This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TSR.BOOT virus [Solved]

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

I was looking through Eset's Log Files & I've come across the following log:

27/02/2012 09:37:51	Startup scanner / boot sector / active boot sector of the 0. physical disk	/ probably unknown TSR.BOOT virus / unable to clean

I have had no other reports since 27/02/12; but as the above log states, Eset was unable to clean whatever was/is present on my machine.
Would someone from the Malware team be so kind as to look at my scan please?

Thank you.



OTL Extras logfile created on: 03/03/2012 02:23:21 - Run 1
OTL by OldTimer - Version 3.2.33.2	 Folder = C:\Users\Dan\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
2.93 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 53.46% Memory free
6.06 Gb Paging File | 4.73 Gb Available in Paging File | 78.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.52 Gb Total Space | 36.27 Gb Free Space | 52.18% Space Free | Partition Type: NTFS
Drive D: | 69.53 Gb Total Space | 69.44 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
 
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17AD3DEB-554C-4ADF-BE36-5C4FB8D0EBAB}" = lport=445 | protocol=6 | dir=in | app=system | 
"{46BC9395-43FF-4DCC-8878-A37067345835}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{4F512E7D-9742-4444-B4C0-D6D7F8EEAF7A}" = lport=139 | protocol=6 | dir=in | app=system | 
"{5D676F3F-1244-42BD-A79A-7742D101353E}" = rport=139 | protocol=6 | dir=out | app=system | 
"{6BA1358D-1B0F-4C8A-A5BD-ACD623C9D427}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{A0C0C593-6D01-42E8-9B5D-648971B1E798}" = lport=137 | protocol=17 | dir=in | app=system | 
"{B35DC04C-9E79-49D7-B33D-A0096D6D9CB7}" = rport=138 | protocol=17 | dir=out | app=system | 
"{BAEBA52A-23C7-4967-A91D-501F1C2FE1EB}" = rport=137 | protocol=17 | dir=out | app=system | 
"{E40FB2BA-5F65-493B-A206-00EED6868231}" = rport=445 | protocol=6 | dir=out | app=system | 
"{E7BF4D8A-3F14-4924-B282-2D696F4B9E5D}" = lport=138 | protocol=17 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1133CE77-13C8-4DF4-87EF-4C98A94ACB63}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{1F5DF333-5926-4E00-96F7-970D60B0104B}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{7EFF4BA9-A366-403E-B3A4-8B46393AFBE0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{82040567-0499-429D-98A5-DF9D7B833DF1}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{99401448-DB03-4DE6-B611-5B2C65B47933}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{A4661313-C541-42D4-91C4-B93F95AD7C74}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{AB501317-3CBB-42B4-85FB-A1CEEA019AEA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{EDEE1EDE-8451-495F-874B-E9620542F8A4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}" = Acronis True Image Home 2011
"{10F498FF-5392-4DF3-8F73-FE172A9F3800}" = Winbond CIR Device Drivers
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83E3F4E4-CEA1-452B-9180-A40813CD111C}" = ESET Smart Security
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A64A5576-D862-44F8-89DC-2B17FCC9B86E}" = Broadcom Gigabit Integrated Controller
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam 2.0.8
"{CD232781-26CA-4E18-BC70-4343A2F0D583}" = Microsoft IntelliPoint 8.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe  1.4.142.1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)
"AutoCAD 2009 - English" = AutoCAD 2009 - English
"AVerMedia A310 (MiniCard, DVB-T)" = AVerMedia A310 (MiniCard, DVB-T) [removed]
"CCleaner" = CCleaner
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"Foxit Reader" = Foxit Reader
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"RESIDENT EVIL" = RESIDENT EVIL
"Sandboxie" = Sandboxie 3.62 (32-bit)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.8.3.2499
"UltraISO_is1" = UltraISO Premium V9.31
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR archiver
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 27/02/2012 05:33:03 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 27/02/2012 05:33:04 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 27/02/2012 05:33:04 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3028
Description = 
 
Error - 27/02/2012 05:33:04 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3058
Description = 
 
Error - 27/02/2012 05:34:30 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 27/02/2012 12:15:13 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 05:12:57 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 08:52:10 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 13:14:09 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 14:11:17 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 14/11/2011 03:08:20 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7009
Description = 
 
Error - 14/11/2011 03:08:20 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 14/11/2011 03:08:20 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7032
Description = 
 
Error - 14/11/2011 15:23:19 | Computer Name = Dan-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
 address 00238B0A095C has been denied by the DHCP server 192.168.0.1 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 21/11/2011 03:22:06 | Computer Name = Dan-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7024
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7031
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7009
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7032
Description = 
 
 
< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

When you ran OTL there should have been a log named OTL.txt that was created as well. Could you post that.
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the OTL.txt log that was created and the log made by aswMBR. :)
Hi jeffce & thank you for looking at my scans.

I forgot to include the 'extras.txt' from the OTL scan, so here it is:

OTL Extras logfile created on: 03/03/2012 02:23:21 - Run 1
OTL by OldTimer - Version 3.2.33.2	 Folder = C:\Users\Dan\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
2.93 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 53.46% Memory free
6.06 Gb Paging File | 4.73 Gb Available in Paging File | 78.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.52 Gb Total Space | 36.27 Gb Free Space | 52.18% Space Free | Partition Type: NTFS
Drive D: | 69.53 Gb Total Space | 69.44 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
 
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17AD3DEB-554C-4ADF-BE36-5C4FB8D0EBAB}" = lport=445 | protocol=6 | dir=in | app=system | 
"{46BC9395-43FF-4DCC-8878-A37067345835}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{4F512E7D-9742-4444-B4C0-D6D7F8EEAF7A}" = lport=139 | protocol=6 | dir=in | app=system | 
"{5D676F3F-1244-42BD-A79A-7742D101353E}" = rport=139 | protocol=6 | dir=out | app=system | 
"{6BA1358D-1B0F-4C8A-A5BD-ACD623C9D427}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{A0C0C593-6D01-42E8-9B5D-648971B1E798}" = lport=137 | protocol=17 | dir=in | app=system | 
"{B35DC04C-9E79-49D7-B33D-A0096D6D9CB7}" = rport=138 | protocol=17 | dir=out | app=system | 
"{BAEBA52A-23C7-4967-A91D-501F1C2FE1EB}" = rport=137 | protocol=17 | dir=out | app=system | 
"{E40FB2BA-5F65-493B-A206-00EED6868231}" = rport=445 | protocol=6 | dir=out | app=system | 
"{E7BF4D8A-3F14-4924-B282-2D696F4B9E5D}" = lport=138 | protocol=17 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1133CE77-13C8-4DF4-87EF-4C98A94ACB63}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{1F5DF333-5926-4E00-96F7-970D60B0104B}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{7EFF4BA9-A366-403E-B3A4-8B46393AFBE0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{82040567-0499-429D-98A5-DF9D7B833DF1}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{99401448-DB03-4DE6-B611-5B2C65B47933}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{A4661313-C541-42D4-91C4-B93F95AD7C74}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{AB501317-3CBB-42B4-85FB-A1CEEA019AEA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{EDEE1EDE-8451-495F-874B-E9620542F8A4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}" = Acronis True Image Home 2011
"{10F498FF-5392-4DF3-8F73-FE172A9F3800}" = Winbond CIR Device Drivers
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83E3F4E4-CEA1-452B-9180-A40813CD111C}" = ESET Smart Security
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A64A5576-D862-44F8-89DC-2B17FCC9B86E}" = Broadcom Gigabit Integrated Controller
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam 2.0.8
"{CD232781-26CA-4E18-BC70-4343A2F0D583}" = Microsoft IntelliPoint 8.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe  1.4.142.1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)
"AutoCAD 2009 - English" = AutoCAD 2009 - English
"AVerMedia A310 (MiniCard, DVB-T)" = AVerMedia A310 (MiniCard, DVB-T) [removed]
"CCleaner" = CCleaner
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"Foxit Reader" = Foxit Reader
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"RESIDENT EVIL" = RESIDENT EVIL
"Sandboxie" = Sandboxie 3.62 (32-bit)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.8.3.2499
"UltraISO_is1" = UltraISO Premium V9.31
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR archiver
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 27/02/2012 05:33:03 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 27/02/2012 05:33:04 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 27/02/2012 05:33:04 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3028
Description = 
 
Error - 27/02/2012 05:33:04 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3058
Description = 
 
Error - 27/02/2012 05:34:30 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 27/02/2012 12:15:13 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 05:12:57 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 08:52:10 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 13:14:09 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 28/02/2012 14:11:17 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 14/11/2011 03:08:20 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7009
Description = 
 
Error - 14/11/2011 03:08:20 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 14/11/2011 03:08:20 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7032
Description = 
 
Error - 14/11/2011 15:23:19 | Computer Name = Dan-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
 address 00238B0A095C has been denied by the DHCP server 192.168.0.1 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 21/11/2011 03:22:06 | Computer Name = Dan-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7024
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7031
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7009
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 21/11/2011 03:23:29 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7032
Description = 
 
 
< End of report >



__________________________________
SKScanner Log:
__________________________________

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.CENATX
 —– EOF —–

__________________________________
aswMRR Log:
__________________________________
N.B I ran the scan without downloading Avast's scanner

aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-03-05 18:25:28
—————————–
18:25:28.187	OS Version: Windows 6.0.6002 Service Pack 2
18:25:28.187	Number of processors: 2 586 0xF0D
18:25:28.187	ComputerName: DAN-PC  UserName: Dan
18:25:48.498	Initialize success
18:26:19.302	Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:26:19.302	Disk 0 Vendor: Hitachi_ BBCO Size: 152627MB BusType: 3
18:26:19.317	Disk 0 MBR read successfully
18:26:19.317	Disk 0 MBR scan
18:26:19.317	Disk 0 unknown MBR code
18:26:19.333	Disk 0 Partition 1 00	 27 Hidden NTFS WinRE NTFS		10240 MB offset 2048
18:26:19.348	Disk 0 Partition 2 80 (A) 07	HPFS/NTFS NTFS		71190 MB offset 20973582
18:26:19.380	Disk 0 Partition 3 00	 07	HPFS/NTFS NTFS		71194 MB offset 166770768
18:26:19.380	Disk 0 scanning sectors +312576705
18:26:19.442	Disk 0 scanning C:\Windows\system32\drivers
18:26:27.460	Service scanning
18:26:47.335	Modules scanning
18:26:54.620	Disk 0 trace - called modules:
18:26:54.636	ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys 
18:26:55.150	1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x879be250]
18:26:55.150	3 CLASSPNP.SYS[8bb3a8b3] -> nt!IofCallDriver -> [0x86c35280]
18:26:55.150	5 acpi.sys[8068f6bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86680028]
18:26:55.166	Scan finished successfully
18:27:13.964	Disk 0 MBR has been saved successfully to "C:\Users\Dan\Downloads\MBR.dat"
18:27:13.964	The log file has been saved successfully to "C:\Users\Dan\Downloads\aswMBR.txt"

Thank you
Hi jeffce

OTL isn't generating the Extras.txt
Here is the OTL scan as requested


__________________________________
OTL Log:
__________________________________


OTL logfile created on: 06/03/2012 20:02:43 - Run 2
OTL by OldTimer - Version 3.2.33.2	 Folder = C:\Users\Dan\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
2.93 Gb Total Physical Memory | 1.81 Gb Available Physical Memory | 61.79% Memory free
6.06 Gb Paging File | 4.81 Gb Available in Paging File | 79.35% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.52 Gb Total Space | 30.29 Gb Free Space | 43.56% Space Free | Partition Type: NTFS
Drive D: | 69.53 Gb Total Space | 69.44 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
 
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Dan\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Users\Dan\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\ACER\Mobility Center\MobilityService.exe ()
PRC - C:\Windows\PLFSetI.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\PLFSetI.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ekrn) – C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (IAANTMON) Intel(R) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MobilityService) – C:\Acer\Mobility Center\MobilityService.exe ()
 
 
========== Driver Services (SafeList) ==========
 
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (afcdp) – C:\Windows\System32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman273) Acronis Try&Decide; and Restore Points filter (build 273) – C:\Windows\system32\DRIVERS\tdrpm273.sys (Acronis)
DRV - (timounter) – C:\Windows\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\Windows\system32\DRIVERS\snapman.sys (Acronis)
DRV - (eamonm) – C:\Windows\System32\drivers\eamonm.sys (ESET)
DRV - (epfw) – C:\Windows\System32\drivers\epfw.sys (ESET)
DRV - (epfwwfp) – C:\Windows\system32\DRIVERS\epfwwfp.sys (ESET)
DRV - (EpfwLWF) – C:\Windows\System32\drivers\EpfwLWF.sys (ESET)
DRV - (ehdrv) – C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (IntcHdmiAddService) Intel(R) – C:\Windows\System32\drivers\IntcHdmi.sys (Intel(R) Corporation)
DRV - (ISODrive) – C:\Program Files\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)
DRV - (NETw5v32) Intel(R) – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (JMCR) – C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corp.)
DRV - (A310) – C:\Windows\System32\drivers\AVerA310USB.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (BDASwCap) – C:\Windows\System32\drivers\AVerA310Cap.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (WSVD) – C:\Windows\System32\drivers\WSVD.sys (Wasay)
DRV - (winbondcir) – C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=0710&m;=aspire_7730
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=0710&m;=aspire_7730
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.15.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..network.proxy.type: 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Firefox-3.6.16\components [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Firefox-3.6.16\plugins [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/12/28 18:46:14 | 000,000,000 | —D | M]
 
[2011/11/13 23:53:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
[2011/11/11 01:56:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/02/06 18:32:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions
[2011/11/13 23:53:58 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2012/02/06 18:32:12 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions\[removed]
[2012/01/12 22:01:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions
[2011/11/14 00:14:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/01/12 22:01:42 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2012/01/07 22:08:32 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/02/19 20:37:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/19 20:37:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
() (No name found) – C:\USERS\DAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\23I9OVQ6.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2010/07/31 18:09:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/02/18 02:41:51 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/19 20:37:20 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/02 21:30:05 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2012/02/18 02:41:46 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/02/18 02:41:46 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/18 02:41:46 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/02/18 02:41:46 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/02/18 02:41:46 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2011/10/29 23:37:22 | 000,000,759 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1	   localhost
O1 - Hosts: ::1			 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D1BAFBA-2E42-4BF5-8DF9-8C3CC90677F6}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{9b1182ec-fe68-11e0-8ccd-00238b0a095c}\Shell - "" = AutoRun
O33 - MountPoints2\{9b1182ec-fe68-11e0-8ccd-00238b0a095c}\Shell\AutoRun\command - "" = H:\Enterprise_Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/04 02:49:52 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\smooky_by_razzor40-d4rpm86
[2012/03/04 02:49:52 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\idrops_wallpaper_by_nyolc8-d2v9de1
[2012/03/04 02:49:52 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\blend_by_razzor40-d4rpmhq
[2012/03/04 02:49:51 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\apple_texture_pack_by_shapshapy-d4hnm2e
[2012/03/03 15:24:53 | 000,100,864 | —- | C] (GMER) – C:\kxtdapow.sys
[2012/03/03 02:15:03 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\Microsoft
[2012/03/02 19:18:08 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2012/03/02 19:14:16 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Audacity
[2012/03/02 19:14:01 | 000,000,000 | —D | C] – C:\Program Files\Audacity 1.3 Beta (Unicode)
[2012/02/26 00:44:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CAPCOM
[2012/02/26 00:44:03 | 000,000,000 | —D | C] – C:\Program Files\RESIDENT EVIL
[2012/02/25 20:45:36 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\ResidentEvil1
[2012/02/20 22:00:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/02/20 22:00:04 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/02/19 20:38:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/02/19 20:37:40 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/02/19 20:37:40 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/02/19 20:37:40 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/02/15 17:40:52 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/02/15 17:40:51 | 001,798,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/02/15 17:40:50 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/02/15 17:40:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/02/15 17:40:50 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/02/15 17:40:47 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/02/15 08:21:35 | 002,044,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/02/12 16:04:34 | 000,000,000 | —D | C] – C:\ProgramData\EPSON
[2012/02/11 21:34:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Autodesk Shared
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\ProgramData\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Program Files\AutoCAD 2009
[2012/02/11 21:31:07 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2012/02/11 21:30:56 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_30.dll
[2012/02/11 20:47:02 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\Haircut
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/06 19:16:21 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/06 19:16:21 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/06 19:16:17 | 000,067,584 | —- | M] () – C:\Windows\bootstat.dat
[2012/03/06 16:55:58 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2012/03/04 02:49:02 | 051,960,345 | —- | M] () – C:\Users\Dan\Desktop\apple_texture_pack_by_shapshapy-d4hnm2e.zip
[2012/03/04 02:48:27 | 018,065,926 | —- | M] () – C:\Users\Dan\Desktop\idrops_wallpaper_by_nyolc8-d2v9de1.zip
[2012/03/04 02:15:41 | 001,944,430 | —- | M] () – C:\Users\Dan\Desktop\blend_by_razzor40-d4rpmhq.zip
[2012/03/04 02:15:30 | 001,580,820 | —- | M] () – C:\Users\Dan\Desktop\smooky_by_razzor40-d4rpm86.zip
[2012/03/03 19:37:29 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/03/03 19:37:29 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/03/03 15:24:53 | 000,100,864 | —- | M] (GMER) – C:\kxtdapow.sys
[2012/02/26 00:44:18 | 000,000,331 | —- | M] () – C:\Users\Dan\Desktop\RESIDENT EVIL.lnk
[2012/02/24 02:39:16 | 000,016,896 | —- | M] () – C:\Users\Dan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/19 20:38:47 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/02/19 20:37:19 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2012/02/19 20:37:19 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/02/19 20:37:19 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/02/19 20:37:19 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/02/15 21:12:08 | 000,369,344 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2012/03/04 02:52:45 | 000,000,331 | —- | C] () – C:\Users\Dan\Desktop\RESIDENT EVIL.lnk
[2012/03/04 02:48:05 | 051,960,345 | —- | C] () – C:\Users\Dan\Desktop\apple_texture_pack_by_shapshapy-d4hnm2e.zip
[2012/03/04 02:47:58 | 018,065,926 | —- | C] () – C:\Users\Dan\Desktop\idrops_wallpaper_by_nyolc8-d2v9de1.zip
[2012/03/04 02:15:41 | 001,944,430 | —- | C] () – C:\Users\Dan\Desktop\blend_by_razzor40-d4rpmhq.zip
[2012/03/04 02:15:30 | 001,580,820 | —- | C] () – C:\Users\Dan\Desktop\smooky_by_razzor40-d4rpm86.zip
[2012/03/02 19:14:11 | 000,000,957 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity 1.3 Beta (Unicode).lnk
[2011/12/24 19:50:55 | 000,001,604 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/11/13 01:49:02 | 000,173,646 | —- | C] () – C:\Users\Dan\AppData\Local\census.cache
[2011/11/13 01:48:54 | 000,000,000 | —- | C] () – C:\Users\Dan\AppData\Local\ars.cache
[2011/11/12 23:36:15 | 000,000,036 | —- | C] () – C:\Users\Dan\AppData\Local\housecall.guid.cache
[2011/11/09 18:59:02 | 000,000,783 | —- | C] () – C:\Windows\NTIWVEDT.INI
[2011/10/29 01:13:10 | 000,016,896 | —- | C] () – C:\Users\Dan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/31 18:30:19 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/07/31 18:30:19 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/31 02:59:32 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2010/07/31 02:59:32 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/07/31 02:59:32 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2010/07/31 02:42:36 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
 
========== LOP Check ==========
 
[2011/10/20 20:44:18 | 000,000,000 | —D | M] – C:\Users\Dan\AppData\Roaming\Acronis
[2012/03/03 01:02:35 | 000,000,000 | —D | M] – C:\Users\Dan\AppData\Roaming\Audacity
[2012/02/11 21:43:24 | 000,000,000 | —D | M] – C:\Users\Dan\AppData\Roaming\Autodesk
[2011/12/28 18:38:02 | 000,000,000 | —D | M] – C:\Users\Dan\AppData\Roaming\ESET
[2011/11/11 01:56:48 | 000,000,000 | —D | M] – C:\Users\Dan\AppData\Roaming\TomTom
[2012/03/06 16:55:58 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*.* >
[2006/09/18 21:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 06:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/04/17 16:10:10 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 21:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2012/03/03 15:24:53 | 000,100,864 | —- | M] (GMER) – C:\kxtdapow.sys
[2012/03/06 19:16:11 | 3460,235,264 | -HS- | M] () – C:\pagefile.sys
[2010/07/31 11:50:00 | 000,000,091 | —- | M] () – C:\PS.log
[2008/04/17 15:25:22 | 000,000,426 | —- | M] () – C:\RHDSetup.log
 
< %systemroot%\Fonts\*.com >
[2006/11/02 12:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 12:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 12:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/07/31 19:26:16 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2006/09/18 21:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/27 02:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.jpg >
 
< %systemroot%\*.png >
 
< %systemroot%\*.scr >
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
[2008/01/21 02:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\System32\config\*.sav >
[2008/01/21 03:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 03:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 03:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 10:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 10:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
 
< %PROGRAMFILES%\bak. /s >
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/15 22:22:37 | 000,000,221 | -HS- | M] () – C:\Users\Dan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
 
< %USERPROFILE%\Desktop\*.exe >
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.* >
 
< %systemroot%\AppPatch\Custom\*.* >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-15 23:03:30

< End of report >
Hi, Great! That is what I was looking for! Oh don't worry about there not being an Extras log. It is only made the first time unless I give different instructions to get another. I will return as quickly as I can with the next set of instructions. :)
Hi manicd,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0710&m=aspire_7730
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0710&m=aspire_7730
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
    O33 - MountPoints2\{9b1182ec-fe68-11e0-8ccd-00238b0a095c}\Shell - "" = AutoRun
    O33 - MountPoints2\{9b1182ec-fe68-11e0-8ccd-00238b0a095c}\Shell\AutoRun\command - "" = H:\Enterprise_Launcher.exe
    [2012/02/24 02:39:16 | 000,016,896 | —- | M] () – C:\Users\Dan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Good evening Jeffce, I hope you are well.

Here is my log as requested



OTL logfile created on: 07/03/2012 20:56:21 - Run 4
OTL by OldTimer - Version 3.2.33.2	 Folder = C:\Users\Dan\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
2.93 Gb Total Physical Memory | 1.85 Gb Available Physical Memory | 63.18% Memory free
6.06 Gb Paging File | 4.99 Gb Available in Paging File | 82.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.52 Gb Total Space | 29.04 Gb Free Space | 41.77% Space Free | Partition Type: NTFS
Drive D: | 69.53 Gb Total Space | 69.44 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
 
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Dan\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Users\Dan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\ACER\Mobility Center\MobilityService.exe ()
PRC - C:\Windows\PLFSetI.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\PLFSetI.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ekrn) – C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (IAANTMON) Intel(R) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MobilityService) – C:\Acer\Mobility Center\MobilityService.exe ()
 
 
========== Driver Services (SafeList) ==========
 
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (afcdp) – C:\Windows\System32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman273) Acronis Try&Decide; and Restore Points filter (build 273) – C:\Windows\system32\DRIVERS\tdrpm273.sys (Acronis)
DRV - (timounter) – C:\Windows\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\Windows\system32\DRIVERS\snapman.sys (Acronis)
DRV - (eamonm) – C:\Windows\System32\drivers\eamonm.sys (ESET)
DRV - (epfw) – C:\Windows\System32\drivers\epfw.sys (ESET)
DRV - (epfwwfp) – C:\Windows\system32\DRIVERS\epfwwfp.sys (ESET)
DRV - (EpfwLWF) – C:\Windows\System32\drivers\EpfwLWF.sys (ESET)
DRV - (ehdrv) – C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (IntcHdmiAddService) Intel(R) – C:\Windows\System32\drivers\IntcHdmi.sys (Intel(R) Corporation)
DRV - (ISODrive) – C:\Program Files\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)
DRV - (NETw5v32) Intel(R) – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (JMCR) – C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corp.)
DRV - (A310) – C:\Windows\System32\drivers\AVerA310USB.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (BDASwCap) – C:\Windows\System32\drivers\AVerA310Cap.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (WSVD) – C:\Windows\System32\drivers\WSVD.sys (Wasay)
DRV - (winbondcir) – C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.15.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..network.proxy.type: 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Firefox-3.6.16\components [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Firefox-3.6.16\plugins [2012/02/20 22:00:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/12/28 18:46:14 | 000,000,000 | —D | M]
 
[2011/11/13 23:53:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
[2011/11/11 01:56:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/02/06 18:32:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions
[2011/11/13 23:53:58 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2012/02/06 18:32:12 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions\[removed]
[2012/03/06 21:42:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions
[2011/11/14 00:14:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/01/12 22:01:42 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2012/01/07 22:08:32 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/02/19 20:37:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/19 20:37:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
() (No name found) – C:\USERS\DAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\23I9OVQ6.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2010/07/31 18:09:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/02/18 02:41:51 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/19 20:37:20 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/02 21:30:05 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2012/02/18 02:41:46 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/02/18 02:41:46 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/18 02:41:46 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/02/18 02:41:46 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/02/18 02:41:46 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2012/03/07 20:44:49 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1	   localhost
O1 - Hosts: ::1	   localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D1BAFBA-2E42-4BF5-8DF9-8C3CC90677F6}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dan\Pictures\Wallpapers\Help.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dan\Pictures\Wallpapers\Help.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/07 20:44:35 | 000,000,000 | —D | C] – C:\_OTL
[2012/03/03 15:24:53 | 000,100,864 | —- | C] (GMER) – C:\kxtdapow.sys
[2012/03/02 19:18:08 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2012/03/02 19:14:16 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Audacity
[2012/03/02 19:14:01 | 000,000,000 | —D | C] – C:\Program Files\Audacity 1.3 Beta (Unicode)
[2012/02/26 00:44:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CAPCOM
[2012/02/26 00:44:03 | 000,000,000 | —D | C] – C:\Program Files\RESIDENT EVIL
[2012/02/25 20:45:36 | 000,000,000 | —D | C] – C:\Users\Dan\Desktop\ResidentEvil1
[2012/02/23 21:25:43 | 000,583,680 | —- | C] (OldTimer Tools) – C:\Users\Dan\Desktop\OTL.exe
[2012/02/20 22:00:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/02/20 22:00:04 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/02/19 20:38:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/02/19 20:37:40 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/02/19 20:37:40 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/02/19 20:37:40 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/02/15 17:40:52 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/02/15 17:40:51 | 001,798,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/02/15 17:40:50 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/02/15 17:40:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/02/15 17:40:50 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/02/15 17:40:47 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/02/15 08:21:35 | 002,044,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/02/12 16:04:34 | 000,000,000 | —D | C] – C:\ProgramData\EPSON
[2012/02/11 21:34:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Autodesk Shared
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\ProgramData\Autodesk
[2012/02/11 21:31:30 | 000,000,000 | —D | C] – C:\Program Files\AutoCAD 2009
[2012/02/11 21:31:07 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2012/02/11 21:30:56 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_30.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/07 20:45:53 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/07 20:45:52 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/07 20:45:49 | 000,067,584 | —- | M] () – C:\Windows\bootstat.dat
[2012/03/07 20:45:02 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2012/03/07 20:44:49 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2012/03/03 19:37:29 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/03/03 19:37:29 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/03/03 15:24:53 | 000,100,864 | —- | M] (GMER) – C:\kxtdapow.sys
[2012/02/26 00:44:18 | 000,000,331 | —- | M] () – C:\Users\Dan\Desktop\RESIDENT EVIL.lnk
[2012/02/23 21:25:48 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Users\Dan\Desktop\OTL.exe
[2012/02/19 20:38:47 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/02/19 20:37:19 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2012/02/19 20:37:19 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/02/19 20:37:19 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/02/19 20:37:19 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/02/15 21:12:08 | 000,369,344 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2012/03/04 02:52:45 | 000,000,331 | —- | C] () – C:\Users\Dan\Desktop\RESIDENT EVIL.lnk
[2012/03/02 19:14:11 | 000,000,957 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity 1.3 Beta (Unicode).lnk
[2011/12/24 19:50:55 | 000,001,604 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/11/13 01:49:02 | 000,173,646 | —- | C] () – C:\Users\Dan\AppData\Local\census.cache
[2011/11/13 01:48:54 | 000,000,000 | —- | C] () – C:\Users\Dan\AppData\Local\ars.cache
[2011/11/12 23:36:15 | 000,000,036 | —- | C] () – C:\Users\Dan\AppData\Local\housecall.guid.cache
[2011/11/09 18:59:02 | 000,000,783 | —- | C] () – C:\Windows\NTIWVEDT.INI
[2010/07/31 18:30:19 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/07/31 18:30:19 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/31 02:59:32 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2010/07/31 02:59:32 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/07/31 02:59:32 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2010/07/31 02:42:36 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin

< End of report >
Hi,

I am well thanks as I hope you are. :)
——–


Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs made by Malwarebytes and ESET online scanner.
Hi jeffce, I'm glad to hear it :)

Sorry for the late reply - here are my scans as requested:

📎Malwarebytes_icon.jpg

Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.09.08

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Dan :: DAN-PC [administrator]

Protection: Enabled

09/03/2012 20:08:14
mbam-log-2012-03-09 (20-08-14).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 266191
Time elapsed: 41 minute(s), 46 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

📎eset_nod32.jpeg

The scan didn't produce a .txt file, so I've included a screen shot of the scan

📎ESET_Online_Scanner_Results.jpg
Hi,

My system seems to be running fine. I haven't noticed any presence of Malware & I assume my logs/Scans reflect that.
However I thought I would mention these two things:
  • I have a computer game that when launched alters the screen resolution. Upon quitting the game resolution is restored, but I get a notification from NOD saying it requires attention. When I click on the notification everything seems fine. :wacko:
  • I had a redirect in my browser earlier, but that could be me inadvertently clicking on an advert or link.

Apart from that, all seems fine.
Thank you.
Hi manicd, Play around with your system for a bit and see if there are any more redirects. What is the name of the game that you are referring to?
Hi Jeffce,

Oh it's an old Game called 'Resident Evil.'
I went on a site called 'Chorley FM' which causes NOD to block JS/Agent.NEJ trojan.
These sites list it as safe -

Norton Safe Web:
http://safeweb.norton.com/report/show?url=www.chorley.fm
McAffee SiteAdvisor:
http://www.siteadvisor.pl/sites/www.chorley.fm
Hi manicd, Seems that if it is an "old game" than possibly the game is not completely compatible with your video card? I am just thinking though and not for sure. As for the "Chorley FM" web site I saw what you had provided from both Norton and McAfee. The site itself seems to be rated as safe. Any more redirects?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI