This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

my start incredibar redirect [Solved]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I feel so foolish, I just got rid of the conduit redirect 1 week ago & turned right around & picked up this "mystart" "incredibar" redirect from a "youtube downloader" program downloaded from cnet.com. I scanned the youtube downloader with Malwarebytes anti malware, super antispyware free addition & AVG free at each step of the download & install. ARRRRGH. Plz Help
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back shortly with a response.
Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")

Please disable any running anti-virus, anti-spyware, etc. programs before carrying out a fix as they may interfere.

  • aswMBR

    • Please download aswMBR.exe and save it to your desktop.
    • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
    • When prompted to download virus definitions, please do so.
    • Click Scan. Note: Do NOT attempt any Fix yet.
    • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
    • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
  • OTL

    Download OTL by OldTimer to your Desktop.

    If you already have a copy of OTL, delete it and use this version.

    • Launch OTL.exe.
    • Check the following.
    • Scan all users.
    • Standard Output.
    • Lop check.
    • Purity check.
  • Under Extra Registry section, select Use SafeList
  • Click the Run Scan button and wait for the scan to finish (usually about 10-15 minutes).
  • When finished it will produce two logs.
    • OTL.txt (open on your desktop)
    • Extras.txt (minimized in your taskbar)
  • Please post me both logs.
Thank you so much for your help, here R the logs U asked for

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-08 12:23:49
—————————–
12:23:49.125 OS Version: Windows 5.1.2600 Service Pack 3
12:23:49.125 Number of processors: 2 586 0x401
12:23:49.125 ComputerName: A UserName: b
12:23:50.500 Initialize success
12:25:25.359 AVAST engine defs: 12010801
12:29:04.625 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
12:29:04.625 Disk 0 Vendor: FUJITSU_MHV2080AT_PL 000000A0 Size: 76319MB BusType: 3
12:29:04.656 Disk 0 MBR read successfully
12:29:04.656 Disk 0 MBR scan
12:29:04.734 Disk 0 unknown MBR code
12:29:04.734 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76316 MB offset 63
12:29:04.734 Disk 0 scanning sectors +156296385
12:29:04.812 Disk 0 scanning C:\WINDOWS\system32\drivers
12:29:18.671 Service scanning
12:29:20.000 Modules scanning
12:29:26.484 Module: C:\WINDOWS\system32\dla\tfsndres.sys **SUSPICIOUS**
12:29:28.031 Disk 0 trace - called modules:
12:29:28.046 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
12:29:28.046 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a713ab8]
12:29:28.046 3 CLASSPNP.SYS[f7657fd7] -> nt!IofCallDriver -> \Device\0000007a[0x8a74d268]
12:29:28.046 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a716940]
12:29:28.937 AVAST engine scan C:\WINDOWS
12:29:35.437 AVAST engine scan C:\WINDOWS\system32
12:31:30.718 AVAST engine scan C:\WINDOWS\system32\drivers
12:31:49.375 AVAST engine scan C:\Documents and Settings\b
12:31:58.703 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\b\Desktop\MBR.dat"
12:31:58.703 The log file has been saved successfully to "C:\Documents and Settings\b\Desktop\aswMBR.txt"


+OTL logfile created on: 1/8/2012 12:52:48 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\b\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 61.26% Memory free
3.35 Gb Paging File | 2.69 Gb Available in Paging File | 80.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 56.85 Gb Free Space | 76.28% Space Free | Partition Type: NTFS
Drive E: | 149.01 Gb Total Space | 64.35 Gb Free Space | 43.18% Space Free | Partition Type: FAT32
Drive G: | 1.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 17.59 Mb Total Space | 17.28 Mb Free Space | 98.23% Space Free | Partition Type: FAT

Computer Name: A | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/08 12:33:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\b\Desktop\OTL.exe
PRC - [2012/01/08 12:23:31 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\b\Desktop\aswMBR.exe
PRC - [2012/01/05 01:48:46 | 001,047,024 | —- | M] (Google Inc.) – C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/12/31 16:33:39 | 000,161,664 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011/12/03 01:22:12 | 002,415,456 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 05:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 05:23:34 | 000,973,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 19:53:26 | 000,743,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/18 15:15:51 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2011/08/15 05:21:40 | 000,337,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 05:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/06/28 10:03:22 | 001,843,000 | —- | M] (Orbitdownloader.com) – C:\Program Files\Orbitdownloader\orbitdm.exe
PRC - [2011/06/27 10:05:26 | 000,557,056 | —- | M] (Orbitdownloader.com) – C:\Program Files\Orbitdownloader\orbitnet.exe
PRC - [2011/04/07 20:11:16 | 000,331,776 | —- | M] (Western Digital Technologies, Inc.) – C:\WINDOWS\system32\WDBtnMgr.exe
PRC - [2008/11/09 12:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2004/08/06 14:14:42 | 000,643,072 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
PRC - [2004/08/05 20:49:24 | 000,028,672 | —- | M] (TOSHIBA) – C:\WINDOWS\system32\TCtrlIOHook.exe
PRC - [2004/07/28 15:23:30 | 000,053,248 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
PRC - [2004/07/26 16:32:32 | 000,114,688 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
PRC - [2004/07/14 15:07:32 | 000,024,576 | —- | M] (TOSHIBA) – C:\WINDOWS\system32\ZoomingHook.exe
PRC - [2004/07/13 04:51:04 | 000,892,928 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2004/07/07 14:16:24 | 000,036,864 | —- | M] () – C:\WINDOWS\system32\acs.exe
PRC - [2004/06/15 23:44:06 | 000,036,864 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2004/03/02 12:45:28 | 000,135,168 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
PRC - [2004/02/03 13:47:06 | 001,089,589 | —- | M] (TOSHIBA) – C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
PRC - [2003/12/11 02:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\wdsvc.exe
PRC - [2003/11/12 12:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\retrorun.exe
PRC - [2003/09/26 14:43:00 | 000,184,320 | —- | M] (Agere Systems) – C:\Program Files\ltmoh\ltmoh.exe
PRC - [2003/09/05 02:24:46 | 000,065,536 | —- | M] (TOSHIBA) – C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
PRC - [2003/05/22 20:38:26 | 000,106,496 | —- | M] (Matsushita Electric Industrial Co., Ltd.) – C:\WINDOWS\system32\DVDRAMSV.exe


========== Modules (No Company Name) ==========

MOD - [2011/06/28 10:01:38 | 000,397,312 | —- | M] () – C:\Program Files\Orbitdownloader\wtlctrl.dll
MOD - [2008/04/13 16:11:59 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2004/07/12 06:02:00 | 000,073,728 | —- | M] () – C:\Program Files\Sonic\RecordNow!\shlext.dll
MOD - [2004/07/07 14:16:24 | 000,036,864 | —- | M] () – C:\WINDOWS\system32\acs.exe
MOD - [2001/04/16 15:39:02 | 000,037,808 | —- | M] () – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/12/31 16:33:39 | 000,161,664 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2011/10/12 05:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/18 15:15:51 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2011/08/02 05:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/07/06 18:52:38 | 000,366,640 | —- | M] (Malwarebytes Corporation) [Disabled | Stopped] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2010/02/19 12:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2008/11/09 12:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2006/01/05 00:06:02 | 000,163,840 | —- | M] (Alex Feinman) [On_Demand | Stopped] – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe – (Imapi Helper)
SRV - [2004/07/07 14:16:24 | 000,036,864 | —- | M] () [Auto | Running] – C:\WINDOWS\system32\acs.exe – (ACS)
SRV - [2004/06/15 23:44:06 | 000,036,864 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe – (CFSvcs)
SRV - [2003/12/11 02:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\wdsvc.exe – (RetroWDSvc)
SRV - [2003/11/12 12:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\retrorun.exe – (RetroLauncher)
SRV - [2003/05/22 20:38:26 | 000,106,496 | —- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] – C:\WINDOWS\system32\DVDRAMSV.exe – (DVD-RAM_Service)


========== Driver Services (SafeList) ==========

DRV - [2011/10/07 05:23:48 | 000,230,608 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2011/10/04 05:21:42 | 000,016,720 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2011/09/13 05:30:10 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2011/08/08 05:08:58 | 000,040,016 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/07/22 08:27:02 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2011/07/12 13:55:22 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2011/07/11 00:14:38 | 000,295,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2011/07/11 00:14:28 | 000,024,272 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2011/07/11 00:14:28 | 000,023,120 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2011/07/11 00:14:26 | 000,134,608 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2011/07/06 18:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2011/04/07 17:46:26 | 000,015,890 | —- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2010/05/24 23:59:24 | 000,121,576 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadmdm.sys – (ssadmdm)
DRV - [2010/05/24 23:59:24 | 000,096,488 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadbus.sys – (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2010/05/24 23:59:24 | 000,012,776 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadmdfl.sys – (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2007/02/03 09:32:36 | 000,041,504 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2007/02/03 09:25:56 | 001,075,360 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Camdrl.sys – (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
DRV - [2004/08/20 08:30:36 | 000,006,528 | —- | M] (TOSHIBA ) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\TPwSav.sys – (TPwSav)
DRV - [2004/08/03 14:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/08/02 13:32:26 | 000,004,992 | —- | M] (TOSHIBA ) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\TCtrlIO.sys – (TCtrlIO)
DRV - [2004/07/30 14:05:08 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\SSIOMngr.sys – (SrvcSSIOMngr)
DRV - [2004/07/30 14:05:06 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\TPIOMngr.sys – (SrvcTPIOMngr)
DRV - [2004/07/30 14:05:04 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EKIOMngr.sys – (SrvcEKIOMngr)
DRV - [2004/07/30 14:05:04 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EPIOMngr.sys – (SerTVOutCtlr)
DRV - [2004/07/10 05:37:00 | 000,747,008 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/06/24 19:00:00 | 000,336,244 | —- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ESM7SK.sys – (ESMCR)
DRV - [2004/06/24 18:37:00 | 000,058,240 | —- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\EMS7SK.sys – (EMSCR)
DRV - [2004/06/24 18:37:00 | 000,036,736 | —- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ESD7SK.sys – (ESDCR)
DRV - [2004/06/21 00:53:00 | 000,626,204 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/05/27 18:45:00 | 000,390,944 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ar5211.sys – (AR5211)
DRV - [2004/05/08 04:38:00 | 000,101,833 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2004/02/23 19:08:00 | 000,400,384 | —- | M] (Sensaura) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS)
DRV - [2004/02/20 14:00:00 | 001,265,388 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2004/01/29 17:32:32 | 000,090,480 | —- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\meiudf.sys – (meiudf)
DRV - [2003/10/27 00:59:00 | 000,013,842 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\atisgkaf.sys – (caboagp)
DRV - [2003/09/19 00:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/08/12 23:27:00 | 000,065,280 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtlnic51.sys – (RTL8023)
DRV - [2003/01/28 21:35:00 | 000,012,032 | —- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\Netdevio.sys – (Netdevio)
DRV - [2002/01/24 13:43:40 | 000,006,528 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Tbiosdrv.sys – (TBiosDrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\b\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2011/12/22 12:37:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/22 12:37:20 | 000,000,000 | —D | M]

[2012/01/07 18:40:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: MyStart Search (Enabled)
CHR - default_search_provider: search_url = http://mystart.incredibar.com/?loc=IB_DS&a;…b2liz8&i;=26
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Panda ActiveScan 2.0 (Enabled) = C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: AddThis - Share & Bookmark (new) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde\2.9.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/01/04 20:58:22 | 000,610,942 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 16256 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe ()
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\system32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TFncKy] TFncKy.exe File not found
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [WD Button Manager] C:\WINDOWS\System32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\b\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA45BDE3-54B5-4737-BA88-B1F605D31D42}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\b\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\b\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/01 23:19:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,027,992 | R— | M] (magicJack L.P.) - G:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,016,158 | R— | M] () - G:\autorun.ico – [ CDFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,000,308 | R— | M] () - G:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,706,144 | R— | M] (magicJack L.P.) - G:\autorunu.exe – [ CDFS ]
O32 - AutoRun File - [2008/06/10 15:12:12 | 000,000,270 | —- | M] () - H:\autorun.inf – [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/08 12:33:55 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\b\Desktop\OTL.exe
[2012/01/08 12:23:31 | 004,713,472 | —- | C] (AVAST Software) – C:\Documents and Settings\b\Desktop\aswMBR.exe
[2012/01/08 11:25:23 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\ProgSense
[2012/01/08 11:25:23 | 000,000,000 | —D | C] – C:\Downloads
[2012/01/08 11:25:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Orbit
[2012/01/08 11:25:14 | 000,000,000 | —D | C] – C:\Program Files\Orbitdownloader
[2012/01/08 11:25:14 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Orbit
[2012/01/07 18:40:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/01/07 14:29:10 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Desktop\Conspiracy Docs
[2012/01/05 15:05:34 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\WinZip
[2012/01/05 15:04:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2012/01/05 15:03:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/01/05 15:03:00 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2012/01/04 19:49:11 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2012/01/04 19:05:56 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012/01/03 14:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Desktop\good time pics
[2012/01/02 10:27:02 | 000,000,000 | —D | C] – C:\Program Files\Alex Feinman
[2012/01/02 09:26:01 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\ImgBurn
[2012/01/02 09:22:03 | 000,000,000 | —D | C] – C:\Program Files\ImgBurn
[2012/01/02 09:15:51 | 006,055,875 | —- | C] (LIGHTNING UK!) – C:\Documents and Settings\b\Desktop\SetupImgBurn_2.5.6.0.exe
[2011/12/31 16:38:44 | 000,248,480 | —- | C] (Adobe Systems, Inc.) – C:\Documents and Settings\b\Desktop\uninstall_flash_player_32bit.exe
[2011/12/31 16:35:36 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\Sun
[2011/12/31 16:34:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/12/31 16:34:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/31 16:33:58 | 000,637,848 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npdeployJava1.dll
[2011/12/31 16:33:58 | 000,567,184 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 16:33:58 | 000,223,112 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 16:33:58 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 16:33:58 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2011/12/31 16:33:58 | 000,141,312 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2011/12/31 16:33:33 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/12/31 16:29:45 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/31 10:13:33 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/12/29 14:19:43 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Curiolab
[2011/12/29 14:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\GetRightToGo
[2011/12/21 21:11:10 | 000,000,000 | —D | C] – C:\Documents and Settings\b\My Documents\Recipes
[2011/04/07 17:46:24 | 000,028,672 | —- | C] ( ) – C:\WINDOWS\System32\ControlACS.exe
[2004/09/01 23:03:29 | 000,131,072 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/08 12:36:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006UA.job
[2012/01/08 12:33:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\b\Desktop\OTL.exe
[2012/01/08 12:33:09 | 000,000,544 | —- | M] () – C:\Documents and Settings\b\Desktop\MBR.zip
[2012/01/08 12:31:58 | 000,000,512 | —- | M] () – C:\Documents and Settings\b\Desktop\MBR.dat
[2012/01/08 12:28:00 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/08 12:23:31 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\b\Desktop\aswMBR.exe
[2012/01/08 11:33:46 | 000,002,263 | —- | M] () – C:\Documents and Settings\b\Desktop\Google Chrome.lnk
[2012/01/08 11:33:46 | 000,002,241 | —- | M] () – C:\Documents and Settings\b\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/08 11:25:17 | 000,000,737 | —- | M] () – C:\Documents and Settings\b\Desktop\Orbit.lnk
[2012/01/08 10:35:48 | 000,147,456 | —- | M] () – C:\Documents and Settings\b\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/08 09:54:43 | 000,000,292 | —- | M] () – C:\Documents and Settings\b\Desktop\Shortcut to White lions.lnk
[2012/01/08 09:34:10 | 086,269,174 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/01/08 09:07:51 | 000,000,872 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/08 09:07:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/08 09:07:45 | 1609,617,408 | -HS- | M] () – C:\hiberfil.sys
[2012/01/07 18:40:06 | 000,000,447 | —- | M] () – C:\user.js
[2012/01/07 18:16:41 | 000,222,465 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/01/07 15:36:00 | 000,000,910 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006Core.job
[2012/01/05 17:02:01 | 000,148,014 | —- | M] () – C:\Documents and Settings\b\My Documents\Gregs ROE 2011.pdf
[2012/01/05 15:16:31 | 000,000,777 | —- | M] () – C:\Documents and Settings\b\Desktop\Trillian.lnk
[2012/01/05 15:16:31 | 000,000,705 | —- | M] () – C:\Documents and Settings\b\Start Menu\Programs\Startup\Trillian.lnk
[2012/01/05 15:04:08 | 000,001,743 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/01/05 11:52:19 | 000,000,991 | —- | M] () – C:\Documents and Settings\b\Desktop\magicJack.lnk
[2012/01/04 20:58:22 | 000,610,942 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2012/01/04 19:10:02 | 003,850,224 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/04 02:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-A-b.job
[2012/01/03 15:26:53 | 000,781,450 | —- | M] () – C:\Documents and Settings\b\working opportunity growth fund redemption.jpg
[2012/01/02 10:23:11 | 000,369,152 | —- | M] () – C:\Documents and Settings\b\Desktop\ISORecorderV2RC1.msi
[2012/01/02 10:06:26 | 106,524,672 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2012/01/02 09:22:11 | 000,001,539 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2012/01/02 09:15:58 | 006,055,875 | —- | M] (LIGHTNING UK!) – C:\Documents and Settings\b\Desktop\SetupImgBurn_2.5.6.0.exe
[2011/12/31 16:38:44 | 000,248,480 | —- | M] (Adobe Systems, Inc.) – C:\Documents and Settings\b\Desktop\uninstall_flash_player_32bit.exe
[2011/12/31 16:33:39 | 000,637,848 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npdeployJava1.dll
[2011/12/31 16:33:39 | 000,567,184 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 16:33:39 | 000,223,112 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 16:33:39 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 16:33:39 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2011/12/31 16:33:39 | 000,141,312 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2011/12/31 10:11:00 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
[2011/12/30 15:38:45 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2011/12/27 20:10:36 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 12:37:21 | 000,000,713 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/12/19 09:28:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/15 00:41:38 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/08 12:33:09 | 000,000,544 | —- | C] () – C:\Documents and Settings\b\Desktop\MBR.zip
[2012/01/08 12:31:58 | 000,000,512 | —- | C] () – C:\Documents and Settings\b\Desktop\MBR.dat
[2012/01/08 11:25:17 | 000,000,737 | —- | C] () – C:\Documents and Settings\b\Desktop\Orbit.lnk
[2012/01/07 18:40:06 | 000,000,447 | —- | C] () – C:\user.js
[2012/01/05 17:01:59 | 000,148,014 | —- | C] () – C:\Documents and Settings\b\My Documents\Gregs ROE 2011.pdf
[2012/01/05 15:16:31 | 000,000,705 | —- | C] () – C:\Documents and Settings\b\Start Menu\Programs\Startup\Trillian.lnk
[2012/01/05 15:04:08 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/01/03 23:24:13 | 000,781,450 | —- | C] () – C:\Documents and Settings\b\working opportunity growth fund redemption.jpg
[2012/01/02 10:23:11 | 000,369,152 | —- | C] () – C:\Documents and Settings\b\Desktop\ISORecorderV2RC1.msi
[2012/01/02 09:22:10 | 000,001,539 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/12/30 15:38:25 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2011/09/10 12:30:39 | 000,000,000 | —- | C] () – C:\WINDOWS\JDSecure31.INI
[2011/08/05 20:24:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\06807e882eed5f29381fe74271ecdccf_c
[2011/06/25 09:49:57 | 000,103,509 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/25 09:49:57 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/01 19:57:08 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/06/01 19:57:08 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/06/01 16:27:15 | 000,147,456 | —- | C] () – C:\Documents and Settings\b\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 06:40:39 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/22 12:21:22 | 000,000,113 | —- | C] () – C:\WINDOWS\(null)toolkit.ini
[2011/04/07 17:46:24 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\ControlWZCS.exe
[2011/04/07 17:46:23 | 000,218,003 | —- | C] () – C:\WINDOWS\dssec.dat
[2011/04/07 17:46:23 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2011/04/07 17:46:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2011/04/07 17:33:17 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2011/04/07 17:33:17 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2011/04/07 17:33:17 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2011/04/07 17:33:17 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2011/04/07 17:32:33 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2007/02/03 07:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2004/09/02 09:15:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/09/02 08:33:41 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/09/02 08:13:04 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2004/09/02 08:10:55 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/09/02 08:10:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/09/02 08:10:04 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/09/02 08:10:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/09/02 08:10:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/09/02 08:10:04 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/09/02 08:10:04 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/09/02 08:06:23 | 000,000,000 | —- | C] () – C:\WINDOWS\TPTray.INI
[2004/09/01 23:30:55 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2004/09/01 23:30:40 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\EMCRI.dll
[2004/09/01 23:28:11 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/09/01 23:28:11 | 000,001,048 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2004/09/01 23:28:11 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\alcxhweq.dat
[2004/09/01 23:23:18 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/09/01 23:21:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/09/01 23:17:12 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/09/01 23:03:29 | 000,385,024 | —- | C] () – C:\WINDOWS\System32\ati2evxx.exe
[2004/09/01 23:03:29 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2004/09/01 23:02:55 | 000,002,388 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/09/01 23:02:26 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/01 23:02:23 | 000,441,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/09/01 23:02:23 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/09/01 23:02:23 | 000,071,462 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/09/01 23:02:23 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/09/01 23:02:23 | 000,004,631 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/09/01 23:02:21 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/09/01 23:02:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/09/01 23:02:16 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/09/01 23:02:16 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/09/01 23:02:10 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/09/01 23:02:03 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/09/01 16:12:06 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/01 16:11:14 | 003,850,224 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/07/12 06:18:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini

========== LOP Check ==========

[2011/08/06 18:20:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/12/27 20:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/10/14 14:42:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG
[2011/08/30 22:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2012/01/07 19:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/08/30 22:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Backup
[2011/04/09 08:22:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/10 21:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2012/01/08 09:34:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/11 15:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2011/11/22 07:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2011/10/19 21:52:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Software
[2011/07/17 14:33:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/07/17 12:41:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2011/07/20 08:58:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/08/10 06:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2012/01/05 15:05:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/10/14 10:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG
[2011/04/09 08:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG10
[2011/09/30 16:45:50 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG2012
[2011/08/10 07:27:58 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/29 14:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Curiolab
[2011/12/29 14:12:35 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\GetRightToGo
[2012/01/02 09:26:01 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\ImgBurn
[2004/09/02 08:08:28 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\InterTrust
[2011/06/04 20:11:41 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\InterVideo
[2012/01/05 11:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\mjusbsp
[2011/07/16 11:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\OpenCandy
[2012/01/03 14:54:44 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\OpenOffice.org1.9.79
[2012/01/08 12:34:03 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Orbit
[2012/01/08 11:25:23 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\ProgSense
[2011/11/11 15:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\SmartDraw
[2004/09/02 08:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\toshiba
[2011/04/22 12:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Trillian
[2011/08/03 17:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Unity
[2011/04/07 17:45:57 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 1.job

========== Purity Check ==========



< End of report >


+OTL logfile created on: 1/8/2012 12:52:48 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\b\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 61.26% Memory free
3.35 Gb Paging File | 2.69 Gb Available in Paging File | 80.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 56.85 Gb Free Space | 76.28% Space Free | Partition Type: NTFS
Drive E: | 149.01 Gb Total Space | 64.35 Gb Free Space | 43.18% Space Free | Partition Type: FAT32
Drive G: | 1.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 17.59 Mb Total Space | 17.28 Mb Free Space | 98.23% Space Free | Partition Type: FAT

Computer Name: A | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/08 12:33:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\b\Desktop\OTL.exe
PRC - [2012/01/08 12:23:31 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\b\Desktop\aswMBR.exe
PRC - [2012/01/05 01:48:46 | 001,047,024 | —- | M] (Google Inc.) – C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/12/31 16:33:39 | 000,161,664 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011/12/03 01:22:12 | 002,415,456 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 05:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 05:23:34 | 000,973,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 19:53:26 | 000,743,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/18 15:15:51 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2011/08/15 05:21:40 | 000,337,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 05:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/06/28 10:03:22 | 001,843,000 | —- | M] (Orbitdownloader.com) – C:\Program Files\Orbitdownloader\orbitdm.exe
PRC - [2011/06/27 10:05:26 | 000,557,056 | —- | M] (Orbitdownloader.com) – C:\Program Files\Orbitdownloader\orbitnet.exe
PRC - [2011/04/07 20:11:16 | 000,331,776 | —- | M] (Western Digital Technologies, Inc.) – C:\WINDOWS\system32\WDBtnMgr.exe
PRC - [2008/11/09 12:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2004/08/06 14:14:42 | 000,643,072 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
PRC - [2004/08/05 20:49:24 | 000,028,672 | —- | M] (TOSHIBA) – C:\WINDOWS\system32\TCtrlIOHook.exe
PRC - [2004/07/28 15:23:30 | 000,053,248 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
PRC - [2004/07/26 16:32:32 | 000,114,688 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
PRC - [2004/07/14 15:07:32 | 000,024,576 | —- | M] (TOSHIBA) – C:\WINDOWS\system32\ZoomingHook.exe
PRC - [2004/07/13 04:51:04 | 000,892,928 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2004/07/07 14:16:24 | 000,036,864 | —- | M] () – C:\WINDOWS\system32\acs.exe
PRC - [2004/06/15 23:44:06 | 000,036,864 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2004/03/02 12:45:28 | 000,135,168 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
PRC - [2004/02/03 13:47:06 | 001,089,589 | —- | M] (TOSHIBA) – C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
PRC - [2003/12/11 02:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\wdsvc.exe
PRC - [2003/11/12 12:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\retrorun.exe
PRC - [2003/09/26 14:43:00 | 000,184,320 | —- | M] (Agere Systems) – C:\Program Files\ltmoh\ltmoh.exe
PRC - [2003/09/05 02:24:46 | 000,065,536 | —- | M] (TOSHIBA) – C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
PRC - [2003/05/22 20:38:26 | 000,106,496 | —- | M] (Matsushita Electric Industrial Co., Ltd.) – C:\WINDOWS\system32\DVDRAMSV.exe


========== Modules (No Company Name) ==========

MOD - [2011/06/28 10:01:38 | 000,397,312 | —- | M] () – C:\Program Files\Orbitdownloader\wtlctrl.dll
MOD - [2008/04/13 16:11:59 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2004/07/12 06:02:00 | 000,073,728 | —- | M] () – C:\Program Files\Sonic\RecordNow!\shlext.dll
MOD - [2004/07/07 14:16:24 | 000,036,864 | —- | M] () – C:\WINDOWS\system32\acs.exe
MOD - [2001/04/16 15:39:02 | 000,037,808 | —- | M] () – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/12/31 16:33:39 | 000,161,664 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2011/10/12 05:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/18 15:15:51 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2011/08/02 05:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/07/06 18:52:38 | 000,366,640 | —- | M] (Malwarebytes Corporation) [Disabled | Stopped] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2010/02/19 12:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2008/11/09 12:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2006/01/05 00:06:02 | 000,163,840 | —- | M] (Alex Feinman) [On_Demand | Stopped] – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe – (Imapi Helper)
SRV - [2004/07/07 14:16:24 | 000,036,864 | —- | M] () [Auto | Running] – C:\WINDOWS\system32\acs.exe – (ACS)
SRV - [2004/06/15 23:44:06 | 000,036,864 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe – (CFSvcs)
SRV - [2003/12/11 02:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\wdsvc.exe – (RetroWDSvc)
SRV - [2003/11/12 12:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\retrorun.exe – (RetroLauncher)
SRV - [2003/05/22 20:38:26 | 000,106,496 | —- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] – C:\WINDOWS\system32\DVDRAMSV.exe – (DVD-RAM_Service)


========== Driver Services (SafeList) ==========

DRV - [2011/10/07 05:23:48 | 000,230,608 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2011/10/04 05:21:42 | 000,016,720 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2011/09/13 05:30:10 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2011/08/08 05:08:58 | 000,040,016 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/07/22 08:27:02 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2011/07/12 13:55:22 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2011/07/11 00:14:38 | 000,295,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2011/07/11 00:14:28 | 000,024,272 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2011/07/11 00:14:28 | 000,023,120 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2011/07/11 00:14:26 | 000,134,608 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2011/07/06 18:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2011/04/07 17:46:26 | 000,015,890 | —- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2010/05/24 23:59:24 | 000,121,576 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadmdm.sys – (ssadmdm)
DRV - [2010/05/24 23:59:24 | 000,096,488 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadbus.sys – (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2010/05/24 23:59:24 | 000,012,776 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadmdfl.sys – (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2007/02/03 09:32:36 | 000,041,504 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2007/02/03 09:25:56 | 001,075,360 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Camdrl.sys – (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
DRV - [2004/08/20 08:30:36 | 000,006,528 | —- | M] (TOSHIBA ) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\TPwSav.sys – (TPwSav)
DRV - [2004/08/03 14:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/08/02 13:32:26 | 000,004,992 | —- | M] (TOSHIBA ) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\TCtrlIO.sys – (TCtrlIO)
DRV - [2004/07/30 14:05:08 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\SSIOMngr.sys – (SrvcSSIOMngr)
DRV - [2004/07/30 14:05:06 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\TPIOMngr.sys – (SrvcTPIOMngr)
DRV - [2004/07/30 14:05:04 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EKIOMngr.sys – (SrvcEKIOMngr)
DRV - [2004/07/30 14:05:04 | 000,006,400 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EPIOMngr.sys – (SerTVOutCtlr)
DRV - [2004/07/10 05:37:00 | 000,747,008 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/06/24 19:00:00 | 000,336,244 | —- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ESM7SK.sys – (ESMCR)
DRV - [2004/06/24 18:37:00 | 000,058,240 | —- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\EMS7SK.sys – (EMSCR)
DRV - [2004/06/24 18:37:00 | 000,036,736 | —- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ESD7SK.sys – (ESDCR)
DRV - [2004/06/21 00:53:00 | 000,626,204 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/05/27 18:45:00 | 000,390,944 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ar5211.sys – (AR5211)
DRV - [2004/05/08 04:38:00 | 000,101,833 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2004/02/23 19:08:00 | 000,400,384 | —- | M] (Sensaura) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS)
DRV - [2004/02/20 14:00:00 | 001,265,388 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2004/01/29 17:32:32 | 000,090,480 | —- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\meiudf.sys – (meiudf)
DRV - [2003/10/27 00:59:00 | 000,013,842 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\atisgkaf.sys – (caboagp)
DRV - [2003/09/19 00:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/08/12 23:27:00 | 000,065,280 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtlnic51.sys – (RTL8023)
DRV - [2003/01/28 21:35:00 | 000,012,032 | —- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\Netdevio.sys – (Netdevio)
DRV - [2002/01/24 13:43:40 | 000,006,528 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Tbiosdrv.sys – (TBiosDrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\b\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2011/12/22 12:37:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/22 12:37:20 | 000,000,000 | —D | M]

[2012/01/07 18:40:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: MyStart Search (Enabled)
CHR - default_search_provider: search_url = http://mystart.incredibar.com/?loc=IB_DS&a;…b2liz8&i;=26
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\b\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Panda ActiveScan 2.0 (Enabled) = C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: AddThis - Share & Bookmark (new) = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde\2.9.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/01/04 20:58:22 | 000,610,942 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 16256 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe ()
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\system32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TFncKy] TFncKy.exe File not found
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [WD Button Manager] C:\WINDOWS\System32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\b\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA45BDE3-54B5-4737-BA88-B1F605D31D42}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\b\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\b\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/01 23:19:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,027,992 | R— | M] (magicJack L.P.) - G:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,016,158 | R— | M] () - G:\autorun.ico – [ CDFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,000,308 | R— | M] () - G:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2008/07/21 05:20:07 | 000,706,144 | R— | M] (magicJack L.P.) - G:\autorunu.exe – [ CDFS ]
O32 - AutoRun File - [2008/06/10 15:12:12 | 000,000,270 | —- | M] () - H:\autorun.inf – [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/08 12:33:55 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\b\Desktop\OTL.exe
[2012/01/08 12:23:31 | 004,713,472 | —- | C] (AVAST Software) – C:\Documents and Settings\b\Desktop\aswMBR.exe
[2012/01/08 11:25:23 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\ProgSense
[2012/01/08 11:25:23 | 000,000,000 | —D | C] – C:\Downloads
[2012/01/08 11:25:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Orbit
[2012/01/08 11:25:14 | 000,000,000 | —D | C] – C:\Program Files\Orbitdownloader
[2012/01/08 11:25:14 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Orbit
[2012/01/07 18:40:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/01/07 14:29:10 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Desktop\Conspiracy Docs
[2012/01/05 15:05:34 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\WinZip
[2012/01/05 15:04:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2012/01/05 15:03:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/01/05 15:03:00 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2012/01/04 19:49:11 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2012/01/04 19:05:56 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012/01/03 14:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Desktop\good time pics
[2012/01/02 10:27:02 | 000,000,000 | —D | C] – C:\Program Files\Alex Feinman
[2012/01/02 09:26:01 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\ImgBurn
[2012/01/02 09:22:03 | 000,000,000 | —D | C] – C:\Program Files\ImgBurn
[2012/01/02 09:15:51 | 006,055,875 | —- | C] (LIGHTNING UK!) – C:\Documents and Settings\b\Desktop\SetupImgBurn_2.5.6.0.exe
[2011/12/31 16:38:44 | 000,248,480 | —- | C] (Adobe Systems, Inc.) – C:\Documents and Settings\b\Desktop\uninstall_flash_player_32bit.exe
[2011/12/31 16:35:36 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\Sun
[2011/12/31 16:34:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/12/31 16:34:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/31 16:33:58 | 000,637,848 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npdeployJava1.dll
[2011/12/31 16:33:58 | 000,567,184 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 16:33:58 | 000,223,112 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 16:33:58 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 16:33:58 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2011/12/31 16:33:58 | 000,141,312 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2011/12/31 16:33:33 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/12/31 16:29:45 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/31 10:13:33 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/12/29 14:19:43 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Curiolab
[2011/12/29 14:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\GetRightToGo
[2011/12/21 21:11:10 | 000,000,000 | —D | C] – C:\Documents and Settings\b\My Documents\Recipes
[2011/04/07 17:46:24 | 000,028,672 | —- | C] ( ) – C:\WINDOWS\System32\ControlACS.exe
[2004/09/01 23:03:29 | 000,131,072 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/08 12:36:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006UA.job
[2012/01/08 12:33:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\b\Desktop\OTL.exe
[2012/01/08 12:33:09 | 000,000,544 | —- | M] () – C:\Documents and Settings\b\Desktop\MBR.zip
[2012/01/08 12:31:58 | 000,000,512 | —- | M] () – C:\Documents and Settings\b\Desktop\MBR.dat
[2012/01/08 12:28:00 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/08 12:23:31 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\b\Desktop\aswMBR.exe
[2012/01/08 11:33:46 | 000,002,263 | —- | M] () – C:\Documents and Settings\b\Desktop\Google Chrome.lnk
[2012/01/08 11:33:46 | 000,002,241 | —- | M] () – C:\Documents and Settings\b\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/08 11:25:17 | 000,000,737 | —- | M] () – C:\Documents and Settings\b\Desktop\Orbit.lnk
[2012/01/08 10:35:48 | 000,147,456 | —- | M] () – C:\Documents and Settings\b\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/08 09:54:43 | 000,000,292 | —- | M] () – C:\Documents and Settings\b\Desktop\Shortcut to White lions.lnk
[2012/01/08 09:34:10 | 086,269,174 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/01/08 09:07:51 | 000,000,872 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/08 09:07:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/08 09:07:45 | 1609,617,408 | -HS- | M] () – C:\hiberfil.sys
[2012/01/07 18:40:06 | 000,000,447 | —- | M] () – C:\user.js
[2012/01/07 18:16:41 | 000,222,465 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/01/07 15:36:00 | 000,000,910 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006Core.job
[2012/01/05 17:02:01 | 000,148,014 | —- | M] () – C:\Documents and Settings\b\My Documents\Gregs ROE 2011.pdf
[2012/01/05 15:16:31 | 000,000,777 | —- | M] () – C:\Documents and Settings\b\Desktop\Trillian.lnk
[2012/01/05 15:16:31 | 000,000,705 | —- | M] () – C:\Documents and Settings\b\Start Menu\Programs\Startup\Trillian.lnk
[2012/01/05 15:04:08 | 000,001,743 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/01/05 11:52:19 | 000,000,991 | —- | M] () – C:\Documents and Settings\b\Desktop\magicJack.lnk
[2012/01/04 20:58:22 | 000,610,942 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2012/01/04 19:10:02 | 003,850,224 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/04 02:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-A-b.job
[2012/01/03 15:26:53 | 000,781,450 | —- | M] () – C:\Documents and Settings\b\working opportunity growth fund redemption.jpg
[2012/01/02 10:23:11 | 000,369,152 | —- | M] () – C:\Documents and Settings\b\Desktop\ISORecorderV2RC1.msi
[2012/01/02 10:06:26 | 106,524,672 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2012/01/02 09:22:11 | 000,001,539 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2012/01/02 09:15:58 | 006,055,875 | —- | M] (LIGHTNING UK!) – C:\Documents and Settings\b\Desktop\SetupImgBurn_2.5.6.0.exe
[2011/12/31 16:38:44 | 000,248,480 | —- | M] (Adobe Systems, Inc.) – C:\Documents and Settings\b\Desktop\uninstall_flash_player_32bit.exe
[2011/12/31 16:33:39 | 000,637,848 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npdeployJava1.dll
[2011/12/31 16:33:39 | 000,567,184 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 16:33:39 | 000,223,112 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 16:33:39 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 16:33:39 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2011/12/31 16:33:39 | 000,141,312 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2011/12/31 10:11:00 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
[2011/12/30 15:38:45 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2011/12/27 20:10:36 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 12:37:21 | 000,000,713 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/12/19 09:28:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/15 00:41:38 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/08 12:33:09 | 000,000,544 | —- | C] () – C:\Documents and Settings\b\Desktop\MBR.zip
[2012/01/08 12:31:58 | 000,000,512 | —- | C] () – C:\Documents and Settings\b\Desktop\MBR.dat
[2012/01/08 11:25:17 | 000,000,737 | —- | C] () – C:\Documents and Settings\b\Desktop\Orbit.lnk
[2012/01/07 18:40:06 | 000,000,447 | —- | C] () – C:\user.js
[2012/01/05 17:01:59 | 000,148,014 | —- | C] () – C:\Documents and Settings\b\My Documents\Gregs ROE 2011.pdf
[2012/01/05 15:16:31 | 000,000,705 | —- | C] () – C:\Documents and Settings\b\Start Menu\Programs\Startup\Trillian.lnk
[2012/01/05 15:04:08 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/01/03 23:24:13 | 000,781,450 | —- | C] () – C:\Documents and Settings\b\working opportunity growth fund redemption.jpg
[2012/01/02 10:23:11 | 000,369,152 | —- | C] () – C:\Documents and Settings\b\Desktop\ISORecorderV2RC1.msi
[2012/01/02 09:22:10 | 000,001,539 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/12/30 15:38:25 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2011/09/10 12:30:39 | 000,000,000 | —- | C] () – C:\WINDOWS\JDSecure31.INI
[2011/08/05 20:24:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\06807e882eed5f29381fe74271ecdccf_c
[2011/06/25 09:49:57 | 000,103,509 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/25 09:49:57 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/01 19:57:08 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/06/01 19:57:08 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/06/01 16:27:15 | 000,147,456 | —- | C] () – C:\Documents and Settings\b\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 06:40:39 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/22 12:21:22 | 000,000,113 | —- | C] () – C:\WINDOWS\(null)toolkit.ini
[2011/04/07 17:46:24 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\ControlWZCS.exe
[2011/04/07 17:46:23 | 000,218,003 | —- | C] () – C:\WINDOWS\dssec.dat
[2011/04/07 17:46:23 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2011/04/07 17:46:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2011/04/07 17:33:17 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2011/04/07 17:33:17 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2011/04/07 17:33:17 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2011/04/07 17:33:17 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2011/04/07 17:32:33 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2007/02/03 07:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2004/09/02 09:15:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/09/02 08:33:41 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/09/02 08:13:04 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2004/09/02 08:10:55 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/09/02 08:10:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/09/02 08:10:04 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/09/02 08:10:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/09/02 08:10:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/09/02 08:10:04 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/09/02 08:10:04 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/09/02 08:06:23 | 000,000,000 | —- | C] () – C:\WINDOWS\TPTray.INI
[2004/09/01 23:30:55 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2004/09/01 23:30:40 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\EMCRI.dll
[2004/09/01 23:28:11 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/09/01 23:28:11 | 000,001,048 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2004/09/01 23:28:11 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\alcxhweq.dat
[2004/09/01 23:23:18 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/09/01 23:21:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/09/01 23:17:12 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/09/01 23:03:29 | 000,385,024 | —- | C] () – C:\WINDOWS\System32\ati2evxx.exe
[2004/09/01 23:03:29 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2004/09/01 23:02:55 | 000,002,388 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/09/01 23:02:26 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/01 23:02:23 | 000,441,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/09/01 23:02:23 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/09/01 23:02:23 | 000,071,462 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/09/01 23:02:23 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/09/01 23:02:23 | 000,004,631 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/09/01 23:02:21 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/09/01 23:02:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/09/01 23:02:16 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/09/01 23:02:16 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/09/01 23:02:10 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/09/01 23:02:03 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/09/01 16:12:06 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/01 16:11:14 | 003,850,224 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/07/12 06:18:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini

========== LOP Check ==========

[2011/08/06 18:20:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/12/27 20:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/10/14 14:42:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG
[2011/08/30 22:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2012/01/07 19:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/08/30 22:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Backup
[2011/04/09 08:22:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/10 21:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2012/01/08 09:34:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/11 15:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2011/11/22 07:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2011/10/19 21:52:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Software
[2011/07/17 14:33:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/07/17 12:41:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2011/07/20 08:58:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/08/10 06:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2012/01/05 15:05:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/10/14 10:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG
[2011/04/09 08:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG10
[2011/09/30 16:45:50 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG2012
[2011/08/10 07:27:58 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/29 14:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Curiolab
[2011/12/29 14:12:35 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\GetRightToGo
[2012/01/02 09:26:01 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\ImgBurn
[2004/09/02 08:08:28 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\InterTrust
[2011/06/04 20:11:41 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\InterVideo
[2012/01/05 11:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\mjusbsp
[2011/07/16 11:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\OpenCandy
[2012/01/03 14:54:44 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\OpenOffice.org1.9.79
[2012/01/08 12:34:03 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Orbit
[2012/01/08 11:25:23 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\ProgSense
[2011/11/11 15:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\SmartDraw
[2004/09/02 08:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\toshiba
[2011/04/22 12:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Trillian
[2011/08/03 17:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Unity
[2011/04/07 17:45:57 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 1.job

========== Purity Check ==========



< End of report >
OTL Extras logfile created on: 1/8/2012 12:52:48 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\b\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 61.26% Memory free
3.35 Gb Paging File | 2.69 Gb Available in Paging File | 80.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 56.85 Gb Free Space | 76.28% Space Free | Partition Type: NTFS
Drive E: | 149.01 Gb Total Space | 64.35 Gb Free Space | 43.18% Space Free | Partition Type: FAT32
Drive G: | 1.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 17.59 Mb Total Space | 17.28 Mb Free Space | 98.23% Space Free | Partition Type: FAT

Computer Name: A | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – G:\Adobe InDesign Cs5\Adobe Bridge CS5\Bridge.exe "%L"
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\b\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\b\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\WINDOWS\system32\javaw.exe" = C:\WINDOWS\system32\javaw.exe:*:Enabled:javaw – (Oracle Corporation)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\Documents and Settings\b\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\b\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack – (magicJack L.P.)
"C:\Program Files\Trillian\trillian.exe" = C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian – (Cerulean Studios)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02EED746-8C5A-43C8-BB3D-D29C8B363A4D}" = TOSHIBA Zooming Hotkey Hook
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{16DABD39-A174-4C6B-A2C4-A492E64933C8}" = AVG 2012
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217002FF}" = Java™ 7 Update 2
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{4447D5B5-95ED-4C4D-A9C3-1D8E892D5377}" = AVG 2012
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E74D41C-5864-4561-9F6B-069372513A0B}" = AVG 2012
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{59FDFDFB-52FE-45B1-8A2A-A00079B07FF0}" = TOSHIBA Power Saver Driver
"{5BCA8D15-BCB6-421E-9654-238B43456A4F}" = TOSHIBA Controls Driver
"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{73B69C5C-87D6-471E-B695-0BD736C4B644}" = Retrospect 6.5
"{7D004944-C4F1-4C44-AAD4-E7F85190ED00}" = AVG 2012
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{8398852A-7B61-4808-8F58-D0A40D1B2CB6}" = AVG 2012
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3DDA019-40B7-491C-AC88-62B94491FE8A}" = TouchPad On/Off Utility
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1940CF0-E2DD-11E0-BB25-B8AC6F97B88E}" = Google Earth
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C6}" = WinZip 16.0
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9789BA3-4033-4D81-9B10-7EE99EFA4691}" = OpenOffice.org 1.9.79
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DFC6573E-124D-4026-BFA4-B433C9D3FF21}" = ISO Recorder
"{E171F5DA-6F17-472D-A223-92468142C5E8}" = AVG 2012
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F9450605-65E7-45E4-B071-BD759E10F072}" = TOSHIBA Hotkey Utility
"{F9766AC1-1461-1033-B862-DF8FE1C033BE}" = Adobe InDesign CS5
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2012
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ffdshow_is1" = ffdshow [rev 3124] [2009-11-03]
"HP Photo & Imaging" = HP Image Zone 4.2
"ImgBurn" = ImgBurn
"InstallShield_{A3DDA019-40B7-491C-AC88-62B94491FE8A}" = TouchPad On/Off Utility
"InstallShield_{F9450605-65E7-45E4-B071-BD759E10F072}" = TOSHIBA Hotkey Utility
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSNINST" = MSN
"Orbit_is1" = Orbit Downloader
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"Power Saver" = TOSHIBA Power Saver
"Security Task Manager" = Security Task Manager 1.8d
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"Trillian" = Trillian
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"ZoomPlayer" = Zoom Player (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"magicJack" = magicJack
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/30/2011 8:15:43 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/2/2012 6:55:47 PM | Computer Name = A | Source = CardSpace 3.0.0.0 | ID = 327949
Description = The Windows CardSpace service is too busy to process this request.
User has too many outstanding requests. Additional Information: at System.Environment.GetStackTrace(Exception
e, Boolean needFileInfo) at System.Environment.get_StackTrace() at Microsoft.InfoCards.Diagnostics.InfoCardTrace.BuildMessage(InfoCardBaseException
ie) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.TraceAndLogException(Exception
e) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.ThrowHelperError(Exception
e) at Microsoft.InfoCards.UIAgentMonitor.AddNewClient(UIAgentMonitorHandle handle)

at Microsoft.InfoCards.UIAgentMonitorHandle.CreateAgent(Int32 callerPid, WindowsIdentity
callerIdentity, Int32 tsSessionId) at Microsoft.InfoCards.RequestFactory.CreateClientRequestInstance(UIAgentMonitorHan
dle
monitorHandle, String reqName, IntPtr rpcHandle, Stream inStream, Stream outStream)

at Microsoft.InfoCards.RequestFactory.ProcessNewRequest(Int32 parentRequestHandle,
IntPtr rpcHandle, IntPtr inArgs, IntPtr& outArgs)

Error - 1/3/2012 7:08:35 PM | Computer Name = A | Source = .NET Runtime | ID = 1023
Description = Application: chrome.exe CoreCLR Version: 4.0.60831.0 Description: The
process was terminated due to an internal error in the .NET Runtime at IP 7928D2A6
(79150000) with exit code 8013150a.

Error - 1/3/2012 7:08:41 PM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 16.0.912.63, faulting module
coreclr.dll, version 4.0.60831.0, fault address 0x0013d2a6.

Error - 1/3/2012 7:27:59 PM | Computer Name = A | Source = .NET Runtime | ID = 1023
Description = Application: chrome.exe CoreCLR Version: 4.0.60831.0 Description: The
process was terminated due to an internal error in the .NET Runtime at IP 7928D2A6
(79150000) with exit code 8013150a.

Error - 1/3/2012 7:28:01 PM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 16.0.912.63, faulting module
coreclr.dll, version 4.0.60831.0, fault address 0x0013d2a6.

Error - 1/4/2012 11:01:11 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application magicJack.exe, version 2.0.607.3, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/5/2012 6:56:40 PM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting
module msi196.tmp, version 1.69.9660.0, fault address 0x00010621.

Error - 1/5/2012 6:57:20 PM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting
module msi1a9.tmp, version 1.61.9511.0, fault address 0x0000ed35.

Error - 1/5/2012 7:05:20 PM | Computer Name = A | Source = MsiInstaller | ID = 11316
Description = Product: WinZip Courier – Error 1316. A network error occurred while
attempting to read from the file: C:\DOCUME~1\b\LOCALS~1\Temp\WZSE1.TMP\WZCOURIER35.MSI

[ System Events ]
Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:39 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:40 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/7/2012 11:59:40 PM | Computer Name = A | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126


< End of report >

Attachments:

  • VirusTotal

    We need to upload files to VirusTotal for inspection.

    • Please visit VirusTotal by clicking here.
    • Click the Browse… button and search for the following file:
      • C:\WINDOWS\system32\dla\tfsndres.sys
    • Click Open.
    • Click Send File.
    • Please be patient while the file is scanned.
    • If VirusTotal tells you that the file has already been scanned, click "reanalyse now".
    • Once scanned, copy and paste the link to the results page in your next reply.
    If you're having trouble loading VirusTotal, try VirSCAN or Jotti.

  • OTL

    Run OTL.exe.

    • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      CHR - default_search_provider: MyStart Search (Enabled)
      CHR - default_search_provider: search_url = http://mystart.incredibar.com/?loc=IB_DS&a…b2liz8&i=26
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
      [2011/08/05 20:24:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\06807e882eed5f29381fe74271ecdccf_c
      
      :Commands
      [createrestorepoint]
      [purity]
      [emptytemp]
    • Click the Run Fix button.
    • OTL will now process the instructions.
    • When finished a box will open asking you to open the fix log, click OK.
    • The fix log will open.
    • Copy/Paste the log in your next reply please.

    Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.

  • GMER

    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Launch GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
      • IAT/EAT
      • All drives/partitions except C:\)
      • Show All (don't miss this one)
    • Then click the Scan button & wait for it to finish.
    • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
    • Save it where you can easily find it, such as your desktop, and attach it in your reply.
    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
—-

In your next reply, please include:

  • VirusTotal report
  • OTL.txt
  • Gmer.txt
Hi, unfortunately I lost the link to the virustotal log but the log showwed only a line - in the results column beside every antivirus name
Also, is it important, the fact that I am running XP? I ask because your profile shows U using windows 7
All processes killed
========== OTL ==========
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
C:\Documents and Settings\All Users\Application Data\06807e882eed5f29381fe74271ecdccf_c moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: b
->Temp folder emptied: 74527311 bytes
->Temporary Internet Files folder emptied: 127459940 bytes
->Google Chrome cache emptied: 365111220 bytes
->Flash cache emptied: 23868 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 222 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 39184862 bytes

Total Files Cleaned = 578.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01082012_154846

Files\Folders moved on Reboot…
C:\Documents and Settings\b\Local Settings\Temporary Internet Files\Content.IE5\UT2DW907\index[3].php moved successfully.
C:\Documents and Settings\b\Local Settings\Temporary Internet Files\Content.IE5\UT2DW907\report[1].htm moved successfully.
C:\Documents and Settings\b\Local Settings\Temporary Internet Files\Content.IE5\RRKT8N12\index[5].php moved successfully.
C:\Documents and Settings\b\Local Settings\Temporary Internet Files\Content.IE5\KSA8FZGR\iframe[2].htm moved successfully.

Registry entries deleted on Reboot…

GMER log

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-08 18:51:44
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 FUJITSU_MHV2080AT_PL rev.000000A0
Running: gmer.exe; Driver: C:\DOCUME~1\b\LOCALS~1\Temp\ugtdrpow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xACA9AF3C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAD36D640]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xACA9B080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xACA9B11C]

—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xB9858900]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \FileSystem\Udfs \UdfsCdRom tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-
Hi Jason1970,

It is fine that you are running Windows XP. ;)

  • ComboFix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.
  • Double click on ComboFix.exe & follow the prompts.

  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
—-

How is your computer running now?
the redirect is still there, here is the combofix log

ComboFix 12-01-09.01 - b 01/08/2012 21:26:39.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.789 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\alcrmv.exe
c:\windows\EventSystem.log
.
.
((((((((((((((((((((((((( Files Created from 2011-12-09 to 2012-01-09 )))))))))))))))))))))))))))))))
.
.
2012-01-08 23:48 . 2012-01-08 23:48 ——– d—–w- C:\_OTL
2012-01-08 19:25 . 2012-01-09 00:02 ——– d—–w- C:\Downloads
2012-01-08 19:25 . 2012-01-08 19:25 ——– d—–w- c:\documents and settings\b\Application Data\ProgSense
2012-01-08 19:25 . 2012-01-09 05:22 ——– d—–w- c:\documents and settings\b\Application Data\Orbit
2012-01-08 19:25 . 2012-01-08 19:25 ——– d—–w- c:\program files\Orbitdownloader
2012-01-08 02:40 . 2012-01-08 02:40 447 —-a-w- C:\user.js
2012-01-05 23:05 . 2012-01-05 23:05 ——– d—–w- c:\documents and settings\b\Local Settings\Application Data\WinZip
2012-01-05 23:03 . 2012-01-05 23:05 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2012-01-05 03:49 . 2012-01-05 03:49 ——– d—–w- c:\windows\Sun
2012-01-02 18:27 . 2012-01-02 18:27 ——– d—–w- c:\program files\Alex Feinman
2012-01-02 17:26 . 2012-01-02 17:26 ——– d—–w- c:\documents and settings\b\Application Data\ImgBurn
2012-01-02 17:22 . 2012-01-02 17:22 ——– d—–w- c:\program files\ImgBurn
2012-01-01 00:35 . 2012-01-01 00:35 ——– d—–w- c:\documents and settings\b\Local Settings\Application Data\Sun
2012-01-01 00:34 . 2012-01-01 00:34 ——– d—–w- c:\program files\Common Files\Java
2012-01-01 00:33 . 2012-01-01 00:33 637848 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-01-01 00:33 . 2012-01-01 00:33 567184 —-a-w- c:\windows\system32\deployJava1.dll
2012-01-01 00:33 . 2012-01-01 00:33 141312 —-a-w- c:\windows\system32\javacpl.cpl
2012-01-01 00:33 . 2012-01-01 00:33 ——– d—–w- c:\program files\Java
2011-12-29 22:19 . 2011-12-29 22:19 ——– d—–w- c:\documents and settings\b\Application Data\Curiolab
2011-12-29 22:09 . 2011-12-29 22:12 ——– d—–w- c:\documents and settings\b\Application Data\GetRightToGo
2011-12-28 03:31 . 2008-04-14 00:12 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2004-09-02 07:02 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 20:35 . 2004-09-02 07:02 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2004-09-02 07:02 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:35 . 2004-09-02 07:02 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 16:07 . 2004-09-02 07:02 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02 . 2004-09-02 07:02 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31 . 2004-09-02 07:02 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-09-02 07:02 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-09-02 07:02 186880 —-a-w- c:\windows\system32\encdec.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"cdloader"="c:\documents and settings\b\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-28 4616064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-11 339968]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2004-08-06 643072]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-30 192512]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2004-07-28 53248]
"NDSTray.exe"="NDSTray.exe" [BU]
"ZoomingHook"="c:\windows\System32\ZoomingHook.exe" [2004-07-14 24576]
"TCtryIOHook"="c:\windows\System32\TCtrlIOHook.exe" [2004-08-06 28672]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-07-20 122939]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 1089589]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-03-02 135168]
"TFncKy"="TFncKy.exe" [BU]
"LtMoh"="c:\\Program Files\\ltmoh\\Ltmoh.exe" [2003-09-26 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 88363]
"WD Button Manager"="WDBtnMgr.exe" [2011-04-08 331776]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-09-30 252296]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-02-03 430080]
.
c:\documents and settings\b\Start Menu\Programs\Startup\
Trillian.lnk - c:\program files\Trillian\trillian.exe [2011-1-17 2068832]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\b\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Documents and Settings\\b\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 12:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7/11/2011 12:13 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/11/2011 12:13 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 12:14 AM 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 8:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 1:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [7/18/2011 4:02 PM 116608]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 12:14 AM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 12:14 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [7/11/2011 12:14 AM 16720]
S0 rebllw;rebllw;c:\windows\system32\drivers\sxsrtabj.sys –> c:\windows\system32\drivers\sxsrtabj.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/20/2011 9:08 AM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/20/2011 9:08 AM 136176]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/6/2011 11:57 AM 22712]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [7/20/2011 9:01 AM 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [7/20/2011 9:01 AM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [7/20/2011 9:01 AM 121576]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/6/2011 11:58 AM 366640]
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-04 c:\windows\Tasks\AdobeAAMUpdater-1.0-A-b.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-07-17 10:44]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-20 17:07]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-20 17:07]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006Core.job
- c:\documents and settings\b\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-09 16:03]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006UA.job
- c:\documents and settings\b\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-09 16:03]
.
2011-04-08 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-09-02 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchAssistant =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
TCP: DhcpNameServer = [removed] [removed] [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-08 21:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2012-01-08 21:35:09
ComboFix-quarantined-files.txt 2012-01-09 05:35
.
Pre-Run: 61,404,237,824 bytes free
Post-Run: 61,387,616,256 bytes free
.
- - End Of File - - 957BFAAF6B28EC4B2047582245CC4CA2
I maybe should mention that after I rebooted my computer after the combofix scan I opened my chrome browser to see if the redirect was there & a pop up stated that Google was not my home page & would I like tp make google my home pg so I clicked yes not thinking that it could have been the redirect trying to stay alive. So I closed the chrome browser & reopened it & the redirect was still there.
Open notepad and copy/paste the text in the code box below into it (including the URL, excluding "CODE"):

http://forums.whatthetech.com/index.php?showtopic=121912&st=0&p=767487&#entry767487

Collect::
c:\windows\system32\drivers\sxsrtabj.sys

Driver::
rebllw

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Referring to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

—-

Are you still being redirected?
I don't know what just happened but I did as instructed & Combofix started it's thing so I left my computer to run & came back a few mins later to find windows media player open and an entertainment site of some kind was showing on the screen so I closed it & found Combofix had finished so I went searching for the log & found this 1, & yes I am still being redirected

ComboFix 12-01-09.01 - b 01/08/2012 21:26:39.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.789 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\alcrmv.exe
c:\windows\EventSystem.log
.
.
((((((((((((((((((((((((( Files Created from 2011-12-09 to 2012-01-09 )))))))))))))))))))))))))))))))
.
.
2012-01-08 23:48 . 2012-01-08 23:48 ——– d—–w- C:\_OTL
2012-01-08 19:25 . 2012-01-09 00:02 ——– d—–w- C:\Downloads
2012-01-08 19:25 . 2012-01-08 19:25 ——– d—–w- c:\documents and settings\b\Application Data\ProgSense
2012-01-08 19:25 . 2012-01-09 05:22 ——– d—–w- c:\documents and settings\b\Application Data\Orbit
2012-01-08 19:25 . 2012-01-08 19:25 ——– d—–w- c:\program files\Orbitdownloader
2012-01-08 02:40 . 2012-01-08 02:40 447 —-a-w- C:\user.js
2012-01-05 23:05 . 2012-01-05 23:05 ——– d—–w- c:\documents and settings\b\Local Settings\Application Data\WinZip
2012-01-05 23:03 . 2012-01-05 23:05 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2012-01-05 03:49 . 2012-01-05 03:49 ——– d—–w- c:\windows\Sun
2012-01-02 18:27 . 2012-01-02 18:27 ——– d—–w- c:\program files\Alex Feinman
2012-01-02 17:26 . 2012-01-02 17:26 ——– d—–w- c:\documents and settings\b\Application Data\ImgBurn
2012-01-02 17:22 . 2012-01-02 17:22 ——– d—–w- c:\program files\ImgBurn
2012-01-01 00:35 . 2012-01-01 00:35 ——– d—–w- c:\documents and settings\b\Local Settings\Application Data\Sun
2012-01-01 00:34 . 2012-01-01 00:34 ——– d—–w- c:\program files\Common Files\Java
2012-01-01 00:33 . 2012-01-01 00:33 637848 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-01-01 00:33 . 2012-01-01 00:33 567184 —-a-w- c:\windows\system32\deployJava1.dll
2012-01-01 00:33 . 2012-01-01 00:33 141312 —-a-w- c:\windows\system32\javacpl.cpl
2012-01-01 00:33 . 2012-01-01 00:33 ——– d—–w- c:\program files\Java
2011-12-29 22:19 . 2011-12-29 22:19 ——– d—–w- c:\documents and settings\b\Application Data\Curiolab
2011-12-29 22:09 . 2011-12-29 22:12 ——– d—–w- c:\documents and settings\b\Application Data\GetRightToGo
2011-12-28 03:31 . 2008-04-14 00:12 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2004-09-02 07:02 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 20:35 . 2004-09-02 07:02 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2004-09-02 07:02 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:35 . 2004-09-02 07:02 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 16:07 . 2004-09-02 07:02 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02 . 2004-09-02 07:02 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31 . 2004-09-02 07:02 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-09-02 07:02 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-09-02 07:02 186880 —-a-w- c:\windows\system32\encdec.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"cdloader"="c:\documents and settings\b\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-28 4616064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-11 339968]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2004-08-06 643072]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-30 192512]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2004-07-28 53248]
"NDSTray.exe"="NDSTray.exe" [BU]
"ZoomingHook"="c:\windows\System32\ZoomingHook.exe" [2004-07-14 24576]
"TCtryIOHook"="c:\windows\System32\TCtrlIOHook.exe" [2004-08-06 28672]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-07-20 122939]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 1089589]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-03-02 135168]
"TFncKy"="TFncKy.exe" [BU]
"LtMoh"="c:\\Program Files\\ltmoh\\Ltmoh.exe" [2003-09-26 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 88363]
"WD Button Manager"="WDBtnMgr.exe" [2011-04-08 331776]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-09-30 252296]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-02-03 430080]
.
c:\documents and settings\b\Start Menu\Programs\Startup\
Trillian.lnk - c:\program files\Trillian\trillian.exe [2011-1-17 2068832]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\b\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Documents and Settings\\b\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 12:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7/11/2011 12:13 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/11/2011 12:13 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 12:14 AM 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 8:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 1:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [7/18/2011 4:02 PM 116608]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 12:14 AM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 12:14 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [7/11/2011 12:14 AM 16720]
S0 rebllw;rebllw;c:\windows\system32\drivers\sxsrtabj.sys –> c:\windows\system32\drivers\sxsrtabj.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/20/2011 9:08 AM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/20/2011 9:08 AM 136176]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/6/2011 11:57 AM 22712]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [7/20/2011 9:01 AM 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [7/20/2011 9:01 AM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [7/20/2011 9:01 AM 121576]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/6/2011 11:58 AM 366640]
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-04 c:\windows\Tasks\AdobeAAMUpdater-1.0-A-b.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-07-17 10:44]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-20 17:07]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-20 17:07]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006Core.job
- c:\documents and settings\b\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-09 16:03]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006UA.job
- c:\documents and settings\b\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-09 16:03]
.
2011-04-08 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-09-02 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchAssistant =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
TCP: DhcpNameServer = [removed] [removed] [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-08 21:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2012-01-08 21:35:09
ComboFix-quarantined-files.txt 2012-01-09 05:35
.
Pre-Run: 61,404,237,824 bytes free
Post-Run: 61,387,616,256 bytes free
.
- - End Of File - - 957BFAAF6B28EC4B2047582245CC4CA2
Hi Jason1970,

  • TDSSKiller

    Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and double-click on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)


  • If an infected file is detected, the default action will be Cure, click on Continue.


    🖼Click to load external image (Posted Image)


  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)


  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)


  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
17:50:18.0328 3584 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 17:50:18.0953 3584 ============================================================ 17:50:18.0953 3584 Current date / time: 2012/01/09 17:50:18.0953 17:50:18.0953 3584 SystemInfo: 17:50:18.0953 3584 17:50:18.0953 3584 OS Version: 5.1.2600 ServicePack: 3.0 17:50:18.0953 3584 Product type: Workstation 17:50:18.0953 3584 ComputerName: A 17:50:18.0953 3584 UserName: b 17:50:18.0953 3584 Windows directory: C:\WINDOWS 17:50:18.0953 3584 System windows directory: C:\WINDOWS 17:50:18.0953 3584 Processor architecture: Intel x86 17:50:18.0953 3584 Number of processors: 2 17:50:18.0953 3584 Page size: 0x1000 17:50:18.0953 3584 Boot type: Normal boot 17:50:18.0953 3584 ============================================================ 17:50:28.0765 3584 Initialize success 17:50:32.0484 1000 ============================================================ 17:50:32.0484 1000 Scan started 17:50:32.0484 1000 Mode: Manual; 17:50:32.0484 1000 ============================================================ 17:50:35.0546 1000 Abiosdsk - ok 17:50:35.0593 1000 abp480n5 - ok 17:50:35.0703 1000 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 17:50:35.0703 1000 ACPI - ok 17:50:35.0765 1000 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 17:50:35.0765 1000 ACPIEC - ok 17:50:35.0828 1000 adpu160m - ok 17:50:35.0937 1000 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 17:50:35.0937 1000 aec - ok 17:50:36.0171 1000 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 17:50:36.0187 1000 AFD - ok 17:50:36.0453 1000 AgereSoftModem (052343cd49c8da20c48958cfe73c7d44) C:\WINDOWS\system32\DRIVERS\AGRSM.sys 17:50:36.0562 1000 AgereSoftModem - ok 17:50:36.0640 1000 Aha154x - ok 17:50:36.0765 1000 aic78u2 - ok 17:50:36.0828 1000 aic78xx - ok 17:50:37.0015 1000 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS 17:50:37.0031 1000 ALCXSENS - ok 17:50:37.0156 1000 ALCXWDM (5ff6f7e58c798f1474c0bbffc23cb78d) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 17:50:37.0203 1000 ALCXWDM - ok 17:50:37.0265 1000 AliIde - ok 17:50:37.0312 1000 amsint - ok 17:50:37.0406 1000 ApfiltrService (3ed81e8b4709d13e5a38db2d8e792b28) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 17:50:37.0406 1000 ApfiltrService - ok 17:50:37.0546 1000 AR5211 (466708ae500e11cfa56483ee7fb9ad11) C:\WINDOWS\system32\DRIVERS\ar5211.sys 17:50:37.0546 1000 AR5211 - ok 17:50:37.0671 1000 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 17:50:37.0671 1000 Arp1394 - ok 17:50:37.0718 1000 asc - ok 17:50:37.0750 1000 asc3350p - ok 17:50:37.0765 1000 asc3550 - ok 17:50:37.0828 1000 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 17:50:37.0828 1000 AsyncMac - ok 17:50:37.0906 1000 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 17:50:37.0906 1000 atapi - ok 17:50:37.0984 1000 Atdisk - ok 17:50:38.0218 1000 ati2mtag (3729639e9dd14facf8b927240c5236de) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 17:50:38.0265 1000 ati2mtag - ok 17:50:38.0328 1000 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 17:50:38.0328 1000 Atmarpc - ok 17:50:38.0453 1000 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 17:50:38.0453 1000 audstub - ok 17:50:38.0640 1000 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 17:50:38.0656 1000 AVGIDSDriver - ok 17:50:38.0718 1000 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 17:50:38.0718 1000 AVGIDSEH - ok 17:50:38.0796 1000 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 17:50:38.0796 1000 AVGIDSFilter - ok 17:50:38.0906 1000 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 17:50:38.0921 1000 AVGIDSShim - ok 17:50:39.0093 1000 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 17:50:39.0093 1000 Avgldx86 - ok 17:50:39.0218 1000 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 17:50:39.0218 1000 Avgmfx86 - ok 17:50:39.0312 1000 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 17:50:39.0328 1000 Avgrkx86 - ok 17:50:39.0765 1000 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 17:50:39.0765 1000 Avgtdix - ok 17:50:39.0906 1000 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 17:50:39.0906 1000 Beep - ok 17:50:39.0984 1000 caboagp (906fcf0d1dc5b573015bbd21ef54bd88) C:\WINDOWS\system32\DRIVERS\atisgkaf.sys 17:50:39.0984 1000 caboagp - ok 17:50:40.0109 1000 CamDrL (0f5ca31bb3fdb5c1e63c170cfbecc93b) C:\WINDOWS\system32\DRIVERS\Camdrl.sys 17:50:40.0187 1000 CamDrL - ok 17:50:40.0359 1000 catchme - ok 17:50:40.0437 1000 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 17:50:40.0437 1000 cbidf2k - ok 17:50:40.0484 1000 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 17:50:40.0515 1000 CCDECODE - ok 17:50:40.0546 1000 cd20xrnt - ok 17:50:40.0640 1000 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 17:50:40.0640 1000 Cdaudio - ok 17:50:40.0734 1000 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 17:50:40.0734 1000 Cdfs - ok 17:50:40.0765 1000 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 17:50:40.0765 1000 Cdrom - ok 17:50:40.0781 1000 Changer - ok 17:50:40.0828 1000 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 17:50:40.0843 1000 CmBatt - ok 17:50:40.0859 1000 CmdIde - ok 17:50:40.0875 1000 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 17:50:40.0875 1000 Compbatt - ok 17:50:40.0921 1000 Cpqarray - ok 17:50:40.0937 1000 dac2w2k - ok 17:50:40.0968 1000 dac960nt - ok 17:50:41.0000 1000 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 17:50:41.0000 1000 Disk - ok 17:50:41.0093 1000 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 17:50:41.0140 1000 dmboot - ok 17:50:41.0187 1000 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 17:50:41.0187 1000 dmio - ok 17:50:41.0312 1000 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 17:50:41.0312 1000 dmload - ok 17:50:41.0375 1000 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 17:50:41.0375 1000 DMusic - ok 17:50:41.0437 1000 dpti2o - ok 17:50:41.0500 1000 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 17:50:41.0500 1000 drmkaud - ok 17:50:41.0546 1000 drvmcdb (ae4f1425f8da291136c788fb17d34f4d) C:\WINDOWS\system32\drivers\drvmcdb.sys 17:50:41.0562 1000 drvmcdb - ok 17:50:41.0578 1000 drvnddm (b295700e684ed1984db1d6be40354421) C:\WINDOWS\system32\drivers\drvnddm.sys 17:50:41.0578 1000 drvnddm - ok 17:50:41.0656 1000 EMSCR (6428a1ce5abe3e71a97dfdda0a19546f) C:\WINDOWS\system32\DRIVERS\EMS7SK.sys 17:50:41.0656 1000 EMSCR - ok 17:50:41.0687 1000 ESDCR (6cdec6bd22234133ade3c784373c1177) C:\WINDOWS\system32\DRIVERS\ESD7SK.sys 17:50:41.0687 1000 ESDCR - ok 17:50:41.0718 1000 ESMCR (bb3a330c759b5833914c346019c05a0b) C:\WINDOWS\system32\DRIVERS\ESM7SK.sys 17:50:41.0734 1000 ESMCR - ok 17:50:41.0796 1000 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 17:50:41.0796 1000 Fastfat - ok 17:50:41.0843 1000 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 17:50:41.0843 1000 Fdc - ok 17:50:41.0859 1000 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 17:50:41.0875 1000 Fips - ok 17:50:41.0890 1000 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 17:50:41.0890 1000 Flpydisk - ok 17:50:41.0984 1000 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 17:50:41.0984 1000 FltMgr - ok 17:50:42.0015 1000 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 17:50:42.0015 1000 Fs_Rec - ok 17:50:42.0062 1000 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 17:50:42.0062 1000 Ftdisk - ok 17:50:42.0125 1000 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 17:50:42.0125 1000 Gpc - ok 17:50:42.0171 1000 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 17:50:42.0171 1000 HidUsb - ok 17:50:42.0203 1000 hpn - ok 17:50:42.0265 1000 HPZid412 (5faba4775d4c61e55ec669d643ffc71f) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 17:50:42.0265 1000 HPZid412 - ok 17:50:42.0281 1000 HPZipr12 (a3c43980ee1f1beac778b44ea65dbdd4) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 17:50:42.0296 1000 HPZipr12 - ok 17:50:42.0343 1000 HPZius12 (2906949bd4e206f2bb0dd1896ce9f66f) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 17:50:42.0343 1000 HPZius12 - ok 17:50:42.0421 1000 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 17:50:42.0421 1000 HTTP - ok 17:50:42.0453 1000 i2omgmt - ok 17:50:42.0468 1000 i2omp - ok 17:50:42.0562 1000 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 17:50:42.0562 1000 i8042prt - ok 17:50:42.0625 1000 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 17:50:42.0625 1000 Imapi - ok 17:50:42.0671 1000 ini910u - ok 17:50:42.0687 1000 IntelIde - ok 17:50:42.0734 1000 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 17:50:42.0750 1000 intelppm - ok 17:50:42.0781 1000 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 17:50:42.0781 1000 Ip6Fw - ok 17:50:42.0875 1000 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 17:50:42.0875 1000 IpFilterDriver - ok 17:50:42.0953 1000 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 17:50:42.0953 1000 IpInIp - ok 17:50:43.0000 1000 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 17:50:43.0000 1000 IpNat - ok 17:50:43.0031 1000 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 17:50:43.0046 1000 IPSec - ok 17:50:43.0078 1000 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 17:50:43.0093 1000 IRENUM - ok 17:50:43.0156 1000 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 17:50:43.0156 1000 isapnp - ok 17:50:43.0171 1000 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 17:50:43.0187 1000 Kbdclass - ok 17:50:43.0203 1000 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 17:50:43.0203 1000 kbdhid - ok 17:50:43.0265 1000 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 17:50:43.0265 1000 kmixer - ok 17:50:43.0312 1000 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 17:50:43.0328 1000 KSecDD - ok 17:50:43.0390 1000 lbrtfdc - ok 17:50:43.0484 1000 LVUSBSta (64bc29c3a0388bfc580bb8b1346f7659) C:\WINDOWS\system32\drivers\LVUSBSta.sys 17:50:43.0484 1000 LVUSBSta - ok 17:50:43.0562 1000 MBAMProtector (eca00eed9ab95489007b0ef84c7149de) C:\WINDOWS\system32\drivers\mbam.sys 17:50:43.0562 1000 MBAMProtector - ok 17:50:43.0671 1000 MDC8021X (8fee53c104223973ed9919936d9cd156) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys 17:50:43.0671 1000 MDC8021X - ok 17:50:43.0750 1000 meiudf (6a75fd0b5f008d711dc44d9693e8d632) C:\WINDOWS\system32\Drivers\meiudf.sys 17:50:43.0750 1000 meiudf - ok 17:50:43.0765 1000 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 17:50:43.0781 1000 mnmdd - ok 17:50:43.0828 1000 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 17:50:43.0828 1000 Modem - ok 17:50:43.0859 1000 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 17:50:43.0859 1000 Mouclass - ok 17:50:43.0921 1000 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 17:50:43.0921 1000 mouhid - ok 17:50:43.0968 1000 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 17:50:43.0984 1000 MountMgr - ok 17:50:44.0000 1000 mraid35x - ok 17:50:44.0031 1000 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 17:50:44.0031 1000 MRxDAV - ok 17:50:44.0109 1000 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 17:50:44.0140 1000 MRxSmb - ok 17:50:44.0218 1000 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 17:50:44.0218 1000 Msfs - ok 17:50:44.0296 1000 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 17:50:44.0296 1000 MSKSSRV - ok 17:50:44.0375 1000 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 17:50:44.0375 1000 MSPCLOCK - ok 17:50:44.0421 1000 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 17:50:44.0421 1000 MSPQM - ok 17:50:44.0484 1000 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 17:50:44.0484 1000 mssmbios - ok 17:50:44.0531 1000 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 17:50:44.0531 1000 MSTEE - ok 17:50:44.0578 1000 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 17:50:44.0578 1000 Mup - ok 17:50:44.0640 1000 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 17:50:44.0640 1000 NABTSFEC - ok 17:50:44.0718 1000 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 17:50:44.0718 1000 NDIS - ok 17:50:44.0781 1000 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 17:50:44.0781 1000 NdisIP - ok 17:50:44.0890 1000 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 17:50:44.0890 1000 NdisTapi - ok 17:50:44.0921 1000 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 17:50:44.0921 1000 Ndisuio - ok 17:50:44.0953 1000 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 17:50:44.0953 1000 NdisWan - ok 17:50:45.0000 1000 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 17:50:45.0000 1000 NDProxy - ok 17:50:45.0015 1000 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 17:50:45.0015 1000 NetBIOS - ok 17:50:45.0062 1000 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 17:50:45.0078 1000 NetBT - ok 17:50:45.0125 1000 Netdevio (1265eb253ed4ebe4acb3bd5f548ff796) C:\WINDOWS\system32\DRIVERS\netdevio.sys 17:50:45.0125 1000 Netdevio - ok 17:50:45.0187 1000 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 17:50:45.0203 1000 NIC1394 - ok 17:50:45.0218 1000 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 17:50:45.0218 1000 Npfs - ok 17:50:45.0281 1000 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 17:50:45.0328 1000 Ntfs - ok 17:50:45.0390 1000 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 17:50:45.0406 1000 Null - ok 17:50:45.0453 1000 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 17:50:45.0453 1000 NwlnkFlt - ok 17:50:45.0468 1000 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 17:50:45.0468 1000 NwlnkFwd - ok 17:50:45.0515 1000 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 17:50:45.0515 1000 ohci1394 - ok 17:50:45.0562 1000 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 17:50:45.0578 1000 Parport - ok 17:50:45.0656 1000 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 17:50:45.0656 1000 PartMgr - ok 17:50:45.0703 1000 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 17:50:45.0718 1000 ParVdm - ok 17:50:45.0765 1000 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 17:50:45.0765 1000 PCI - ok 17:50:45.0781 1000 PCIDump - ok 17:50:45.0812 1000 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 17:50:45.0812 1000 PCIIde - ok 17:50:45.0843 1000 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 17:50:45.0859 1000 Pcmcia - ok 17:50:45.0890 1000 PDCOMP - ok 17:50:45.0906 1000 PDFRAME - ok 17:50:45.0937 1000 PDRELI - ok 17:50:45.0953 1000 PDRFRAME - ok 17:50:45.0984 1000 perc2 - ok 17:50:46.0000 1000 perc2hib - ok 17:50:46.0078 1000 Pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys 17:50:46.0078 1000 Pfc - ok 17:50:46.0156 1000 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 17:50:46.0156 1000 PptpMiniport - ok 17:50:46.0218 1000 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 17:50:46.0218 1000 PSched - ok 17:50:46.0250 1000 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 17:50:46.0250 1000 Ptilink - ok 17:50:46.0281 1000 PxHelp20 (d90730239f13a4b05e6d685db5699288) C:\WINDOWS\system32\Drivers\PxHelp20.sys 17:50:46.0281 1000 PxHelp20 - ok 17:50:46.0328 1000 ql1080 - ok 17:50:46.0375 1000 Ql10wnt - ok 17:50:46.0421 1000 ql12160 - ok 17:50:46.0468 1000 ql1240 - ok 17:50:46.0500 1000 ql1280 - ok 17:50:46.0609 1000 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 17:50:46.0609 1000 RasAcd - ok 17:50:46.0656 1000 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 17:50:46.0656 1000 Rasl2tp - ok 17:50:46.0687 1000 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 17:50:46.0687 1000 RasPppoe - ok 17:50:46.0734 1000 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 17:50:46.0734 1000 Raspti - ok 17:50:46.0828 1000 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 17:50:46.0843 1000 Rdbss - ok 17:50:46.0875 1000 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 17:50:46.0890 1000 RDPCDD - ok 17:50:46.0984 1000 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 17:50:47.0000 1000 RDPWD - ok 17:50:47.0015 1000 rebllw - ok 17:50:47.0062 1000 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 17:50:47.0062 1000 redbook - ok 17:50:47.0171 1000 RTL8023 (29f9879a1fd386f7251ae9fdadb2cbf1) C:\WINDOWS\system32\DRIVERS\Rtlnic51.sys 17:50:47.0171 1000 RTL8023 - ok 17:50:47.0250 1000 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 17:50:47.0250 1000 rtl8139 - ok 17:50:47.0406 1000 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 17:50:47.0406 1000 SASDIFSV - ok 17:50:47.0421 1000 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 17:50:47.0421 1000 SASKUTIL - ok 17:50:47.0625 1000 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 17:50:47.0640 1000 sdbus - ok 17:50:47.0750 1000 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 17:50:47.0765 1000 Secdrv - ok 17:50:47.0906 1000 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 17:50:47.0906 1000 Serial - ok 17:50:47.0968 1000 SerTVOutCtlr (c996c839a3261cab5409c61e5702b620) C:\WINDOWS\system32\drivers\EPIOMngr.sys 17:50:47.0984 1000 SerTVOutCtlr - ok 17:50:48.0171 1000 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 17:50:48.0171 1000 Sfloppy - ok 17:50:48.0218 1000 Simbad - ok 17:50:48.0265 1000 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 17:50:48.0265 1000 SLIP - ok 17:50:48.0390 1000 Sparrow - ok 17:50:48.0515 1000 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 17:50:48.0515 1000 splitter - ok 17:50:48.0546 1000 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 17:50:48.0562 1000 sr - ok 17:50:48.0640 1000 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 17:50:48.0656 1000 Srv - ok 17:50:48.0937 1000 SrvcEKIOMngr (3b01a9316255cdd17f9c8e79aa573406) C:\WINDOWS\system32\Drivers\EKIoMngr.sys 17:50:48.0937 1000 SrvcEKIOMngr - ok 17:50:48.0953 1000 SrvcSSIOMngr (79b7af340d55861df1d69e7bac975fcc) C:\WINDOWS\system32\Drivers\SSIoMngr.sys 17:50:48.0968 1000 SrvcSSIOMngr - ok 17:50:49.0000 1000 SrvcTPIOMngr (cbc0be9758bace83fc9ac25f4cca20e7) C:\WINDOWS\system32\Drivers\TPIoMngr.sys 17:50:49.0000 1000 SrvcTPIOMngr - ok 17:50:49.0062 1000 ssadbus (406776fe3c2b66796bac1a7afb9ac8a1) C:\WINDOWS\system32\DRIVERS\ssadbus.sys 17:50:49.0062 1000 ssadbus - ok 17:50:49.0093 1000 ssadmdfl (b19532d015a5d295e2aa34bb521202cf) C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys 17:50:49.0109 1000 ssadmdfl - ok 17:50:49.0187 1000 ssadmdm (2aebf9108e6f435458b9499c27394da4) C:\WINDOWS\system32\DRIVERS\ssadmdm.sys 17:50:49.0203 1000 ssadmdm - ok 17:50:49.0265 1000 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 17:50:49.0265 1000 sscdbhk5 - ok 17:50:49.0328 1000 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 17:50:49.0343 1000 ssrtln - ok 17:50:49.0437 1000 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 17:50:49.0437 1000 streamip - ok 17:50:49.0531 1000 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 17:50:49.0531 1000 swenum - ok 17:50:49.0609 1000 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 17:50:49.0609 1000 swmidi - ok 17:50:49.0640 1000 symc810 - ok 17:50:49.0656 1000 symc8xx - ok 17:50:49.0687 1000 sym_hi - ok 17:50:49.0703 1000 sym_u3 - ok 17:50:49.0750 1000 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 17:50:49.0765 1000 sysaudio - ok 17:50:49.0828 1000 TBiosDrv (1f26d86828039c0b594399f7f2ffef09) C:\WINDOWS\system32\Drivers\Tbiosdrv.sys 17:50:49.0828 1000 TBiosDrv - ok 17:50:49.0906 1000 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 17:50:49.0921 1000 Tcpip - ok 17:50:50.0000 1000 TCtrlIO (812bb312e4ba401770e094447755b478) C:\WINDOWS\system32\drivers\TCtrlIO.sys 17:50:50.0000 1000 TCtrlIO - ok 17:50:50.0062 1000 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 17:50:50.0062 1000 TDPIPE - ok 17:50:50.0078 1000 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 17:50:50.0093 1000 TDTCP - ok 17:50:50.0125 1000 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 17:50:50.0140 1000 TermDD - ok 17:50:50.0203 1000 tfsnboio (12534d6993893ece8ccb6e141eca167b) C:\WINDOWS\system32\dla\tfsnboio.sys 17:50:50.0203 1000 tfsnboio - ok 17:50:50.0218 1000 tfsncofs (2b9b9da9b1d6d29aadd6e25a22c4d07f) C:\WINDOWS\system32\dla\tfsncofs.sys 17:50:50.0234 1000 tfsncofs - ok 17:50:50.0250 1000 tfsndrct (284b4f17ad218b1709831252734e0092) C:\WINDOWS\system32\dla\tfsndrct.sys 17:50:50.0250 1000 tfsndrct - ok 17:50:50.0281 1000 tfsndres (474d8a43a7d4939bfa5bc24abe7499e8) C:\WINDOWS\system32\dla\tfsndres.sys 17:50:50.0281 1000 tfsndres - ok 17:50:50.0312 1000 tfsnifs (8965155985656f130909d9be37d6e8c2) C:\WINDOWS\system32\dla\tfsnifs.sys 17:50:50.0312 1000 tfsnifs - ok 17:50:50.0328 1000 tfsnopio (7187844d442b3b983bab0f98087aa276) C:\WINDOWS\system32\dla\tfsnopio.sys 17:50:50.0328 1000 tfsnopio - ok 17:50:50.0359 1000 tfsnpool (7a82f090a98d692573334f956a9826cc) C:\WINDOWS\system32\dla\tfsnpool.sys 17:50:50.0359 1000 tfsnpool - ok 17:50:50.0375 1000 tfsnudf (9ba9cbc21414475e488af0dab74ed9bd) C:\WINDOWS\system32\dla\tfsnudf.sys 17:50:50.0390 1000 tfsnudf - ok 17:50:50.0406 1000 tfsnudfa (21246b5aa05afe2861a0e30c018c79f6) C:\WINDOWS\system32\dla\tfsnudfa.sys 17:50:50.0406 1000 tfsnudfa - ok 17:50:50.0437 1000 TosIde - ok 17:50:50.0484 1000 TPwSav (9054f1467268aef3949dfc05f2223f89) C:\WINDOWS\system32\DRIVERS\TPwSav.sys 17:50:50.0500 1000 TPwSav - ok 17:50:50.0562 1000 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 17:50:50.0562 1000 Udfs - ok 17:50:50.0609 1000 ultra - ok 17:50:50.0703 1000 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 17:50:50.0734 1000 Update - ok 17:50:50.0796 1000 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 17:50:50.0812 1000 usbaudio - ok 17:50:50.0828 1000 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 17:50:50.0828 1000 usbccgp - ok 17:50:50.0890 1000 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 17:50:50.0890 1000 usbehci - ok 17:50:50.0937 1000 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 17:50:50.0953 1000 usbhub - ok 17:50:50.0984 1000 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 17:50:50.0984 1000 usbohci - ok 17:50:51.0046 1000 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 17:50:51.0046 1000 usbprint - ok 17:50:51.0078 1000 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 17:50:51.0078 1000 usbscan - ok 17:50:51.0093 1000 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 17:50:51.0109 1000 USBSTOR - ok 17:50:51.0125 1000 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 17:50:51.0125 1000 VgaSave - ok 17:50:51.0140 1000 ViaIde - ok 17:50:51.0203 1000 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 17:50:51.0203 1000 VolSnap - ok 17:50:51.0265 1000 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 17:50:51.0281 1000 Wanarp - ok 17:50:51.0296 1000 WDICA - ok 17:50:51.0343 1000 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 17:50:51.0343 1000 wdmaud - ok 17:50:51.0453 1000 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 17:50:51.0453 1000 WS2IFSL - ok 17:50:51.0546 1000 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 17:50:51.0546 1000 WSTCODEC - ok 17:50:51.0625 1000 MBR (0x1B8) (b20939cd98b7710036274839082ae757) \Device\Harddisk0\DR0 17:50:51.0656 1000 \Device\Harddisk0\DR0 - ok 17:50:51.0703 1000 MBR (0x1B8) (a63be3b7eee842a9b05d5348a2ed67d2) \Device\Harddisk1\DR2 17:50:52.0156 1000 \Device\Harddisk1\DR2 - ok 17:50:52.0156 1000 MBR (0x1B8) (8ff255184f078c9c04e6a2ce66117c5c) \Device\Harddisk2\DR4 17:50:52.0171 1000 \Device\Harddisk2\DR4 - ok 17:50:52.0171 1000 Boot (0x1200) (0f72d2ff47c460b228c4d4e79d651495) \Device\Harddisk0\DR0\Partition0 17:50:52.0171 1000 \Device\Harddisk0\DR0\Partition0 - ok 17:50:52.0187 1000 Boot (0x1200) (07cfcaf5712856b643b771fdf05f1e12) \Device\Harddisk2\DR4\Partition0 17:50:52.0187 1000 \Device\Harddisk2\DR4\Partition0 - ok 17:50:52.0187 1000 ============================================================ 17:50:52.0187 1000 Scan finished 17:50:52.0187 1000 ============================================================ 17:50:52.0218 2156 Detected object count: 0 17:50:52.0218 2156 Actual detected object count: 0
Hi Jason1970,

Are you being redirected in all your browsers, or just Chrome?

Please do the following:

Reset your Router:

  • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
  • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • If you don’t know the router's default password, you can look it up. HERE
  • You also need to reconfigure any security settings you had in place prior to the reset.
  • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

NEXT

  • Go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.
the flush did not work, it says "Windows IP Configuration Could not flush the dns resolver cache:function failed during execution" It is only chrome that is affected by the redirect

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI