This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe virus - removal help required

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI
Hope you can help me out.
Spotted my system slowing down this morning and then antivirus picked up (and quarantined/deleted) a large number of items. Loaded up task manager and noticed ping.exe taking up a large amount of CPU. Did an end task, and a full system scan, but still getting some errors.

———————————–

OTL log below:

OTL logfile created on: 03/12/2011 17:16:35 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 70.12% Memory free
4.25 Gb Paging File | 3.17 Gb Available in Paging File | 74.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 51.44 Gb Free Space | 34.51% Space Free | Partition Type: NTFS

Computer Name: DESKTOP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe (SMART Technologies ULC)
PRC - C:\Program Files\Process Lasso\ProcessLasso.exe (Bitsum Technologies)
PRC - C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum Technologies)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\StkASv2K.exe (Syntek America Inc.)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\TBFireWall.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\TbTapeBrowse.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\ExImage.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\ExchBackupSize.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\EnumTapeDevice.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\CodeLog.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.7.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetect.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll ()
MOD - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtNetwork4.dll ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtGui4.dll ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtCore4.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll ()
MOD - C:\Program Files\NVIDIA Corporation\nView\nvShell.dll ()
MOD - C:\WINDOWS\system32\mkunicode.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\system32\mmfinfo.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\libxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naXML71.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naisign.dll ()
MOD - C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\zlib1.dll ()
MOD - C:\WINDOWS\system32\redmonnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AMService) – File not found
SRV - (vToolbarUpdater) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (Guard Agent) – C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (EaseUS Agent) – C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (PassThru Service) – C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Response Hardware) – C:\Program Files\SMART Technologies\SMART Response\ResponseHardwareService.exe (SMART Technologies)
SRV - (SMART SNMP Agent Service) – C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe (SMART Technologies ULC)
SRV - (SMART Display Controller) – C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe (SMART Technologies ULC)
SRV - (SMART Board Service) – C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe (SMART Technologies)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (RalinkRegistryWriter) – C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe (Ralink Technology, Corp.)
SRV - (bgsvcgen) – C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (StkASSrv) – C:\WINDOWS\system32\StkASv2K.exe (Syntek America Inc.)


========== Driver Services (SafeList) ==========

DRV - (EUFDDISK) – C:\WINDOWS\system32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) – C:\WINDOWS\system32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) – C:\WINDOWS\system32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) – C:\WINDOWS\system32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (htcnprot) – C:\WINDOWS\system32\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (HTCAND32) – C:\WINDOWS\system32\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s125mgmt.sys (MCCI Corporation)
DRV - (s125obex) – C:\WINDOWS\system32\drivers\s125obex.sys (MCCI Corporation)
DRV - (s125mdm) – C:\WINDOWS\system32\drivers\s125mdm.sys (MCCI Corporation)
DRV - (s125mdfl) – C:\WINDOWS\system32\drivers\s125mdfl.sys (MCCI Corporation)
DRV - (s125bus) Sony Ericsson Device 125 driver (WDM) – C:\WINDOWS\system32\drivers\s125bus.sys (MCCI Corporation)
DRV - (StkAMini) – C:\WINDOWS\system32\drivers\StkAMini.sys (Syntek America Inc.)
DRV - (StkScan) – C:\WINDOWS\system32\drivers\StkScan.sys (Syntek America Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (WLAN(WLAN)) XPC 802.11b/g Wireless Kit Driver(WLAN) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (itchfltr) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\Lhidusb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHIDFLT2.SYS (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\system32\drivers\LCCFLTR.SYS (Logitech, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin…5&mkt;=en-gb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\WINDOWS\system32\C2MP\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/03 13:42:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Components: C:\Program Files\Flock\components [2011/06/26 15:57:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/09/20 05:12:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components [2011/06/26 15:57:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/09/20 05:12:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/05/17 19:09:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\AVG\AVG2012\Thunderbird\ [2011/12/03 13:40:05 | 000,000,000 | —D | M]

[2011/11/03 18:30:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/05/17 19:09:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/01/20 21:36:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2011/12/03 13:42:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0kmlj45t.default\extensions
[2011/12/03 13:42:12 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0kmlj45t.default\extensions\avg@toolbar
[2011/12/03 13:42:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fzsbi80z.default\extensions
[2011/12/03 13:42:13 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fzsbi80z.default\extensions\avg@toolbar
[2011/12/03 14:00:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/20 14:18:19 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/03 13:08:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/24 08:45:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/01/20 22:33:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2010/04/24 08:45:17 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/16 15:52:28 | 000,258,560 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\mozilla firefox\plugins\npEModelPlugin.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\WINDOWS\system32\C2MP\npdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: EModel scriptable Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2_0\
CHR - Extension: Click to call with Skype = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\
CHR - Extension: Google Maps = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.1_0\

Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Nectar Search Toolbar BHO) - {B7C2F0D8-2209-4693-A15D-5A537211D48B} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Nectar Search Toolbar) - {8020143D-5926-4394-A04D-DD0B649DA121} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Nectar Search Toolbar) - {8020143D-5926-4394-A04D-DD0B649DA121} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O4 - HKLM..\Run: [ATICustomerCare] c:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Backup & Storage] C:\Program Files\VirginMedia\V Stuff Backup\Backup & Storage.exe (F-Secure)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [ProcessGovernor] C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum Technologies)
O4 - HKLM..\Run: [ProcessLassoManagementConsole] C:\Program Files\Process Lasso\ProcessLasso.exe (Bitsum Technologies)
O4 - HKLM..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office 2000\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\system32\wshbth.dll File not found
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{304CF739-292E-4E2A-9414-76780C32B3A3}: NameServer = 192.168.1.1,194.168.4.100,194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{394666F2-4A2B-46A1-825F-B558D84F8CFE}: NameServer = 192.168.1.1,194.168.4.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B44340C7-9743-45CE-B533-6494F1628BE7}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E008F58B-BC5F-4520-A452-4F8D42130309}: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/18 14:02:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/03 17:18:15 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/03 14:31:46 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/12/03 14:04:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/12/03 14:03:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/12/03 13:43:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG2012
[2011/12/03 13:42:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2011/12/03 13:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG Secure Search
[2011/12/03 13:41:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2011/12/03 13:41:56 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2011/12/03 13:41:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/12/03 13:41:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 13:39:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/12/03 13:39:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/12/03 13:39:17 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/12/03 13:38:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/12/03 13:33:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/12/03 13:32:33 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/12/03 12:39:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 12:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/26 08:49:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/26 08:49:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Anvsoft
[2011/11/26 08:48:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\AnvSoft
[2011/11/13 09:47:25 | 000,184,072 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\EuFdDisk.sys
[2011/11/13 09:47:24 | 000,038,920 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\eubakup.sys
[2011/11/13 09:47:24 | 000,016,008 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\eudskacs.sys
[2011/11/13 09:47:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EaseUS Todo Backup 3.5
[2011/11/13 09:45:58 | 000,020,616 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\fbnative.exe
[2011/11/13 09:45:30 | 000,000,000 | —D | C] – C:\Program Files\EaseUS
[2011/11/07 17:47:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\MagicISO
[2011/11/07 17:47:23 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2011/11/06 17:12:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\VirginMedia
[2011/11/06 17:12:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VirginMedia
[2011/11/06 17:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\VirginMedia
[2011/11/06 17:09:11 | 004,292,096 | —- | C] (dimastr.com) – C:\WINDOWS\System32\Redemption.dll
[2011/11/06 17:09:09 | 000,000,000 | —D | C] – C:\Program Files\VirginMedia
[2011/11/03 18:54:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Downloads
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/03 17:18:15 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/03 16:49:11 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003UA.job
[2011/12/03 14:17:58 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/03 13:50:42 | 000,000,065 | —- | M] () – C:\WINDOWS\iTouch.ini
[2011/12/03 13:50:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/03 13:50:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/03 13:50:25 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2011/12/03 13:46:10 | 071,994,407 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/03 13:46:10 | 000,619,258 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/12/02 13:49:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003Core.job
[2011/11/30 22:08:41 | 000,001,854 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spotify.lnk
[2011/11/19 13:49:50 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/12 03:15:55 | 000,000,024 | —- | M] () – C:\Documents and Settings\Owner\.idx
[2011/11/09 03:03:03 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/07 13:39:01 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\debutShakeIcon.job
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/03 13:46:10 | 071,994,407 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/03 13:46:10 | 000,619,258 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/12/03 13:33:13 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2011/12/03 13:25:25 | 021,067,257 | —- | C] () – C:\Documents and Settings\Owner\Desktop\McAfee8.5.zip
[2011/12/03 13:25:07 | 006,469,352 | —- | C] () – C:\Documents and Settings\Owner\Desktop\avgas-setup-7.5.0.50.exe
[2011/11/30 22:08:41 | 000,001,860 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Spotify.lnk
[2011/11/13 09:47:23 | 000,042,376 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/11/08 06:26:54 | 000,000,024 | —- | C] () – C:\Documents and Settings\Owner\.idx
[2011/08/12 20:30:59 | 000,314,632 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-484763869-412668190-725345543-1003-0.dat
[2011/07/26 07:57:48 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2011/06/25 10:06:12 | 000,015,060 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\u5xl0b2006300aa8rlh0r6
[2011/06/25 10:06:12 | 000,015,060 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\u5xl0b2006300aa8rlh0r6
[2011/05/02 16:04:20 | 000,212,198 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/05/02 12:06:30 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/29 14:34:32 | 000,000,087 | —- | C] () – C:\WINDOWS\bi_group.ini
[2011/04/23 07:05:44 | 000,043,136 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/21 20:40:15 | 000,037,211 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Comma Separated Values (Windows).ADR
[2011/04/08 21:14:56 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/01/27 16:58:56 | 000,000,054 | —- | C] () – C:\Documents and Settings\Owner\Application Data\tigersetting.dll
[2011/01/25 20:10:22 | 000,000,043 | —- | C] () – C:\WINDOWS\gswin32.ini
[2011/01/25 20:03:39 | 000,000,136 | —- | C] () – C:\WINDOWS\UNlock.dat
[2011/01/25 19:52:42 | 000,000,417 | —- | C] () – C:\WINDOWS\crackpdf.INI
[2011/01/22 14:18:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2010/12/23 13:25:28 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2010/12/23 13:25:04 | 000,014,640 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2010/12/23 13:25:04 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\drivers\rt2870.bin
[2010/12/17 13:38:04 | 000,231,792 | —- | C] () – C:\WINDOWS\libactivboardex.dll
[2010/12/17 13:37:48 | 000,257,888 | —- | C] () – C:\WINDOWS\ActivDRV.dll
[2010/10/27 07:51:54 | 000,000,701 | —- | C] () – C:\Documents and Settings\Owner\Application Data\init.dll
[2010/10/27 07:51:54 | 000,000,006 | —- | C] () – C:\Documents and Settings\Owner\Application Data\SYSTEM32.dll
[2010/10/27 07:51:44 | 000,000,701 | —- | C] () – C:\Documents and Settings\Owner\Application Data\sound.dll
[2010/10/27 07:50:14 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/10/27 07:50:03 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2010/09/26 16:00:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2010/09/26 15:21:08 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/08/24 12:39:25 | 000,000,954 | —- | C] () – C:\WINDOWS\exampro32.ini
[2010/08/24 12:39:23 | 000,536,576 | —- | C] () – C:\WINDOWS\System32\Tx32.dll
[2010/08/24 12:39:23 | 000,000,478 | —- | C] () – C:\WINDOWS\System32\ic32.ini
[2010/08/24 12:37:38 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2010/08/23 13:39:40 | 000,000,421 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/08/03 07:09:55 | 000,000,062 | —- | C] () – C:\WINDOWS\GPM2MICP.INI
[2010/08/02 20:04:51 | 000,348,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/13 14:24:04 | 000,000,297 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2010/03/29 17:55:44 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/03/26 18:18:10 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/03/26 18:17:54 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/03/26 18:17:54 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2010/03/26 18:17:52 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2010/03/26 18:17:52 | 000,224,342 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/03/26 18:17:52 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/02/07 16:03:31 | 000,000,449 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/02/07 16:03:30 | 000,000,092 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/02/07 16:03:12 | 000,000,088 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.inf
[2010/02/05 18:38:38 | 000,000,083 | —- | C] () – C:\WINDOWS\wwp.INI
[2010/01/24 15:00:14 | 000,058,368 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/24 14:28:06 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/24 08:28:29 | 000,000,167 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/01/21 21:04:28 | 000,000,065 | —- | C] () – C:\WINDOWS\iTouch.ini
[2010/01/21 19:59:46 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2010/01/20 21:36:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/19 22:44:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/19 22:44:07 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2010/01/12 20:18:20 | 001,409,890 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/01/12 20:18:18 | 000,882,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/01/12 20:18:18 | 000,556,491 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/12 20:18:16 | 004,507,983 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/12 20:18:10 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/01/12 20:18:10 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/01/12 20:18:10 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/01/12 20:18:10 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/01/12 20:18:10 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/12 20:18:10 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/01/12 20:18:08 | 000,169,984 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/01/12 20:18:08 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/01/12 20:18:08 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/01/12 20:18:08 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/01/12 20:12:36 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/01/01 00:00:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/01 00:00:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2009/11/14 18:37:08 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/11/14 18:33:40 | 000,357,888 | —- | C] () – C:\WINDOWS\System32\gdsmux.exe
[2009/11/14 18:33:38 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/11/14 18:11:50 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/11/14 18:11:42 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/11/14 18:11:42 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/11/14 18:11:40 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/11/14 18:11:40 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/11/14 18:11:38 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/11/14 18:11:36 | 000,136,704 | —- | C] () – C:\WINDOWS\System32\mkv2vfr.exe
[2009/11/14 18:11:36 | 000,113,152 | —- | C] () – C:\WINDOWS\System32\dsmux.exe
[2009/11/14 18:11:32 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 18:11:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2009/08/11 20:21:26 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\ac3config.exe
[2009/01/18 14:11:06 | 000,006,136 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2009/01/18 14:09:28 | 002,283,526 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/01/18 14:04:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/18 14:00:43 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/01/18 13:54:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/18 13:51:58 | 000,216,064 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/10 22:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/12/03 22:11:50 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/06 16:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/13 22:53:22 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\JPeg32.dll
[2007/10/13 09:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/03/15 10:47:48 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\BuEResNT.dll
[2006/12/05 10:34:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/04/17 17:45:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\LEXPING.EXE
[2006/02/28 12:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 12:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 12:00:00 | 000,502,278 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 12:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 12:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 12:00:00 | 000,088,184 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 12:00:00 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2006/02/28 12:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 12:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 12:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 12:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 12:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 12:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/01/30 12:42:22 | 000,000,270 | —- | C] () – C:\WINDOWS\System32\lxczcoin.ini
[2003/03/24 04:03:00 | 000,279,552 | —- | C] () – C:\WINDOWS\System32\FGWVB32.DLL
[2002/11/13 07:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxczvs.dll
[2001/01/19 07:50:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE
[1999/01/22 18:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2011/01/25 19:49:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A-PDF
[2011/07/17 13:58:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activ Software
[2011/12/03 13:45:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/09/23 16:45:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Codemasters
[2011/12/03 13:41:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/26 07:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/09/26 18:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/12/23 13:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Edimax Driver
[2011/02/04 06:31:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/12/03 13:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/04/04 12:30:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/03/06 17:17:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2011/04/27 16:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PearlMountainSoft
[2011/07/17 14:19:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Promethean
[2011/04/08 21:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies
[2010/02/24 21:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies Inc
[2010/10/23 18:57:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/01/22 16:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2011/12/03 17:22:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/06 17:12:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirginMedia
[2011/06/24 05:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\xml_param
[2011/04/08 05:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/22 07:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\4Media
[2011/07/17 13:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ACTIV Software
[2010/03/31 17:39:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/11/26 08:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2011/04/17 12:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ASAP Utilities
[2011/12/03 14:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/12/03 13:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG Secure Search
[2011/12/03 13:43:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG2012
[2011/07/26 07:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DassaultSystemes
[2011/04/23 17:48:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Digiarty
[2011/03/22 21:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DocumentsToGoDesktopAndroid
[2011/11/10 19:45:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EA300
[2011/08/09 07:52:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Easy Watermark Studio
[2011/07/26 08:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EDrawings
[2011/10/30 06:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eMusic
[2010/09/02 15:11:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FCTB000061465
[2011/06/26 15:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flock
[2010/01/18 22:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2011/04/08 18:53:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2011/08/07 11:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HTC
[2011/08/07 11:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2010/12/04 11:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InfraRecorder
[2010/08/12 15:30:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mael
[2011/06/28 05:53:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MyPhoneExplorer
[2011/10/18 19:22:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2011/08/07 11:26:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Outlook
[2010/03/06 17:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2011/04/27 16:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PearlMountainSoft
[2010/09/01 08:12:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ProcessLasso
[2011/07/17 14:19:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Promethean
[2010/09/26 16:02:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Samsung
[2011/04/08 21:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SMART Technologies
[2010/02/24 21:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SMART Technologies Inc
[2010/11/30 15:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sports Interactive
[2011/12/03 13:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spotify
[2010/06/21 15:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Teleca
[2011/05/17 19:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Thunderbird
[2011/07/26 09:09:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/04/22 20:42:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Video DVD Maker FREE
[2010/02/09 19:04:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Voxmobili
[2011/11/07 13:39:01 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\debutShakeIcon.job
[2011/10/26 12:02:42 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\videopadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/28 19:04:47 | 000,001,457 | —- | M] () – C:\amg.xml
[2009/01/18 14:02:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/22 17:39:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/26 16:01:36 | 000,000,074 | —- | M] () – C:\CMLoader.log
[2009/01/18 14:02:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/02/08 20:43:08 | 000,129,050 | —- | M] () – C:\FlockInstaller.log
[2011/12/03 13:50:25 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2011/09/07 18:21:24 | 000,766,465 | —- | M] () – C:\Image0004.PDF
[2009/01/18 14:02:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/18 14:02:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/01/25 07:08:28 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/03 13:50:20 | 1509,949,440 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/18 14:02:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/03/14 03:06:40 | 000,019,968 | —- | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\BuEProNT.dll
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/19 04:33:38 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 10:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/18 13:51:17 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/01/18 13:51:17 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/01/18 13:51:17 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/01/25 07:12:52 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/18 14:08:04 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2007/07/09 20:17:06 | 006,469,352 | —- | M] () – C:\Documents and Settings\Owner\Desktop\avgas-setup-7.5.0.50.exe
[2011/12/03 17:18:15 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-12 03:00:51

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB49169$] -> -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63CD0333
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >


OTL Extras log
OTL Extras logfile created on: 03/12/2011 17:16:35 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 70.12% Memory free
4.25 Gb Paging File | 3.17 Gb Available in Paging File | 74.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 51.44 Gb Free Space | 34.51% Space Free | Partition Type: NTFS

Computer Name: DESKTOP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
jsfile [open] – "C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Compress folder to .wad] – "C:\Program Files\ZaZ Gp4 tools\Easywad.exe" /C "%l" (ZaZ)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5900:TCP" = 5900:TCP:LocalSubNet:Enabled:VNC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Infogrames\Grand Prix 4\GP4.exe" = C:\Program Files\Infogrames\Grand Prix 4\GP4.exe:*:Enabled:GP4 – ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Team17\Worms World Party\wwp.exe" = C:\Team17\Worms World Party\wwp.exe:*:Enabled:Worms World Party – (Team17 Software Ltd)
"C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe:*:Enabled:Dreamweaver MX – (Macromedia, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Nectar Search Toolbar\TroubleShooter.exe" = C:\Program Files\Nectar Search Toolbar\TroubleShooter.exe:*:Enabled:Nectar Search Toolbar (Helper) – (FreeCause Inc.)
"C:\Program Files\Nectar Search Toolbar\ToolbarUpdate.exe" = C:\Program Files\Nectar Search Toolbar\ToolbarUpdate.exe:*:Enabled:Nectar Search Toolbar (Update) – (FreeCause Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Amazon\MP3 Downloader\AmazonMP3Downloader.exe" = C:\Program Files\Amazon\MP3 Downloader\AmazonMP3Downloader.exe:*:Enabled:Amazon MP3 Downloader – (Amazon.com)
"C:\Program Files\SMART Technologies\SMART Response\ResponseSoftwareService.exe" = C:\Program Files\SMART Technologies\SMART Response\ResponseSoftwareService.exe:*:Enabled:SMART Response Software Service – (SMART Technologies)
"C:\Program Files\SMART Technologies\SMART Product Drivers\UCGui.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\UCGui.exe:*:Enabled:SMART Universal Controller Interface – (SMART Technologies ULC)
"C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe:*:Enabled:SMART SNMPAgent – (SMART Technologies ULC)
"C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe:*:Enabled:SMART Universal Controller Service – (SMART Technologies ULC)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Opera Next\opera.exe" = C:\Program Files\Opera Next\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe" = C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe:*:Enabled:Agent.exe – (CHENGDU YIWO Tech Development Co., Ltd)
"C:\Documents and Settings\Owner\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\Owner\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B67D40E-01ED-43FC-8BD8-9CD284550766}" = SolidWorks eDrawings 2011
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{0E5DD7A3-BE29-430C-970B-C553F4A58C39}" = SMART Common Platform
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A3E23D7-7A1E-43EC-B35D-EB2A31BED943}" = Video DVD Maker v3.27.0.69
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{25BEC3AB-5CD4-481D-9143-215C1BBB189E}" = Sony Ericsson PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = EDIMAX Edimax Wireless LAN
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{32C747FB-2576-4503-B75D-DEE95161C60E}" = ActivInspire Core Resources (ENU) v1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{434D0831-A4CC-401A-9E74-621000018401}" = F1 2010
"{4451B8AB-D156-BA14-03EF-152E40A9DE48}" = ATI AVIVO Codecs
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C2E5A82-DA8B-4c72-91A6-EBB4E0463537}_is1" = Backup & Storage v2.3.1.37683
"{4CE6C6E8-0DAD-4757-86ED-7FB4035BA98B}" = SMART Product Drivers
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.75
"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
"{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 2.5.7
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E599D8-0D7C-411F-BC18-5B80F13DF968}" = ActivInspire Help (GBR) v1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7D7715C0-9C0F-3F08-D326-1C6268AC5530}" = ATI Catalyst Install Manager
"{7F57E0DE-D0F7-47CC-A4AB-D21EB8E4BE48}" = ActivInspire v1
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8B4CE9CA-ECB7-47D1-845E-E1167FFB3F1B}" = SMART Response Software
"{8D4B716A-0ABE-4238-9090-D208E5F57A5E}" = SMART Product Update
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{914CEAB8-B2B7-1CCB-D0D4-5C472EAD6AAC}" = CCC Help English
"{936E2131-D9DB-42F9-96E7-52D2050ACB09}" = ActivDriver x86 v5.7
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9550F8A6-3D21-4544-8B87-F9FE7E01B964}" = SMART Notebook
"{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3
"{9A200E68-D5F4-4E70-910F-2871753A0E2B}" = Worms World Party
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EDF1A5D-D8E0-413E-9782-75DD4A8C831B}" = VideoCam Suite 2.0
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AEM384L1-28E3-1232-1233-1JD74JDIEK32}_is1" = PDFTigerDriver
"{B45FABE7-D101-4D99-A671-E16DA40AF7F0}" = Microsoft Games for Windows - LIVE
"{B539E69D-DD59-457D-A926-CF01ACA6D04C}" = Microsoft Image Composite Editor
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B7FB0C86-41A4-4402-9A33-912C462042A0}" = Roxio Creator 9 LE
"{BB071E36-0596-4919-A5B5-608BFFE8673A}_is1" = ZaZ GP4 Tools 1.26
"{BD31FF1E-088E-A139-C772-7A5777529042}" = Catalyst Control Center Graphics Previews Common
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2EBC2F1-B766-4AE3-A10C-6EBBC1EE3B02}" = Data Sync
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C7D27207-0F86-4B6F-859C-21800A2C592E}" = Grand Prix 4
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE246151-F0E8-ABC8-AEB2-7F3E188EFBF5}" = TweetDeck
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D1F94690-C59F-4BF1-A9C5-012DCCE8364D}_is1" = X2X Free Video Trim 2.0
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.26 Game
"{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DB078F4F-FC74-4A07-9E07-A6623A18A667}" = ActivInspire HWR Resources (ENU) v1
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DE252510-5687-4C60-A705-C43E19F12C9D}_is1" = PDFTiger Kernel
"{DEB7B7C6-C931-08C3-1059-60C0AF3FB781}" = ccc-utility
"{DEEDF1BA-ADD7-6EA0-D017-A89ACAD64E9F}" = ccc-core-static
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F943B1DF-711F-7D8E-3257-ED05026895E1}" = Catalyst Control Center InstallProxy
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon Kindle For PC" = Amazon Kindle For PC v1.1
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"AnvSoft Photo Flash Maker Professional" = AnvSoft Photo Flash Maker Professional 5.40
"Any Video Converter_is1" = Any Video Converter 3.0.4
"A-PDF Restrictions Remover_is1" = A-PDF Restrictions Remover 1.6
"Artensoft Photo Mosaic Wizard_is1" = Artensoft Photo Mosaic Wizard
"ASAP Utilities_is1" = ASAP Utilities
"Audacity_is1" = Audacity 1.2.6
"AVG" = AVG 2012
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Daniusoft MOD Converter_is1" = Daniusoft MOD Converter(Build [removed])
"Daniusoft Video Converter_is1" = Daniusoft Video Converter(Build 2.3.2.0)
"Debut" = Debut Video Capture Software
"DTGDesktop-Android" = Documents To Go Desktop for Android
"DVD Flick_is1" = DVD Flick 1.3.0.7
"EA300 DVD-ROM" = EA300 DVD-ROM
"EaseUS Todo Backup Free 3.5_is1" = EaseUS Todo Backup Free 3.5
"Easy Watermark Studio3.1" = Easy Watermark Studio
"Exampro AA_MACO" = Exampro AQA GCE Core Mathematics
"Exampro AA_MAME" = Exampro AQA GCE Mechanics
"Exampro AA_MAST" = Exampro AQA GCE Statistics
"get_iplayer" = get_iplayer 4.2
"GPL Ghostscript 9.00" = GPL Ghostscript 9.00
"HandBrake" = HandBrake 0.9.5
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hugin" = Hugin 2010.4.0
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"InfraRecorder" = InfraRecorder
"JPG2PDF_is1" = JPG2PDF 2.2
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lexmark 1200 Series" = Lexmark 1200 Series
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicScore_is1" = MagicScore
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Thunderbird (3.1.10)" = Mozilla Thunderbird (3.1.10)
"MPE" = MyPhoneExplorer
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nectar Search Toolbar" = Nectar Search Toolbar
"Need For Speed High Stakes" = Need For Speed Road Challenge
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Opera 11.52.1100" = Opera 11.52
"Opera 12.00.1116" = Opera Next 12.00 alpha build 1116
"pdfsam" = pdfsam
"PDFTiger_is1" = PDFTiger
"ProcessLasso" = Process Lasso
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.3
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Shockwave" = Shockwave
"Sierra Utilities" = Sierra Utilities
"Simple Family Tree" = Simple Family Tree (remove only)
"Spotify" = Spotify
"Steam App 410" = Portal: First Slice
"Testbase UK_MT" = Testbase UKMT Challenge Questions
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"VideoPad" = VideoPad Video Editor
"VLC media player" = VLC media player 1.1.10
"Wdf01001" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 2.0.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{EE19063F-7048-4094-9A1D-D69D9C591119}_is1" = Albelli Photo books
"GeoGebra WebStart" = GeoGebra WebStart
"Google Chrome" = Google Chrome
"Spotify" = Spotify

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 03/12/2011 04:04:18 | Computer Name = DESKTOP | Source = Application Hang | ID = 1002
Description = Hanging application GPxPatch.exe, version 3.9.3.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/12/2011 08:48:15 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 08:49:00 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 08:58:06 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 09:03:02 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 09:47:59 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 10:03:44 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 10:05:11 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 10:14:59 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

Error - 03/12/2011 10:18:16 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.

[ OSession Events ]
Error - 02/01/2011 03:26:38 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 96
seconds with 60 seconds of active time. This session ended with a crash.

Error - 02/01/2011 03:27:38 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 29
seconds with 0 seconds of active time. This session ended with a crash.

Error - 03/06/2011 01:26:49 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 34 seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 03/12/2011 13:10:40 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:10:54 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:13:34 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:14:36 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:14:38 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:16:12 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:17:46 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:19:31 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:21:05 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 03/12/2011 13:23:12 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127


< End of report >
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)








Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
TDSSKiller log 18:35:18.0218 2988 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 18:35:18.0515 2988 ============================================================ 18:35:18.0515 2988 Current date / time: 2011/12/06 18:35:18.0515 18:35:18.0515 2988 SystemInfo: 18:35:18.0515 2988 18:35:18.0515 2988 OS Version: 5.1.2600 ServicePack: 3.0 18:35:18.0515 2988 Product type: Workstation 18:35:18.0515 2988 ComputerName: DESKTOP 18:35:18.0515 2988 UserName: Owner 18:35:18.0515 2988 Windows directory: C:\WINDOWS 18:35:18.0515 2988 System windows directory: C:\WINDOWS 18:35:18.0515 2988 Processor architecture: Intel x86 18:35:18.0515 2988 Number of processors: 2 18:35:18.0515 2988 Page size: 0x1000 18:35:18.0515 2988 Boot type: Normal boot 18:35:18.0515 2988 ============================================================ 18:35:20.0359 2988 Initialize success 18:35:08.0443 3584 ============================================================ 18:35:08.0443 3584 Scan started 18:35:08.0443 3584 Mode: Manual; 18:35:08.0443 3584 ============================================================ 18:35:09.0802 3584 Abiosdsk - ok 18:35:09.0849 3584 abp480n5 - ok 18:35:09.0943 3584 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 18:35:09.0959 3584 ACPI - ok 18:35:10.0224 3584 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 18:35:10.0240 3584 ACPIEC - ok 18:35:10.0349 3584 adpu160m - ok 18:35:10.0443 3584 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 18:35:10.0474 3584 aec - ok 18:35:10.0646 3584 AegisP (023867b6606fbabcdd52e089c4a507da) C:\WINDOWS\system32\DRIVERS\AegisP.sys 18:35:10.0646 3584 AegisP - ok 18:35:10.0724 3584 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 18:35:10.0724 3584 AFD - ok 18:35:10.0943 3584 Aha154x - ok 18:35:10.0990 3584 aic78u2 - ok 18:35:11.0084 3584 aic78xx - ok 18:35:11.0271 3584 AliIde - ok 18:35:11.0459 3584 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys 18:35:11.0568 3584 Ambfilt - ok 18:35:11.0771 3584 amsint - ok 18:35:11.0849 3584 asc - ok 18:35:12.0052 3584 asc3350p - ok 18:35:12.0131 3584 asc3550 - ok 18:35:12.0474 3584 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 18:35:12.0506 3584 AsyncMac - ok 18:35:12.0552 3584 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 18:35:12.0552 3584 atapi - ok 18:35:12.0615 3584 Atdisk - ok 18:35:13.0568 3584 ati2mtag (662c08fef641d8d6e9dcdb39168895b0) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 18:35:13.0599 3584 ati2mtag - ok 18:35:13.0771 3584 AtiHdmiService (dc6957811ff95f2dd3004361b20d8d3f) C:\WINDOWS\system32\drivers\AtiHdmi.sys 18:35:13.0771 3584 AtiHdmiService - ok 18:35:13.0881 3584 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 18:35:13.0896 3584 Atmarpc - ok 18:35:14.0162 3584 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 18:35:14.0177 3584 audstub - ok 18:35:14.0318 3584 Avgfwdx (841b0a982065bffc7d7e84009f2fa76f) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys 18:35:14.0318 3584 Avgfwdx - ok 18:35:14.0349 3584 Avgfwfd (841b0a982065bffc7d7e84009f2fa76f) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys 18:35:14.0349 3584 Avgfwfd - ok 18:35:14.0443 3584 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 18:35:14.0443 3584 AVGIDSDriver - ok 18:35:14.0490 3584 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 18:35:14.0490 3584 AVGIDSEH - ok 18:35:14.0771 3584 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 18:35:14.0771 3584 AVGIDSFilter - ok 18:35:15.0052 3584 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 18:35:15.0052 3584 AVGIDSShim - ok 18:35:15.0115 3584 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 18:35:15.0115 3584 Avgldx86 - ok 18:35:15.0381 3584 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 18:35:15.0381 3584 Avgmfx86 - ok 18:35:15.0506 3584 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 18:35:15.0537 3584 Avgrkx86 - ok 18:35:15.0677 3584 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 18:35:15.0677 3584 Avgtdix - ok 18:35:15.0787 3584 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 18:35:15.0787 3584 Beep - ok 18:35:15.0927 3584 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys 18:35:15.0927 3584 BthEnum - ok 18:35:16.0115 3584 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys 18:35:16.0115 3584 BTHMODEM - ok 18:35:16.0240 3584 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys 18:35:16.0256 3584 BthPan - ok 18:35:16.0381 3584 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys 18:35:16.0396 3584 BTHPORT - ok 18:35:16.0443 3584 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys 18:35:16.0443 3584 BTHUSB - ok 18:35:16.0584 3584 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 18:35:16.0584 3584 cbidf2k - ok 18:35:16.0646 3584 CCDECODE (fdc06e2ada8c468ebb161624e03976cf) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 18:35:16.0646 3584 CCDECODE - ok 18:35:16.0740 3584 cd20xrnt - ok 18:35:16.0834 3584 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 18:35:16.0865 3584 Cdaudio - ok 18:35:16.0912 3584 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 18:35:16.0912 3584 Cdfs - ok 18:35:16.0974 3584 cdrbsdrv (e0042bd5bef17a6a3ef1df576bde24d1) C:\WINDOWS\system32\drivers\cdrbsdrv.sys 18:35:16.0974 3584 cdrbsdrv - ok 18:35:17.0115 3584 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys 18:35:17.0115 3584 Cdrom - ok 18:35:17.0131 3584 Changer - ok 18:35:17.0162 3584 CmdIde - ok 18:35:17.0302 3584 Cpqarray - ok 18:35:17.0490 3584 dac2w2k - ok 18:35:17.0646 3584 dac960nt - ok 18:35:17.0802 3584 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 18:35:17.0802 3584 Disk - ok 18:35:17.0927 3584 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 18:35:17.0959 3584 dmboot - ok 18:35:18.0052 3584 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 18:35:18.0052 3584 dmio - ok 18:35:18.0115 3584 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 18:35:18.0115 3584 dmload - ok 18:35:18.0209 3584 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 18:35:18.0209 3584 DMusic - ok 18:35:18.0334 3584 dpti2o - ok 18:35:18.0412 3584 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 18:35:18.0412 3584 drmkaud - ok 18:35:18.0537 3584 EUBAKUP (369f5f00e6cbf612ea1fd12e5c7cfa30) C:\WINDOWS\system32\drivers\eubakup.sys 18:35:18.0568 3584 EUBAKUP - ok 18:35:18.0615 3584 EUBKMON (55c5c98722c1a89770b4ac50e4c55794) C:\WINDOWS\system32\drivers\EUBKMON.sys 18:35:18.0615 3584 EUBKMON - ok 18:35:18.0677 3584 EUDSKACS (772cb91987dcda3c349e1134857c54ba) C:\WINDOWS\system32\drivers\eudskacs.sys 18:35:18.0677 3584 EUDSKACS - ok 18:35:18.0740 3584 EUFDDISK (47bfdc87edb1d77e507736f25c0391ad) C:\WINDOWS\system32\drivers\EuFdDisk.sys 18:35:18.0740 3584 EUFDDISK - ok 18:35:18.0865 3584 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 18:35:18.0896 3584 Fastfat - ok 18:35:19.0021 3584 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 18:35:19.0021 3584 Fdc - ok 18:35:19.0115 3584 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 18:35:19.0115 3584 Fips - ok 18:35:19.0287 3584 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 18:35:19.0287 3584 Flpydisk - ok 18:35:19.0459 3584 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 18:35:19.0490 3584 FltMgr - ok 18:35:19.0771 3584 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 18:35:19.0787 3584 Fs_Rec - ok 18:35:20.0115 3584 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 18:35:20.0146 3584 Ftdisk - ok 18:35:20.0318 3584 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 18:35:20.0349 3584 Gpc - ok 18:35:20.0599 3584 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 18:35:20.0599 3584 HDAudBus - ok 18:35:20.0927 3584 HidBth (7bd2de4c85eb4241eed57672b16a7d8d) C:\WINDOWS\system32\DRIVERS\hidbth.sys 18:35:20.0943 3584 HidBth - ok 18:35:21.0162 3584 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 18:35:21.0162 3584 HidUsb - ok 18:35:21.0443 3584 hpn - ok 18:35:21.0537 3584 HTCAND32 (cbd09ed9cf6822177ee85aea4d8816a2) C:\WINDOWS\system32\Drivers\ANDROIDUSB.sys 18:35:21.0552 3584 HTCAND32 - ok 18:35:21.0974 3584 htcnprot (04e3b3554076b8192a668efe88a682a1) C:\WINDOWS\system32\DRIVERS\htcnprot.sys 18:35:22.0006 3584 htcnprot - ok 18:35:22.0240 3584 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 18:35:22.0287 3584 HTTP - ok 18:35:22.0318 3584 i2omgmt - ok 18:35:22.0662 3584 i2omp - ok 18:35:22.0818 3584 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 18:35:22.0818 3584 i8042prt - ok 18:35:23.0006 3584 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 18:35:23.0006 3584 Imapi - ok 18:35:23.0146 3584 ini910u - ok 18:35:24.0162 3584 IntcAzAudAddService (0cacdcbbc8e6f11e2865c47bfc509848) C:\WINDOWS\system32\drivers\RtkHDAud.sys 18:35:24.0193 3584 IntcAzAudAddService - ok 18:35:24.0443 3584 IntelIde - ok 18:35:24.0599 3584 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 18:35:24.0677 3584 Ip6Fw - ok 18:35:24.0990 3584 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 18:35:25.0084 3584 IpFilterDriver - ok 18:35:25.0459 3584 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 18:35:25.0459 3584 IpInIp - ok 18:35:25.0537 3584 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 18:35:25.0568 3584 IpNat - ok 18:35:25.0740 3584 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 18:35:25.0740 3584 IPSec - ok 18:35:25.0865 3584 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 18:35:25.0865 3584 IRENUM - ok 18:35:26.0209 3584 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 18:35:26.0240 3584 isapnp - ok 18:35:26.0584 3584 itchfltr (936123d83e80c1cb3ea042d7fb98da25) C:\WINDOWS\system32\DRIVERS\itchfltr.sys 18:35:26.0584 3584 itchfltr - ok 18:35:26.0693 3584 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 18:35:26.0693 3584 Kbdclass - ok 18:35:27.0021 3584 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 18:35:27.0037 3584 kbdhid - ok 18:35:27.0318 3584 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 18:35:27.0427 3584 kmixer - ok 18:35:27.0537 3584 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 18:35:27.0568 3584 KSecDD - ok 18:35:27.0709 3584 L8042pr2 (733ececf4371ac99410ee0f00bfd51e7) C:\WINDOWS\system32\DRIVERS\L8042pr2.Sys 18:35:27.0724 3584 L8042pr2 - ok 18:35:27.0834 3584 lbrtfdc - ok 18:35:28.0006 3584 LCcfltr (6dbfde591322242ecec5c48fca325e82) C:\WINDOWS\system32\Drivers\LCcFltr.Sys 18:35:28.0006 3584 LCcfltr - ok 18:35:28.0037 3584 LHidFlt2 (5bc552b8a4bb668ac169a24d7ff5b9b8) C:\WINDOWS\system32\DRIVERS\LHidFlt2.Sys 18:35:28.0037 3584 LHidFlt2 - ok 18:35:28.0224 3584 LHidUsb (387cb1e73b17656f406fc13dc17eda6a) C:\WINDOWS\system32\Drivers\LHidUsb.Sys 18:35:28.0224 3584 LHidUsb - ok 18:35:28.0506 3584 LMouFlt2 (128f0b4cd156872d440ae77202923a32) C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys 18:35:28.0506 3584 LMouFlt2 - ok 18:35:28.0599 3584 mferkdk - ok 18:35:28.0865 3584 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 18:35:28.0865 3584 mnmdd - ok 18:35:28.0974 3584 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 18:35:28.0974 3584 Modem - ok 18:35:29.0209 3584 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys 18:35:29.0302 3584 Monfilt - ok 18:35:29.0537 3584 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 18:35:29.0537 3584 Mouclass - ok 18:35:29.0615 3584 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 18:35:29.0631 3584 mouhid - ok 18:35:29.0724 3584 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 18:35:29.0724 3584 MountMgr - ok 18:35:29.0865 3584 mraid35x - ok 18:35:29.0912 3584 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 18:35:29.0912 3584 MRxDAV - ok 18:35:30.0068 3584 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 18:35:30.0099 3584 MRxSmb - ok 18:35:30.0537 3584 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 18:35:30.0568 3584 Msfs - ok 18:35:30.0677 3584 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 18:35:30.0677 3584 MSKSSRV - ok 18:35:30.0802 3584 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 18:35:30.0834 3584 MSPCLOCK - ok 18:35:30.0959 3584 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 18:35:30.0959 3584 MSPQM - ok 18:35:31.0349 3584 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 18:35:31.0349 3584 mssmbios - ok 18:35:31.0552 3584 MSTEE (d5059366b361f0e1124753447af08aa2) C:\WINDOWS\system32\drivers\MSTEE.sys 18:35:31.0584 3584 MSTEE - ok 18:35:31.0740 3584 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 18:35:31.0756 3584 Mup - ok 18:35:31.0787 3584 NABTSFEC (ac31b352ce5e92704056d409834beb74) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 18:35:31.0802 3584 NABTSFEC - ok 18:35:31.0912 3584 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 18:35:31.0927 3584 NDIS - ok 18:35:32.0068 3584 NdisIP (abd7629cf2796250f315c1dd0b6cf7a0) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 18:35:32.0084 3584 NdisIP - ok 18:35:32.0146 3584 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 18:35:32.0146 3584 NdisTapi - ok 18:35:32.0287 3584 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 18:35:32.0302 3584 Ndisuio - ok 18:35:32.0381 3584 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 18:35:32.0412 3584 NdisWan - ok 18:35:32.0552 3584 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 18:35:32.0584 3584 NDProxy - ok 18:35:32.0631 3584 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 18:35:32.0631 3584 NetBIOS - ok 18:35:32.0756 3584 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 18:35:32.0756 3584 NetBT - ok 18:35:32.0834 3584 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 18:35:32.0834 3584 Npfs - ok 18:35:33.0021 3584 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 18:35:33.0052 3584 Ntfs - ok 18:35:33.0474 3584 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 18:35:33.0506 3584 Null - ok 18:35:34.0209 3584 nv (cb0ce8de9f66a297cd86eb98921b8e58) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 18:35:34.0912 3584 nv - ok 18:35:35.0052 3584 NVENETFD (a12ec731bb00adad2d016d41c1f18fa4) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 18:35:35.0052 3584 NVENETFD - ok 18:35:35.0240 3584 nvgts (619d8943725402d1179941fd58574cc8) C:\WINDOWS\system32\DRIVERS\nvgts.sys 18:35:35.0240 3584 nvgts - ok 18:35:35.0412 3584 nvnetbus (5dc6a149897820de315916b6ec984ec9) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 18:35:35.0412 3584 nvnetbus - ok 18:35:35.0490 3584 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 18:35:35.0490 3584 NwlnkFlt - ok 18:35:35.0537 3584 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 18:35:35.0537 3584 NwlnkFwd - ok 18:35:35.0677 3584 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 18:35:35.0693 3584 Parport - ok 18:35:35.0740 3584 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 18:35:35.0740 3584 PartMgr - ok 18:35:35.0865 3584 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 18:35:35.0865 3584 ParVdm - ok 18:35:36.0052 3584 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 18:35:36.0052 3584 PCI - ok 18:35:36.0052 3584 PCIDump - ok 18:35:36.0099 3584 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 18:35:36.0099 3584 PCIIde - ok 18:35:36.0115 3584 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 18:35:36.0115 3584 Pcmcia - ok 18:35:36.0115 3584 PDCOMP - ok 18:35:36.0131 3584 PDFRAME - ok 18:35:36.0146 3584 PDRELI - ok 18:35:36.0146 3584 PDRFRAME - ok 18:35:36.0162 3584 perc2 - ok 18:35:36.0162 3584 perc2hib - ok 18:35:36.0224 3584 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 18:35:36.0271 3584 PptpMiniport - ok 18:35:36.0599 3584 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 18:35:36.0615 3584 Processor - ok 18:35:36.0615 3584 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 18:35:36.0631 3584 PSched - ok 18:35:36.0662 3584 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 18:35:36.0662 3584 Ptilink - ok 18:35:36.0693 3584 PxHelp20 (feffcfdc528764a04c8ed63d5fa6e711) C:\WINDOWS\system32\Drivers\PxHelp20.sys 18:35:36.0693 3584 PxHelp20 - ok 18:35:36.0756 3584 ql1080 - ok 18:35:36.0771 3584 Ql10wnt - ok 18:35:36.0787 3584 ql12160 - ok 18:35:36.0787 3584 ql1240 - ok 18:35:36.0802 3584 ql1280 - ok 18:35:36.0818 3584 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 18:35:36.0818 3584 RasAcd - ok 18:35:36.0881 3584 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 18:35:36.0881 3584 Rasl2tp - ok 18:35:36.0896 3584 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 18:35:36.0896 3584 RasPppoe - ok 18:35:36.0896 3584 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 18:35:36.0896 3584 Raspti - ok 18:35:36.0927 3584 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 18:35:36.0927 3584 Rdbss - ok 18:35:36.0959 3584 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 18:35:36.0959 3584 RDPCDD - ok 18:35:37.0052 3584 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 18:35:37.0084 3584 RDPWD - ok 18:35:37.0209 3584 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 18:35:37.0209 3584 redbook - ok 18:35:37.0256 3584 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys 18:35:37.0256 3584 RFCOMM - ok 18:35:37.0302 3584 rt2870 (5532f69d0a845ffe9d70b9e0392fe50a) C:\WINDOWS\system32\DRIVERS\rt2870.sys 18:35:37.0318 3584 rt2870 - ok 18:35:37.0459 3584 s125bus (06847aa6f3a9bf7c44134d00a2e578c0) C:\WINDOWS\system32\DRIVERS\s125bus.sys 18:35:37.0459 3584 s125bus - ok 18:35:37.0506 3584 s125mdfl (f83f88e1b125308fb5015ea0349502b0) C:\WINDOWS\system32\DRIVERS\s125mdfl.sys 18:35:37.0506 3584 s125mdfl - ok 18:35:37.0521 3584 s125mdm (402a97756c14940ad6ae5169c2fb105e) C:\WINDOWS\system32\DRIVERS\s125mdm.sys 18:35:37.0521 3584 s125mdm - ok 18:35:37.0552 3584 s125mgmt (82b14c51de76825ec769a6374e4c57d6) C:\WINDOWS\system32\DRIVERS\s125mgmt.sys 18:35:37.0552 3584 s125mgmt - ok 18:35:37.0662 3584 s125obex (bedfc5707c356fd073bf1a4afe442d91) C:\WINDOWS\system32\DRIVERS\s125obex.sys 18:35:37.0662 3584 s125obex - ok 18:35:37.0756 3584 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 18:35:37.0756 3584 Secdrv - ok 18:35:37.0771 3584 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 18:35:37.0771 3584 serenum - ok 18:35:37.0818 3584 Serial (96ba5dd5770a7704d56af931bc9cce0b) C:\WINDOWS\system32\DRIVERS\serial.sys 18:35:37.0818 3584 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\serial.sys. Real md5: 96ba5dd5770a7704d56af931bc9cce0b, Fake md5: cca207a8896d4c6a0c9ce29a4ae411a7 18:35:37.0818 3584 Serial ( Rootkit.Win32.ZAccess.aml ) - infected 18:35:37.0818 3584 Serial - detected Rootkit.Win32.ZAccess.aml (0) 18:35:37.0927 3584 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 18:35:37.0927 3584 Sfloppy - ok 18:35:37.0943 3584 Simbad - ok 18:35:38.0037 3584 SLIP (1ffc44d6787ec1ea9a2b1440a90fa5c1) C:\WINDOWS\system32\DRIVERS\SLIP.sys 18:35:38.0037 3584 SLIP - ok 18:35:38.0099 3584 Sparrow - ok 18:35:38.0131 3584 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 18:35:38.0131 3584 splitter - ok 18:35:38.0146 3584 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 18:35:38.0146 3584 sr - ok 18:35:38.0240 3584 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 18:35:38.0240 3584 Srv - ok 18:35:38.0271 3584 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys 18:35:38.0271 3584 StarOpen - ok 18:35:38.0318 3584 StkAMini (69a926dbca12046633e3d6e6d46e7087) C:\WINDOWS\system32\Drivers\StkAMini.sys 18:35:38.0318 3584 StkAMini - ok 18:35:38.0381 3584 StkScan (83406fb18cb0abfec501add986d63572) C:\WINDOWS\system32\Drivers\StkScan.sys 18:35:38.0381 3584 StkScan - ok 18:35:38.0412 3584 streamip (a9f9fd0212e572b84edb9eb661f6bc04) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 18:35:38.0427 3584 streamip - ok 18:35:38.0568 3584 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 18:35:38.0568 3584 swenum - ok 18:35:38.0584 3584 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 18:35:38.0584 3584 swmidi - ok 18:35:38.0599 3584 symc810 - ok 18:35:38.0615 3584 symc8xx - ok 18:35:38.0615 3584 sym_hi - ok 18:35:38.0631 3584 sym_u3 - ok 18:35:38.0646 3584 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 18:35:38.0646 3584 sysaudio - ok 18:35:38.0756 3584 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 18:35:38.0771 3584 Tcpip - ok 18:35:38.0865 3584 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 18:35:38.0865 3584 TDPIPE - ok 18:35:38.0865 3584 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 18:35:38.0881 3584 TDTCP - ok 18:35:38.0912 3584 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 18:35:38.0912 3584 TermDD - ok 18:35:38.0943 3584 TosIde - ok 18:35:38.0990 3584 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 18:35:38.0990 3584 Udfs - ok 18:35:39.0006 3584 ultra - ok 18:35:39.0021 3584 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 18:35:39.0037 3584 Update - ok 18:35:39.0099 3584 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 18:35:39.0099 3584 usbaudio - ok 18:35:39.0224 3584 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 18:35:39.0224 3584 usbccgp - ok 18:35:39.0318 3584 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 18:35:39.0318 3584 usbehci - ok 18:35:39.0396 3584 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 18:35:39.0396 3584 usbhub - ok 18:35:39.0474 3584 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 18:35:39.0474 3584 usbohci - ok 18:35:39.0834 3584 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 18:35:39.0849 3584 usbprint - ok 18:35:40.0052 3584 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 18:35:40.0068 3584 usbscan - ok 18:35:40.0162 3584 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 18:35:40.0162 3584 USBSTOR - ok 18:35:40.0506 3584 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 18:35:40.0537 3584 VgaSave - ok 18:35:40.0615 3584 ViaIde - ok 18:35:40.0865 3584 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 18:35:40.0865 3584 VolSnap - ok 18:35:41.0068 3584 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 18:35:41.0099 3584 Wanarp - ok 18:35:41.0459 3584 Wdf01000 (4769596d7cc0f5fa447d2babc239672a) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 18:35:41.0474 3584 Wdf01000 - ok 18:35:41.0756 3584 WDICA - ok 18:35:41.0896 3584 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 18:35:41.0927 3584 wdmaud - ok 18:35:42.0224 3584 WLAN(WLAN) (b183823cfa0ec393556261a817cd4ad8) C:\WINDOWS\system32\DRIVERS\zd1211u.sys 18:35:42.0396 3584 WLAN(WLAN) - ok 18:35:42.0584 3584 WSTCODEC (233cdd1c06942115802eb7ce6669e099) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 18:35:42.0584 3584 WSTCODEC - ok 18:35:42.0677 3584 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 18:35:42.0709 3584 WudfPf - ok 18:35:43.0146 3584 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 18:35:43.0193 3584 WudfRd - ok 18:35:43.0412 3584 xusb21 (ee9144207ee0211eb5656ba6808ac4a0) C:\WINDOWS\system32\DRIVERS\xusb21.sys 18:35:43.0412 3584 xusb21 - ok 18:35:43.0506 3584 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 18:35:45.0068 3584 \Device\Harddisk0\DR0 - ok 18:35:45.0099 3584 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR2 18:35:45.0115 3584 \Device\Harddisk1\DR2 - ok 18:35:45.0131 3584 Boot (0x1200) (43ecb6c277c1acc448c48dda2c82a55d) \Device\Harddisk0\DR0\Partition0 18:35:45.0131 3584 \Device\Harddisk0\DR0\Partition0 - ok 18:35:45.0146 3584 Boot (0x1200) (839978f6648c4372c61ae36c697603e1) \Device\Harddisk1\DR2\Partition0 18:35:45.0146 3584 \Device\Harddisk1\DR2\Partition0 - ok 18:35:45.0146 3584 ============================================================ 18:35:45.0146 3584 Scan finished 18:35:45.0146 3584 ============================================================ 18:35:45.0162 3724 Detected object count: 1 18:35:45.0162 3724 Actual detected object count: 1 18:36:12.0943 3724 Backup copy found, using it.. 18:36:12.0943 3724 C:\WINDOWS\system32\DRIVERS\serial.sys - will be cured on reboot 18:36:15.0849 3724 Serial ( Rootkit.Win32.ZAccess.aml ) - User select action: Cure 18:36:24.0115 1484 Deinitialize success
Combofix log

ComboFix 11-12-06.01 - Owner 06/12/2011 18:52:32.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3071.2458 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\LomboFix.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Owner\WINDOWS
c:\windows\$NtUninstallKB49169$
c:\windows\$NtUninstallKB49169$\3057546799\@
c:\windows\$NtUninstallKB49169$\3057546799\bckfg.tmp
c:\windows\$NtUninstallKB49169$\3057546799\cfg.ini
c:\windows\$NtUninstallKB49169$\3057546799\Desktop.ini
c:\windows\$NtUninstallKB49169$\3057546799\keywords
c:\windows\$NtUninstallKB49169$\3057546799\kwrd.dll
c:\windows\$NtUninstallKB49169$\3057546799\L\gzregqij
c:\windows\$NtUninstallKB49169$\3057546799\U\00000001.@
c:\windows\$NtUninstallKB49169$\3057546799\U\00000002.@
c:\windows\$NtUninstallKB49169$\3057546799\U\00000004.@
c:\windows\$NtUninstallKB49169$\3057546799\U\80000000.@
c:\windows\$NtUninstallKB49169$\3057546799\U\80000004.@
c:\windows\$NtUninstallKB49169$\3057546799\U\80000032.@
c:\windows\$NtUninstallKB49169$\4076387898
c:\windows\.log
c:\windows\bwUnin-6.1.4.36-8876480L.exe
c:\windows\jestertb.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_AMSERVICE
——-\Service_AMService
.
.
((((((((((((((((((((((((( Files Created from 2011-11-06 to 2011-12-06 )))))))))))))))))))))))))))))))
.
.
2011-12-06 19:08 . 2011-12-06 19:08 9310 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2011-12-06 19:08 . 2011-12-06 19:08 8646 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-12-06 19:08 . 2011-12-06 19:08 6429 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-12-06 19:08 . 2011-12-06 19:08 63115 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-12-06 19:08 . 2011-12-06 19:08 5927 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2011-12-06 19:08 . 2011-12-06 19:08 4599 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-12-06 19:08 . 2011-12-06 19:08 8613 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2011-12-06 19:08 . 2011-12-06 19:08 1651 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2011-12-06 19:08 . 2011-12-06 19:08 6910 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2011-12-06 19:08 . 2011-12-06 19:08 8288 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2011-12-06 19:08 . 2011-12-06 19:08 6208 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2011-12-06 19:08 . 2011-12-06 19:08 18541 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2011-12-06 19:07 . 2011-12-06 19:07 8782 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-12-06 19:07 . 2011-12-06 19:07 7271 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-12-06 19:07 . 2011-12-06 19:07 51852 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2011-12-06 19:07 . 2011-12-06 19:07 23327 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-12-06 19:07 . 2011-12-06 19:07 20719 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-12-03 14:31 . 2011-12-03 14:31 ——– d—–w- C:\$AVG
2011-12-03 14:04 . 2011-12-03 14:40 ——– d—–w- c:\documents and settings\Owner\Application Data\AVG
2011-12-03 13:42 . 2011-12-03 13:42 ——– d—–w- c:\documents and settings\Owner\Application Data\AVG Secure Search
2011-12-03 13:41 . 2011-12-03 13:42 ——– d—–w- c:\program files\AVG Secure Search
2011-12-03 13:41 . 2011-12-03 13:41 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-03 13:41 . 2011-12-03 13:41 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-12-03 13:39 . 2011-12-03 13:46 ——– d—–w- c:\windows\system32\drivers\AVG
2011-12-03 13:39 . 2011-12-03 13:45 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG2012
2011-12-03 13:39 . 2011-12-03 14:02 ——– d—–w- c:\program files\AVG
2011-12-03 13:38 . 2011-12-03 13:53 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-12-03 13:33 . 2011-12-03 13:33 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2011-12-03 13:32 . 2011-12-03 13:47 ——– d—–w- c:\program files\McAfee
2011-12-03 13:08 . 2011-12-03 13:08 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-13 09:47 . 2011-10-21 22:46 184072 —-a-w- c:\windows\system32\drivers\EuFdDisk.sys
2011-11-13 09:47 . 2011-10-21 22:46 16008 —-a-w- c:\windows\system32\drivers\eudskacs.sys
2011-11-13 09:47 . 2011-10-21 22:46 38920 —-a-w- c:\windows\system32\drivers\eubakup.sys
2011-11-13 09:47 . 2011-10-21 22:46 42376 —-a-w- c:\windows\system32\drivers\EUBKMON.sys
2011-11-13 09:45 . 2011-10-21 22:47 20616 —-a-w- c:\windows\system32\fbnative.exe
2011-11-13 09:45 . 2011-11-13 09:45 ——– d—–w- c:\program files\EaseUS
2011-11-07 17:47 . 2011-11-07 17:47 ——– d—–w- c:\program files\MagicISO
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-06 18:37 . 2006-02-28 12:00 64512 —-a-w- c:\windows\system32\drivers\serial.sys
2011-10-10 14:22 . 2009-01-18 14:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 06:23 . 2011-10-07 06:23 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 06:21 . 2011-10-04 06:21 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2006-02-28 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 19:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 06:30 . 2011-09-13 06:30 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-03 13:41 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7C2F0D8-2209-4693-A15D-5A537211D48B}]
2010-09-02 15:09 1499136 —-a-w- c:\program files\Nectar Search Toolbar\Toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8020143D-5926-4394-A04D-DD0B649DA121}"= "c:\program files\Nectar Search Toolbar\Toolbar.dll" [2010-09-02 1499136]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-03 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{8020143d-5926-4394-a04d-dd0b649da121}]
[HKEY_CLASSES_ROOT\FCTB000061465.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{22466F1F-0B10-41B0-A971-3A28599AA7C7}]
[HKEY_CLASSES_ROOT\FCTB000061465.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8020143D-5926-4394-A04D-DD0B649DA121}"= "c:\program files\Nectar Search Toolbar\Toolbar.dll" [2010-09-02 1499136]
.
[HKEY_CLASSES_ROOT\clsid\{8020143d-5926-4394-a04d-dd0b649da121}]
[HKEY_CLASSES_ROOT\FCTB000061465.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{22466F1F-0B10-41B0-A971-3A28599AA7C7}]
[HKEY_CLASSES_ROOT\FCTB000061465.IEToolbar]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoBackuped]
@="{7E5951A0-8683-432A-9483-5F43168D6A8C}"
[HKEY_CLASSES_ROOT\CLSID\{7E5951A0-8683-432A-9483-5F43168D6A8C}]
2011-09-28 10:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoSelected]
@="{15054241-49B4-4FA6-B4C7-A0071F118110}"
[HKEY_CLASSES_ROOT\CLSID\{15054241-49B4-4FA6-B4C7-A0071F118110}]
2011-09-28 10:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2002-11-23 631362]
"Logitech Utility"="Logi_MwX.Exe" [2002-11-08 19968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-11 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"ProcessLassoManagementConsole"="c:\program files\Process Lasso\processlasso.exe" [2010-08-30 414224]
"ProcessGovernor"="c:\program files\Process Lasso\processgovernor.exe" [2010-08-30 241680]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-10 98304]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Backup & Storage"="c:\program files\VirginMedia\V Stuff Backup\Backup & Storage.exe" [2011-09-28 12465840]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-24 2415456]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-03 218464]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2010-1-21 169472]
Microsoft Office.lnk - c:\program files\Microsoft Office 2000\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Wireless Utility.lnk
backup=c:\windows\pss\Wireless Utility.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^DeskPins.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\DeskPins.lnk
backup=c:\windows\pss\DeskPins.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ActivControl]
2010-12-17 13:37 1094000 —-a-w- c:\program files\Activ Software\ActivDriver\ActivControl2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 11:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-03-17 22:19 136176 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-08-25 11:11 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-08-25 11:11 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2006-11-28 21:08 228088 —-a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-06-13 08:16 528384 —-a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 11:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-01-24 14:48 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-27 01:05 734264 —-a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"bgsvcgen"=2 (0x2)
"SMART Web Server"=3 (0x3)
"SMART Board Service"=3 (0x3)
"RoxMediaDB9"=3 (0x3)
"Response Hardware"=3 (0x3)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Infogrames\\Grand Prix 4\\GP4.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Team17\\Worms World Party\\wwp.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Nectar Search Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\Nectar Search Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Amazon\\MP3 Downloader\\AmazonMP3Downloader.exe"=
"c:\\Program Files\\SMART Technologies\\SMART Response\\ResponseSoftwareService.exe"=
"c:\\Program Files\\SMART Technologies\\SMART Product Drivers\\UCGui.exe"=
"c:\\Program Files\\SMART Technologies\\SMART Product Drivers\\SMARTSNMPAgent.exe"=
"c:\\Program Files\\SMART Technologies\\SMART Product Drivers\\UCService.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera Next\\opera.exe"=
"c:\\Program Files\\EaseUS\\Todo Backup\\bin\\Agent.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\Spotify\\spotify.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11/07/2011 01:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 06:30 32592]
R0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [13/11/2011 09:47 38920]
R0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [13/11/2011 09:47 42376]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [07/10/2011 06:23 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 01:14 295248]
R1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [13/11/2011 09:47 16008]
R1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [13/11/2011 09:47 184072]
R2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [24/10/2011 20:29 2398512]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 06:25 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [02/08/2011 06:09 192776]
R2 EaseUS Agent;EaseUS Agent;c:\program files\EaseUS\Todo Backup\bin\Agent.exe [13/11/2011 09:45 60552]
R2 Guard Agent;Guard Agent;c:\program files\EaseUS\Todo Backup\bin\GuardAgent.exe [13/11/2011 09:45 23176]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [12/08/2011 16:13 87040]
R2 SMART Display Controller;SMART Display Controller;c:\program files\SMART Technologies\SMART Product Drivers\UCService.exe [25/01/2011 17:10 846704]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [03/12/2011 13:41 246624]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [23/05/2011 01:03 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11/07/2011 01:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11/07/2011 01:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [04/10/2011 06:21 16720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [18/01/2009 14:17 1684736]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [23/05/2011 01:03 30944]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [07/08/2011 11:05 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [22/06/2010 17:01 21248]
S3 SMART SNMP Agent Service;SMART SNMP Agent Service;c:\program files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe [25/01/2011 17:13 1678704]
S3 WLAN(WLAN);XPC 802.11b/g Wireless Kit Driver(WLAN);c:\windows\system32\drivers\ZD1211U.sys [16/08/2005 14:50 278016]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
S4 Response Hardware;Response Hardware;c:\program files\SMART Technologies\SMART Response\ResponseHardwareService.exe [04/02/2011 16:48 14704]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-07 c:\windows\Tasks\debutShakeIcon.job
- c:\program files\NCH Software\Debut\debut.exe [2011-10-22 20:49]
.
2011-12-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-03-17 22:19]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-03-17 22:19]
.
2011-10-26 c:\windows\Tasks\videopadShakeIcon.job
- c:\program files\NCH Software\VideoPad\videopad.exe [2011-10-23 08:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1282818778&rver=6.0.5285.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx&lc=2057&id=64855&mkt=en-gb
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{304CF739-292E-4E2A-9414-76780C32B3A3}: NameServer = 192.168.1.1,194.168.4.100,194.168.8.100
TCP: Interfaces\{394666F2-4A2B-46A1-825F-B558D84F8CFE}: NameServer = 192.168.1.1,194.168.4.100
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-18842045.sys
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-Flock Update - c:\documents and settings\Owner\Local Settings\Application Data\Flock\Update\FlockUpdate.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-06 19:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-484763869-412668190-725345543-1003\Software\G*e*n*i*e*"!\FM Genie Scout 11]
"GameDir"="c:\\Documents and Settings\\Owner\\My Documents\\Sports Interactive\\Football Manager 2011\\games"
"ShortlistDir"=""
"FMPath"="c:\\program files\\steam\\steamapps\\common\\football manager 2011\\"
"ScreenshotsDir"="c:\\Documents and Settings\\Owner\\My Documents\\Sports Interactive\\Football Manager 2011"
"SaveDir"="c:\\Documents and Settings\\Owner\\My Documents\\Sports Interactive\\Football Manager 2011\\"
"HistoryDir"="c:\\FM Genie Scout 11\\History Points"
"LangDB"="c:\\program files\\steam\\steamapps\\common\\football manager 2011\\data\\updates\\update-1130\\db\\1130\\lang_db.dat"
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="PSV Eindhoven"
"LastUpdateCheck"=dword:00009f3f
"VersionOf"=dword:0000007b
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000081
"UniqueID"="A4-FD75-2353"
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
"PlayerSearchFeatureNum"=dword:00000000
"StaffSearchFeatureNum"=dword:00000000
"ClubSearchFeatureNum"=dword:00000000
"FilterByClubFeatureNum"=dword:00000000
"CompareFeatureNum"=dword:00000000
"ShortlistFeatureNum"=dword:00000000
"ExportFeatureNum"=dword:00000000
"HistoryFeatureNum"=dword:00000000
"LanguageDBFeatureNum"=dword:00000000
"HintsFeatureNum"=dword:00000000
"GenieReportFeatureNum"=dword:00000000
"TopFormationFeatureNum"=dword:00000000
"ScreenshotFeatureNum"=dword:00000000
.
[HKEY_USERS\S-1-5-21-484763869-412668190-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:f5,43,85,37,33,ef,6a,2d,be,28,a3,4e,0b,bd,37,c1,6e,f6,92,9f,79,
2f,73,92,c8,f3,0e,c3,8f,b1,bd,f6,f8,17,44,c9,3d,00,ca,1f,5e,d6,5f,49,9b,88,\
"rkeysecu"=hex:2d,a0,97,6e,a2,0e,25,80,7f,80,ee,03,96,92,f0,91
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1168)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(3248)
c:\windows\system32\WININET.dll
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\program files\Logitech\iTouch\iTchHk.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\program files\Logitech\MouseWare\system\em_exec.exe
c:\program files\EDIMAX\Common\RalinkRegistryWriter.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\System32\StkASv2K.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\VirginMedia\V Stuff Backup\AGMailAgent.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-12-06 19:14:35 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-06 19:14
.
Pre-Run: 57,071,501,312 bytes free
Post-Run: 57,579,679,744 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 51CBDD25A1AA49865DF548997315BE8E
That went really well,lets continue.


Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please












Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Malwarebytes log Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8323 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 06/12/2011 20:13:08 mbam-log-2011-12-06 (20-13-08).txt Scan type: Quick scan Objects scanned: 163217 Time elapsed: 17 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
ESET scan complete. Log below AVG was running in the background and also found threats in the system restore folders and quarantined 5 items. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=f42458af36859441bb80d070febc30cd # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-06 10:15:50 # local_time=2011-12-06 10:15:50 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777175 100 0 285654 285654 0 0 # compatibility_mode=8192 67108863 100 0 3956 3956 0 0 # scanned=189358 # found=1 # cleaned=1 # scan_time=6726 C:\System Volume Information\_restore{21496528-ACD5-4C5B-96DB-422B061F3ADA}\RP527\A0075825.exe a variant of Win32/MediaGet application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
The system seems to be running pretty well now. Speed is back to normal and haven't had any redirects when searching, which was happening at the weekend.
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.











Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean











[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and save it to your desktop.
  • Scroll down to where it says JDK 7 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 7 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
I was running a java session, so that might have been my vulnerability. Also beefed up my firewall with AVG after being infected - was previously just running the windows firewall. Have followed all the clean up steps. Can I also delete the logs? Thanks for all your help and a speedy resolution.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI