hewlett Packard)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0221176E-9BDE-4F51-91EA-406CED5B3D0F}" = Cashflow Manager 2004
"{083CBC43-57A9-4DC8-8BE7-AF9CB5899953}" = Cashflow Manager
"{0E448256-D515-4C3E-A5BE-0A7B76CED5D4}" = hppP1100P1560P1600SeriesLaserJetService
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}" = ATK Media
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{17E2F183-BAC4-4D01-BD7A-59F781E17EFA}" = REALTEK PCIE NIC Driver
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{1976B721-8F15-4B86-92D2-725364AF8CE0}" = AUSkey software 1.4.0.3
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = LifeFrame2
"{208232B9-98B0-40CD-96B5-1362534D3830}" = Cashflow Manager [removed]
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 29
"{2792F12C-3515-4D69-8083-B557AF35F06F}" = LightScribe [removed]
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2E5F8579-12A8-4169-A3EC-688EC7004A00}" = AuthenTec Fingerprint Sensor Minimum Install
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{3FE3D6A5-2F5E-4870-A3AC-D1D88E0B2797}" = Intel® PROSet/Wireless WiFi Software
"{4462AD13-F2AA-4CBD-9F95-293C38EED870}" = Power4 Gear
"{4859F8D6-D994-4927-93CF-BB0DAA814DDB}" = Cashflow Manager Gold 7.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}" = Microsoft SQL Server Native Client
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{57B15AD4-8C9D-4164-82BB-E33D8644E757}" = ASUS InstantFun
"{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2
"{65179FD8-04C0-40A7-87FC-007F2CD5BF1E}" = LogMeIn
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = ASUSDVD
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7736FD0A-9BF4-40F3-AF12-2E95D65D964F}" = TEAM MANAGER 5.0 for Swimming
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help
"{7CE480FF-5B49-490E-BC18-1C663ECC0B61}" = MEET MANAGER 2.0 for Swimming
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{853F464A-B2B8-404E-BA3E-B98FF6862C41}" = hppusgP1100P1560P1600Series
"{89DDBCD4-B326-4545-9A05-26C7B16C1DEB}" = PowerForPhone
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8F722FA9-B994-4C9B-B292-FD32D6206EDF}" = ASUS WLAN Card Utilities/Driver
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9650DF15-A909-4FE3-AE28-F1909356AD27}" = TEAM MANAGER 6.0 for Swimming
"{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = Asus MultiFrame
"{9D6D7811-43B3-463C-BC79-5D1755269989}" = Net4Switch
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AEC544CF-5D36-4F0A-86BD-DF3065258A5B}" = Fingerprint Sensor Minimum Install
"{AF1EA239-9F8A-475B-91BE-3DA009599D73}" = Acer My Start-up Screen
"{B59C861D-B9AC-4601-A304-668D9B7C244D}" = Cashflow Manager Gold 7.7
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B90450DF-E781-46FD-B1F1-0C86DA40E443}" = PIF DESIGNER
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C078C299-C2C2-4110-A6EF-8D5E66C228DA}" = e-tax 2011
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}" = System Requirements Lab for Intel
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows
"{D371F551-0DB9-4CEC-844B-4C90CE91EA0B}" = hppLaserJetService
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
"{D83899AB-9964-4CFC-A246-F1BD430A455F}" = ASUS Security Protect Manager
"{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software
"{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
"{DE659AC8-EEF0-4115-AA0C-6500D194FB10}" = Garmin Training Center v5
"{DE730F37-A198-4112-A3B6-97786F34354A}" = ECI Client v6.0
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E161E7E7-9875-4F7F-AFC7-72D40B45B5F3}" = ATI Catalyst Control Center
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200
"{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Defcon_is1" = Defcon v1.43
"Elasto Mania" = Elasto Mania
"EPSON Scanner" = EPSON Scan
"Game Booster_is1" = Game Booster
"HControl" = ATK0100 ACPI UTILITY
"HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"iMesh 1 MediaBar" = MediaBar
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"IObit Malware Fighter_is1" = IObit Malware Fighter
"Lexmark 2400 Series" = Lexmark 2400 Series
"M3" = Asus MiVo Messenger
"Magic ISO Maker v5.4 (build 0256)" = Magic ISO Maker v5.4 (build 0256)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Converter SA Edition" = Media Converter SA Edition 0.8
"Micro Flight" = Micro Flight
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"MSNINST" = MSN
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ProInst" = Intel PROSet Wireless
"PROR" = Microsoft Office Professional 2007
"SearchCore for Browsers" = SearchCore for Browsers
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"Shop for HP Supplies" = Shop for HP Supplies
"Smart Defrag 2_is1" = Smart Defrag 2
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"USB2.0 1.3M WebCam" = USB2.0 1.3M WebCam
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebRipper" = WebRipper 1.31
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 24/11/2011 5:02:49 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2721234

Error - 24/11/2011 5:02:51 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 24/11/2011 5:02:51 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2723188

Error - 24/11/2011 5:02:51 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2723188

Error - 24/11/2011 5:02:53 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 24/11/2011 5:02:53 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2725172

Error - 24/11/2011 5:02:53 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2725172

Error - 24/11/2011 5:02:55 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 24/11/2011 5:02:55 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2727125

Error - 24/11/2011 5:02:55 AM | Computer Name = TTGSC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2727125

[ ASUS Security Protect Manager Events ]
Error - 10/05/2007 10:47:48 PM | Computer Name = TTGSC | Source = AuthServer | ID = 100811779
Description = The system failed to authenticate the submitted user credentials. User:
Competition@TTGSC Client GUID: {Password} Error: 0xC516020B Client Host: localhost

Client
Address: 127.0.0.1 Authority: ASUS Server Host: localhost Protocol: HTTP

Error - 10/05/2007 10:48:05 PM | Computer Name = TTGSC | Source = AuthServer | ID = 100811779
Description = The system failed to authenticate the submitted user credentials. User:
Competition@TTGSC Client GUID: {Password} Error: 0xC516020B Client Host: localhost

Client
Address: 127.0.0.1 Authority: ASUS Server Host: localhost Protocol: HTTP

[ OSession Events ]
Error - 14/09/2009 4:29:32 AM | Computer Name = TTGSC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1389
seconds with 60 seconds of active time. This session ended with a crash.

Error - 13/06/2011 6:43:27 PM | Computer Name = TTGSC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 67942
seconds with 360 seconds of active time. This session ended with a crash.

Error - 26/06/2011 12:11:24 AM | Computer Name = TTGSC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 132
seconds with 120 seconds of active time. This session ended with a crash.

Error - 26/06/2011 12:18:20 AM | Computer Name = TTGSC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 107
seconds with 60 seconds of active time. This session ended with a crash.

Error - 26/06/2011 1:27:13 AM | Computer Name = TTGSC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 99
seconds with 60 seconds of active time. This session ended with a crash.

Error - 26/06/2011 3:30:34 AM | Computer Name = TTGSC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 107
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 20/11/2011 11:03:37 PM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7000
Description = The Optus Mobile Broadband. OUC service failed to start due to the
following error: %%1053

Error - 21/11/2011 2:02:13 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Optus Mobile Broadband.
OUC service to connect.

Error - 21/11/2011 2:02:13 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7000
Description = The Optus Mobile Broadband. OUC service failed to start due to the
following error: %%1053

Error - 21/11/2011 2:30:32 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Optus Mobile Broadband.
OUC service to connect.

Error - 21/11/2011 2:30:32 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7000
Description = The Optus Mobile Broadband. OUC service failed to start due to the
following error: %%1053

Error - 22/11/2011 5:49:13 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Optus Mobile Broadband.
OUC service to connect.

Error - 22/11/2011 5:49:13 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7000
Description = The Optus Mobile Broadband. OUC service failed to start due to the
following error: %%1053

Error - 22/11/2011 6:12:17 AM | Computer Name = TTGSC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
2147749155 (0x80040D23).

Error - 24/11/2011 2:42:53 AM | Computer Name = TTGSC | Source = DCOM | ID = 10010
Description = The server {2692A9D5-61DF-46D5-A5A1-A6CCA921D578} did not register
with DCOM within the required timeout.

Error - 24/11/2011 3:23:36 AM | Computer Name = TTGSC | Source = DCOM | ID = 10010
Description = The server {2692A9D5-61DF-46D5-A5A1-A6CCA921D578} did not register
with DCOM within the required timeout.


< End of report >


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-25 07:32:43
—————————–
07:32:43.562 OS Version: Windows 5.1.2600 Service Pack 3
07:32:43.562 Number of processors: 2 586 0xF06
07:32:43.562 ComputerName: TTGSC UserName:
07:32:44.109 Initialize success
19:34:36.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:34:36.015 Disk 0 Vendor: Hitachi_HTS541680J9SA00 SB2OC70P Size: 76319MB BusType: 3
19:34:38.046 Disk 0 MBR read successfully
19:34:38.046 Disk 0 MBR scan
19:34:38.046 Disk 0 Windows XP default MBR code
19:34:38.093 Disk 0 scanning sectors +156296385
19:34:38.296 Disk 0 scanning C:\WINDOWS\system32\drivers
19:34:56.453 Service scanning
19:35:00.843 Modules scanning
19:35:17.328 Disk 0 trace - called modules:
19:35:17.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
19:35:17.343 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8716fab8]
19:35:17.343 3 CLASSPNP.SYS[f753cfd7] -> nt!IofCallDriver -> \Device\00000080[0x871639e8]
19:35:17.343 5 ACPI.sys[f73b3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x870fd940]
19:35:17.343 Scan finished successfully
19:38:54.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Competition\My Documents\MBR.dat"
19:38:54.656 The log file has been saved successfully to "C:\Documents and Settings\Competition\My Documents\aswMBR.txt"
Hi TTGSC,

Sorry about the delay, but with Thanksgiving and family it made it kind of hard.



Is this a business/institution computer?

  • If it is, are you the domain administrator? If you are not, have you informed your domain administrator, (business manager, Systems Analyst, or Information Technology (IT) Specialist)?
  • I am asking this for several reasons:
  • There may be restrictions and modifications installed on such machines that could be damaged or altered by the actions we take to remove Malware.
  • Any infection could jump terminals in a computer network.
  • There may also be legal issues regarding any loss of business data that I do not wish to deal with.
  • Some people who come here use their computers for work, and the computers may contain the patient records of a physician or the financial records of an accountant's clients or credit card and bank account information of their employer's customers.
  • There may be tremendous risks and legal liability for such users for not fully securing the computer. We will not know this unless we ask. We do not want to be accidentally putting those we help in vulnerable positions for law suits.
  • Business factors outweigh technical factors in making the reformat and reinstall decision. Sometimes friends give missing CDs or lack of expertise as a reason for not doing a reformat and reinstall.
  • The cost of replacing missing Windows XP and MS Office CDs and getting an Microsoft Certified Systems Engineer to come in for 3 hours to do the reinstall and apply all the critical updates, is trivial compared with the potential cost of a multi-million dollar lawsuit for breach of trust if confidential client or patient information is disclosed.
  • In specific situations where highly confidential information about others is on the computer, and a backdoor virus or trojan is found, we are helping people more by identifying that they have a backdoor trojan which puts them in a particularly vulnerable situation and sending them to seek local professional help from a Microsoft Certified Systems Engineer or Certified Information Systems Security Professional or Global Information Assurance Certification Certified Security Expert or Certified Computing Professional or Internet Service Provider than we would be trying to fully resolve their problems long distance.
==============
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

Summary of the logs I need from you in your next post:
Answer to my question about the computer being a business/institution computer
CKScanner log
Not a business, local swimming club computer. CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.MN.11.QBLBNW —– EOF —–
Hi TTGSC,

Thank you for the log. :thumbup:


MediaBar:

iMesh <–File sharing in any form is dangerous, that file your downloading is from and unknown source and could contain malware.
You may want to think about uninstalling this.

IOBIT Products

  • We note you are using one or more products from IOBit (Advanced SystemCare 3).
  • IOBit has been accused by Malwarebytes of illegally using their intellectual property without permission.
  • Please see this for additional information on these allegations: http://www.malwarebytes.org/forums/index.php?showtopic=29681.
  • A thread in the IOBit’s forum responded to the accusations from MalwareBytes. It is noteworthy that several responses from users raising specific questions about IOBit’s response and finding it unsatisfactory were deleted and the thread was closed. The bottom line from IOBit was: “No hard proof shows that IObit stole the database of Malwarebytes.”
  • From what is said above, at least until the issues of possible database theft and spyware packaging is resolved, we do not recommend the use of IOBit products.
  • You can remove IOBit products by clicking on "Start" and then on "Control Panel" and then on "Add or Remove Programs".

Next


Please go to Start>Control Panel>Add Remove Programs. On the list you should find an entry for SearchCore for Browsers.
Click Remove and allow Windows to completely remove.Then reboot your computer to complete this part of the process.
===================
Next

Please go to one of the below sites to scan the following files:

Virus Total
jotti.org
Kaspersky Virus File Scanner


click on Browse, and upload the following file for analysis:

C:\WINDOWS\CDE RX650EC.ini
C:\WINDOWS\smp3m45j.ini
C:\WINDOWS\System32\ABF3JP.DAT


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
===================
Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\datamngrUI.exe (iMesh, Inc)
    PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
    PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
    PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
    SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
    SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
    DRV - (FileMonitor) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys ()
    DRV - (UrlFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys (IObit.com)
    DRV - (RegFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys (IObit.com)
    [2011/10/10 12:45:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
    File not found (No name found) – C:\DOCUMENTS AND SETTINGS\COMPETITION\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0FNGCZBI.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}
    [2011/11/22 20:39:56 | 000,000,000 | —D | M] (No name found) – C:\PROGRAM FILES\SEARCHCORE FOR BROWSERS\SEARCHCORE FOR BROWSERS\FIREFOXEXTENSION
    O2 - BHO: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - Reg Error: Value error. File not found
    O2 - BHO: (SearchCore for Browsers) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\BrowserConnection.dll (SearchCore for Browsers)
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\datamngrUI.exe (iMesh, Inc)
    O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
    O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
    O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll) -C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\DATAMNGR.DLL (iMesh, Inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll) -C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\IEBHO.DLL (iMesh, Inc)
    O33 - MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\Shell - "" = AutoRun
    O33 - MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\Shell - "" = AutoRun
    O33 - MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\Shell\AutoRun\command - "" = F:\SISetup.exe
    O33 - MountPoints2\{dee612c5-6072-11df-816d-0019d2bd5c91}\Shell\AutoRun\command - "" = F:\CA-SCool-Cricket.exe
    [2011/11/22 20:39:54 | 000,000,000 | —D | C] – C:\Program Files\SearchCore for Browsers
    [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2008/02/05 16:09:19 | 000,005,119 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ywasvxup.hvs
    [2011/06/09 08:26:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
    [2011/06/09 14:17:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\IObit
    [2011/10/22 19:59:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Competition\Application Data\uTorrent
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Summary of the logs I need from you in your next post:
virustotal log
OTL log
How is your computer running?
Have tried getting rid of imesh to no avail, its remains are still somewhere on this machine. - speed and connection is better than before we started. Jotti's malware scan - Nothing found All processes killed ========== OTL ========== No active process named datamngrUI.exe was found! No active process named ASCTray.exe was found! No active process named ASCService.exe was found! No active process named IMFsrv.exe was found! Service AdvancedSystemCareService stopped successfully! Service AdvancedSystemCareService deleted successfully! C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe moved successfully. Error: No service named IMFservice was found to stop! Service\Driver key IMFservice not found. File C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe not found. Error: No service named FileMonitor was found to stop! Service\Driver key FileMonitor not found. File C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys not found. Error: No service named UrlFilter was found to stop! Service\Driver key UrlFilter not found. File C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys not found. Error: No service named RegFilter was found to stop! Service\Driver key RegFilter not found. File C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys not found. Folder C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found. Folder C:\PROGRAM FILES\SEARCHCORE FOR BROWSERS\SEARCHCORE FOR BROWSERS\FIREFOXEXTENSION\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28387537-e3f9-4ed7-860c-11e69af4a8a0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}\ not found. File C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\BrowserConnection.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR not found. File C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\datamngrUI.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 4 deleted successfully. C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe moved successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Search the Web\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll deleted successfully. File pInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll) -C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\DATAMNGR.DLL not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll deleted successfully. File pInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll) -C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\IEBHO.DLL not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08c33b14-9be9-11e0-81c0-0019d2bd5c91}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c5c33f40-a385-11e0-81dd-0019d2bd5c91}\ not found. File F:\SISetup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dee612c5-6072-11df-816d-0019d2bd5c91}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{dee612c5-6072-11df-816d-0019d2bd5c91}\ not found. File F:\CA-SCool-Cricket.exe not found. Folder C:\Program Files\SearchCore for Browsers\ not found. C:\WINDOWS\System32\SET52.tmp deleted successfully. C:\WINDOWS\System32\SET57.tmp deleted successfully. C:\WINDOWS\System32\SETA6.tmp deleted successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\WINDOWS\002887_.tmp deleted successfully. C:\Documents and Settings\All Users\Application Data\ywasvxup.hvs moved successfully. C:\Documents and Settings\All Users\Application Data\IObit\Game Booster\Opt folder moved successfully. C:\Documents and Settings\All Users\Application Data\IObit\Game Booster folder moved successfully. C:\Documents and Settings\All Users\Application Data\IObit folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit\IObit Malware Fighter folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit\Smart Defrag 2 folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit\Advanced SystemCare V4\Log folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit\Advanced SystemCare V4\Backup folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit\Advanced SystemCare V4\PMonitor folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit\Advanced SystemCare V4 folder moved successfully. C:\Documents and Settings\Competition\Application Data\IObit folder moved successfully. C:\Documents and Settings\Competition\Application Data\uTorrent\ie folder moved successfully. C:\Documents and Settings\Competition\Application Data\uTorrent\dlimagecache folder moved successfully. C:\Documents and Settings\Competition\Application Data\uTorrent\apps folder moved successfully. C:\Documents and Settings\Competition\Application Data\uTorrent folder moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 81090865 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Competition ->Temp folder emptied: 69662335 bytes ->Temporary Internet Files folder emptied: 10204047 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 157265374 bytes ->Flash cache emptied: 2152 bytes User: LogMeInRemoteUser ->Temporary Internet Files folder emptied: 32768 bytes User: Treasurer ->Flash cache emptied: 0 bytes User: LogMeInRemoteUser.TTGSC ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1856779 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 52821116 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 6940711 bytes Total Files Cleaned = 362.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 11292011_175428 Files\Folders moved on Reboot… C:\Documents and Settings\Competition\Local Settings\Temporary Internet Files\Content.Word\~WRS{623DB5EA-BA77-48E6-AC2E-F500566DEFA5}.tmp moved successfully. C:\Documents and Settings\Competition\Local Settings\Temporary Internet Files\Content.Word\~WRS{67CB6FB0-5DAC-417C-AE4D-05EAEAA27F07}.tmp moved successfully. Registry entries deleted on Reboot…
Hi TTGSC,

Please run another scan of OTL for me please.

Double click OTL.exe to launch the programme.
Check the following.
Scan all users.
Standard Output.
Lop check.
Purity check.
Under Extra Registry section, select Use SafeList
Click the Run Scan button and wait for the scan to finish (usually about 10-15 mins).
When finished it will produce two logs.
OTL.txt (open on your desktop).
Extras.txt (minimised in your taskbar)
Please post me both logs.

Next

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    iMesh
    MediaBar
    :folderfind
    iMesh
    MediaBar
    :regfind
    iMesh
    MediaBar
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Summary of the logs I need from you in your next post:
OTL.txt
Extras.txt
SystemLook log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI