This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

google chrome not working properly

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sometimes when I go to run google chrome it comes up with the windows error reporting thing and won't run and then sometimes firefox just won't run at all. After I run spybot at least one or the others runs fine.


OTL logfile created on: 2/12/2012 2:26:17 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = D:\malware
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 56.01% Memory free
3.85 Gb Paging File | 3.07 Gb Available in Paging File | 79.89% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092C:\pagefile.sys 2 2 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.13 Gb Total Space | 1.11 Gb Free Space | 7.87% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 31.57 Gb Free Space | 32.33% Space Free | Partition Type: NTFS
Drive F: | 3.75 Gb Total Space | 3.75 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive G: | 14.65 Gb Total Space | 8.30 Gb Free Space | 56.66% Space Free | Partition Type: NTFS
Drive H: | 218.20 Gb Total Space | 76.86 Gb Free Space | 35.23% Space Free | Partition Type: NTFS

Computer Name: DANIEL-65C6EC9E | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/12 14:24:50 | 000,584,192 | —- | M] (OldTimer Tools) – D:\malware\OTL.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – D:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/01/19 23:35:36 | 001,047,024 | —- | M] (Google Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | —- | M] (AVG Technologies CZ, s.r.o.) – D:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/09/08 19:53:26 | 000,743,264 | —- | M] (AVG Technologies CZ, s.r.o.) – D:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/09/05 20:51:14 | 000,273,528 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/08/15 05:21:40 | 000,337,760 | —- | M] (AVG Technologies CZ, s.r.o.) – D:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 05:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – D:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/06/28 09:03:22 | 001,843,000 | —- | M] (Orbitdownloader.com) – D:\Program Files\Orbitdownloader\orbitdm.exe
PRC - [2011/06/27 09:05:26 | 000,557,056 | —- | M] (Orbitdownloader.com) – D:\Program Files\Orbitdownloader\orbitnet.exe
PRC - [2009/12/23 15:34:20 | 000,370,688 | —- | M] (StarWind Software) – d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2009/01/26 14:31:12 | 005,365,592 | RHS- | M] (Safer Networking Limited) – D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PRC - [2005/06/20 09:31:34 | 000,036,864 | —- | M] () – C:\WINDOWS\system32\acs.exe
PRC - [2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/19 23:35:35 | 000,411,120 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppgooglenaclpluginchrome.dll
MOD - [2012/01/19 23:35:34 | 003,767,792 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
MOD - [2012/01/19 23:34:10 | 000,122,880 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avutil-51.dll
MOD - [2012/01/19 23:34:09 | 000,222,208 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avformat-53.dll
MOD - [2012/01/19 23:34:07 | 001,746,432 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avcodec-53.dll
MOD - [2012/01/19 20:14:40 | 008,593,056 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
MOD - [2011/06/28 09:01:38 | 000,397,312 | —- | M] () – D:\Program Files\Orbitdownloader\wtlctrl.dll
MOD - [2010/02/05 12:40:58 | 001,291,264 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2008/06/19 16:35:36 | 000,333,288 | —- | M] () – D:\Program Files\Spybot - Search & Destroy\sqlite3.dll
MOD - [2008/03/05 08:34:32 | 000,795,520 | —- | M] () – D:\Program Files\Spybot - Search & Destroy\Plugins\Fennel.dll
MOD - [2008/03/04 13:52:00 | 000,790,392 | —- | M] () – D:\Program Files\Spybot - Search & Destroy\Plugins\Chai.dll
MOD - [2008/02/26 10:04:40 | 000,717,176 | —- | M] () – D:\Program Files\Spybot - Search & Destroy\Plugins\Mate.dll
MOD - [2007/12/24 00:05:00 | 000,121,344 | —- | M] () – D:\Program Files\Spybot - Search & Destroy\Plugins\TCPIPAddress.dll
MOD - [2005/06/20 09:31:34 | 000,036,864 | —- | M] () – C:\WINDOWS\system32\acs.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - [2011/08/02 05:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – D:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2009/12/23 15:34:20 | 000,370,688 | —- | M] (StarWind Software) [Auto | Running] – d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe – (StarWindServiceAE)
SRV - [2005/06/20 09:31:34 | 000,036,864 | —- | M] () [Auto | Running] – C:\WINDOWS\system32\acs.exe – (ACS)


========== Driver Services (SafeList) ==========

DRV - [2011/10/07 05:23:48 | 000,230,608 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2011/09/13 05:30:10 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2011/08/08 05:08:58 | 000,040,016 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/08/05 15:13:34 | 000,436,792 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd)
DRV - [2011/07/11 00:14:38 | 000,295,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2011/07/11 00:14:28 | 000,023,120 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2009/10/22 00:23:18 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/10/22 00:23:18 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/07/07 17:53:02 | 000,028,160 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\libusb0.sys – (libusb0)
DRV - [2009/05/03 20:04:49 | 004,737,024 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/05/03 18:14:20 | 000,096,384 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtnicxp.sys – (RTL8023xp)
DRV - [2006/07/02 00:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/03/22 16:27:10 | 000,488,992 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SHP5211.sys – (AR5211)
DRV - [2002/09/03 19:31:12 | 000,019,296 | —- | M] (Minolta Co., Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\MLPTDR_C.SYS – (MLPTDR_C)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "http://search.orbitdownloader.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: d:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: d:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: D:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/31 16:25:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/05 20:51:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/10/24 10:02:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins

[2009/07/12 11:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions
[2009/07/12 11:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions\[removed]
[2012/01/30 12:51:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions
[2012/01/30 12:51:50 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/05 20:43:54 | 000,003,739 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\searchplugins\avg-secure-search.xml
[2011/09/05 20:32:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 11:57:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/09/05 20:46:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/01/31 16:25:06 | 000,000,000 | —D | M] (AVG Safe Search) – D:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2010/05/23 11:57:22 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = d:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\plugins/avgnpss.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/02/12 14:18:07 | 000,440,549 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15168 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AVG_TRAY] D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] d:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk = D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1278997763765 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E589DD42-B43E-4529-ACFC-F949BA30505E}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\video/x-flv - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/09 15:04:31 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/04/30 16:01:00 | 000,000,053 | -HS- | M] () - G:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (D:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3filter - ac3filter.acm File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ffdshow.ax ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/09 02:05:34 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2004/11/24 13:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/12 14:18:07 | 000,440,549 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/12 14:16:00 | 000,001,014 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2012/02/12 13:34:48 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2012/02/12 13:34:47 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2012/02/12 12:49:15 | 088,773,504 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/12 12:44:25 | 000,000,656 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2012/02/12 12:43:30 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/12 12:43:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/10 22:16:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2012/02/09 02:05:34 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/08 21:24:59 | 000,087,592 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Under-Construction-Facebook-Profile-Timeline-Cover.jpg
[2012/02/08 21:22:57 | 000,132,724 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\cover disabled fb cover.jpg
[2012/02/08 18:30:11 | 000,554,661 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/02/03 01:35:43 | 000,000,278 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\12TE01703536026000170350.pdf
[2012/01/31 16:25:07 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2012/01/31 02:01:12 | 000,111,340 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\tumblr_lyfqnsTbqV1r9a6eho1_500.jpg
[2012/01/30 21:36:29 | 000,440,303 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120212-141807.backup
[2012/01/30 03:08:05 | 000,181,248 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/29 01:30:36 | 000,057,660 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\403853_10151222810475440_666740439_22823383_926526662_n.jpg
[2012/01/27 14:48:34 | 000,130,573 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Statement.pdf
[2012/01/25 13:12:55 | 000,002,411 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2012/01/25 13:12:55 | 000,002,389 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/23 12:25:43 | 000,439,490 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120130-213629.backup
[2012/01/17 21:40:54 | 000,439,340 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120123-122543.backup
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/08 21:25:00 | 000,087,592 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Under-Construction-Facebook-Profile-Timeline-Cover.jpg
[2012/02/08 21:22:59 | 000,132,724 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\cover disabled fb cover.jpg
[2012/02/03 01:35:45 | 000,000,278 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\12TE01703536026000170350.pdf
[2012/01/31 02:01:15 | 000,111,340 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\tumblr_lyfqnsTbqV1r9a6eho1_500.jpg
[2012/01/29 01:30:39 | 000,057,660 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\403853_10151222810475440_666740439_22823383_926526662_n.jpg
[2012/01/27 14:48:36 | 000,130,573 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Statement.pdf
[2011/10/19 11:46:58 | 002,128,778 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/10/02 21:00:49 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2011/10/02 21:00:49 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2140.DAT
[2011/09/30 13:48:00 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/15 12:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\vvgo2823x2r50oejm
[2011/07/15 12:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\vvgo2823x2r50oejm
[2010/07/12 12:54:24 | 000,280,796 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/07/12 12:54:22 | 000,280,796 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/07/12 12:54:22 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/07/09 12:32:43 | 002,292,678 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/05/02 08:09:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/17 16:35:31 | 000,000,036 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\housecall.guid.cache
[2009/10/08 11:47:02 | 000,025,964 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/06/28 14:21:30 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/06/28 14:21:30 | 000,022,328 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PnkBstrK.sys
[2009/06/28 14:21:14 | 000,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/06/28 14:21:14 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/06/28 14:21:12 | 000,000,319 | —- | C] () – C:\WINDOWS\game.ini
[2009/06/22 12:36:15 | 000,002,528 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\$_hpcst$.hpc
[2009/05/13 01:27:58 | 000,004,914 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/05/05 18:26:14 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/05/05 11:21:23 | 000,181,248 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/03 20:06:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/05/03 18:45:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/05/03 18:41:05 | 000,022,720 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/05/03 13:35:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/05/03 13:33:21 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/04 17:31:29 | 000,180,224 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/12/19 09:15:58 | 004,338,246 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/12/17 11:41:18 | 000,884,237 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2008/12/17 11:22:58 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/17 11:22:48 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/17 11:17:34 | 000,239,247 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 10:59:54 | 000,560,802 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/08/09 15:04:08 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2006/11/02 10:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2005/06/20 09:31:34 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2005/06/20 09:31:34 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2004/10/03 11:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 00:07:22 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/02 13:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/17 10:36:38 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/10 13:09:52 | 000,021,282 | —- | C] () – C:\WINDOWS\MSTMON_C.INI
[2002/09/03 20:38:42 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MCMM___C.DLL
[2002/09/03 16:38:04 | 000,010,242 | —- | C] () – C:\WINDOWS\MSUMLT_C.INI
[2001/08/23 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 06:00:00 | 000,311,934 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 06:00:00 | 000,040,196 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 06:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/09/05 20:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG10
[2011/09/05 21:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2009/05/03 20:49:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2010/10/06 15:18:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2012/02/12 12:49:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2011/09/02 20:43:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
[2009/08/09 10:48:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/06/27 14:48:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/03 12:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/07/13 13:15:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Auslogics
[2010/10/06 15:19:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG10
[2011/09/05 20:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/07/13 12:56:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Azureus
[2011/12/26 00:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\com.amazon.music.uploader
[2011/05/05 11:16:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\FrostWire
[2009/12/08 13:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GetRightToGo
[2010/04/17 14:27:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GrabPro
[2011/06/01 13:26:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\MechCAD
[2010/08/15 21:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\OpenCandy
[2012/02/12 12:44:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Orbit
[2010/08/15 21:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\ProgSense
[2009/08/25 16:36:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Trillian

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/05/02 12:46:57 | 000,010,524 | —- | M] () – C:\aaw7boot.log
[2008/09/02 17:12:28 | 000,000,645 | —- | M] () – C:\Active SMART.lnk
[2009/02/25 21:05:49 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2007/08/09 15:04:31 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2009/05/05 23:59:40 | 000,000,487 | -HS- | M] () – C:\Boot.bak
[2011/07/14 04:00:52 | 000,000,440 | -HS- | M] () – C:\boot.ini
[2009/05/06 00:54:32 | 000,000,580 | RHS- | M] () – C:\Boot.ini.saved
[2009/04/21 23:28:23 | 000,383,200 | RHS- | M] () – C:\bootmgr
[2009/05/06 00:54:33 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/08/09 15:04:31 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2008/03/29 03:54:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2007/08/09 15:04:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/30 17:52:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2007/08/09 15:04:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 21:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/03 20:22:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[1993/02/20 11:49:52 | 000,000,030 | —- | M] () – C:\readme.bat
[2010/04/18 13:12:45 | 000,000,387 | —- | M] () – C:\rkill.log
[2009/12/06 19:11:35 | 000,002,870 | —- | M] () – C:\RootRepeal report 12-06-09 (19-11-35).txt
[2009/05/03 12:07:45 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/05/03 12:23:21 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/05/03 12:28:05 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/05/03 13:23:03 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/05/03 16:23:38 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/05/03 17:28:06 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/04/29 10:51:11 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/04/29 20:49:31 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/04/30 15:07:14 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/04/30 15:36:05 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/04/30 16:19:43 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/05/01 14:39:25 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/05/02 12:39:29 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/05/02 12:40:22 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/05/02 12:40:38 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/05/02 13:11:14 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/05/02 13:43:31 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/05/02 14:11:06 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/05/02 14:23:57 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/05/03 01:10:55 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/05/03 12:07:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/05/03 12:23:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/05/03 12:28:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/05/03 13:23:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/05/03 16:23:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/05/03 17:28:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/04/29 10:51:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/04/29 20:49:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/04/30 15:07:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/04/30 15:36:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/04/30 16:19:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/05/01 14:39:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/05/02 12:39:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/05/02 12:40:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/05/02 12:40:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/05/02 13:11:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/05/02 13:43:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/05/02 14:11:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/05/02 14:23:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/05/03 01:10:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/07/12 12:27:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2002/09/03 17:19:44 | 000,009,728 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\MIMFPR_C.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2007/08/09 15:04:08 | 000,000,271 | -HS- | M] () – C:\Program Files\desktop.ini
[2007/08/09 15:04:08 | 000,021,952 | -H– | M] () – C:\Program Files\folder.htt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/07/12 06:51:07 | 004,718,592 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/07/12 00:54:06 | 000,049,152 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2010/07/12 06:51:07 | 028,311,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/07/12 06:51:07 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/12 12:27:58 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/03 20:30:13 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/03 18:48:35 | 000,000,079 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/10/11 20:15:27 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\ATF-Cleaner.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-19 05:49:48

< End of report >
Hello karamazov,

Not seeing anything very amiss in these logs. I am not well read on Chrome, as it uses it's own functions atypical of other browsers. But let's get a different, detailed look at things, then decide.

OTL created a second, Extras.txt log, in the same location as OTL.exe. Please post that in your next reply.


To make sure you have an accurate view of files there, make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"



To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs. Here are some antivirus disable tips if needed.


———

Click here and download the installer for Gmer to your desktop, then click that file to run Gmer.


Once the opening scan finishes, click on Scan (again, before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.

Note - If Gmer shows it has located infection once it's opening scan completes, do not click the Scan button. We don't want hidden malware settings to cause any problems. Instead, just click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.

———–

Download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • If you can have an open Internet connection, and allow it to download the latest Avast engine detections.
  • {i}If avast! antivirus is already installed, just do the next step.{/i}
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI