smiffy1972
Topic Starter
Hello
New to the forum,read a few posts on this and decided i would register and see if i could get some help removing it.
i have three logs from the programs advised
OTL
OTL logfile created on: 25/11/2011 09:32:11 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\smiffer\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 37.24% Memory free
4.00 Gb Paging File | 2.32 Gb Available in Paging File | 58.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 89.57 Gb Free Space | 38.46% Space Free | Partition Type: NTFS
Computer Name: SMIFFER-PC | User Name: smiffer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\smiffer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\js3250.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (IDMWFP) – C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:64bit: - (pwipf6) – C:\Windows\SysNative\drivers\pwipf6.sys (Privacyware/PWI, Inc.)
DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfmonm) – C:\Windows\SysNative\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TFsExDisk) – C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (cmuda3) – C:\Windows\SysNative\drivers\cmudax3.sys (C-Media Inc)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (FETNDIS) – C:\Windows\SysNative\drivers\fet6x64.sys (VIA Technologies, Inc. )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Almico Software)
DRV - (TFsExDisk) – C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 178.76.252.58:9090
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.8
FF - prefs.js..extensions.enabledItems: [removed]:2011.11.10
FF - prefs.js..extensions.enabledItems: [removed]:0.7.0
FF - prefs.js..extensions.enabledItems: {E4091D66-127C-11DB-903A-DE80D2EFDFE8}:[removed]
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {99079a25-328f-4bd4-be04-00955acaa0a7}:4.5.1.00
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\smiffer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\smiffer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3DF533F5-FB3C-4c4c-A1D7-99717F8C3038}: C:\Program Files (x86)\Webroot\Security\current\plugins\browserextension\ff_ptc\ [2011/07/27 08:24:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/11/16 16:12:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/09 19:05:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/09 19:05:51 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\smiffer\AppData\Roaming\IDM\idmmzcc5 [2011/06/18 11:15:00 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\smiffer\AppData\Roaming\IDM\idmmzcc5 [2011/06/18 11:15:00 | 000,000,000 | —D | M]
[2011/11/05 17:20:28 | 000,000,000 | —D | M] (No name found) – C:\Users\smiffer\AppData\Roaming\Mozilla\Extensions
[2011/11/24 15:43:48 | 000,000,000 | —D | M] (No name found) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions
[2011/09/03 08:37:19 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/07/27 08:24:42 | 000,000,000 | —D | M] (No name found) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda}
[2011/11/05 17:20:23 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/09/26 11:05:37 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/10/15 12:22:52 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/11/05 10:53:10 | 000,000,000 | —D | M] ("ImageHost Grabber") – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
[2011/10/12 13:02:06 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/09/03 08:37:20 | 000,000,000 | —D | M] (FB Chat Sidebar Disabler) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\[removed]
[2011/11/05 10:24:02 | 000,000,000 | —D | M] (Save Images) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\[removed]
[2011/11/23 16:14:04 | 000,000,000 | —D | M] (leethax.net extension) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\[removed]
[2011/11/05 17:20:17 | 000,002,519 | —- | M] () – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\searchplugins\SearchResults.xml
[2011/11/05 17:20:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/05 17:20:28 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/04/20 23:07:17 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/20 23:07:17 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/20 23:07:17 | 000,000,769 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/05 17:20:17 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml
[2011/04/20 23:07:17 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Veetle TV Player (Disabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Disabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\smiffer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Disabled) = C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Disabled) = default_plugin
CHR - Extension: AT_Porsche = C:\Users\smiffer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0\
CHR - Extension: AVG Safe Search = C:\Users\smiffer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
O1 HOSTS File: ([2011/06/11 10:09:10 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Webroot Browser Helper Object) - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\Program Files (x86)\Webroot\Security\Current\products\WISC\toolbar\LPBar.dll (Webroot Software, Inc.)
O2 - BHO: (WebrootBHO Class) - {D93EC24D-8741-4D41-B83D-A5793B998416} - C:\Program Files (x86)\Webroot\Security\Current\plugins\browserextension\WebrootBHO.dll (Webroot Software, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Webroot Toolbar) - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\Program Files (x86)\Webroot\Security\Current\products\WISC\toolbar\LPBar.dll (Webroot Software, Inc.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [TaskTray] File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000..\Run: [Spotify] C:\Users\smiffer\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{230AFB54-BFC1-408A-B94E-6A749E25B2AA}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{b3f37272-9a67-11e0-9b5d-00138fae1e4a}\Shell - "" = AutoRun
O33 - MountPoints2\{b3f37272-9a67-11e0-9b5d-00138fae1e4a}\Shell\AutoRun\command - "" = F:\OnSpcLCK.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\OnSpcLCK.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/25 09:24:06 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\smiffer\Desktop\OTL.exe
[2011/11/23 19:36:21 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Spotify
[2011/11/23 19:36:14 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\Spotify
[2011/11/22 16:47:06 | 000,000,000 | —D | C] – C:\Users\Public\Documents\MAGIX_Music_Maker_MX_Production_Suite_Download_Version
[2011/11/21 18:14:42 | 000,000,000 | —D | C] – C:\Users\Public\Documents\MAGIX_Music_Maker_MX_Premium_Download_Version
[2011/11/21 18:14:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2011/11/21 18:14:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\MAGIX
[2011/11/21 15:31:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect Uninstaller
[2011/11/21 15:31:35 | 000,000,000 | —D | C] – C:\Program Files\Perfect Uninstaller
[2011/11/16 18:04:23 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\New folder
[2011/11/16 17:05:39 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX_Music_Maker_17_Premium_Download_Version
[2011/11/16 16:32:19 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\content packs
[2011/11/14 19:08:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2011/11/14 18:35:41 | 000,000,000 | —D | C] – C:\ProgramData\Yellow Tools
[2011/11/13 12:08:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/11/13 12:07:57 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/11/12 17:45:41 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\Magix stuff
[2011/11/12 13:51:28 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX downloads
[2011/11/12 13:51:27 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX
[2011/11/12 13:50:33 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX_MusicEditor
[2011/11/12 13:50:16 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\MAGIX
[2011/11/12 13:47:03 | 000,000,000 | —D | C] – C:\ProgramData\MAGIX
[2011/11/12 13:46:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\MAGIX Services
[2011/11/09 18:27:40 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/09 18:27:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/09 18:27:23 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/09 18:27:23 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/11/09 18:18:19 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\smiffer\Desktop\aswMBR.exe
[2011/11/05 20:34:03 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\mkvtoolnix
[2011/11/05 20:31:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVtoolnix
[2011/11/05 20:31:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\MKVtoolnix
[2011/11/05 19:36:36 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\Malwarebytes
[2011/11/05 19:36:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/05 19:36:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/05 19:36:05 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/11/05 19:36:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/05 17:21:04 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Ilivid Player
[2011/11/05 17:20:17 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2011/11/05 17:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/11/02 17:42:27 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Facebook
[2011/10/31 17:01:03 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\AVG
[2011/10/31 16:59:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2011/10/30 15:23:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/10/30 15:21:54 | 000,000,000 | —D | C] – C:\fb57e5fc458dbc61f7497b1d
[2011/10/30 15:12:47 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Windows Live
[2011/10/30 15:12:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2011/10/27 14:22:14 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\New folder (2)
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/25 09:30:05 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/25 09:24:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\smiffer\Desktop\OTL.exe
[2011/11/25 09:09:58 | 110,680,446 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/11/25 09:03:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/25 09:03:48 | 1610,063,872 | -HS- | M] () – C:\hiberfil.sys
[2011/11/24 17:47:03 | 000,000,936 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/24 17:47:02 | 000,000,914 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/11/24 13:36:37 | 000,000,062 | —- | M] () – C:\Users\smiffer\Desktop\The Strokes – You Only Live Once.url
[2011/11/23 19:36:20 | 000,000,923 | —- | M] () – C:\Users\smiffer\Desktop\Spotify.lnk
[2011/11/23 18:30:01 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/11/23 17:21:48 | 000,390,226 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/11/23 15:19:02 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/23 15:19:02 | 000,628,414 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/23 15:19:02 | 000,110,598 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/23 15:14:59 | 004,898,472 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/22 21:39:05 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/22 21:39:04 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/22 16:49:11 | 000,001,175 | —- | M] () – C:\Users\Public\Desktop\MAGIX Music Maker MX Production Suite Download Version.lnk
[2011/11/21 20:31:18 | 000,002,413 | —- | M] () – C:\Users\smiffer\Desktop\Google Chrome.lnk
[2011/11/21 15:31:56 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/11/21 15:31:39 | 000,000,779 | —- | M] () – C:\Users\smiffer\Desktop\Perfect Uninstaller.lnk
[2011/11/17 17:19:24 | 000,002,744 | —- | M] () – C:\Users\smiffer\Desktop\fliss letter.rtf
[2011/11/16 16:12:14 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/11/13 12:17:36 | 000,025,216 | —- | M] () – C:\Users\smiffer\Documents\cc_20111113_121720.reg
[2011/11/13 12:08:01 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/09 18:27:29 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/09 18:18:25 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\smiffer\Desktop\aswMBR.exe
[2011/11/05 20:31:50 | 000,001,866 | —- | M] () – C:\Users\Public\Desktop\mkvmerge GUI.lnk
[2011/11/05 19:36:09 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/31 16:59:56 | 000,001,181 | —- | M] () – C:\Users\smiffer\Desktop\AVG PC Tuneup 2011.lnk
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/24 13:36:37 | 000,000,062 | —- | C] () – C:\Users\smiffer\Desktop\The Strokes – You Only Live Once.url
[2011/11/23 19:36:20 | 000,000,923 | —- | C] () – C:\Users\smiffer\Desktop\Spotify.lnk
[2011/11/23 19:36:19 | 000,000,909 | —- | C] () – C:\Users\smiffer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2011/11/22 16:49:11 | 000,001,175 | —- | C] () – C:\Users\Public\Desktop\MAGIX Music Maker MX Production Suite Download Version.lnk
[2011/11/21 15:31:56 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/11/21 15:31:39 | 000,000,779 | —- | C] () – C:\Users\smiffer\Desktop\Perfect Uninstaller.lnk
[2011/11/17 15:14:01 | 000,002,744 | —- | C] () – C:\Users\smiffer\Desktop\fliss letter.rtf
[2011/11/13 12:17:25 | 000,025,216 | —- | C] () – C:\Users\smiffer\Documents\cc_20111113_121720.reg
[2011/11/13 12:08:01 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/09 18:27:29 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/05 20:31:50 | 000,001,866 | —- | C] () – C:\Users\Public\Desktop\mkvmerge GUI.lnk
[2011/11/05 19:36:09 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/02 17:42:52 | 000,000,936 | —- | C] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/02 17:42:50 | 000,000,914 | —- | C] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/10/31 16:59:56 | 000,001,181 | —- | C] () – C:\Users\smiffer\Desktop\AVG PC Tuneup 2011.lnk
[2011/09/24 09:59:51 | 000,645,632 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/09/24 09:59:51 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/09/06 09:29:25 | 000,000,020 | —- | C] () – C:\Windows\SysWow64\AVGUARD.EXE
[2011/08/02 15:54:34 | 000,798,183 | —- | C] () – C:\Users\smiffer\AppData\Local\census.cache
[2011/08/02 15:51:33 | 000,094,707 | —- | C] () – C:\Users\smiffer\AppData\Local\ars.cache
[2011/08/02 15:41:37 | 000,000,036 | —- | C] () – C:\Users\smiffer\AppData\Local\housecall.guid.cache
[2011/07/27 14:07:43 | 000,017,408 | —- | C] () – C:\Users\smiffer\AppData\Local\WebpageIcons.db
[2011/05/27 10:45:50 | 000,030,424 | —- | C] () – C:\Windows\SysWow64\wrLZMA.dll
[2011/05/26 08:17:55 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\VmixP6.dll
[2011/05/26 08:17:53 | 000,000,188 | —- | C] () – C:\Windows\Cmicnfg3.ini.cfl
[2011/05/26 08:17:25 | 000,002,123 | —- | C] () – C:\Windows\Cmicnfg3.ini.cfg
[2011/05/26 08:17:25 | 000,000,154 | —- | C] () – C:\Windows\Cmicnfg3.ini.imi
[2011/05/26 08:17:24 | 000,002,641 | —- | C] () – C:\Windows\cmudax3.ini
[2011/05/24 20:25:13 | 000,007,598 | —- | C] () – C:\Users\smiffer\AppData\Local\Resmon.ResmonCfg
[2009/07/14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2007/10/25 16:26:10 | 000,005,632 | —- | C] () – C:\Windows\SysWow64\drivers\StarOpen.sys
[2007/04/27 10:43:58 | 000,120,200 | —- | C] () – C:\Windows\SysWow64\DLLDEV32i.dll
========== LOP Check ==========
[2011/10/31 17:01:34 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\AVG
[2011/10/22 09:24:12 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\AVG LiveKive
[2011/10/12 17:19:15 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\AVG2012
[2011/11/24 17:34:25 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\BitTorrent
[2011/06/10 11:28:46 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Blitware
[2011/11/24 17:34:23 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\DMCache
[2011/09/26 13:24:45 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\DVDVideoSoft
[2011/09/26 11:05:36 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/11/16 17:52:50 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\IDM
[2011/06/22 12:08:59 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Leadertech
[2011/11/16 17:18:59 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\MAGIX
[2011/11/05 20:34:03 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\mkvtoolnix
[2011/07/24 08:18:38 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\PCToolsFirewallPlus
[2011/05/25 22:59:53 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Samsung
[2011/07/24 08:18:23 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Spam Monitor
[2011/11/24 14:12:18 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Spotify
[2011/05/26 14:25:36 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Unity
[2011/11/02 15:29:54 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\UseNeXT
[2011/06/11 10:08:36 | 000,000,352 | —- | M] () – C:\Windows\Tasks\Driver Robot.job
[2011/11/24 17:47:02 | 000,000,914 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/11/24 17:47:03 | 000,000,936 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/09 17:02:50 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Users\smiffer\Documents\DriverGenius\Backup\Driver Backup 5-26-2011-83832\IDE Channel#1\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Users\smiffer\Documents\DriverGenius\Backup\Driver Backup 5-26-2011-83832\IDE Channel\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Users\smiffer\Documents\DriverGenius\Backup\Driver Backup 5-26-2011-83832\VIA Bus Master IDE Controller - 0571\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009/07/14 01:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 01:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2010/11/20 13:33:38 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 06:19:16 | 000,410,496 | —- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 06:41:26 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\SysNative\drivers\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 06:25:49 | 000,410,496 | —- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009/07/14 01:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\SysNative\netlogon.dll
[2009/07/14 01:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010/11/20 13:27:22 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 12:20:28 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 06:25:53 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011/03/11 06:19:21 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 06:41:34 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 13:33:48 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009/07/14 01:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 01:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\SysNative\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 12:21:04 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 13:27:25 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2011/04/18 17:04:54 | 000,030,424 | —- | M] () Unable to obtain MD5 – C:\Windows\system32\wrLZMA.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
========== Alternate Data Streams ==========
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >
EXTRAS
OTL Extras logfile created on: 25/11/2011 09:32:11 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\smiffer\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 37.24% Memory free
4.00 Gb Paging File | 2.32 Gb Available in Paging File | 58.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 89.57 Gb Free Space | 38.46% Space Free | Partition Type: NTFS
Computer Name: SMIFFER-PC | User Name: smiffer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3471145204-2569720348-4161465656-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00BCC0AD-0699-48B6-9900-3C53BBCD4DAC}" = AVG 2011
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{34C5BC15-2401-4980-9D95-ABD2CE8DD08A}" = AVG 2011
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{42B40185-E134-43FD-9381-69F92B317417}" = AVG 2012
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{5349A735-7482-406F-9FE4-3BB24608479D}" = AVG 2012
"{76202DBC-6FDA-47EA-B32F-F88512C03B18}" = AVG 2012
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{88381CA0-AB27-45B5-8BB8-E68987822AF8}" = AVG 2012
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B639AFD8-48E9-49BC-88DF-C5C55A471D94}" = AVG 2012
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"CCleaner" = CCleaner
"C-Media PCI Audio Driver" = C-Media PCI Audio Device
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Perfect Uninstaller_is1" = Perfect Uninstaller v6.3.3.9
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A36CF15-DF66-4756-9482-A9ABF3DDACE6}_is1" = Driver Robot
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3D472A59-BB35-4094-95A9-C982862DFAA5}" = MAGIX Music Maker MX Production Suite Download Version
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{59B6CD4A-C676-4B05-B8D6-73BA3AE159E5}" = MAGIX Music Maker MX Production Suite Download Version (Instrument package 2)
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C5F8503-55D2-4398-858C-362B7A7AF51C}" = Firebird SQL Server - MAGIX Edition
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{7E890D16-5CB9-4F18-BAA1-CCD0A543CAE5}" = MAGIX Music Maker MX Premium Download Version
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACD0467-0912-42A6-AD74-A9AA0B4D4B46}" = MAGIX Speed burnR (MSI)
"{8B287B75-DF8D-40C8-9620-8E4492C38EF1}" = Webroot Software
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{93DB912E-9D5C-46AD-AD32-91F31E528567}" = MAGIX Screenshare
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C2}" = WinZip 15.5
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E511636F-C3AA-46C4-9832-D1BE79D907EC}" = MAGIX Music Maker MX Production Suite Download Version (Instrument package 1)
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F5C96B8B-73C3-4198-A33B-9053EE5A46E7}" = MAGIX Music Maker MX Production Suite Trial (Sound package)
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG LiveKive" = AVG LiveKive
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"conduitEngine" = Conduit Engine
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"Free Studio_is1" = Free Studio version 5.2.1
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Internet Download Manager" = Internet Download Manager
"MAGIX_MSI_mm18pro" = MAGIX Music Maker MX Production Suite Download Version (Instrument package 2)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"MKVtoolnix" = MKVtoolnix 5.0.1
"Mozilla Firefox (3.6.24)" = Mozilla Firefox (3.6.24)
"Photo Stamp Remover Retail by minimaL_is1" = Photo Stamp Remover 1.2 Retail by minimaL
"Photo Stamp Remover_is1" = Photo Stamp Remover 4.2
"SopCast" = SopCast 3.4.0
"SpeedFan" = SpeedFan (remove only)
"UseNeXT_is1" = UseNeXT
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.11
"Webroot Software" = Webroot Software
"Windows Searchqu Toolbar" = Windows iLivid Toolbar
"Xvid Video Codec 1.3.2" = Xvid Video Codec
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3471145204-2569720348-4161465656-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 22/11/2011 15:45:50 | Computer Name = smiffer-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005
Error - 22/11/2011 16:45:50 | Computer Name = smiffer-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005
Error - 22/11/2011 17:38:43 | Computer Name = smiffer-PC | Source = EventSystem | ID = 4621
Description =
Error - 23/11/2011 11:14:07 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 23/11/2011 11:23:48 | Computer Name = smiffer-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Photoshop.exe, version: 12.1.0.0, time
stamp: 0x4d90d339 Faulting module name: nvoglv64.DLL, version: 8.17.12.5896, time
stamp: 0x4c378ebb Exception code: 0xc0000005 Fault offset: 0x00000000007506ce Faulting
process id: 0xa3c Faulting application start time: 0x01cca9f3cc8cad58 Faulting application
path: C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe Faulting
module path: C:\Windows\system32\nvoglv64.DLL Report Id: 23af23ed-15e7-11e1-8fee-00138fae1e4a
Error - 23/11/2011 11:37:47 | Computer Name = smiffer-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Photoshop.exe, version: 12.1.0.0, time
stamp: 0x4d90d339 Faulting module name: nvoglv64.DLL, version: 8.17.12.5896, time
stamp: 0x4c378ebb Exception code: 0xc0000005 Fault offset: 0x00000000007506ce Faulting
process id: 0x8b0 Faulting application start time: 0x01cca9f5d1663264 Faulting application
path: C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe Faulting
module path: C:\Windows\system32\nvoglv64.DLL Report Id: 17954afc-15e9-11e1-8fee-00138fae1e4a
Error - 24/11/2011 09:10:31 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 24/11/2011 14:49:17 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 25/11/2011 05:04:18 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 25/11/2011 05:28:22 | Computer Name = smiffer-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.31.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 8b0 Start Time:
01ccab540332e6e3 Termination Time: 4 Application Path: C:\Users\smiffer\Downloads\OTL.exe
Report
Id: c07e64a4-1747-11e1-8cc8-00138fae1e4a
[ Media Center Events ]
Error - 05/11/2011 04:44:54 | Computer Name = smiffer-PC | Source = MCUpdate | ID = 0
Description = 08:44:53 - Error connecting to the internet. 08:44:53 - Unable
to contact server..
[ System Events ]
Error - 24/11/2011 14:48:24 | Computer Name = smiffer-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description = Some processor performance power management features have been disabled
due to a known firmware problem. Check with the computer manufacturer for updated
firmware.
Error - 24/11/2011 14:48:59 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Webroot
Client Service service to connect.
Error - 24/11/2011 14:48:59 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Webroot Client Service service failed to start due to the following
error: %%1053
Error - 24/11/2011 14:49:06 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%2
Error - 24/11/2011 14:49:10 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%2
Error - 25/11/2011 05:03:35 | Computer Name = smiffer-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description = Some processor performance power management features have been disabled
due to a known firmware problem. Check with the computer manufacturer for updated
firmware.
Error - 25/11/2011 05:04:00 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Webroot
Client Service service to connect.
Error - 25/11/2011 05:04:00 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Webroot Client Service service failed to start due to the following
error: %%1053
Error - 25/11/2011 05:04:10 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%2
Error - 25/11/2011 05:04:16 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%2
< End of report >
HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:29:44, on 25/11/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\smiffer\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 178.76.252.58:9090
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI3C8A~1\Datamngr\BROWSE~1.DLL
O2 - BHO: Webroot Browser Helper Object - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
O2 - BHO: WRCommonBHO - {D93EC24D-8741-4D41-B83D-A5793B998416} - C:\Program Files (x86)\Webroot\Security\current\plugins\browserextension\WebrootBHO.dll
O3 - Toolbar: Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe
–
End of file - 8600 bytes
DDS
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 15:31:16.53 on 25/11/2011
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.2047.1172 [GMT 0:00]
.
AV: Webroot Internet Security Complete *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
AV: AVG Internet Security 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot Internet Security Complete *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\smiffer\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com/406
uInternet Settings,ProxyServer = 178.76.252.58:9090
uInternet Settings,ProxyOverride =
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
mWinlogon: Userinit=userinit.exe,
BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - C:\PROGRA~2\WI3C8A~1\Datamngr\BROWSE~1.DLL
BHO: Webroot Browser Helper Object: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
BHO: WebrootBHO Class: {d93ec24d-8741-4d41-b83d-a5793b998416} - C:\Program Files (x86)\Webroot\Security\current\plugins\browserextension\WebrootBHO.dll
TB: Webroot Toolbar: {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
mRun: [NPSStartup]
mRun: [TaskTray]
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll
BHO-X64: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
BHO-X64: IDM Helper - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: DataMngr: {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI3C8A~1\Datamngr\x64\BROWSE~1.DLL
AppInit_DLLs-X64: C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&sr;=0&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency.dll
FF - component: C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency3.5.dll
FF - component: C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency3.6.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Users\smiffer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\smiffer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\system32\Wat\npWatWeb.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: leethax.net extension: [removed] - %profile%\extensions\[removed]
FF - Ext: Save Images: [removed] - %profile%\extensions\[removed]
FF - Ext: ImageHost Grabber: {E4091D66-127C-11DB-903A-DE80D2EFDFE8} - %profile%\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
FF - Ext: SearchquToolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - %profile%\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-7-11 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2011-9-13 37456]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2011-10-7 283728]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-8-8 46672]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-7-11 375376]
R1 pwipf6;Privacyware Filter Driver;C:\Windows\System32\drivers\pwipf6.sys [2011-5-27 109864]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2011-5-24 83120]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
R2 IDMWFP;IDMWFP;C:\Windows\System32\drivers\idmwfp.sys [2011-6-9 153248]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-5 366152]
R2 ssfmonm;ssfmonm;C:\Windows\System32\drivers\ssfmonm.sys [2011-5-27 58480]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe [2011-5-27 3900032]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2011-7-11 120400]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2011-7-11 29776]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232]
R3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\drivers\LVUSBS64.sys [2007-5-9 50208]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-11-5 25416]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" –> C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [?]
S2 AntiVirService;Avira AntiVir Guard;"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" –> C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 WRConsumerService;Webroot Client Service;C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-5-27 3276136]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\System32\drivers\ssadadb.sys [2011-5-25 36328]
S3 lvpepf64;Volume Adapter;C:\Windows\System32\drivers\lv302a64.sys [2007-5-9 16032]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\System32\drivers\ssadbus.sys [2011-5-25 125416]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\System32\drivers\ssadmdfl.sys [2011-5-25 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\System32\drivers\ssadmdm.sys [2011-5-25 159208]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2011-5-25 16448]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-5-26 1255736]
.
=============== Created Last 30 ================
.
2011-11-23 19:36:21 ——– d—–w- C:\Users\smiffer\AppData\Local\Spotify
2011-11-23 19:36:14 ——– d—–w- C:\Users\smiffer\AppData\Roaming\Spotify
2011-11-21 18:14:04 ——– d—–w- C:\Program Files (x86)\MAGIX
2011-11-21 15:31:35 ——– d—–w- C:\Program Files\Perfect Uninstaller
2011-11-14 19:08:26 ——– d—–w- C:\Windows\System32\appmgmt
2011-11-14 18:35:41 ——– d—–w- C:\PROGRA~3\Yellow Tools
2011-11-13 12:07:57 ——– d—–w- C:\Program Files\CCleaner
2011-11-12 13:50:16 ——– d—–w- C:\Users\smiffer\AppData\Roaming\MAGIX
2011-11-12 13:47:03 ——– d—–w- C:\PROGRA~3\MAGIX
2011-11-12 13:46:59 ——– d—–w- C:\Program Files (x86)\Common Files\MAGIX Services
2011-11-09 18:27:40 ——– d—–w- C:\Users\smiffer\AppData\Roaming\SUPERAntiSpyware.com
2011-11-09 18:27:23 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-11-09 18:27:23 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-11-09 16:29:26 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 16:29:26 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 16:29:24 1897328 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 16:29:21 3141120 —-a-w- C:\Windows\System32\win32k.sys
2011-11-05 20:34:03 ——– d—–w- C:\Users\smiffer\AppData\Roaming\mkvtoolnix
2011-11-05 20:31:43 ——– d—–w- C:\Program Files (x86)\MKVtoolnix
2011-11-05 19:36:36 ——– d—–w- C:\Users\smiffer\AppData\Roaming\Malwarebytes
2011-11-05 19:36:08 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-11-05 19:36:05 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-11-05 19:36:05 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-05 17:21:04 ——– d—–w- C:\Users\smiffer\AppData\Local\Ilivid Player
2011-11-05 17:20:17 ——– d—–w- C:\PROGRA~3\boost_interprocess
2011-11-05 17:20:16 ——– d—–w- C:\Program Files (x86)\Windows iLivid Toolbar
2011-11-02 17:42:27 ——– d—–w- C:\Users\smiffer\AppData\Local\Facebook
2011-10-31 18:20:56 2301208 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-10-31 18:10:39 42776 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-10-31 18:10:33 710976 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-10-31 17:01:03 ——– d—–w- C:\Users\smiffer\AppData\Roaming\AVG
2011-10-30 15:21:54 ——– d—–w- C:\fb57e5fc458dbc61f7497b1d
2011-10-30 15:15:30 7450888 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\bef6a3b21cc97160a\bingbarsetup.exe
2011-10-30 15:15:09 15712 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ab19c4671cc971609\MeshBetaRemover.exe
2011-10-30 15:14:46 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\a4d261021cc971608\DSETUP.dll
2011-10-30 15:14:46 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\a4d261021cc971608\DXSETUP.exe
2011-10-30 15:14:46 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\a4d261021cc971608\dsetup32.dll
2011-10-30 15:14:33 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\9f4377911cc971607\DSETUP.dll
2011-10-30 15:14:33 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\9f4377911cc971607\DXSETUP.exe
2011-10-30 15:14:33 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\9f4377911cc971607\dsetup32.dll
2011-10-30 15:14:24 6260088 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\994ff8eb1cc971606\Silverlight.4.0.exe
2011-10-30 15:12:47 ——– d—–w- C:\Users\smiffer\AppData\Local\Windows Live
2011-10-30 15:12:40 ——– d—–w- C:\Program Files (x86)\Common Files\Windows Live
.
==================== Find3M ====================
.
2011-10-07 06:23:46 283728 —-a-w- C:\Windows\System32\drivers\avgldx64.sys
2011-10-06 16:15:33 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-13 05:30:08 37456 —-a-w- C:\Windows\System32\drivers\avgrkx64.sys
2011-09-06 09:29:25 20 —-a-w- C:\Windows\SysWow64\AVGUARD.EXE
2011-09-01 05:24:07 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 —-a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 15:32:54.29 ===============
thanks in advance for looking at my post.
New to the forum,read a few posts on this and decided i would register and see if i could get some help removing it.
i have three logs from the programs advised
OTL
OTL logfile created on: 25/11/2011 09:32:11 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\smiffer\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 37.24% Memory free
4.00 Gb Paging File | 2.32 Gb Available in Paging File | 58.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 89.57 Gb Free Space | 38.46% Space Free | Partition Type: NTFS
Computer Name: SMIFFER-PC | User Name: smiffer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\smiffer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\js3250.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (IDMWFP) – C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:64bit: - (pwipf6) – C:\Windows\SysNative\drivers\pwipf6.sys (Privacyware/PWI, Inc.)
DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfmonm) – C:\Windows\SysNative\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TFsExDisk) – C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (cmuda3) – C:\Windows\SysNative\drivers\cmudax3.sys (C-Media Inc)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (FETNDIS) – C:\Windows\SysNative\drivers\fet6x64.sys (VIA Technologies, Inc. )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Almico Software)
DRV - (TFsExDisk) – C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 178.76.252.58:9090
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.8
FF - prefs.js..extensions.enabledItems: [removed]:2011.11.10
FF - prefs.js..extensions.enabledItems: [removed]:0.7.0
FF - prefs.js..extensions.enabledItems: {E4091D66-127C-11DB-903A-DE80D2EFDFE8}:[removed]
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {99079a25-328f-4bd4-be04-00955acaa0a7}:4.5.1.00
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\smiffer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\smiffer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3DF533F5-FB3C-4c4c-A1D7-99717F8C3038}: C:\Program Files (x86)\Webroot\Security\current\plugins\browserextension\ff_ptc\ [2011/07/27 08:24:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/11/16 16:12:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/09 19:05:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/09 19:05:51 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\smiffer\AppData\Roaming\IDM\idmmzcc5 [2011/06/18 11:15:00 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\smiffer\AppData\Roaming\IDM\idmmzcc5 [2011/06/18 11:15:00 | 000,000,000 | —D | M]
[2011/11/05 17:20:28 | 000,000,000 | —D | M] (No name found) – C:\Users\smiffer\AppData\Roaming\Mozilla\Extensions
[2011/11/24 15:43:48 | 000,000,000 | —D | M] (No name found) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions
[2011/09/03 08:37:19 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/07/27 08:24:42 | 000,000,000 | —D | M] (No name found) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda}
[2011/11/05 17:20:23 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/09/26 11:05:37 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/10/15 12:22:52 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/11/05 10:53:10 | 000,000,000 | —D | M] ("ImageHost Grabber") – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
[2011/10/12 13:02:06 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/09/03 08:37:20 | 000,000,000 | —D | M] (FB Chat Sidebar Disabler) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\[removed]
[2011/11/05 10:24:02 | 000,000,000 | —D | M] (Save Images) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\[removed]
[2011/11/23 16:14:04 | 000,000,000 | —D | M] (leethax.net extension) – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\[removed]
[2011/11/05 17:20:17 | 000,002,519 | —- | M] () – C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\searchplugins\SearchResults.xml
[2011/11/05 17:20:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/05 17:20:28 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/04/20 23:07:17 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/20 23:07:17 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/20 23:07:17 | 000,000,769 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/05 17:20:17 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml
[2011/04/20 23:07:17 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\smiffer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Veetle TV Player (Disabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Disabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\smiffer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Disabled) = C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Disabled) = default_plugin
CHR - Extension: AT_Porsche = C:\Users\smiffer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0\
CHR - Extension: AVG Safe Search = C:\Users\smiffer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
O1 HOSTS File: ([2011/06/11 10:09:10 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Webroot Browser Helper Object) - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\Program Files (x86)\Webroot\Security\Current\products\WISC\toolbar\LPBar.dll (Webroot Software, Inc.)
O2 - BHO: (WebrootBHO Class) - {D93EC24D-8741-4D41-B83D-A5793B998416} - C:\Program Files (x86)\Webroot\Security\Current\plugins\browserextension\WebrootBHO.dll (Webroot Software, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Webroot Toolbar) - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\Program Files (x86)\Webroot\Security\Current\products\WISC\toolbar\LPBar.dll (Webroot Software, Inc.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [TaskTray] File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3471145204-2569720348-4161465656-1000..\Run: [Spotify] C:\Users\smiffer\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{230AFB54-BFC1-408A-B94E-6A749E25B2AA}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{b3f37272-9a67-11e0-9b5d-00138fae1e4a}\Shell - "" = AutoRun
O33 - MountPoints2\{b3f37272-9a67-11e0-9b5d-00138fae1e4a}\Shell\AutoRun\command - "" = F:\OnSpcLCK.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\OnSpcLCK.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/25 09:24:06 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\smiffer\Desktop\OTL.exe
[2011/11/23 19:36:21 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Spotify
[2011/11/23 19:36:14 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\Spotify
[2011/11/22 16:47:06 | 000,000,000 | —D | C] – C:\Users\Public\Documents\MAGIX_Music_Maker_MX_Production_Suite_Download_Version
[2011/11/21 18:14:42 | 000,000,000 | —D | C] – C:\Users\Public\Documents\MAGIX_Music_Maker_MX_Premium_Download_Version
[2011/11/21 18:14:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2011/11/21 18:14:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\MAGIX
[2011/11/21 15:31:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect Uninstaller
[2011/11/21 15:31:35 | 000,000,000 | —D | C] – C:\Program Files\Perfect Uninstaller
[2011/11/16 18:04:23 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\New folder
[2011/11/16 17:05:39 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX_Music_Maker_17_Premium_Download_Version
[2011/11/16 16:32:19 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\content packs
[2011/11/14 19:08:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2011/11/14 18:35:41 | 000,000,000 | —D | C] – C:\ProgramData\Yellow Tools
[2011/11/13 12:08:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/11/13 12:07:57 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/11/12 17:45:41 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\Magix stuff
[2011/11/12 13:51:28 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX downloads
[2011/11/12 13:51:27 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX
[2011/11/12 13:50:33 | 000,000,000 | —D | C] – C:\Users\smiffer\Documents\MAGIX_MusicEditor
[2011/11/12 13:50:16 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\MAGIX
[2011/11/12 13:47:03 | 000,000,000 | —D | C] – C:\ProgramData\MAGIX
[2011/11/12 13:46:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\MAGIX Services
[2011/11/09 18:27:40 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/09 18:27:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/09 18:27:23 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/09 18:27:23 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/11/09 18:18:19 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\smiffer\Desktop\aswMBR.exe
[2011/11/05 20:34:03 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\mkvtoolnix
[2011/11/05 20:31:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVtoolnix
[2011/11/05 20:31:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\MKVtoolnix
[2011/11/05 19:36:36 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\Malwarebytes
[2011/11/05 19:36:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/05 19:36:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/05 19:36:05 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/11/05 19:36:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/05 17:21:04 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Ilivid Player
[2011/11/05 17:20:17 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2011/11/05 17:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/11/02 17:42:27 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Facebook
[2011/10/31 17:01:03 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Roaming\AVG
[2011/10/31 16:59:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2011/10/30 15:23:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/10/30 15:21:54 | 000,000,000 | —D | C] – C:\fb57e5fc458dbc61f7497b1d
[2011/10/30 15:12:47 | 000,000,000 | —D | C] – C:\Users\smiffer\AppData\Local\Windows Live
[2011/10/30 15:12:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2011/10/27 14:22:14 | 000,000,000 | —D | C] – C:\Users\smiffer\Desktop\New folder (2)
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/25 09:30:05 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/25 09:24:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\smiffer\Desktop\OTL.exe
[2011/11/25 09:09:58 | 110,680,446 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/11/25 09:03:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/25 09:03:48 | 1610,063,872 | -HS- | M] () – C:\hiberfil.sys
[2011/11/24 17:47:03 | 000,000,936 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/24 17:47:02 | 000,000,914 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/11/24 13:36:37 | 000,000,062 | —- | M] () – C:\Users\smiffer\Desktop\The Strokes – You Only Live Once.url
[2011/11/23 19:36:20 | 000,000,923 | —- | M] () – C:\Users\smiffer\Desktop\Spotify.lnk
[2011/11/23 18:30:01 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/11/23 17:21:48 | 000,390,226 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/11/23 15:19:02 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/23 15:19:02 | 000,628,414 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/23 15:19:02 | 000,110,598 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/23 15:14:59 | 004,898,472 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/22 21:39:05 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/22 21:39:04 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/22 16:49:11 | 000,001,175 | —- | M] () – C:\Users\Public\Desktop\MAGIX Music Maker MX Production Suite Download Version.lnk
[2011/11/21 20:31:18 | 000,002,413 | —- | M] () – C:\Users\smiffer\Desktop\Google Chrome.lnk
[2011/11/21 15:31:56 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/11/21 15:31:39 | 000,000,779 | —- | M] () – C:\Users\smiffer\Desktop\Perfect Uninstaller.lnk
[2011/11/17 17:19:24 | 000,002,744 | —- | M] () – C:\Users\smiffer\Desktop\fliss letter.rtf
[2011/11/16 16:12:14 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/11/13 12:17:36 | 000,025,216 | —- | M] () – C:\Users\smiffer\Documents\cc_20111113_121720.reg
[2011/11/13 12:08:01 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/09 18:27:29 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/09 18:18:25 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\smiffer\Desktop\aswMBR.exe
[2011/11/05 20:31:50 | 000,001,866 | —- | M] () – C:\Users\Public\Desktop\mkvmerge GUI.lnk
[2011/11/05 19:36:09 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/31 16:59:56 | 000,001,181 | —- | M] () – C:\Users\smiffer\Desktop\AVG PC Tuneup 2011.lnk
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/24 13:36:37 | 000,000,062 | —- | C] () – C:\Users\smiffer\Desktop\The Strokes – You Only Live Once.url
[2011/11/23 19:36:20 | 000,000,923 | —- | C] () – C:\Users\smiffer\Desktop\Spotify.lnk
[2011/11/23 19:36:19 | 000,000,909 | —- | C] () – C:\Users\smiffer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2011/11/22 16:49:11 | 000,001,175 | —- | C] () – C:\Users\Public\Desktop\MAGIX Music Maker MX Production Suite Download Version.lnk
[2011/11/21 15:31:56 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/11/21 15:31:39 | 000,000,779 | —- | C] () – C:\Users\smiffer\Desktop\Perfect Uninstaller.lnk
[2011/11/17 15:14:01 | 000,002,744 | —- | C] () – C:\Users\smiffer\Desktop\fliss letter.rtf
[2011/11/13 12:17:25 | 000,025,216 | —- | C] () – C:\Users\smiffer\Documents\cc_20111113_121720.reg
[2011/11/13 12:08:01 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/09 18:27:29 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/05 20:31:50 | 000,001,866 | —- | C] () – C:\Users\Public\Desktop\mkvmerge GUI.lnk
[2011/11/05 19:36:09 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/02 17:42:52 | 000,000,936 | —- | C] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/02 17:42:50 | 000,000,914 | —- | C] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/10/31 16:59:56 | 000,001,181 | —- | C] () – C:\Users\smiffer\Desktop\AVG PC Tuneup 2011.lnk
[2011/09/24 09:59:51 | 000,645,632 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/09/24 09:59:51 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/09/06 09:29:25 | 000,000,020 | —- | C] () – C:\Windows\SysWow64\AVGUARD.EXE
[2011/08/02 15:54:34 | 000,798,183 | —- | C] () – C:\Users\smiffer\AppData\Local\census.cache
[2011/08/02 15:51:33 | 000,094,707 | —- | C] () – C:\Users\smiffer\AppData\Local\ars.cache
[2011/08/02 15:41:37 | 000,000,036 | —- | C] () – C:\Users\smiffer\AppData\Local\housecall.guid.cache
[2011/07/27 14:07:43 | 000,017,408 | —- | C] () – C:\Users\smiffer\AppData\Local\WebpageIcons.db
[2011/05/27 10:45:50 | 000,030,424 | —- | C] () – C:\Windows\SysWow64\wrLZMA.dll
[2011/05/26 08:17:55 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\VmixP6.dll
[2011/05/26 08:17:53 | 000,000,188 | —- | C] () – C:\Windows\Cmicnfg3.ini.cfl
[2011/05/26 08:17:25 | 000,002,123 | —- | C] () – C:\Windows\Cmicnfg3.ini.cfg
[2011/05/26 08:17:25 | 000,000,154 | —- | C] () – C:\Windows\Cmicnfg3.ini.imi
[2011/05/26 08:17:24 | 000,002,641 | —- | C] () – C:\Windows\cmudax3.ini
[2011/05/24 20:25:13 | 000,007,598 | —- | C] () – C:\Users\smiffer\AppData\Local\Resmon.ResmonCfg
[2009/07/14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2007/10/25 16:26:10 | 000,005,632 | —- | C] () – C:\Windows\SysWow64\drivers\StarOpen.sys
[2007/04/27 10:43:58 | 000,120,200 | —- | C] () – C:\Windows\SysWow64\DLLDEV32i.dll
========== LOP Check ==========
[2011/10/31 17:01:34 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\AVG
[2011/10/22 09:24:12 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\AVG LiveKive
[2011/10/12 17:19:15 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\AVG2012
[2011/11/24 17:34:25 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\BitTorrent
[2011/06/10 11:28:46 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Blitware
[2011/11/24 17:34:23 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\DMCache
[2011/09/26 13:24:45 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\DVDVideoSoft
[2011/09/26 11:05:36 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/11/16 17:52:50 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\IDM
[2011/06/22 12:08:59 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Leadertech
[2011/11/16 17:18:59 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\MAGIX
[2011/11/05 20:34:03 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\mkvtoolnix
[2011/07/24 08:18:38 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\PCToolsFirewallPlus
[2011/05/25 22:59:53 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Samsung
[2011/07/24 08:18:23 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Spam Monitor
[2011/11/24 14:12:18 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Spotify
[2011/05/26 14:25:36 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\Unity
[2011/11/02 15:29:54 | 000,000,000 | —D | M] – C:\Users\smiffer\AppData\Roaming\UseNeXT
[2011/06/11 10:08:36 | 000,000,352 | —- | M] () – C:\Windows\Tasks\Driver Robot.job
[2011/11/24 17:47:02 | 000,000,914 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000Core.job
[2011/11/24 17:47:03 | 000,000,936 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3471145204-2569720348-4161465656-1000UA.job
[2011/11/09 17:02:50 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Users\smiffer\Documents\DriverGenius\Backup\Driver Backup 5-26-2011-83832\IDE Channel#1\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Users\smiffer\Documents\DriverGenius\Backup\Driver Backup 5-26-2011-83832\IDE Channel\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Users\smiffer\Documents\DriverGenius\Backup\Driver Backup 5-26-2011-83832\VIA Bus Master IDE Controller - 0571\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009/07/14 01:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 01:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2010/11/20 13:33:38 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 06:19:16 | 000,410,496 | —- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 06:41:26 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\SysNative\drivers\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 06:25:49 | 000,410,496 | —- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009/07/14 01:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\SysNative\netlogon.dll
[2009/07/14 01:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010/11/20 13:27:22 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 12:20:28 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 06:25:53 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011/03/11 06:19:21 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 06:41:34 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 13:33:48 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009/07/14 01:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 01:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\SysNative\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 12:21:04 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 13:27:25 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2011/04/18 17:04:54 | 000,030,424 | —- | M] () Unable to obtain MD5 – C:\Windows\system32\wrLZMA.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
========== Alternate Data Streams ==========
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >
EXTRAS
OTL Extras logfile created on: 25/11/2011 09:32:11 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\smiffer\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 37.24% Memory free
4.00 Gb Paging File | 2.32 Gb Available in Paging File | 58.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 89.57 Gb Free Space | 38.46% Space Free | Partition Type: NTFS
Computer Name: SMIFFER-PC | User Name: smiffer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3471145204-2569720348-4161465656-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00BCC0AD-0699-48B6-9900-3C53BBCD4DAC}" = AVG 2011
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{34C5BC15-2401-4980-9D95-ABD2CE8DD08A}" = AVG 2011
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{42B40185-E134-43FD-9381-69F92B317417}" = AVG 2012
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{5349A735-7482-406F-9FE4-3BB24608479D}" = AVG 2012
"{76202DBC-6FDA-47EA-B32F-F88512C03B18}" = AVG 2012
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{88381CA0-AB27-45B5-8BB8-E68987822AF8}" = AVG 2012
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B639AFD8-48E9-49BC-88DF-C5C55A471D94}" = AVG 2012
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"CCleaner" = CCleaner
"C-Media PCI Audio Driver" = C-Media PCI Audio Device
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Perfect Uninstaller_is1" = Perfect Uninstaller v6.3.3.9
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A36CF15-DF66-4756-9482-A9ABF3DDACE6}_is1" = Driver Robot
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3D472A59-BB35-4094-95A9-C982862DFAA5}" = MAGIX Music Maker MX Production Suite Download Version
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{59B6CD4A-C676-4B05-B8D6-73BA3AE159E5}" = MAGIX Music Maker MX Production Suite Download Version (Instrument package 2)
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C5F8503-55D2-4398-858C-362B7A7AF51C}" = Firebird SQL Server - MAGIX Edition
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{7E890D16-5CB9-4F18-BAA1-CCD0A543CAE5}" = MAGIX Music Maker MX Premium Download Version
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACD0467-0912-42A6-AD74-A9AA0B4D4B46}" = MAGIX Speed burnR (MSI)
"{8B287B75-DF8D-40C8-9620-8E4492C38EF1}" = Webroot Software
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{93DB912E-9D5C-46AD-AD32-91F31E528567}" = MAGIX Screenshare
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C2}" = WinZip 15.5
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E511636F-C3AA-46C4-9832-D1BE79D907EC}" = MAGIX Music Maker MX Production Suite Download Version (Instrument package 1)
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F5C96B8B-73C3-4198-A33B-9053EE5A46E7}" = MAGIX Music Maker MX Production Suite Trial (Sound package)
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG LiveKive" = AVG LiveKive
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"conduitEngine" = Conduit Engine
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"Free Studio_is1" = Free Studio version 5.2.1
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Internet Download Manager" = Internet Download Manager
"MAGIX_MSI_mm18pro" = MAGIX Music Maker MX Production Suite Download Version (Instrument package 2)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"MKVtoolnix" = MKVtoolnix 5.0.1
"Mozilla Firefox (3.6.24)" = Mozilla Firefox (3.6.24)
"Photo Stamp Remover Retail by minimaL_is1" = Photo Stamp Remover 1.2 Retail by minimaL
"Photo Stamp Remover_is1" = Photo Stamp Remover 4.2
"SopCast" = SopCast 3.4.0
"SpeedFan" = SpeedFan (remove only)
"UseNeXT_is1" = UseNeXT
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.11
"Webroot Software" = Webroot Software
"Windows Searchqu Toolbar" = Windows iLivid Toolbar
"Xvid Video Codec 1.3.2" = Xvid Video Codec
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3471145204-2569720348-4161465656-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 22/11/2011 15:45:50 | Computer Name = smiffer-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005
Error - 22/11/2011 16:45:50 | Computer Name = smiffer-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005
Error - 22/11/2011 17:38:43 | Computer Name = smiffer-PC | Source = EventSystem | ID = 4621
Description =
Error - 23/11/2011 11:14:07 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 23/11/2011 11:23:48 | Computer Name = smiffer-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Photoshop.exe, version: 12.1.0.0, time
stamp: 0x4d90d339 Faulting module name: nvoglv64.DLL, version: 8.17.12.5896, time
stamp: 0x4c378ebb Exception code: 0xc0000005 Fault offset: 0x00000000007506ce Faulting
process id: 0xa3c Faulting application start time: 0x01cca9f3cc8cad58 Faulting application
path: C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe Faulting
module path: C:\Windows\system32\nvoglv64.DLL Report Id: 23af23ed-15e7-11e1-8fee-00138fae1e4a
Error - 23/11/2011 11:37:47 | Computer Name = smiffer-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Photoshop.exe, version: 12.1.0.0, time
stamp: 0x4d90d339 Faulting module name: nvoglv64.DLL, version: 8.17.12.5896, time
stamp: 0x4c378ebb Exception code: 0xc0000005 Fault offset: 0x00000000007506ce Faulting
process id: 0x8b0 Faulting application start time: 0x01cca9f5d1663264 Faulting application
path: C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe Faulting
module path: C:\Windows\system32\nvoglv64.DLL Report Id: 17954afc-15e9-11e1-8fee-00138fae1e4a
Error - 24/11/2011 09:10:31 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 24/11/2011 14:49:17 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 25/11/2011 05:04:18 | Computer Name = smiffer-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 25/11/2011 05:28:22 | Computer Name = smiffer-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.31.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 8b0 Start Time:
01ccab540332e6e3 Termination Time: 4 Application Path: C:\Users\smiffer\Downloads\OTL.exe
Report
Id: c07e64a4-1747-11e1-8cc8-00138fae1e4a
[ Media Center Events ]
Error - 05/11/2011 04:44:54 | Computer Name = smiffer-PC | Source = MCUpdate | ID = 0
Description = 08:44:53 - Error connecting to the internet. 08:44:53 - Unable
to contact server..
[ System Events ]
Error - 24/11/2011 14:48:24 | Computer Name = smiffer-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description = Some processor performance power management features have been disabled
due to a known firmware problem. Check with the computer manufacturer for updated
firmware.
Error - 24/11/2011 14:48:59 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Webroot
Client Service service to connect.
Error - 24/11/2011 14:48:59 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Webroot Client Service service failed to start due to the following
error: %%1053
Error - 24/11/2011 14:49:06 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%2
Error - 24/11/2011 14:49:10 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%2
Error - 25/11/2011 05:03:35 | Computer Name = smiffer-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description = Some processor performance power management features have been disabled
due to a known firmware problem. Check with the computer manufacturer for updated
firmware.
Error - 25/11/2011 05:04:00 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Webroot
Client Service service to connect.
Error - 25/11/2011 05:04:00 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Webroot Client Service service failed to start due to the following
error: %%1053
Error - 25/11/2011 05:04:10 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%2
Error - 25/11/2011 05:04:16 | Computer Name = smiffer-PC | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%2
< End of report >
HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:29:44, on 25/11/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\smiffer\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 178.76.252.58:9090
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI3C8A~1\Datamngr\BROWSE~1.DLL
O2 - BHO: Webroot Browser Helper Object - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
O2 - BHO: WRCommonBHO - {D93EC24D-8741-4D41-B83D-A5793B998416} - C:\Program Files (x86)\Webroot\Security\current\plugins\browserextension\WebrootBHO.dll
O3 - Toolbar: Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe
–
End of file - 8600 bytes
DDS
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 15:31:16.53 on 25/11/2011
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.2047.1172 [GMT 0:00]
.
AV: Webroot Internet Security Complete *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
AV: AVG Internet Security 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot Internet Security Complete *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\smiffer\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com/406
uInternet Settings,ProxyServer = 178.76.252.58:9090
uInternet Settings,ProxyOverride =
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
mWinlogon: Userinit=userinit.exe,
BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - C:\PROGRA~2\WI3C8A~1\Datamngr\BROWSE~1.DLL
BHO: Webroot Browser Helper Object: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
BHO: WebrootBHO Class: {d93ec24d-8741-4d41-b83d-a5793b998416} - C:\Program Files (x86)\Webroot\Security\current\plugins\browserextension\WebrootBHO.dll
TB: Webroot Toolbar: {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\Program Files (x86)\Webroot\Security\current\products\WISC\toolbar\LPBar.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
mRun: [NPSStartup]
mRun: [TaskTray]
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: Free YouTube Download - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - C:\Users\smiffer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll
BHO-X64: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
BHO-X64: IDM Helper - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: DataMngr: {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI3C8A~1\Datamngr\x64\BROWSE~1.DLL
AppInit_DLLs-X64: C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid;=101&systemid;=406&sr;=0&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency.dll
FF - component: C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency3.5.dll
FF - component: C:\Users\smiffer\AppData\Roaming\Mozilla\Firefox\Profiles\ilq6cpjj.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency3.6.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Users\smiffer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\smiffer\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\smiffer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\system32\Wat\npWatWeb.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: leethax.net extension: [removed] - %profile%\extensions\[removed]
FF - Ext: Save Images: [removed] - %profile%\extensions\[removed]
FF - Ext: ImageHost Grabber: {E4091D66-127C-11DB-903A-DE80D2EFDFE8} - %profile%\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
FF - Ext: SearchquToolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - %profile%\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-7-11 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2011-9-13 37456]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2011-10-7 283728]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-8-8 46672]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-7-11 375376]
R1 pwipf6;Privacyware Filter Driver;C:\Windows\System32\drivers\pwipf6.sys [2011-5-27 109864]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2011-5-24 83120]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
R2 IDMWFP;IDMWFP;C:\Windows\System32\drivers\idmwfp.sys [2011-6-9 153248]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-5 366152]
R2 ssfmonm;ssfmonm;C:\Windows\System32\drivers\ssfmonm.sys [2011-5-27 58480]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe [2011-5-27 3900032]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2011-7-11 120400]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2011-7-11 29776]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232]
R3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\drivers\LVUSBS64.sys [2007-5-9 50208]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-11-5 25416]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" –> C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [?]
S2 AntiVirService;Avira AntiVir Guard;"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" –> C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 WRConsumerService;Webroot Client Service;C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-5-27 3276136]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\System32\drivers\ssadadb.sys [2011-5-25 36328]
S3 lvpepf64;Volume Adapter;C:\Windows\System32\drivers\lv302a64.sys [2007-5-9 16032]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\System32\drivers\ssadbus.sys [2011-5-25 125416]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\System32\drivers\ssadmdfl.sys [2011-5-25 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\System32\drivers\ssadmdm.sys [2011-5-25 159208]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2011-5-25 16448]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-5-26 1255736]
.
=============== Created Last 30 ================
.
2011-11-23 19:36:21 ——– d—–w- C:\Users\smiffer\AppData\Local\Spotify
2011-11-23 19:36:14 ——– d—–w- C:\Users\smiffer\AppData\Roaming\Spotify
2011-11-21 18:14:04 ——– d—–w- C:\Program Files (x86)\MAGIX
2011-11-21 15:31:35 ——– d—–w- C:\Program Files\Perfect Uninstaller
2011-11-14 19:08:26 ——– d—–w- C:\Windows\System32\appmgmt
2011-11-14 18:35:41 ——– d—–w- C:\PROGRA~3\Yellow Tools
2011-11-13 12:07:57 ——– d—–w- C:\Program Files\CCleaner
2011-11-12 13:50:16 ——– d—–w- C:\Users\smiffer\AppData\Roaming\MAGIX
2011-11-12 13:47:03 ——– d—–w- C:\PROGRA~3\MAGIX
2011-11-12 13:46:59 ——– d—–w- C:\Program Files (x86)\Common Files\MAGIX Services
2011-11-09 18:27:40 ——– d—–w- C:\Users\smiffer\AppData\Roaming\SUPERAntiSpyware.com
2011-11-09 18:27:23 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-11-09 18:27:23 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-11-09 16:29:26 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 16:29:26 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 16:29:24 1897328 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 16:29:21 3141120 —-a-w- C:\Windows\System32\win32k.sys
2011-11-05 20:34:03 ——– d—–w- C:\Users\smiffer\AppData\Roaming\mkvtoolnix
2011-11-05 20:31:43 ——– d—–w- C:\Program Files (x86)\MKVtoolnix
2011-11-05 19:36:36 ——– d—–w- C:\Users\smiffer\AppData\Roaming\Malwarebytes
2011-11-05 19:36:08 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-11-05 19:36:05 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-11-05 19:36:05 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-05 17:21:04 ——– d—–w- C:\Users\smiffer\AppData\Local\Ilivid Player
2011-11-05 17:20:17 ——– d—–w- C:\PROGRA~3\boost_interprocess
2011-11-05 17:20:16 ——– d—–w- C:\Program Files (x86)\Windows iLivid Toolbar
2011-11-02 17:42:27 ——– d—–w- C:\Users\smiffer\AppData\Local\Facebook
2011-10-31 18:20:56 2301208 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-10-31 18:10:39 42776 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-10-31 18:10:33 710976 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-10-31 17:01:03 ——– d—–w- C:\Users\smiffer\AppData\Roaming\AVG
2011-10-30 15:21:54 ——– d—–w- C:\fb57e5fc458dbc61f7497b1d
2011-10-30 15:15:30 7450888 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\bef6a3b21cc97160a\bingbarsetup.exe
2011-10-30 15:15:09 15712 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ab19c4671cc971609\MeshBetaRemover.exe
2011-10-30 15:14:46 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\a4d261021cc971608\DSETUP.dll
2011-10-30 15:14:46 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\a4d261021cc971608\DXSETUP.exe
2011-10-30 15:14:46 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\a4d261021cc971608\dsetup32.dll
2011-10-30 15:14:33 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\9f4377911cc971607\DSETUP.dll
2011-10-30 15:14:33 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\9f4377911cc971607\DXSETUP.exe
2011-10-30 15:14:33 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\9f4377911cc971607\dsetup32.dll
2011-10-30 15:14:24 6260088 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\994ff8eb1cc971606\Silverlight.4.0.exe
2011-10-30 15:12:47 ——– d—–w- C:\Users\smiffer\AppData\Local\Windows Live
2011-10-30 15:12:40 ——– d—–w- C:\Program Files (x86)\Common Files\Windows Live
.
==================== Find3M ====================
.
2011-10-07 06:23:46 283728 —-a-w- C:\Windows\System32\drivers\avgldx64.sys
2011-10-06 16:15:33 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-13 05:30:08 37456 —-a-w- C:\Windows\System32\drivers\avgrkx64.sys
2011-09-06 09:29:25 20 —-a-w- C:\Windows\SysWow64\AVGUARD.EXE
2011-09-01 05:24:07 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 —-a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 15:32:54.29 ===============
thanks in advance for looking at my post.