Infected/win32//Fakesysdef [Closed]
66 min read
My name is Satchfan and I would be glad to help you with your computer problem.
IMPORTANT DO NOT run any programs unless asked or you may not get your missing files/folders back.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
You can try directly downloading these to the desktop and will probably be able to see them as long as you don’t reboot but if you can’t see them, save them to a flash drive and run them from there.
Run RogueKiller
Note: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run roguekiller again
Download RogueKiller to your desktop.
- close all running programs
- for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
- when prompted, type 1 and press Enter
- the RKreport.txt will be generated next to the executable, (on the desktop).
If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Remember: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run roguekiller again
===================================================
Run Unhide
Download Unhide.exe
Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run. This program will remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run.
Satchfan
thanks for your help..I opened unhide first then ran Roguekiller…
Here is the report from Roguekiller
RogueKiller V6.2.4 [01/12/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Owner [Admin rights]
Mode: Scan – Date : 01/25/2012 07:35:19
¤¤¤ Bad processes: 2 ¤¤¤
[SUSP PATH] V0350Mon.exe – C:\WINDOWS\V0350Mon.exe -> KILLED [TermProc]
[SUSP PATH] WeatherEye.exe – C:\Documents and Settings\Owner\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 13 ¤¤¤
[SUSP PATH] HKCU\[…]\Run : WeatherEye (C:\Documents and Settings\Owner\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe) -> FOUND
[SUSP PATH] HKLM\[…]\Run : V0350Mon.exe (C:\WINDOWS\V0350Mon.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-1908935787-3774082646-2132798181-1003[…]\Run : WeatherEye (C:\Documents and Settings\Owner\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe) -> FOUND
[WallPP] HKCU\[…]\Desktop : Wallpaper () -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowUser (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ] HKCU\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
[…]
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
— User —
[MBR] 0c45dbe12ed3f2b12bab63c0bb27c7ca
[BSP] 785403c40b2e57190234204681ec45a9 : MBR Code unknown
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 8835750 | Size: 155515 Mo
1 - [XXXXXX] FAT32 [VISIBLE] Offset (sectors): 63 | Size: 4523 Mo
2 - [XXXXXX] NTFS [HIDDEN!] Offset (sectors): 312576705 | Size: 2 Mo
User = LL1 … OK!
User = LL2 … OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
Download and run OTL
- download OTL to your desktop.
- double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- when the window appears, underneath Output at the top change it to Minimal Output.
- check the boxes beside LOP Check and Purity Check.
- under Custom Scan paste this in
netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
%appdata%\Microsoft\Windows\Start Menu\*.* /s
%programdata%\Microsoft\Windows\Start Menu\*.* /s
- click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
- when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- you may need two posts to fit them both in.
Run aswMBR
- download aswMBR.exe to your desktop.
- double click the aswMBR.exe to run it
- if asked, accept the AVAST virus definition download
- click the "Scan" button to start scan
- on completion of the scan click Save log, save it to your desktop and post in your next reply
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
Here are the first 2 from OTL
OTL logfile created on: 1/25/2012 9:39:20 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
501.53 Mb Total Physical Memory | 47.32 Mb Available Physical Memory | 9.44% Memory free
1.20 Gb Paging File | 0.69 Gb Available in Paging File | 57.92% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.83 Gb Total Space | 123.35 Gb Free Space | 85.17% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 1.67 Gb Free Space | 39.83% Space Free | Partition Type: FAT32
Computer Name: HEATHER | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\AGI\core\4.2.0.10754\AGCoreService.exe (AG Interactive)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\zHotkey.exe ()
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\34449ab6ace474494e782a831f7d6050\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f0401e48e7cc962cd42ce56247e76b79\System.Configuration.Install.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\c01c7686e392bd6ed929c9f6075723b8\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\e86477a3569303b7984658ab8537028c\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\8334ba1b9bd3d989b48c5849d776c948\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\0115819dcd2638560c9fe8f4523a6776\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\4e82a0b51b82ffb8127c48c7d13485d7\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\Program Files\Lexmark 1200 Series\ConvDIB.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL ()
MOD - C:\WINDOWS\zHotkey.exe ()
MOD - C:\WINDOWS\HKNTDLL.dll ()
========== Win32 Services (SafeList) ==========
SRV - (McAfee SiteAdvisor Service) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AGCoreService) – C:\Program Files\AGI\core\4.2.0.10754\AGCoreService.exe (AG Interactive)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
========== Driver Services (SafeList) ==========
DRV - (MpKsl63b2b899) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF995668-C374-4D49-AB8F-D9CBA4C1C009}\MpKsl63b2b899.sys (Microsoft Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (VF0350Afx) – C:\WINDOWS\system32\drivers\V0350Afx.sys (Creative Technology Ltd.)
DRV - (VF0350Vid) Live! Cam Video Chat (VF0350) – C:\WINDOWS\system32\drivers\V0350Vid.sys (Creative Technology Ltd.)
DRV - (VF0350Vfx) – C:\WINDOWS\system32\drivers\V0350Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (SunkFilt39) – C:\WINDOWS\system32\drivers\Sunkfilt39.sys (Alcor Micro Corp.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o;=14196
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Components: C:\Program Files\Flock\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Plugins: C:\Program Files\Flock\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.2\extensions\\Components: C:\Program Files\Flock\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.2\extensions\\Plugins: C:\Program Files\Flock\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 20:59:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/13 05:05:57 | 000,000,000 | —D | M]
[2010/03/10 16:10:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/03/10 16:10:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2011/11/16 06:26:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\blt0eygm.default\extensions
[2011/10/25 14:48:22 | 000,002,568 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\blt0eygm.default\searchplugins\askcom.xml
[2011/04/10 11:10:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\BLT0EYGM.DEFAULT\EXTENSIONS\{C6FB3A99-0BF0-4AB3-9B5B-9FE631D6CDE3}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\BLT0EYGM.DEFAULT\EXTENSIONS\[removed]
[2010/03/25 20:45:49 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/30 20:59:17 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 02:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/10 05:39:14 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/02/12 20:38:19 | 000,429,858 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14799 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [ShowWnd] C:\WINDOWS\ShowWnd.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [V0350Mon.exe] C:\WINDOWS\V0350Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\ccleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [WeatherEye] C:\Documents and Settings\Owner\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe (Pelmorex Media Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\3.1.5.7619\Launcher.exe (Webshots.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: skillsoft.com ([support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: wwwskillwsa.com ([]* in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1267658964562 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1267659049906 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15116/CTPID.cab (Creative Software AutoUpdate Support Package 1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{31C6F763-C5BA-4F6D-95C5-2987B73E8DE9}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\sacore - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 12:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/25 09:24:26 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/25 09:23:14 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/25 07:34:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\RK_Quarantine
[2012/01/25 06:58:13 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner\Recent
[2012/01/23 17:37:51 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/01/23 16:56:11 | 000,200,976 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2012/01/23 16:50:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\System Check
[2012/01/18 10:41:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\BlackBerry
[2012/01/18 10:34:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Research In Motion
[2012/01/18 10:34:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Research In Motion
[2012/01/18 07:27:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2012/01/18 07:25:55 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/17 19:46:57 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsgXP_2k3.dll
[2012/01/17 19:46:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\BlackBerry
[2012/01/17 19:46:06 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion
[2012/01/17 19:46:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/25 09:39:01 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1908935787-3774082646-2132798181-1003UA.job
[2012/01/25 09:24:26 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/25 09:23:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/25 07:44:01 | 000,111,872 | —- | M] () – C:\WINDOWS\System32\drivers\TrueSight.sys
[2012/01/25 07:28:56 | 000,684,297 | —- | M] () – C:\Documents and Settings\Owner\Desktop\unhide.exe
[2012/01/25 07:25:26 | 000,789,504 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/01/25 07:02:45 | 000,000,424 | —- | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/01/25 06:57:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/25 06:57:32 | 525,959,168 | -HS- | M] () – C:\hiberfil.sys
[2012/01/24 22:39:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1908935787-3774082646-2132798181-1003Core.job
[2012/01/23 16:50:41 | 000,000,296 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~RlZt6bOqrBSHvD
[2012/01/23 16:50:41 | 000,000,184 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~RlZt6bOqrBSHvDr
[2012/01/23 16:50:39 | 000,000,853 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/23 16:50:36 | 000,000,328 | —- | M] () – C:\Documents and Settings\All Users\Application Data\RlZt6bOqrBSHvD
[2012/01/21 20:40:11 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/21 14:14:36 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2012/01/18 22:13:17 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/01/18 10:39:21 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01007.Wdf
[2012/01/18 07:29:50 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimSerial_01007.Wdf
[2012/01/18 07:27:52 | 000,001,956 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2012/01/17 19:49:17 | 000,442,796 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/17 19:49:17 | 000,071,936 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/17 19:47:05 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2012/01/17 19:47:03 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/01/16 23:00:13 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/27 06:36:36 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/25 07:34:46 | 000,111,872 | —- | C] () – C:\WINDOWS\System32\drivers\TrueSight.sys
[2012/01/25 07:33:50 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/01/25 07:33:50 | 000,002,187 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2012/01/25 07:33:50 | 000,001,956 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2012/01/25 07:33:50 | 000,001,751 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Dell Jukebox by musicmatch.lnk
[2012/01/25 07:33:50 | 000,001,750 | —- | C] () – C:\Documents and Settings\All Users\Desktop\IncrediMail.lnk
[2012/01/25 07:33:50 | 000,001,605 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Snail Mail.lnk
[2012/01/25 07:33:50 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2012/01/25 07:33:50 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/01/25 07:33:50 | 000,000,853 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/25 07:33:50 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2012/01/25 07:33:50 | 000,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Webshots Daily Features.lnk
[2012/01/25 07:33:50 | 000,000,759 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2012/01/25 07:33:50 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/01/25 07:33:50 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/01/25 07:33:45 | 000,001,994 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Journal Viewer.lnk
[2012/01/25 07:33:45 | 000,001,986 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2012/01/25 07:33:45 | 000,001,961 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2003.lnk
[2012/01/25 07:33:45 | 000,001,878 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2012/01/25 07:33:45 | 000,001,854 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Safari.lnk
[2012/01/25 07:33:45 | 000,001,756 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\IncrediMail.lnk
[2012/01/25 07:33:45 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/01/25 07:33:45 | 000,001,603 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Picture It! Photo Premium 9.lnk
[2012/01/25 07:33:45 | 000,001,096 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\MSN Encarta Plus.lnk
[2012/01/25 07:33:45 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012/01/25 07:33:45 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Webshots Daily Features.lnk
[2012/01/25 07:33:45 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/01/25 07:28:55 | 000,684,297 | —- | C] () – C:\Documents and Settings\Owner\Desktop\unhide.exe
[2012/01/25 07:25:21 | 000,789,504 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/01/23 16:50:41 | 000,000,296 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~RlZt6bOqrBSHvD
[2012/01/23 16:50:41 | 000,000,184 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~RlZt6bOqrBSHvDr
[2012/01/23 16:50:35 | 000,000,328 | —- | C] () – C:\Documents and Settings\All Users\Application Data\RlZt6bOqrBSHvD
[2012/01/21 02:01:17 | 000,467,176 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/01/18 10:39:21 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01007.Wdf
[2012/01/18 07:29:50 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimSerial_01007.Wdf
[2012/01/17 19:47:05 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2012/01/17 19:47:03 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/11/16 08:11:58 | 000,249,278 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\census.cache
[2011/11/16 08:11:37 | 000,210,074 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\ars.cache
[2011/11/16 08:02:14 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\housecall.guid.cache
[2011/08/19 20:14:11 | 000,484,352 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/09/09 19:40:58 | 000,001,708 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2010/08/03 17:14:29 | 000,000,256 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2010/05/10 13:19:05 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2010/04/05 18:32:23 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/03/19 19:34:17 | 000,000,366 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/03/19 19:34:13 | 000,000,076 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/03/17 18:03:10 | 000,041,096 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/03/08 21:16:15 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/03/07 08:37:42 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2010/03/06 20:42:38 | 000,027,136 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 10:12:43 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2010/03/03 10:04:09 | 000,000,029 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2010/03/03 08:27:10 | 000,471,300 | —- | C] () – C:\WINDOWS\wallpe.exe
[2010/03/03 08:24:31 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/03 08:22:46 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\RTCOMDLL.dll
[2010/03/03 08:22:46 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/03/03 08:22:46 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/03/03 08:22:26 | 000,543,232 | —- | C] () – C:\WINDOWS\zHotkey.exe
[2010/03/03 08:22:26 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2010/03/03 08:22:26 | 000,036,864 | —- | C] () – C:\WINDOWS\ShowWnd.exe
[2010/03/03 08:22:26 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2010/03/03 08:12:57 | 000,000,060 | —- | C] () – C:\WINDOWS\System32\SYSDRV.DAT
[2010/03/03 08:12:41 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/01/30 06:42:22 | 000,000,270 | —- | C] () – C:\WINDOWS\System32\lxczcoin.ini
[2004/08/27 04:50:59 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/27 03:54:47 | 000,516,096 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2004/08/26 12:07:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/26 12:01:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/26 10:12:43 | 000,001,222 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/08/26 10:12:43 | 000,000,486 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/08/26 10:12:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/26 10:12:10 | 000,442,796 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/26 10:12:10 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/26 10:12:10 | 000,071,936 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/26 10:12:10 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/26 10:12:08 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/26 10:12:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/26 10:12:05 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/26 10:12:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/26 10:11:59 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/26 10:11:54 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/26 10:11:46 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/26 04:54:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/26 04:54:01 | 000,212,880 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/05/24 12:33:16 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\LEXPING.EXE
[2002/11/13 01:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxczvs.dll
[2001/01/19 01:50:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE
========== LOP Check ==========
[2010/03/06 19:02:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\agi
[2011/02/28 11:00:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/04/03 20:14:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/19 19:54:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/10/23 10:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/03/04 13:00:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2010/03/04 12:58:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2011/04/24 06:58:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2010/10/23 11:24:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/12/27 21:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Photo Notifier and Animation Creator
[2010/06/17 18:27:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PhotoMail
[2012/01/18 07:27:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/02/23 12:45:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/03/30 11:50:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2011/11/07 08:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/03 08:25:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/11 09:05:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/04 14:09:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/07 05:59:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AGI
[2010/10/23 10:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG10
[2011/10/24 19:23:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/03/08 07:42:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/04/24 10:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flock
[2011/08/19 20:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FreeBurner
[2011/04/24 10:06:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mjusbsp
[2010/07/22 15:56:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MPEG Streamclip
[2012/01/18 10:36:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Research In Motion
[2010/03/03 08:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2010/08/27 17:40:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SecondLife
[2010/08/03 17:16:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2010/08/06 09:37:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TrueSwitch
[2010/03/06 19:03:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Webshots
[2011/03/09 21:31:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WebshotsDailyFeatures.D47BD63EE77CC0AC7AE23BFA386A3F1EDA7C080D.1
[2011/05/03 15:30:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Live Writer
[2012/01/25 07:02:45 | 000,000,424 | —- | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/26 12:04:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/12 20:26:05 | 000,000,245 | -HS- | M] () – C:\boot.ini
[2004/08/26 12:04:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/01/25 06:57:32 | 525,959,168 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/08/26 12:04:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/03/03 08:25:40 | 000,000,848 | —- | M] () – C:\IPH.PH
[2004/08/26 12:04:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/10/03 06:52:51 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/01/25 06:57:24 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2010/03/03 08:23:04 | 000,000,391 | —- | M] () – C:\RtlAudio_Result.txt
[2010/03/19 19:54:52 | 000,000,168 | —- | M] () – C:\setupfax.log
[2004/10/30 09:41:53 | 000,000,118 | —- | M] () – C:\SmartInstaller.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/19 11:33:38 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 15:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/12/19 06:40:00 | 000,001,658 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/26 04:53:19 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/26 04:53:18 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/26 04:53:18 | 000,864,256 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/10/03 07:00:26 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/01/25 09:24:26 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2011/11/16 07:55:56 | 002,002,320 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HousecallLauncher.exe
[2012/01/25 09:23:15 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/25 07:25:26 | 000,789,504 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/01/25 07:28:56 | 000,684,297 | —- | M] () – C:\Documents and Settings\Owner\Desktop\unhide.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-12 13:58:08
< %appdata%\Microsoft\Windows\Start Menu\*.* /s >
Invalid Environment Variable: programdata
========== Alternate Data Streams ==========
@Alternate Data Stream - 227 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1E16035B
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1AE68282
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37FE31AD
< End of report >
OTL Extras logfile created on: 1/25/2012 9:39:20 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
501.53 Mb Total Physical Memory | 47.32 Mb Available Physical Memory | 9.44% Memory free
1.20 Gb Paging File | 0.69 Gb Available in Paging File | 57.92% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.83 Gb Total Space | 123.35 Gb Free Space | 85.17% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 1.67 Gb Free Space | 39.83% Space Free | Partition Type: FAT32
Computer Name: HEATHER | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe
"C:\Program Files\IncrediMail\Bin\IncMail.exe" = C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImApp.exe" = C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe" = C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer
"C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe" = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe:*:Enabled:TODO: – (TODO: )
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows – (Ares Development Group)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Disabled:BitTorrent
"C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe:*:Disabled:magicJack
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Disabled:AOL
"C:\Program Files\Microsoft Security Client\msseces.exe" = C:\Program Files\Microsoft Security Client\msseces.exe:*:Disabled:Microsoft Security Essentials – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Mozilla Firefox – (Mozilla Corporation)
"C:\Program Files\FrostWire 5\FrostWire.exe" = C:\Program Files\FrostWire 5\FrostWire.exe:*:Enabled:FrostWire
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1C933E76-5795-48D2-BB38-1FFD64AACA4F}" = BlackBerry Device Manager 6.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24b169c2-b793-44b3-b826-28f3d8ba609f}" = DFX for Musicmatch
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{2857dbef-0b50-361c-8690-7d505747009f}" = Webshots Desktop
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5171512e-ab28-4ac9-bd9b-f1a21a07c003}" = DFX for Windows Media Player
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{75AE8014-1184-4BC0-B279-C879540719EE}" = PhotoMail Maker
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{772997BF-C04E-4FD2-B04F-24D06D649C68}" = Windows Live Install Wizard
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11231247}" = Peggle
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9819EF4D-7A28-54B5-8A25-CE97793845A4}" = Webshots Daily Features
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CCF13D13-A87B-34E8-B689-1896D0C2DBA2}" = Google Talk Plugin
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D95877BE-0165-42EC-B558-727F9F41372C}" = oobeFlagNetscape0
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel
"{F909BB1B-3FC1-4EDA-AF1F-8F1A89163591}" = BlackBerry Desktop Software 6.1
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = Multimedia Keyboard Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"Ares" = Ares 2.1.7
"BlackBerry_{1C933E76-5795-48D2-BB38-1FFD64AACA4F}" = BlackBerry Device Manager 6.1
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = Soft Data Fax Modem with SmartCP
"Creative Live! Cam Center" = Creative Live! Cam Center
"Creative Live! Cam Manager" = Creative Live! Cam Manager
"Creative Live! Cam User's Guide" = Creative Live! Cam User's Guide
"Creative Photo Manager" = Creative Photo Manager
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative VF0350" = Creative Live! Cam Video Chat or Video IM Driver (1.02.01.00)
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Digsby" = Digsby
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ESET Online Scanner" = ESET Online Scanner v3
"Free Easy Burner_is1" = Free Easy Burner V 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"IncrediMail" = IncrediMail 2.0
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"Lexmark 1200 Series" = Lexmark 1200 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PartyPoker" = PartyPoker
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"PhotoMail" = PhotoMail Maker
"Picasa 3" = Picasa 3
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"PokerStars.net" = PokerStars.net
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer Basic
"Snail Mail" = Snail Mail (remove only)
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SysInfo" = Creative System Information
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WebshotsDailyFeatures.D47BD63EE77CC0AC7AE23BFA386A3F1EDA7C080D.1" = Webshots Daily Features
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Muziic Player & Encoder" = Muziic Player & Encoder
"WeatherEye" = WeatherEye
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/9/2011 10:29:30 AM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 35592296
Error - 1/9/2011 11:20:50 PM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 1/9/2011 11:20:50 PM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1984
Error - 1/9/2011 11:20:50 PM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1984
Error - 1/9/2011 11:26:53 PM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 1/9/2011 11:26:53 PM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 366937
Error - 1/9/2011 11:26:53 PM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 366937
Error - 1/13/2011 10:56:22 AM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 1/13/2011 10:56:22 AM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 37527422
Error - 1/13/2011 10:56:22 AM | Computer Name = HEATHER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 37527422
[ System Events ]
Error - 1/24/2012 10:38:09 PM | Computer Name = HEATHER | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
HEATHER\Owner Process Name: Unknown Action: %%808 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x800704ec Error description:
Windows cannot open this program because it has been prevented by a software restriction
policy. For more information, open Event Viewer or contact your system administrator.
Signature Version: AV: 1.119.504.0, AS: 1.119.504.0, NIS: 0.0.0.0 Engine Version:
AM: 1.1.8001.0, NIS: 0.0.0.0
Error - 1/24/2012 10:43:19 PM | Computer Name = HEATHER | Source = Service Control Manager | ID = 7000
Description = The McAfee SiteAdvisor Service service failed to start due to the
following error: %%3
Error - 1/24/2012 10:47:08 PM | Computer Name = HEATHER | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
HEATHER\Owner Process Name: Unknown Action: %%808 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x800704ec Error description:
Windows cannot open this program because it has been prevented by a software restriction
policy. For more information, open Event Viewer or contact your system administrator.
Signature Version: AV: 1.119.545.0, AS: 1.119.545.0, NIS: 0.0.0.0 Engine Version:
AM: 1.1.8001.0, NIS: 0.0.0.0
Error - 1/25/2012 12:27:01 AM | Computer Name = HEATHER | Source = Service Control Manager | ID = 7000
Description = The McAfee SiteAdvisor Service service failed to start due to the
following error: %%3
Error - 1/25/2012 12:38:14 AM | Computer Name = HEATHER | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
NT AUTHORITY\SYSTEM Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.119.545.0, AS: 1.119.545.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8001.0, NIS: 0.0.0.0
Error - 1/25/2012 12:41:50 AM | Computer Name = HEATHER | Source = Service Control Manager | ID = 7000
Description = The McAfee SiteAdvisor Service service failed to start due to the
following error: %%3
Error - 1/25/2012 12:43:57 AM | Computer Name = HEATHER | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
HEATHER\Owner Process Name: Unknown Action: %%808 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x800704ec Error description:
Windows cannot open this program because it has been prevented by a software restriction
policy. For more information, open Event Viewer or contact your system administrator.
Signature Version: AV: 1.119.545.0, AS: 1.119.545.0, NIS: 0.0.0.0 Engine Version:
AM: 1.1.8001.0, NIS: 0.0.0.0
Error - 1/25/2012 8:58:06 AM | Computer Name = HEATHER | Source = Service Control Manager | ID = 7000
Description = The McAfee SiteAdvisor Service service failed to start due to the
following error: %%3
Error - 1/25/2012 9:09:00 AM | Computer Name = HEATHER | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
NT AUTHORITY\SYSTEM Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.119.545.0, AS: 1.119.545.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8001.0, NIS: 0.0.0.0
Error - 1/25/2012 9:24:07 AM | Computer Name = HEATHER | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%815 User:
NT AUTHORITY\SYSTEM Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.119.545.0, AS: 1.119.545.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8001.0, NIS: 0.0.0.0
< End of report >
P2P - I see you have P2P software, (BitTorrent, Azureus. Ares. FrostWire), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall them now. You can do so via Control Panel, Add remove Programs.
Should you decide to keep them, please don’t use them until we have finished up here.
===================================================
Run TDSSKiller
Please download TDSSKiller.zip
- extract it to your desktop
- double click TDSSKiller.exe
- press Start Scan
- only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
- then click Continue > Reboot now
- copy and paste the log in your next reply
- A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
Download and run ComboFix
Download ComboFix from the following location:
Link
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
- see this Link for programs that need to be disabled and instruction on how to disable them.
- remember to re-enable them when we're done.
- double click on ComboFix.exe & follow the prompts.
- as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt
Please also remember to include the TDSSKiller log
Thanks
Satchfan
No registry cleaner is to be recommended as they are indiscriminate in what they remove and can cause more trouble than they do good. We will get rid of any unwanted entries later.Is there anyway to clean the registry for uninstalled programs safely ?
This entry shows it is on the computer:never heard of that Azureus
[2011/10/24 19:23:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
As it is not installed, you can simply delete the folder.
===========================================
The TDSSKiller log should have been saved to the root of the hard drive. You should be able to locate it at C:\)TDSSKiller_*** - (*** denotes version & date.
For now, just try to locate and send that log.
Thanks
Satchfan
Run DDS
Please download DDS by sUBs from one of the following links and save it to your desktop.
DDS.scr
DDS.pif
• double click DDS icon to run the tool (may take up to 3 minutes to run)
• when done, DDS.txt will open.
• after a few moments, attach.txt will open in a second window.
• save both reports to your desktop.
• Post the contents of the DDS.txt and Attach.txt reports in your next reply
Satchfan
Download/run Rkill:
Please download Rkill from one of the following links and save to your Desktop:
Link One
Link Two
Link Three
Link Four
- Double click on Rkill.
- A command window will open then disappear upon completion, this is normal.
- Please leave Rkill on the Desktop until otherwise advised.
You may have to make repeated attempts to use Rkill several times before it will run as some malware variants try to block it.
You'll be able to tell when rkill has done its job when your desktop (explorer.exe) cycles off and then on again.
Now try running DDS again. If it still doesn’t work, try running it in safe mode.
Satchfan
I know you are keen to solve this problem but I asked you previously not to run any programs unless I asked you to. Indiscriminately running programs can alter and hinder the cleaning process.
Please try doing this in normal mode. If that doesn't work, try safe mode.
Delete the version of ComboFix you have.
Download Combofix from either of the links below. You must rename it to Com123.exe before saving it.
Save it to your desktop. Change the save as file type to "all files"
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
- See this Link for programs that need to be disabled and instruction on how to disable them.
- Remember to re-enable them when we're done.
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt
Satchfan
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI