This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot Remove Boot.Tidserv Virus [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Norton Antivirus reports the following threat : Boot.Tidserv Virus
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++

OTL REPORT :

OTL logfile created on: 06/03/2012 10:11:16 PM - Run 1
OTL by OldTimer - Version 3.2.35.1 Folder = C:\Users\kdavid\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00002c09 | Country: Trinidad y Tobago | Language: ENT | Date Format: dd/MM/yyyy

3.87 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 40.86% Memory free
7.75 Gb Paging File | 5.19 Gb Available in Paging File | 67.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.99 Gb Total Space | 83.83 Gb Free Space | 29.31% Space Free | Partition Type: NTFS
Drive D: | 100.00 Mb Total Space | 60.78 Mb Free Space | 60.78% Space Free | Partition Type: NTFS
Drive E: | 12.00 Gb Total Space | 2.18 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
Drive M: | 2794.49 Gb Total Space | 1720.70 Gb Free Space | 61.57% Space Free | Partition Type: NTFS
Drive Y: | 930.44 Gb Total Space | 930.35 Gb Free Space | 99.99% Space Free | Partition Type: NTFS

Computer Name: KDAVID-PC | User Name: kdavid | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\kdavid\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
PRC - C:\Users\kdavid\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Norton Management\Engine\2.1.0.12\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\ProgramData\bProtector\bProtect.exe (bProtector)
PRC - C:\Program Files (x86)\InstallBrainService\InstallBrainService.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Users\kdavid\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.1.2\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe (Hide My IP)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - \\?\C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-21-2599977786-1247605789-4254286275-1000\Indiv01.key ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MCLIENT) – C:\Program Files (x86)\Norton Management\Engine\2.1.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (bProtector) – C:\ProgramData\bProtector\bProtect.exe (bProtector)
SRV - (InstallBrainService) – C:\Program Files (x86)\InstallBrainService\InstallBrainService.exe ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SpeedDiskService) – C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\19.5.1.2\ccSvcHst.exe (Symantec Corporation)
SRV - (HideMyIpSRV) – C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe (Hide My IP)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (taphss) – C:\Windows\SysNative\drivers\taphss.sys (AnchorFree Inc)
DRV:64bit: - (SymDSMon) – C:\Windows\SysNative\drivers\SymDSMon.sys (Symantec Corporation)
DRV:64bit: - (SYMSpeedDisk) – C:\Windows\SysNative\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ccSet_MCLIENT) – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) – C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1305010.002\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1305010.002\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) – C:\Windows\SysNative\drivers\NISx64\1305010.002\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (tapoas) – C:\Windows\SysNative\drivers\tapoas.sys (The OpenVPN Project)
DRV:64bit: - (athur) – C:\Windows\SysNative\drivers\athurx.sys (Atheros Communications, Inc.)
DRV:64bit: - (msvad_simple) – C:\Windows\SysNative\drivers\povrtdev.sys (MediaMall Technologies, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (AGERESoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\IPSDefs\20120306.002\IDSviA64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\VirusDefs\20120306.003\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\VirusDefs\20120306.003\eng64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\BASHDefs\20120302.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMSpeedDisk) – C:\Windows\SysWOW64\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.goonsearch.com/?source=IBR-IB-PDP-INS-HP
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,bProtectorDefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://www.plusnetwork.com/?q={searchTerms}&sp;=chv
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://www.goonsearch.com/web.html?source=…q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-tt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 0D 3A FC 76 A8 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://www.plusnetwork.com/?q={searchTerms}&sp;=chv
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…00090e6ba3de0c1
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://www.goonsearch.com/web.html?source=…q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enTT459
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={4199A6C…mp;d=2012-02-20 10:51:34&v;=8.0.0.34&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{B026F6F8-F317-4CFC-BCD8-5C2061218484}: "URL" = http://websearch.ask.com/redirect?client=i…73-02F7975CD32B
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "search the web"
FF - prefs.js..browser.search.order.1: "search the web"
FF - prefs.js..browser.search.selectedengine: "search the web"
FF - prefs.js..browser.search.usedbfororder: true
FF - prefs.js..browser.startup.homepage: "WWW.GOOGLE.COM"
FF - prefs.js..keyword.url: "http://www.goonsearch.com/web.html?source=ibr-ib-pdp-ins-dbs&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\kdavid\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\kdavid\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\kdavid\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\kdavid\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/12/01 20:27:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/01/01 10:30:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/19 23:44:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\IPSFFPlgn\ [2012/03/02 07:33:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\coFFPlgn\ [2012/03/06 03:18:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/02/19 20:37:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/13 17:47:18 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/12/01 20:27:25 | 000,000,000 | —D | M]

[2012/01/09 13:30:21 | 000,000,000 | —D | M] (No name found) – C:\Users\kdavid\AppData\Roaming\mozilla\Extensions
[2012/01/07 00:18:11 | 000,000,000 | —D | M] (No name found) – C:\Users\kdavid\AppData\Roaming\mozilla\Extensions\net.openvpn.client
[2012/03/06 21:36:19 | 000,000,000 | —D | M] (No name found) – C:\Users\kdavid\AppData\Roaming\mozilla\Firefox\Profiles\ei95lnbr.default\extensions
[2012/02/19 20:37:29 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\kdavid\AppData\Roaming\mozilla\Firefox\Profiles\ei95lnbr.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2012/01/03 16:27:44 | 000,002,333 | —- | M] () – C:\Users\kdavid\AppData\Roaming\Mozilla\Firefox\Profiles\ei95lnbr.default\searchplugins\askcom.xml
[2012/02/16 21:36:42 | 000,000,931 | —- | M] () – C:\Users\kdavid\AppData\Roaming\Mozilla\Firefox\Profiles\ei95lnbr.default\searchplugins\conduit.xml
[2012/01/09 12:53:55 | 000,002,409 | —- | M] () – C:\Users\kdavid\AppData\Roaming\Mozilla\Firefox\Profiles\ei95lnbr.default\searchplugins\SearchTheWeb.xml
[2012/02/17 21:31:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/19 20:37:35 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/17 14:14:28 | 000,002,149 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012/02/11 06:37:19 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/02/22 00:24:35 | 000,003,768 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2011/12/02 21:53:43 | 000,002,310 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/02/11 06:37:19 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/11 06:37:19 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/02/11 06:37:19 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/02/11 06:37:19 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={4199A6C…mp;d=2012-02-20 10:51:34&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
CHR - default_search_provider: suggest_url = http://clients5.google.com/complete/search…outputEncoding}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\kdavid\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\kdavid\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\kdavid\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: RoxioNow Player (Enabled) = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\njgpehoeakhlffpkgpigbkeagobkaofj\1.9.6.1_0\npRNowPlugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\kdavid\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\kdavid\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Productivity 3.1 = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\fojnkghiggpfagjciliabphpgnbmehjf\2.3.3.3_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Norton Identity Protection = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.1.5_0\
CHR - Extension: RoxioNow Player Extension = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\njgpehoeakhlffpkgpigbkeagobkaofj\1.9.6.1_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\kdavid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/03/02 23:43:13 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.1.2\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.1.2\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.1.2\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\kdavid\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [BitTorrent] C:\Program Files (x86)\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [cdloader] C:\Users\kdavid\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O15 - HKCU\..Trusted Ranges: Range1979 ([http] in Trusted sites)
O16 - DPF: {5852F5ED-8BF4-11D4-A245-0080C6F74284} http://javadl-esd.sun.com/update/1.5.0/jin…indows-i586.cab (isInstalled Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{62C5FA72-BED3-4DDB-B2D0-79D5A13C4122}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.avis - C:\Windows\SysWow64\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/06 22:09:41 | 000,584,704 | —- | C] (OldTimer Tools) – C:\Users\kdavid\Desktop\OTL.exe
[2012/03/05 20:52:09 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/03/05 13:20:57 | 001,544,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/03/05 13:20:57 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2012/03/04 15:21:16 | 000,000,000 | —D | C] – C:\RS_Capture
[2012/03/04 15:21:16 | 000,000,000 | —D | C] – C:\Windows\Router Screen Capture
[2012/03/04 15:21:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Router Screen Capture
[2012/03/03 00:14:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/03 00:14:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/03/02 23:52:09 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/03/02 23:43:27 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/03/02 23:24:12 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/03/02 23:24:12 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/03/02 23:24:12 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/03/02 23:22:42 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/03/02 23:21:20 | 000,000,000 | —D | C] – C:\Qoobox
[2012/03/02 18:50:22 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Local\DDMSettings
[2012/03/02 17:09:42 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/03/02 17:09:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NBRTWizardx64
[2012/03/02 17:09:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NBRTWizardx64\0405000.022
[2012/03/02 17:09:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Bootable Recovery Tool Wizard
[2012/03/02 17:09:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Bootable Recovery Tool Wizard
[2012/03/02 14:30:16 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Local\CrashDumps
[2012/03/02 10:02:04 | 000,167,048 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C\ccSetx64.sys
[2012/03/02 10:01:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\MCLIENTx64
[2012/03/02 10:01:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C
[2012/03/02 10:01:57 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Management
[2012/03/02 10:01:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Management
[2012/03/02 08:50:33 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Local\NPE
[2012/03/02 08:00:33 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\Norton Utilities
[2012/03/02 07:47:11 | 000,000,000 | —D | C] – C:\ProgramData\Norton Installer
[2012/03/02 07:45:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Utilities 15
[2012/03/02 07:45:55 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml4a.dll
[2012/03/02 07:45:53 | 000,191,232 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SymDSMon.sys
[2012/03/02 07:45:53 | 000,163,384 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SymSpeedDisk.sys
[2012/03/02 07:45:53 | 000,108,800 | —- | C] (Symantec Corporation) – C:\Windows\SysWow64\drivers\SymSpeedDisk.sys
[2012/03/02 07:45:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec
[2012/03/02 07:45:51 | 001,101,824 | —- | C] (Woodbury Associates Limited) – C:\Windows\SysWow64\UniBox210.ocx
[2012/03/02 07:45:51 | 000,880,640 | —- | C] (Woodbury Associates Limited) – C:\Windows\SysWow64\UniBox10.ocx
[2012/03/02 07:45:51 | 000,212,992 | —- | C] (Woodbury Associates Limited) – C:\Windows\SysWow64\UniBoxVB12.ocx
[2012/03/02 07:45:50 | 000,658,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSCOMCT2.OCX
[2012/03/02 07:45:50 | 000,506,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml.dll
[2012/03/02 07:45:46 | 000,000,000 | —D | C] – C:\Users\kdavid\Documents\UnErase
[2012/03/02 07:45:46 | 000,000,000 | —D | C] – C:\ProgramData\Symantec
[2012/03/02 07:45:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Utilities 15
[2012/03/02 07:39:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2012/03/02 07:34:30 | 000,000,000 | —D | C] – C:\Users\kdavid\Documents\Symantec
[2012/03/02 07:32:29 | 000,175,736 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/03/02 07:32:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/03/02 07:32:29 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2012/03/02 07:31:40 | 001,092,728 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymEFA64.sys
[2012/03/02 07:31:40 | 000,738,936 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtsp64.sys
[2012/03/02 07:31:40 | 000,451,192 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymDS64.sys
[2012/03/02 07:31:40 | 000,405,624 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\symnets.sys
[2012/03/02 07:31:40 | 000,190,072 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\Ironx64.sys
[2012/03/02 07:31:40 | 000,167,048 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\ccSetx64.sys
[2012/03/02 07:31:40 | 000,037,496 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtspx64.sys
[2012/03/02 07:31:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64
[2012/03/02 07:31:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64\1305010.002
[2012/03/02 07:31:31 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2012/03/02 07:31:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Internet Security
[2012/03/02 07:28:05 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2012/03/02 07:28:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2012/03/02 07:17:46 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2012/03/02 07:17:46 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012/03/02 07:11:13 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2012/03/02 06:22:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2012/03/02 06:22:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/03/02 06:19:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2012/03/02 06:19:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2012/03/02 06:18:53 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2012/03/02 06:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Sync Framework
[2012/03/02 06:13:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2012/03/02 06:12:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2012/03/02 06:11:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2012/03/02 06:09:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2012/03/02 06:08:28 | 000,000,000 | R–D | C] – C:\MSOCache
[2012/03/01 10:57:44 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\WinRAR
[2012/03/01 10:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/03/01 10:57:43 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/03/01 10:57:39 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/03/01 10:56:15 | 002,871,808 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2012/03/01 10:56:15 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2012/03/01 10:54:26 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2012/03/01 10:54:17 | 002,315,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2012/03/01 10:54:17 | 002,223,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2012/03/01 10:54:16 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2012/03/01 10:54:14 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2012/03/01 10:54:14 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2012/03/01 10:54:13 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2012/03/01 10:54:12 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2012/03/01 10:54:11 | 000,778,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2012/03/01 10:54:11 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2012/03/01 10:54:11 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2012/03/01 10:54:10 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2012/03/01 10:54:09 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2012/03/01 10:54:07 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2012/03/01 10:53:51 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2012/03/01 10:53:50 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2012/03/01 10:53:50 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2012/03/01 10:53:50 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2012/03/01 10:53:49 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2012/03/01 10:53:47 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2012/03/01 10:53:47 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2012/03/01 08:49:22 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2012/03/01 08:34:05 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2012/03/01 08:34:04 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2012/03/01 08:33:56 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2012/03/01 08:33:56 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2012/03/01 08:30:30 | 001,465,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2012/03/01 08:30:30 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2012/03/01 08:25:10 | 000,027,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2012/03/01 08:25:01 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2012/03/01 08:24:45 | 000,325,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2012/03/01 08:24:43 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2012/03/01 08:17:32 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2012/03/01 08:17:29 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2012/03/01 06:52:24 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Local\Bible360
[2012/03/01 06:52:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bible360
[2012/03/01 06:26:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Immersion Digital
[2012/03/01 06:26:37 | 000,000,000 | —D | C] – C:\ProgramData\Bible360
[2012/02/23 17:23:38 | 004,448,256 | —- | C] (Google Inc.) – C:\Windows\SysWow64\GPhotos.scr
[2012/02/22 22:38:50 | 000,000,000 | —D | C] – C:\ProgramData\LightScribe
[2012/02/20 10:50:54 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\TuneUp Software
[2012/02/20 10:50:09 | 000,000,000 | —D | C] – C:\ProgramData\TuneUp Software
[2012/02/20 10:28:41 | 000,000,000 | -HSD | C] – C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/02/20 05:28:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Nero
[2012/02/19 20:29:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2012/02/18 22:26:03 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2012/02/18 22:26:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\LightScribe
[2012/02/18 20:56:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vuze
[2012/02/17 21:04:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digiarty
[2012/02/17 21:04:15 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\Digiarty
[2012/02/17 21:04:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Digiarty
[2012/02/16 21:11:49 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\BitTorrent
[2012/02/16 19:09:23 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Local\{79492474-51FE-4FC1-A95D-17159EF673BF}
[2012/02/16 03:00:59 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/16 03:00:58 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/16 03:00:57 | 002,308,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/16 03:00:57 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/16 03:00:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/16 03:00:56 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/16 03:00:55 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/16 03:00:55 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/16 03:00:55 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/16 03:00:54 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/16 03:00:54 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/15 05:51:11 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2012/02/12 17:04:02 | 000,062,464 | —- | C] (Morgan Multimedia) – C:\Windows\SysNative\MMSwitch.ax
[2012/02/12 17:04:01 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Morgan Stream Switcher
[2012/02/12 17:04:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Morgan Stream Switcher
[2012/02/12 13:30:49 | 000,000,000 | —D | C] – C:\Users\kdavid\AppData\Roaming\Peter Souza IV
[2012/02/07 22:19:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/02/07 22:18:50 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/02/07 22:18:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/02/07 22:18:50 | 000,000,000 | —D | C] – C:\Program Files\iPod

========== Files - Modified Within 30 Days ==========

[2012/03/06 22:09:57 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Users\kdavid\Desktop\OTL.exe
[2012/03/06 21:49:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2599977786-1247605789-4254286275-1000UA.job
[2012/03/06 21:44:02 | 000,023,101 | —- | M] () – C:\Users\kdavid\Desktop\170308554_1701548637d3225e16c45586f77abf171ff64801876eb511.jpg
[2012/03/06 21:43:14 | 000,024,343 | —- | M] () – C:\Users\kdavid\Desktop\Greenpacket2.jpg
[2012/03/06 21:28:48 | 000,000,286 | —- | M] () – C:\Windows\reimage.ini
[2012/03/06 21:21:03 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/06 20:53:44 | 000,002,370 | —- | M] () – C:\Users\kdavid\Desktop\Google Chrome.lnk
[2012/03/06 19:22:59 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/03/06 19:21:29 | 000,782,766 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/06 19:21:29 | 000,652,150 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/03/06 19:21:29 | 000,121,082 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/03/06 19:21:08 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/06 19:00:02 | 000,000,262 | —- | M] () – C:\Windows\tasks\NUSchedule.job
[2012/03/06 18:39:55 | 000,000,218 | —- | M] () – C:\Users\kdavid\Desktop\Windows 7 Ultimate product key.rtf
[2012/03/06 18:39:40 | 000,018,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/06 18:39:40 | 000,018,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/06 05:12:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/06 03:17:49 | 3119,374,336 | -HS- | M] () – C:\hiberfil.sys
[2012/03/06 00:49:01 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2599977786-1247605789-4254286275-1000Core.job
[2012/03/05 20:36:37 | 001,747,759 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\Cat.DB
[2012/03/05 19:22:35 | 000,003,072 | —- | M] () – C:\Windows\SysWow64\Cache.db
[2012/03/05 05:39:12 | 000,788,104 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/03/03 13:23:25 | 000,000,999 | —- | M] () – C:\Users\kdavid\Desktop\magicJack.lnk
[2012/03/03 12:32:11 | 000,005,632 | —- | M] () – C:\Users\kdavid\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/03 09:30:56 | 003,919,235 | —- | M] () – C:\Users\kdavid\Desktop\Michael W. Smith Majesty [A New Hallelujah].mp3
[2012/03/03 00:14:16 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/02 23:43:13 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/03/02 23:21:30 | 002,044,252 | —- | M] () – C:\Users\kdavid\Desktop\tdsskiller.zip
[2012/03/02 17:09:40 | 000,001,539 | —- | M] () – C:\Users\Public\Desktop\Norton Bootable Recovery Tool Wizard.LNK
[2012/03/02 10:34:25 | 000,004,782 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\VT20111023.022
[2012/03/02 08:05:19 | 000,416,344 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/03/02 07:46:01 | 000,001,054 | —- | M] () – C:\Users\Public\Desktop\Norton Utilities 15.lnk
[2012/03/02 07:32:29 | 000,175,736 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/03/02 07:32:29 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/03/02 07:32:29 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/03/02 07:32:17 | 000,002,570 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/03/02 07:11:13 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012/03/01 06:52:25 | 000,000,125 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/03/01 06:52:22 | 000,001,333 | —- | M] () – C:\Users\Public\Desktop\Bible360.lnk
[2012/02/23 17:23:38 | 004,448,256 | —- | M] (Google Inc.) – C:\Windows\SysWow64\GPhotos.scr
[2012/02/21 18:16:07 | 000,001,360 | —- | M] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/02/21 18:16:07 | 000,001,336 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/02/19 20:32:06 | 000,000,993 | —- | M] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2012/02/19 20:32:06 | 000,000,969 | —- | M] () – C:\Users\kdavid\Desktop\BitTorrent.lnk
[2012/02/18 22:26:06 | 000,002,039 | —- | M] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/02/18 20:56:40 | 000,001,854 | —- | M] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2012/02/18 19:14:19 | 000,001,336 | —- | M] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX Blu-ray Decrypter.lnk
[2012/02/18 18:33:29 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/16 03:03:51 | 000,000,129 | —- | M] () – C:\Windows\SysNative\MRT.INI
[2012/02/15 23:09:05 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/02/15 23:09:05 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/02/13 09:10:28 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C\isolate.ini
[2012/02/07 22:19:18 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/02/07 03:06:08 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\isolate.ini

========== Files Created - No Company Name ==========

[2012/03/06 21:46:34 | 000,024,343 | —- | C] () – C:\Users\kdavid\Desktop\Greenpacket2.jpg
[2012/03/06 21:44:23 | 000,023,101 | —- | C] () – C:\Users\kdavid\Desktop\170308554_1701548637d3225e16c45586f77abf171ff64801876eb511.jpg
[2012/03/06 18:39:55 | 000,000,218 | —- | C] () – C:\Users\kdavid\Desktop\Windows 7 Ultimate product key.rtf
[2012/03/05 19:13:50 | 000,000,286 | —- | C] () – C:\Windows\reimage.ini
[2012/03/05 19:06:10 | 000,003,072 | —- | C] () – C:\Windows\SysWow64\Cache.db
[2012/03/03 09:29:28 | 003,919,235 | —- | C] () – C:\Users\kdavid\Desktop\Michael W. Smith Majesty [A New Hallelujah].mp3
[2012/03/03 00:14:16 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/02 23:24:12 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/03/02 23:24:12 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/03/02 23:24:12 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/03/02 23:24:12 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/03/02 23:24:12 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/03/02 23:18:22 | 002,044,252 | —- | C] () – C:\Users\kdavid\Desktop\tdsskiller.zip
[2012/03/02 20:55:38 | 000,000,969 | —- | C] () – C:\Users\kdavid\Desktop\BitTorrent.lnk
[2012/03/02 17:09:40 | 000,001,539 | —- | C] () – C:\Users\Public\Desktop\Norton Bootable Recovery Tool Wizard.LNK
[2012/03/02 17:09:13 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NBRTWizardx64\0405000.022\isolate.ini
[2012/03/02 10:35:09 | 000,004,782 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\VT20111023.022
[2012/03/02 10:01:58 | 000,007,468 | R— | C] () – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C\ccSetx64.cat
[2012/03/02 10:01:58 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C\ccSetx64.inf
[2012/03/02 10:01:58 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\MCLIENTx64\0201000.00C\isolate.ini
[2012/03/02 07:48:07 | 000,000,262 | —- | C] () – C:\Windows\tasks\NUSchedule.job
[2012/03/02 07:46:01 | 000,001,054 | —- | C] () – C:\Users\Public\Desktop\Norton Utilities 15.lnk
[2012/03/02 07:45:51 | 000,039,784 | —- | C] () – C:\Windows\SysNative\CleanMFT64.exe
[2012/03/02 07:32:36 | 001,747,759 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\Cat.DB
[2012/03/02 07:32:30 | 000,007,488 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/03/02 07:32:29 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/03/02 07:32:17 | 000,002,570 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/03/02 07:31:33 | 000,003,434 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymEFA.inf
[2012/03/02 07:31:33 | 000,002,852 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymDS.inf
[2012/03/02 07:31:33 | 000,001,441 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymNet.inf
[2012/03/02 07:31:33 | 000,001,438 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtsp64.inf
[2012/03/02 07:31:33 | 000,001,420 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtspx64.inf
[2012/03/02 07:31:33 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\ccSetx64.inf
[2012/03/02 07:31:33 | 000,000,772 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\Iron.inf
[2012/03/02 07:31:32 | 000,007,496 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymDS64.cat
[2012/03/02 07:31:32 | 000,007,468 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\ccSetx64.cat
[2012/03/02 07:31:32 | 000,007,462 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtspx64.cat
[2012/03/02 07:31:32 | 000,007,460 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymEFA64.cat
[2012/03/02 07:31:32 | 000,007,458 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\symnet64.cat
[2012/03/02 07:31:32 | 000,007,458 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\srtsp64.cat
[2012/03/02 07:31:32 | 000,007,450 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\iron.cat
[2012/03/02 07:31:32 | 000,004,782 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\SymVTcer.dat
[2012/03/02 07:31:32 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1305010.002\isolate.ini
[2012/03/02 07:11:13 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012/03/01 06:52:25 | 000,000,125 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/03/01 06:52:22 | 000,001,333 | —- | C] () – C:\Users\Public\Desktop\Bible360.lnk
[2012/02/21 18:16:07 | 000,001,360 | —- | C] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/02/21 18:16:07 | 000,001,336 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/02/19 20:29:35 | 000,000,993 | —- | C] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2012/02/18 22:26:06 | 000,002,039 | —- | C] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/02/18 20:56:40 | 000,001,854 | —- | C] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2012/02/18 20:56:40 | 000,001,854 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
[2012/02/18 19:14:19 | 000,001,336 | —- | C] () – C:\Users\kdavid\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX Blu-ray Decrypter.lnk
[2012/02/12 17:04:02 | 000,077,824 | —- | C] () – C:\Windows\SysNative\MMSwitch.dll
[2012/02/12 17:04:02 | 000,040,960 | —- | C] () – C:\Windows\SysNative\MMAVILNG.exe
[2012/02/07 22:19:18 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/18 22:50:32 | 000,005,632 | —- | C] () – C:\Users\kdavid\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/09 12:53:54 | 000,748,544 | —- | C] () – C:\Windows\SysWow64\protector.dll
[2011/12/03 15:05:57 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/12/01 20:17:22 | 000,221,277 | —- | C] () – C:\Windows\hpoins19.dat
[2011/12/01 20:17:22 | 000,013,898 | —- | C] () – C:\Windows\hpomdl19.dat
[2011/11/26 10:58:21 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/11/26 10:58:21 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/11/21 12:25:15 | 000,788,104 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== LOP Check ==========

[2012/01/14 19:34:50 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\AVG
[2012/03/04 18:26:37 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\Azureus
[2011/12/02 20:35:03 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\Babylon
[2012/03/06 22:17:38 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\BitTorrent
[2011/11/21 12:16:06 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\DAEMON Tools Lite
[2012/02/18 19:14:18 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\Digiarty
[2012/01/28 23:26:15 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\HandBrake
[2011/11/29 23:02:03 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\iPod2PC3
[2012/03/03 13:23:27 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\mjusbsp
[2012/01/07 00:18:09 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\OpenVPN Technologies
[2011/12/31 13:15:38 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\Opera
[2012/02/12 13:30:49 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\Peter Souza IV
[2012/02/20 10:50:54 | 000,000,000 | —D | M] – C:\Users\kdavid\AppData\Roaming\TuneUp Software
[2012/03/06 19:00:02 | 000,000,262 | —- | M] () – C:\Windows\Tasks\NUSchedule.job
[2009/07/14 01:08:49 | 000,028,814 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2012/02/11 18:44:21 | 000,012,914 | —- | M] () – C:\aaw7boot.log
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/11/21 11:49:00 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/03/06 03:17:49 | 3119,374,336 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/03/06 03:17:50 | 4159,168,512 | -HS- | M] () – C:\pagefile.sys
[2012/03/05 21:04:48 | 000,179,980 | —- | M] () – C:\TDSSKiller.2.7.19.0_05.03.2012_20.49.45_log.txt
[2012/03/05 21:16:11 | 000,089,874 | —- | M] () – C:\TDSSKiller.2.7.19.0_05.03.2012_21.06.18_log.txt
[2011/12/02 21:53:51 | 000,000,177 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2012/03/05 19:22:35 | 000,003,072 | —- | M] () – C:\Windows\system32\Cache.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/04 21:10:53 | 000,000,221 | -HS- | M] () – C:\Users\kdavid\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/03/06 22:09:57 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Users\kdavid\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 184 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:D287FACF

< End of report >


OTL Extras logfile created on: 06/03/2012 10:11:16 PM - Run 1
OTL by OldTimer - Version 3.2.35.1 Folder = C:\Users\kdavid\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00002c09 | Country: Trinidad y Tobago | Language: ENT | Date Format: dd/MM/yyyy

3.87 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 40.86% Memory free
7.75 Gb Paging File | 5.19 Gb Available in Paging File | 67.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.99 Gb Total Space | 83.83 Gb Free Space | 29.31% Space Free | Partition Type: NTFS
Drive D: | 100.00 Mb Total Space | 60.78 Mb Free Space | 60.78% Space Free | Partition Type: NTFS
Drive E: | 12.00 Gb Total Space | 2.18 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
Drive M: | 2794.49 Gb Total Space | 1720.70 Gb Free Space | 61.57% Space Free | Partition Type: NTFS
Drive Y: | 930.44 Gb Total Space | 930.35 Gb Free Space | 99.99% Space Free | Partition Type: NTFS

Computer Name: KDAVID-PC | User Name: kdavid | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{D1829BE5-F305-4576-9593-C66FC7E0B008}" = iCloud
"{D8CC254C-C671-4664-9A38-FA368D1E2C97}" = SES Driver
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"422991454CB076E9B856C21BBF99AF2B82317EDA" = Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (03/06/2009 1.0.0008.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Shop for HP Supplies" = Shop for HP Supplies
"WinRAR archiver" = WinRAR 4.11 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E03C8BE-0848-430F-BECA-7D7709401626}" = TP-LINK Wireless Client Utility
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{99341ACA-2A86-4235-A636-02A2A9820987}" = WD Discovery Software
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CCF13D13-A87B-34E8-B689-1896D0C2DBA2}" = Google Talk Plugin
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DB3A97C0-EEC1-43FE-AB56-E2EA972CF111}" = 1600
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}" = LightScribe System Software
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EA79DC46-98B0-4A26-A76F-448A032E5E4D}" = 1600Trb
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FEA5A8ED-93A1-44EE-9A7D-43103DB3F78D}" = 1600_Help
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"AviSynth" = AviSynth 2.5
"Bible360" = Bible360
"BitTorrent" = BitTorrent
"DivX Setup" = DivX Setup
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"file2linkib" = File2LinkIB
"HMIP50_is1" = Hide My IP 5.3
"InstallBrain Updater Service" = InstallBrain Updater Service
"iPod2PC_is1" = iPod2PC 3.9.4
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"MCLIENT" = Norton Management
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"NBRTWizard" = Norton Bootable Recovery Tool Wizard
"NIS" = Norton Internet Security
"Norton Utilities 15_is1" = Norton Utilities 15
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"Router Screen Capture" = Router Screen Capture
"VLC media player" = VLC media player 1.1.11
"WD Livewire Utility" = WD Livewire Utility
"WinLiveSuite" = Windows Live Essentials
"WinX Blu-ray Decrypter_is1" = WinX Blu-ray Decrypter 3.4.1
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 6.8.2
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome
"magicJack" = magicJack

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 02/03/2012 03:31:34 AM | Computer Name = kdavid-PC | Source = Windows Search Service | ID = 3100
Description =

Error - 02/03/2012 05:30:47 AM | Computer Name = kdavid-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\kdavid\Downloads\SoftonicDownloader_for_bittorrent.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 02/03/2012 10:04:48 AM | Computer Name = kdavid-PC | Source = Microsoft-Windows-RestartManager | ID = 10007
Description = Application or service 'Nero MediaHome 4 Service' could not be restarted.

Error - 02/03/2012 02:30:10 PM | Computer Name = kdavid-PC | Source = Application Error | ID = 1000
Description = Faulting application name: vlc.exe, version: 1.1.11.0, time stamp:
0x4e1edf37 Faulting module name: libmkv_plugin.dll, version: 0.0.0.0, time stamp:
0x4e1edf3e Exception code: 0x40000015 Fault offset: 0x00078701 Faulting process id:
0x1c20 Faulting application start time: 0x01ccf8a274227760 Faulting application path:
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe Faulting module path: C:\Program Files
(x86)\VideoLAN\VLC\plugins\libmkv_plugin.dll Report Id: bddc1780-6495-11e1-87d9-90e6ba3de0c1

Error - 02/03/2012 09:04:34 PM | Computer Name = kdavid-PC | Source = Application Error | ID = 1000
Description = Faulting application name: vlc.exe, version: 1.1.11.0, time stamp:
0x4e1edf37 Faulting module name: libmkv_plugin.dll, version: 0.0.0.0, time stamp:
0x4e1edf3e Exception code: 0x40000015 Fault offset: 0x00078701 Faulting process id:
0x1a44 Faulting application start time: 0x01ccf8d98599c688 Faulting application path:
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe Faulting module path: C:\Program Files
(x86)\VideoLAN\VLC\plugins\libmkv_plugin.dll Report Id: d6dc91d8-64cc-11e1-8fb6-90e6ba3de0c1

Error - 04/03/2012 03:25:24 PM | Computer Name = kdavid-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: Flash11e.ocx, version: 11.1.102.55,
time stamp: 0x4eaf89fc Exception code: 0xc0000005 Fault offset: 0x00117408 Faulting
process id: 0x1980 Faulting application start time: 0x01ccfa2af374a4a0 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\Macromed\Flash\Flash11e.ocx Report Id: ca22b9b8-662f-11e1-93c9-90e6ba3de0c1

Error - 05/03/2012 07:59:47 PM | Computer Name = kdavid-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\kdavid\Downloads\SoftonicDownloader_for_bittorrent.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 06/03/2012 01:17:52 AM | Computer Name = kdavid-PC | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "c:\program files\microsoft
security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
security client\MSESysprep.dll" on line 10. The element imaging appears as a child
of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
this version of Windows.

Error - 06/03/2012 05:23:05 AM | Computer Name = kdavid-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Public\Downloads\Norton\{NIS1951002-SHPD-FSD25037}\SoftonicDownloader_for_bittorrent.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 06/03/2012 05:23:05 AM | Computer Name = kdavid-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Public\Downloads\Norton\{NIS1951002-SHPD-FSD25037}\SoftonicDownloader_for_bittorrent.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

[ Media Center Events ]
Error - 02/02/2012 03:32:46 AM | Computer Name = kdavid-PC | Source = MCUpdate | ID = 0
Description = 03:32:39 AM - Error connecting to the internet. 03:32:39 AM - Unable
to contact server..

[ System Events ]
Error - 05/03/2012 08:35:05 PM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 05/03/2012 08:41:22 PM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 05/03/2012 08:47:39 PM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 05/03/2012 08:47:39 PM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 05/03/2012 09:14:25 PM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 06/03/2012 03:16:16 AM | Computer Name = kdavid-PC | Source = DCOM | ID = 10010
Description =

Error - 06/03/2012 03:18:30 AM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 3002
Description =

Error - 06/03/2012 03:29:01 AM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 06/03/2012 03:49:01 AM | Computer Name = kdavid-PC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 06/03/2012 03:55:58 AM | Computer Name = kdavid-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.


< End of report >
Hello kd2012 and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

Norton Antivirus reports the following threat : Boot.Tidserv Virus

Are you being redirected when you perform Internet searches?


I can see that you have ran Combofix on this machine.

While you may see ComboFix being used quite often and without incident, the tool should not be run unsupervised (as stated in the Disclaimer that is first displayed by ComboFix when you run the tool)

Why we don't ask you to run ComboFix from the onset

As stated by the author of ComboFix:

ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop.

We first need to verify if there's any rootkits present and how they could affect our tools.

We can then determine the infections present & decide whether to deploy ComboFix.

That being said, the log produced by ComboFix contains important information for us. Kindly post the contents of the C:\ComboFix.txt

I would also like to see a report form the following tool:

  • aswMBR


  • Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the "Scan" button to start scan.

[external image: Posted Image]

  • On completion of the scan click save log, save it to your desktop and post in your next reply.

[external image: Posted Image]

Please post the Combofix log and the aswMBR log in your next reply.
Hi Jon, I am so happy to hear from you. My computer is working fine apart from the Norton popups about this virus. I cannot seem to locate the combofix.txt see aswMBR log: aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software Run date: 2012-03-07 23:32:34 —————————– 23:32:34.759 OS Version: Windows x64 6.1.7601 Service Pack 1 23:32:34.759 Number of processors: 2 586 0x602 23:32:34.760 ComputerName: KDAVID-PC UserName: kdavid 23:32:37.923 Initialize success 23:37:30.818 AVAST engine defs: 12030701 23:38:53.292 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006e 23:38:53.292 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 3 23:38:53.312 Disk 0 MBR read successfully 23:38:53.312 Disk 0 MBR scan 23:38:53.332 Disk 0 Windows 7 default MBR code 23:38:53.342 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 100 MB offset 2048 23:38:53.352 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 292852 MB offset 206848 23:38:53.402 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 12291 MB offset 599967744 23:38:53.472 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 1 MB offset 625139712 23:38:53.492 Disk 0 Partition 4 **INFECTED** MBR:Alureon-K [Rtk] 23:38:53.552 Disk 0 scanning C:\Windows\system32\drivers 23:39:35.318 Service scanning 23:40:34.083 Modules scanning 23:40:34.443 Disk 0 trace - called modules: 23:40:34.463 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor.sys 23:40:34.473 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80041fd060] 23:40:34.483 3 CLASSPNP.SYS[fffff8800185a43f] -> nt!IofCallDriver -> [0xfffffa800408d6e0] 23:40:34.493 5 ACPI.sys[fffff88000f7e7a1] -> nt!IofCallDriver -> \Device\0000006e[0xfffffa8004096060] 23:40:36.529 AVAST engine scan C:\Windows 23:40:43.720 AVAST engine scan C:\Windows\system32 23:51:35.401 AVAST engine scan C:\Windows\system32\drivers 23:52:39.300 AVAST engine scan C:\Users\kdavid 23:52:45.990 Disk 0 MBR has been saved successfully to "C:\Users\kdavid\Desktop\MBR.dat" 23:52:46.001 The log file has been saved successfully to "C:\Users\kdavid\Desktop\aswMBR.txt" ================================================================================ ================================================================================= =====
Hello kd2012

Thank you for the log.

If you use this machine for any kind of financial transactions please go to an uninfected computer and change all of your passwords as soon as you can.

The malware has created an additional partition on your machine which is being flagged by Norton.

We need to take a closer look at the partition to determine the best course of action. The best way to do this is to create an MBR dump from outside of the normal Windows loading environment.


Please work your way through the following steps:


  • xPUD

    We will need a USB memory stick and access to an uninfected machine.

    We need to prepare the USB stick. It is not absolutely essential that it is formatted, but it may help if it is:

  • Insert your USB drive ino the uninfected machine.
  • Click on Start > My Computer > right click your USB drive > choose Format > Quick format.

Next

  • Please use Firefox to download each required tool (Internet Explorer can sometimes encounter problems).
  • Download both http://sourceforge.net/projects/unetbootin…87.exe/download and http://noahdfear.net/downloads/bootable/xPUD/xpud-0.9.2.iso to the desktop of the uninfected machine.
  • Make sure you have the formatted USB stick in the uninfected system.
  • Double click on the unetbootin-xpud-windows-387.exe that you just downloaded.
  • Press Run and then OK.
  • Select the DiskImage option then click the browse button located on the right side of the textbox field.
  • Browse to and select the xpud-0.9.2.iso file you downloaded.
  • Verify the correct drive letter is selected for your USB device then click OK.
  • It will install a little bootable OS on your USB device
  • After it has completed do not choose to reboot the clean computer, simply close the installer.

Next


Next

  • Take the USB to the infected computer and boot with it.
  • The computer must be set to boot from the USB (as soon as BIOS is loaded tap F12 and choose to boot from the USB drive).
  • A Welcome to xPUD screen will appear.
  • Press File.
  • Expand mnt.
  • sda1,2…usually corresponds to your HDD.
  • sdb1 is likely your USB drive.
  • Click on the folder that represents your USB drive (sdb1 ?).
  • Confirm that you see dumpit that you downloaded there.
  • Double click on dumpit.
  • Once completed, a file called mbr.zip will be saved to the USB drive.
  • Take the USB drive back to the uninfected system and attach the mbr.zip in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI