Virus locked computer [Solved]
28 min read
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
==================================================
Please send the other part of the log, Attach.txt.
Thanks
Satchfan
Meanwhile, please do the following:
Download and run OTL
- download OTL to your desktop.
- double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- when the window appears, underneath Output at the top change it to Minimal Output.
- check the boxes beside LOP Check and Purity Check.
- under Custom Scan paste this in
netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
%appdata%\Microsoft\Windows\Start Menu\*.* /s
%programdata%\Microsoft\Windows\Start Menu\*.* /s
- click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
- when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- you may need two posts to fit them both in.
Run aswMBR
Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
Click to load external image (Posted Image)
On completion of the scan click save log, save it to your desktop and post in your next reply
Click to load external image (Posted Image)
Logs to include with next post:
OTL.txt
Extras.txt
aswMBR log
I have to go out on business now so probably won't reply again until later today.
Thanks
Satchfan
OTL logfile created on: 13/01/2012 10:25:30 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Stan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.92 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 49.98% Memory free
3.84 Gb Paging File | 2.61 Gb Available in Paging File | 68.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 870.39 Gb Free Space | 93.45% Space Free | Partition Type: NTFS
Drive D: | 245.97 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: SMITH | User Name: Colin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Stan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe (Splashtop Inc.)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe (Splashtop Inc.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe (Splashtop Inc.)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe (Splashtop Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (NitroReaderDriverReadSpool2) – C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe (Nitro PDF Software)
SRV:64bit: - (VIAKaraokeService) – C:\Windows\SysNative\ViakaraokeSrv.exe (VIA Technologies, Inc.)
SRV:64bit: - (AppleChargerSrv) – C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (WCUService_STC_FF) – C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe (Splashtop Inc.)
SRV - (WCUService_STC_IE) – C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe (Splashtop Inc.)
SRV - (SCBackService) – C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe (Splashtop Inc.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (avkmgr) – C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AppleCharger) – C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {2877A654-1C9F-4cb5-8438-16022B2FDD9C} - No CLSID value found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 E9 75 A5 9C 95 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {2877A654-1C9F-4cb5-8438-16022B2FDD9C} - No CLSID value found
IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}: C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} [2011/10/24 11:06:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}: C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} [2011/10/24 11:06:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{d9284e50-81fc-11da-a72b-0800200c9a66}: C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} [2011/10/24 11:06:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/10/28 19:26:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/12/12 18:31:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [STCAgent] C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe (Splashtop Inc.)
O4 - HKLM..\Run: [ZyngaGamesAgent] C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe (Splashtop Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{070085F9-871D-440C-8055-CB166F23C919}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/30 03:07:12 | 000,000,038 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{7e6ae660-fe6d-11e0-b519-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7e6ae660-fe6d-11e0-b519-806e6f6e6963}\Shell\AutoRun\command - "" = D:\LGE.EXE – [2009/12/30 20:24:26 | 003,892,532 | R— | M] (Macromedia, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/12 14:04:53 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/01/12 14:02:39 | 000,069,376 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2012/01/12 14:02:39 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012/01/12 14:02:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2012/01/12 14:02:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2012/01/12 14:02:28 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012/01/11 21:17:36 | 000,000,000 | —D | C] – C:\Users\Colin\Desktop\GooredFix Backups
[2012/01/11 21:16:37 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2012/01/11 21:16:36 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2012/01/11 21:16:36 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/01/11 21:16:36 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/01/11 21:16:33 | 000,918,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/01/11 21:16:33 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/01/11 21:16:31 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2012/01/11 21:16:29 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/01/11 21:16:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/01/11 21:06:09 | 000,000,000 | —D | C] – C:\Users\Colin\AppData\Local\ElevatedDiagnostics
[2011/12/25 09:45:26 | 000,000,000 | —D | C] – C:\Users\Colin\AppData\Roaming\Nitro PDF
[2011/12/16 23:41:51 | 000,000,000 | —D | C] – C:\Users\Colin\AppData\Roaming\HpUpdate
[2011/12/16 23:41:49 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/12/15 09:18:54 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/15 09:18:48 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/12/15 09:18:48 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/15 09:18:48 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/15 09:18:48 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/15 09:18:48 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/15 09:18:48 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/15 09:18:47 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/15 09:18:44 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/15 09:18:44 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
========== Files - Modified Within 30 Days ==========
[2012/01/13 08:34:12 | 000,022,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 08:34:12 | 000,022,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 08:31:15 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/13 08:31:15 | 000,628,024 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/13 08:31:15 | 000,110,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/13 08:27:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/13 08:27:00 | 1545,674,752 | -HS- | M] () – C:\hiberfil.sys
[2012/01/12 14:04:53 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/01/12 14:04:52 | 000,016,432 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2012/01/12 14:02:40 | 000,001,060 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2012/01/08 23:49:59 | 000,607,260 | R— | M] (Swearware) – C:\Users\Colin\Desktop\dds.scr
[2012/01/08 23:18:13 | 000,000,448 | —- | M] () – C:\ProgramData\yOXIZiPZMCY1Ej
[2012/01/08 23:15:26 | 000,000,296 | —- | M] () – C:\ProgramData\~yOXIZiPZMCY1Ej
[2012/01/08 23:15:26 | 000,000,200 | —- | M] () – C:\ProgramData\~yOXIZiPZMCY1Ejr
[2011/12/25 00:28:00 | 000,000,326 | —- | M] () – C:\Users\Colin\Desktop\HP Printer Diagnostic Tools.url
[2011/12/23 07:12:12 | 000,069,376 | —- | M] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/12/15 12:54:13 | 000,414,040 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2012/01/12 15:02:50 | 000,016,432 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2012/01/12 14:02:40 | 000,001,060 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2012/01/08 23:15:26 | 000,000,296 | —- | C] () – C:\ProgramData\~yOXIZiPZMCY1Ej
[2012/01/08 23:15:26 | 000,000,200 | —- | C] () – C:\ProgramData\~yOXIZiPZMCY1Ejr
[2012/01/08 23:15:22 | 000,000,448 | —- | C] () – C:\ProgramData\yOXIZiPZMCY1Ej
[2011/12/25 00:28:00 | 000,000,326 | —- | C] () – C:\Users\Colin\Desktop\HP Printer Diagnostic Tools.url
[2011/10/28 19:20:46 | 000,221,537 | —- | C] () – C:\Windows\hpoins19.dat
[2011/10/28 19:20:46 | 000,013,898 | —- | C] () – C:\Windows\hpomdl19.dat
[2011/10/24 11:10:06 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2011/10/24 11:07:53 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2011/10/24 11:07:52 | 013,356,032 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011/10/24 11:07:52 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011/10/24 11:07:52 | 000,218,304 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/10/24 11:07:52 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2011/10/24 11:04:52 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2009/08/27 07:04:14 | 000,207,400 | R— | C] () – C:\Windows\GSetup.exe
[2009/07/14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/10/31 15:01:36 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\Azureus
[2011/11/01 15:50:53 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\DVDVideoSoft
[2011/11/01 15:50:47 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/12/25 09:45:26 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\Nitro PDF
[2011/10/24 11:06:25 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\Splashtop
[2009/07/14 05:08:49 | 000,029,796 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/01/13 08:26:57 | 000,000,489 | —- | M] () – C:\aaw7boot.log
[2011/10/24 11:10:33 | 000,000,180 | —- | M] () – C:\csb.log
[2012/01/13 08:27:00 | 1545,674,752 | -HS- | M] () – C:\hiberfil.sys
[2011/10/31 09:32:26 | 000,000,319 | —- | M] () – C:\hide fold back up.fhf
[2011/10/28 19:49:38 | 000,000,400 | —- | M] () – C:\InstallHelper.log
[2012/01/13 08:27:00 | 2060,902,400 | -HS- | M] () – C:\pagefile.sys
[2012/01/11 21:20:25 | 000,073,624 | —- | M] () – C:\TDSSKiller.2.7.0.0_11.01.2012_21.19.41_log.txt
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/28 17:50:39 | 000,000,221 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< %appdata%\Microsoft\Windows\Start Menu\*.* /s >
[2011/10/24 10:29:28 | 000,000,174 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
[2011/10/28 18:05:33 | 000,000,696 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
[2011/10/24 10:29:29 | 000,001,409 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/10/24 10:29:29 | 000,001,443 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/10/28 18:05:33 | 000,001,422 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk
[2009/07/14 04:54:27 | 000,001,280 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk
[2009/07/14 04:54:32 | 000,000,678 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
[2009/07/14 04:54:32 | 000,001,304 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk
[2009/07/14 04:49:38 | 000,001,228 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
[2009/07/14 04:54:02 | 000,000,704 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
[2009/07/14 04:54:01 | 000,001,358 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk
[2009/07/14 04:54:00 | 000,001,258 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk
[2009/07/14 04:54:02 | 000,001,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
[2009/07/14 04:54:00 | 000,001,250 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk
[2011/10/24 10:29:29 | 000,000,738 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
[2011/10/24 10:29:29 | 000,001,493 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[2009/07/14 04:54:59 | 000,001,306 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk
[2011/10/24 10:29:28 | 000,000,174 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
[2011/10/28 22:08:13 | 000,002,333 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Karen's Power Tools\Replicator.lnk
[2009/07/14 04:49:38 | 000,000,318 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk
[2011/10/24 10:29:28 | 000,000,174 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
< %programdata%\Microsoft\Windows\Start Menu\*.* /s >
[2009/07/14 05:01:14 | 000,001,282 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
[2009/07/14 05:01:14 | 000,000,442 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
[2011/10/28 19:25:24 | 000,001,321 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk
[2009/07/14 04:49:40 | 000,001,266 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
[2011/10/24 18:27:13 | 000,001,130 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
[2011/10/24 11:09:03 | 000,001,214 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
[2011/10/28 19:25:35 | 000,001,054 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/10/24 18:27:11 | 000,001,345 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/11/11 10:17:12 | 000,002,098 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011/11/03 22:45:37 | 000,002,507 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Reader 2.lnk
[2009/07/14 04:57:08 | 000,001,330 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2009/07/14 04:57:09 | 000,001,352 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/10/24 18:27:13 | 000,001,326 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2009/07/14 04:54:59 | 000,001,210 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2010/11/21 03:40:30 | 000,001,547 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2009/07/14 04:57:08 | 000,001,246 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2009/07/14 04:55:00 | 000,001,230 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk
[2011/10/24 18:27:10 | 000,001,726 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
[2009/07/14 04:54:23 | 000,001,266 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk
[2011/10/24 18:27:06 | 000,001,364 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk
[2011/10/24 18:27:05 | 000,001,238 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk
[2009/07/14 04:54:32 | 000,001,242 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk
[2009/07/14 04:53:55 | 000,001,367 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk
[2011/10/24 18:27:10 | 000,001,272 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk
[2009/07/14 04:57:08 | 000,001,330 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk
[2011/10/24 18:27:10 | 000,001,351 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk
[2009/07/14 04:54:58 | 000,001,254 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk
[2009/07/14 04:57:09 | 000,001,579 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk
[2009/07/14 04:54:58 | 000,001,322 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk
[2009/07/14 04:57:07 | 000,000,370 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
[2009/07/14 04:57:07 | 000,001,388 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk
[2009/07/14 04:55:00 | 000,001,248 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk
[2009/07/14 04:57:09 | 000,001,338 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
[2009/07/14 04:54:25 | 000,001,290 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk
[2009/07/14 04:54:58 | 000,001,252 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk
[2009/07/14 04:53:50 | 000,001,242 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk
[2009/07/14 04:53:33 | 000,001,250 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk
[2009/07/14 04:54:57 | 000,001,246 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk
[2009/07/14 04:54:29 | 000,001,268 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk
[2009/07/14 04:57:09 | 000,001,320 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk
[2009/07/14 04:57:09 | 000,001,316 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk
[2011/10/24 18:27:13 | 000,000,343 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
[2011/10/24 18:27:13 | 000,001,436 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk
[2011/10/24 18:27:11 | 000,001,386 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk
[2011/10/24 18:27:06 | 000,001,316 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk
[2009/07/14 04:57:13 | 000,000,216 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
[2009/07/14 05:32:31 | 000,001,989 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk
[2009/07/14 04:57:13 | 000,001,468 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk
[2009/07/14 04:57:13 | 000,001,468 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk
[2009/07/14 05:32:31 | 000,001,899 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
[2009/07/14 04:57:13 | 000,001,242 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk
[2009/07/14 04:54:21 | 000,001,294 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk
[2009/07/14 04:53:52 | 000,001,270 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk
[2009/07/14 04:57:13 | 000,001,674 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
[2009/07/14 04:54:29 | 000,001,298 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk
[2009/07/14 04:54:22 | 000,001,274 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk
[2009/07/14 04:53:33 | 000,001,268 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk
[2011/10/29 15:49:41 | 000,001,539 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 2.0 Configuration.lnk
[2009/07/14 04:53:50 | 000,001,232 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk
[2009/07/14 04:54:05 | 000,001,288 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 04:53:33 | 000,001,246 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk
[2009/07/14 04:54:29 | 000,001,262 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk
[2009/07/14 04:53:58 | 000,001,274 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk
[2009/07/14 05:32:31 | 000,002,741 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk
[2011/10/29 18:26:52 | 000,001,269 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 4.0\Acrobat Reader 4.0.lnk
[2011/10/29 18:26:52 | 000,001,034 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 4.0\Uninstall Adobe Acrobat 4.0.lnk
[2011/10/29 18:28:42 | 000,001,184 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Photoshop 6.0\Adobe ImageReady 3.0.lnk
[2011/10/29 18:28:42 | 000,001,174 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Photoshop 6.0\Adobe Photoshop 6.0.lnk
[2011/10/28 18:28:50 | 000,002,067 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira Free Antivirus Help.lnk
[2011/10/28 18:28:50 | 000,002,083 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira on the Internet.lnk
[2011/10/28 18:28:50 | 000,001,200 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Display readme.lnk
[2011/10/28 18:28:50 | 000,002,090 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Start Avira Free Antivirus.lnk
[2011/10/31 09:38:21 | 000,000,082 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url
[2011/10/31 09:38:21 | 000,000,840 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk
[2011/10/31 09:38:21 | 000,000,603 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk
[2011/11/01 15:50:42 | 000,001,237 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Fix components.lnk
[2011/11/01 15:50:42 | 000,001,257 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Free Studio Manager.lnk
[2011/11/01 15:50:42 | 000,001,347 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Rocket Subscription.lnk
[2011/11/01 15:50:42 | 000,001,217 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Uninstall.lnk
[2011/11/01 15:50:41 | 000,001,319 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free Audio CD Burner.lnk
[2011/11/01 15:50:42 | 000,001,422 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free YouTube to MP3 Converter.lnk
[2011/10/28 19:48:55 | 000,002,061 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay\eBay Turbo Lister 2.lnk
[2011/10/31 08:40:12 | 000,001,031 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide Folder\Free Hide Folder Homepage.lnk
[2011/10/31 08:40:12 | 000,000,982 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide Folder\Free Hide Folder.lnk
[2011/10/31 08:40:12 | 000,000,989 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide Folder\Uninstall Free Hide Folder.lnk
[2011/10/24 18:27:06 | 000,000,352 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk
[2011/10/24 18:27:06 | 000,001,128 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
[2009/07/14 04:55:00 | 000,000,364 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\FreeCell.lnk
[2009/07/14 04:54:59 | 000,000,258 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk
[2009/07/14 04:57:12 | 000,000,356 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Hearts.lnk
[2011/10/24 18:27:06 | 000,000,474 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Backgammon.lnk
[2011/10/24 18:27:05 | 000,000,470 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Checkers.lnk
[2011/10/24 18:27:06 | 000,000,466 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Spades.lnk
[2011/10/24 18:27:06 | 000,000,360 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjong.lnk
[2009/07/14 04:57:12 | 000,000,376 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk
[2009/07/14 04:57:12 | 000,000,370 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\More Games from Microsoft.lnk
[2009/07/14 04:57:12 | 000,000,378 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Purble Place.lnk
[2009/07/14 04:55:01 | 000,000,368 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk
[2009/07/14 04:57:12 | 000,000,392 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Spider Solitaire.lnk
[2011/10/28 19:25:24 | 000,001,333 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Solution Center.lnk
[2011/12/16 23:42:02 | 000,002,109 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Update.lnk
[2011/10/28 19:25:18 | 000,001,055 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Shop for HP Supplies.lnk
[2011/10/28 19:26:02 | 000,002,189 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 3.5\HP Photosmart Essential 3.5.lnk
[2011/10/28 19:26:02 | 000,002,363 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 3.5\Uninstall HP Photosmart Essential 3.5.lnk
[2011/10/28 19:26:13 | 000,002,421 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Smart Web Printing\HP Smart Web Printing Help.lnk
[2011/10/28 19:29:00 | 000,001,329 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Add A Device.lnk
[2011/10/28 19:29:00 | 000,000,950 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Help.lnk
[2011/10/28 19:29:00 | 000,001,119 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Product Registration.lnk
[2011/10/28 19:29:00 | 000,001,349 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Product Support Website.lnk
[2011/10/28 19:29:00 | 000,001,234 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Readme.lnk
[2011/10/28 19:29:00 | 000,001,522 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Uninstall.lnk
[2011/10/24 11:10:12 | 000,000,103 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\desktop.ini
[2011/10/24 11:10:12 | 000,001,427 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel Control Center.lnk
[2011/10/31 09:37:18 | 000,002,315 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Karen's Power Tools\Replicator.lnk
[2012/01/12 14:02:40 | 000,002,014 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware Manual.lnk
[2012/01/12 14:02:40 | 000,002,055 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware Update.lnk
[2012/01/12 14:02:40 | 000,001,084 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware.lnk
[2012/01/12 14:02:40 | 000,002,093 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Lavasoft Homepage.lnk
[2012/01/12 14:02:40 | 000,000,950 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Uninstall Ad-Aware.lnk
[2012/01/12 14:02:40 | 000,001,858 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Toolbox\ThreatWork.lnk
[2009/07/14 04:57:07 | 000,001,304 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk
[2009/07/14 04:57:07 | 000,001,248 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk
[2009/07/14 04:57:09 | 000,000,606 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
[2009/07/14 04:57:09 | 000,001,212 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk
[2011/10/31 00:31:35 | 000,002,643 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk
[2011/10/29 15:49:40 | 000,002,655 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk
[2011/10/29 15:49:41 | 000,002,697 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk
[2011/10/31 00:32:11 | 000,002,687 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk
[2011/10/29 15:49:41 | 000,002,619 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk
[2011/10/29 15:49:41 | 000,002,693 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk
[2011/10/29 15:49:41 | 000,002,645 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk
[2011/10/29 15:49:41 | 000,002,611 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk
[2011/10/29 15:49:41 | 000,002,693 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk
[2011/10/29 15:49:41 | 000,002,647 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk
[2011/10/29 15:49:41 | 000,002,627 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk
[2011/10/29 15:49:41 | 000,002,527 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk
[2011/10/29 15:49:41 | 000,002,625 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk
[2011/10/29 15:49:41 | 000,002,605 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk
[2011/10/29 15:45:29 | 000,001,273 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005\Visual Studio Tools\Visual Studio 2005 Remote Debugger Configuration Wizard.lnk
[2011/10/29 18:28:43 | 000,001,253 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
[2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2011/10/28 19:24:56 | 000,002,099 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/11/02 08:59:37 | 000,002,000 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\Uninstall.lnk
[2011/11/02 08:59:37 | 000,000,063 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\Web site.url
[2011/11/02 08:59:37 | 000,000,072 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\YouTube Downloader Help.url
[2011/11/02 08:59:37 | 000,002,056 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\YouTube Downloader.lnk
< End of report >
OTL Extras logfile created on: 13/01/2012 10:25:30 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Stan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.92 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 49.98% Memory free
3.84 Gb Paging File | 2.61 Gb Available in Paging File | 68.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 870.39 Gb Free Space | 93.45% Space Free | Partition Type: NTFS
Drive D: | 245.97 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: SMITH | User Name: Colin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{5CF37F1F-7C84-421C-8E7A-C8859CCFEBD3}" = Nitro Reader 2
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"CCleaner" = CCleaner
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Shop for HP Supplies" = Shop for HP Supplies
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09F25F86-F957-4051-8AB2-0E0D948BBB5D}" = 1310
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 3.4
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3B983EFD-6E37-4AD9-9A7D-8C83E61674F7}" = Splashtop Connect IE
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45D49CA7-D7D8-4659-B35A-EBD98C30AF28}" = Splashtop Connect for Firefox
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D4553DF-2095-4D10-92C0-17934733B51D}" = 1310_Help
"{6D7E031C-4C05-4265-854A-FE9FDEA9984D}" = 1310Trb
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{8927E07C-97F7-4A54-88FB-D976F50DD46E}" = Turbo Lister 2
"{8E9976D2-E563-43DE-A51F-5AEBC38D1F08}" = Ad-Aware
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{ACEB2BAF-96DF-48FD-ADD5-43842D4C443D}" = Adobe AIR
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe AIR" = Adobe AIR
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"Adobe SVG Viewer" = Adobe SVG Viewer
"Avira AntiVir Desktop" = Avira Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free Hide Folder" = Free Hide Folder
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.11.923
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Karen's Replicator" = Karen's Replicator
"Mozilla Thunderbird 9.0.1 (x86 en-GB)" = Mozilla Thunderbird 9.0.1 (x86 en-GB)
"VLC media player" = VLC media player 1.1.11
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 09/01/2012 04:29:35 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 09/01/2012 05:30:09 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 09/01/2012 06:04:16 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 11/01/2012 17:06:53 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 11/01/2012 17:11:21 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 11/01/2012 17:21:43 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 11/01/2012 17:53:56 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 12/01/2012 04:37:01 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 12/01/2012 07:02:15 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
Error - 13/01/2012 04:27:05 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 11/01/2012 17:21:30 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5
Error - 11/01/2012 17:21:31 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5
Error - 11/01/2012 17:53:44 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5
Error - 11/01/2012 17:53:44 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5
Error - 12/01/2012 04:36:35 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5
Error - 12/01/2012 04:36:36 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5
Error - 12/01/2012 07:01:20 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5
Error - 12/01/2012 07:01:20 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5
Error - 13/01/2012 04:27:04 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5
Error - 13/01/2012 04:27:04 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5
< End of report >
I'd like you to run a different couple of scans
Run TDSSKiller
Please download TDSSKiller.zip
- extract it to your desktop
- double click TDSSKiller.exe
- press Start Scan
only if Malicious objects are found then ensure Cure is selected
then click Continue > Reboot now - copy and paste the log in your next reply
- a copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
Download and run ComboFix
Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Double click on ComboFix.exe & follow the prompts.
- when finished, it will produce a report for you.
- please post the C:\ComboFix.txt and TDSSKiller log.
Satchfan
That log and the ComboFix log looked good.
P2P - I see you have P2P software, (Azureus), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as as their main form of transport for spreading their filth.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.
Should you decide to keep it, please don’t use it until we have finished up here.
===================================================
Download Malwarebytes-Anti-Malware
Click here
- double-click mbam-setup.exe and follow the prompts to install the program.
- at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
- if an update is found, it will download and install the latest version.
- once the program has loaded, select Perform quick scan, then click Scan.
- when the scan is complete, click OK, then Show Results to view the results.
- be sure that everything is checked, and click Remove Selected.
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
================================================
Run Security Check
Download Security Check by screen317 from here or here.
- Save it to your Desktop.
- Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
- A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Mbam.txt
Checkup.txt
Please tell me if there are any remaining symptoms.
Thanks
Satchfan
A couple of other questions.
1. When the virus installed I lost some files off the desktop and also my web favourites, neither is an issue as I do have an external back up but can I assume they will need to be reinstalled etc.
2. Avira I have been unable to update their files should I uninstall and then re install, I also appear to have conflict with avira and adware running and I am sure there is mention of windows defender. What should be on and what off?
In previous PCs I had this spot on but since upgrading to Win 7 I am still trying to find my way around to an extent.
Mbam text…
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.14.02
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Colin :: SMITH [administrator]
14/01/2012 16:24:53
mbam-log-2012-01-14 (16-24-53).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213273
Time elapsed: 1 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCU\Software\SkyMedia (Adware.SkyMedia) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\Colin\Downloads\cnet_ScreenGrabPro_zip.exe (PUP.CNET.Adware.Bundle) -> Quarantined and deleted successfully.
C:\Users\Colin\Downloads\getreader.exe (PUP.BundleInstaller.OI) -> Quarantined and deleted successfully.
(end)
……………………………………………………………………..
………..
Check up….
Results of screen317's Security Check version 0.99.30
Windows 7 x64 (UAC is enabled)
Internet Explorer 8 Out of date!
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
Avira Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Ad-Aware
Mozilla Firefox (for..)
Mozilla Thunderbird (x86 en-GB..)
````````````````````````````````
Process Check:
objlist.exe by Laurent
Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe
Avira Antivir avgnt.exe
``````````End of Log````````````
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI