This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Delayed Write Error pop up

92 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys,

So I booted up my pc today and immidealy got the "Windows Delayed Write Error"

I then rebooted and noticed that my icon's on my quickstart were replaced with blanks and my c:/ is missing from my computer =(

I can't run any virus/anti virus programs

below is my OTL,Hijack This Log and dds

Thanks and Kind reguards

OTL Results

OTL logfile created on: 3/23/2012 6:47:20 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = D:\Documents and Settings\Alex.HOME-0F9204D933
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 74.04% Memory free
5.09 Gb Paging File | 4.29 Gb Available in Paging File | 84.34% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive D: | 76.32 Gb Total Space | 15.69 Gb Free Space | 20.55% Space Free | Partition Type: NTFS
Drive I: | 641.66 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ALEX | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\Alex.HOME-0F9204D933\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - D:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - d:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - D:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - D:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - D:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - D:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - D:\Program Files\PC Tools\PC Tools Security\BDT\BSPatch.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll ()
MOD - D:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - D:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - D:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3154.36854__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3154.36946__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3154.36966__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3154.36827__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3154.36856__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3154.36959__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3154.36848__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3154.36912__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3154.36841__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3154.36988__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3154.36932__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3154.36840__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3154.36939__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3154.36989__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3154.36855__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3154.36939__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3154.36938__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3154.36855__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3154.37008__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3154.37008__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3154.36914__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3154.36960__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3154.36857__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3154.36842__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3154.36952__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3154.36856__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3154.36929__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3154.36914__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3154.36863__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3154.36929__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3154.36933__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3154.36906__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3154.36913__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3154.36912__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3154.36913__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3154.36930__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3127.31122__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3127.31117__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3127.31128__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3127.31131__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3127.31108__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3127.31110__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3127.31134__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3127.31130__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3127.31160__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3127.31160__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3127.31159__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3127.31111__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3127.31124__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3127.31143__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3127.31156__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3127.31186__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3127.31124__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3127.31121__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3127.31118__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3127.31137__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3127.31156__90ba9c70f846762e\DEM.OS.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3127.31135__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3127.31123__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3127.31137__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3127.31135__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3127.31143__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3127.31140__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3127.31140__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3127.31139__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3127.31142__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3127.31130__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3127.31137__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3127.31136__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3127.31131__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3127.31141__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3127.31136__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3127.31130__90ba9c70f846762e\APM.Foundation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3127.31123__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3154.37011__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3154.36972__90ba9c70f846762e\CLI.Component.Systemtray.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3154.36847__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3154.36980__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3154.36979__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3154.37000__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3127.31115__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3127.31119__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3127.31132__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3127.31132__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3127.31114__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll ()
MOD - D:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3154.36825__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3154.36826__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3154.36827__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3127.31133__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3127.31129__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3154.36834__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3154.36826__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3154.36824__90ba9c70f846762e\APM.Server.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3154.36825__90ba9c70f846762e\AEM.Server.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3127.31126__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3154.36980__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - D:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3127.31144__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - D:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - D:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - D:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - D:\Program Files\ASUS\Six Engine\SixEngine.exe ()
MOD - D:\Program Files\ASUS\Six Engine\AsSpindownTimeout.dll ()
MOD - D:\WINDOWS\system32\OemSpi.dll ()
MOD - D:\WINDOWS\system32\AsIO.dll ()
MOD - D:\Program Files\ASUS\Six Engine\pngio.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe File not found
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe File not found
SRV - (sdCoreService) – D:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – D:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) – D:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (Creative Audio Engine Licensing Service) – D:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Microsoft SharePoint Workspace Audit Service) – D:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MsMpSvc) – d:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (NAUpdate) – D:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (SwitchBoard) – D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (CTAudSvcService) – D:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys File not found
DRV - (MpKsl0cf75b23) – d:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AF5BFE65-018E-42E1-A46D-CF4BCE8E48C6}\MpKsl0cf75b23.sys (Microsoft Corporation)
DRV - (PCTSD) – D:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctEFA) – D:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – D:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (sptd) – D:\WINDOWS\system32\drivers\sptd.sys ()
DRV - (PCTCore) – D:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTBD) – D:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (avipbb) – D:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – D:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (wmamp3DriverV32) – D:\WINDOWS\system32\drivers\wmamp3DriverV32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ssmdrv) – D:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (ati2mtag) – D:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – D:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (L1e) – D:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (mv61xx) – D:\WINDOWS\system32\drivers\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – D:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (skfilt) – D:\WINDOWS\system32\drivers\skfilt.SYS (Creative)
DRV - (AsIO) – D:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (P17xfi) – D:\WINDOWS\system32\drivers\P17xfi.sys (Creative Technology Ltd.)
DRV - (p17xfilt) – D:\WINDOWS\system32\drivers\p17xfilt.sys (Creative)
DRV - (P17) – D:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (CTUSFSYN) – D:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (ossrv) – D:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – D:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (MTsensor) – D:\WINDOWS\system32\drivers\ASACPI.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10…;ctid=CT3031743
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3031743
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: D:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2012/03/23 18:19:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/08/11 15:12:12 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Mozilla\Extensions
[2011/08/13 18:40:13 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Mozilla\Firefox\Profiles\ncqar016.default\extensions

O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] D:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] D:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File not found
O4 - HKLM..\Run: [BCSSync] D:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] d:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [P17Helper] D:\WINDOWS\System32\SPIRun.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [Six Engine] D:\Program Files\ASUS\Six Engine\SixEngine.exe ()
O4 - HKLM..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [VolPanel] "c:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe" /r File not found
O4 - HKCU..\Run: [SetDefaultMIDI] D:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - D:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D0C0476-4904-4B71-ABB5-F8F54D3628D5}: DhcpNameServer = [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (D:\WINDOWS\system32\userinit.exe) - D:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/14 17:18:10 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2000/05/11 07:13:12 | 000,000,046 | R— | M] () - I:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{8011f36f-c41a-11e0-8b68-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{8011f36f-c41a-11e0-8b68-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8011f36f-c41a-11e0-8b68-806d6172696f}\Shell\AutoRun\command - "" = I:\SETUP.EXE – [2000/05/20 23:36:50 | 000,032,768 | R— | M] ()
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\SETUP.EXE – [2000/05/20 23:36:50 | 000,032,768 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - D:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.dll (Intel Corporation)
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/23 18:42:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – D:\Documents and Settings\Alex.HOME-0F9204D933\HiJackThis.exe
[2012/03/23 18:42:43 | 000,593,920 | —- | C] (OldTimer Tools) – D:\Documents and Settings\Alex.HOME-0F9204D933\OTL.exe
[2012/03/23 18:34:21 | 000,237,072 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\MpSigStub.exe
[2012/03/23 18:32:12 | 000,000,000 | —D | C] – D:\WINDOWS\LastGood
[2012/03/23 18:31:57 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Security Client
[2012/03/23 18:31:34 | 008,068,864 | —- | C] (Microsoft Corporation) – D:\Documents and Settings\Alex.HOME-0F9204D933\mseinstall.exe
[2012/03/23 18:21:14 | 000,000,000 | —D | C] – D:\Documents and Settings\Alex.HOME-0F9204D933\Local Settings\Application Data\Threat Expert
[2012/03/23 18:19:57 | 000,149,456 | —- | C] (PC Tools) – D:\WINDOWS\SGDetectionTool.dll
[2012/03/23 18:19:57 | 000,056,840 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\PCTBD.sys
[2012/03/23 18:19:56 | 002,250,704 | —- | C] (Threat Expert Ltd.) – D:\WINDOWS\PCTBDCore.dll
[2012/03/23 18:19:56 | 001,681,360 | —- | C] (Threat Expert Ltd.) – D:\WINDOWS\PCTBDRes.dll
[2012/03/23 18:18:45 | 000,253,352 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/03/23 18:18:40 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\PC Tools Security
[2012/03/23 18:18:39 | 000,017,848 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\pctBTFix.sys
[2012/03/23 18:18:32 | 000,070,536 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\pctplsg.sys
[2012/03/23 18:18:23 | 000,000,000 | —D | C] – D:\Program Files\PC Tools
[2012/03/23 18:14:57 | 000,909,728 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\pctEFA.sys
[2012/03/23 18:14:57 | 000,342,168 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\pctDS.sys
[2012/03/23 18:14:54 | 000,331,880 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\PCTCore.sys
[2012/03/23 18:14:54 | 000,162,584 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/03/23 18:14:52 | 000,185,560 | —- | C] (PC Tools) – D:\WINDOWS\System32\drivers\PCTSD.sys
[2012/03/23 18:14:52 | 000,000,000 | —D | C] – D:\Program Files\Common Files\PC Tools
[2012/03/23 18:14:30 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users.WINDOWS\Application Data\PC Tools
[2012/03/23 18:14:29 | 000,000,000 | —D | C] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\TestApp
[2012/03/23 18:14:25 | 003,834,832 | —- | C] (PC Tools) – D:\Documents and Settings\Alex.HOME-0F9204D933\sdsetup.exe
[2012/03/23 17:56:23 | 000,000,000 | -HSD | C] – D:\Documents and Settings\Alex.HOME-0F9204D933\PrivacIE
[2012/03/07 09:21:18 | 000,000,000 | -HSD | C] – D:\Documents and Settings\Alex.HOME-0F9204D933\IETldCache
[2012/03/07 00:44:34 | 000,000,000 | —D | C] – D:\WINDOWS\ie8updates
[2012/03/07 00:43:42 | 011,082,240 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\ieframe.dll
[2012/03/07 00:43:42 | 002,000,384 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\iertutil.dll
[2012/03/07 00:43:42 | 000,743,424 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/03/07 00:43:42 | 000,602,112 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\msfeeds.dll
[2012/03/07 00:43:42 | 000,055,296 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012/03/07 00:43:31 | 000,000,000 | —D | C] – D:\WINDOWS\WBEM
[2012/03/07 00:42:16 | 000,000,000 | -H-D | C] – D:\WINDOWS\ie8
[2012/02/28 21:15:36 | 000,000,000 | —D | C] – D:\Program Files\UDPixel
[2011/11/22 12:07:30 | 000,730,192 | —- | C] (How Inc.) – D:\Program Files\Common Files\ZugoInstaller.exe
[7 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
[5 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/23 18:50:06 | 000,625,664 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\dds.scr
[2012/03/23 18:49:51 | 000,625,664 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\dds.scr
[2012/03/23 18:47:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – D:\Documents and Settings\Alex.HOME-0F9204D933\HiJackThis.exe
[2012/03/23 18:43:00 | 000,593,920 | —- | M] (OldTimer Tools) – D:\Documents and Settings\Alex.HOME-0F9204D933\OTL.exe
[2012/03/23 18:37:20 | 000,000,424 | -H– | M] () – D:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/23 18:37:18 | 000,000,390 | -H– | M] () – D:\WINDOWS\tasks\MpIdleTask.job
[2012/03/23 18:32:32 | 000,001,945 | —- | M] () – D:\WINDOWS\epplauncher.mif
[2012/03/23 18:32:12 | 000,607,138 | —- | M] () – D:\WINDOWS\System32\drivers\Cat.DB
[2012/03/23 18:31:51 | 000,013,646 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2012/03/23 18:31:40 | 008,068,864 | —- | M] (Microsoft Corporation) – D:\Documents and Settings\Alex.HOME-0F9204D933\mseinstall.exe
[2012/03/23 18:18:40 | 000,001,819 | —- | M] () – D:\Documents and Settings\All Users.WINDOWS\Desktop\PC Tools Spyware Doctor.lnk
[2012/03/23 18:14:30 | 000,001,482 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\sdsetup.exe.lnk
[2012/03/23 18:14:28 | 003,834,832 | —- | M] (PC Tools) – D:\Documents and Settings\Alex.HOME-0F9204D933\sdsetup.exe
[2012/03/23 18:10:49 | 000,433,426 | —- | M] () – D:\WINDOWS\System32\perfh009.dat
[2012/03/23 18:10:49 | 000,068,076 | —- | M] () – D:\WINDOWS\System32\perfc009.dat
[2012/03/23 18:06:29 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2012/03/23 18:06:28 | 000,044,964 | —- | M] () – D:\WINDOWS\System32\ativvaxx.cap
[2012/03/17 19:47:00 | 000,000,284 | —- | M] () – D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/03/15 03:20:36 | 003,577,688 | —- | M] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/15 03:01:51 | 000,001,374 | —- | M] () – D:\WINDOWS\imsins.BAK
[2012/03/15 02:00:00 | 000,000,340 | —- | M] () – D:\WINDOWS\tasks\AdobeAAMUpdater-1.0-HOME-0F9204D933-Alex.job
[2012/03/01 13:26:20 | 000,048,128 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/29 09:53:44 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – D:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/28 21:11:05 | 000,000,702 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\.jscreenfix.licence
[2012/02/26 20:17:09 | 000,000,438 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Music.lnk
[2012/02/24 10:37:08 | 000,070,536 | —- | M] (PC Tools) – D:\WINDOWS\System32\drivers\pctplsg.sys
[2012/02/24 10:36:44 | 000,185,560 | —- | M] (PC Tools) – D:\WINDOWS\System32\drivers\PCTSD.sys
[2012/02/24 10:35:50 | 000,017,848 | —- | M] (PC Tools) – D:\WINDOWS\System32\drivers\pctBTFix.sys
[2012/02/24 10:31:08 | 000,253,352 | —- | M] (PC Tools) – D:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/02/23 09:18:36 | 000,237,072 | —- | M] (Microsoft Corporation) – D:\WINDOWS\System32\MpSigStub.exe
[7 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
[5 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/23 18:49:57 | 000,625,664 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\dds.scr
[2012/03/23 18:49:46 | 000,625,664 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\dds.scr
[2012/03/23 18:37:19 | 000,000,424 | -H– | C] () – D:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/23 18:37:18 | 000,000,390 | -H– | C] () – D:\WINDOWS\tasks\MpIdleTask.job
[2012/03/23 18:32:32 | 000,001,945 | —- | C] () – D:\WINDOWS\epplauncher.mif
[2012/03/23 18:32:07 | 000,001,690 | —- | C] () – D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/03/23 18:19:57 | 000,767,952 | —- | C] () – D:\WINDOWS\BDTSupport.dll
[2012/03/23 18:19:57 | 000,000,882 | —- | C] () – D:\WINDOWS\RegSDImport.xml
[2012/03/23 18:19:57 | 000,000,879 | —- | C] () – D:\WINDOWS\RegISSImport.xml
[2012/03/23 18:19:56 | 000,003,488 | —- | C] () – D:\WINDOWS\UDB.zip
[2012/03/23 18:19:56 | 000,000,131 | —- | C] () – D:\WINDOWS\IDB.zip
[2012/03/23 18:18:40 | 000,001,819 | —- | C] () – D:\Documents and Settings\All Users.WINDOWS\Desktop\PC Tools Spyware Doctor.lnk
[2012/03/23 18:14:58 | 000,607,138 | —- | C] () – D:\WINDOWS\System32\drivers\Cat.DB
[2012/03/23 18:14:30 | 000,001,482 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\sdsetup.exe.lnk
[2012/02/28 21:11:04 | 000,000,702 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\.jscreenfix.licence
[2012/02/26 20:17:09 | 000,000,438 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Music.lnk
[2012/02/15 20:01:38 | 000,003,072 | —- | C] () – D:\WINDOWS\System32\iacenc.dll
[2011/12/07 22:22:27 | 000,021,840 | —- | C] () – D:\WINDOWS\System32\SIntfNT.dll
[2011/12/07 22:22:27 | 000,017,212 | —- | C] () – D:\WINDOWS\System32\SIntf32.dll
[2011/12/07 22:22:27 | 000,012,067 | —- | C] () – D:\WINDOWS\System32\SIntf16.dll
[2011/12/07 22:21:10 | 000,019,319 | —- | C] () – D:\WINDOWS\DIIUnin.dat
[2011/12/07 10:40:30 | 000,000,132 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Adobe GIF Format CS5 Prefs
[2011/12/04 10:11:14 | 000,006,006 | —- | C] () – D:\WINDOWS\DiabUnin.dat
[2011/12/02 12:17:21 | 000,000,171 | —- | C] () – D:\WINDOWS\icecast2.ini
[2011/12/02 10:24:25 | 000,000,532 | —- | C] () – D:\WINDOWS\eReg.dat
[2011/11/24 14:50:40 | 000,000,000 | —- | C] () – D:\WINDOWS\PowerReg.dat
[2011/11/22 19:04:52 | 000,000,958 | —- | C] () – D:\WINDOWS\SOFPLAT.ini
[2011/09/29 23:37:17 | 000,000,664 | —- | C] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/08/20 13:04:16 | 000,057,600 | -H– | C] () – D:\WINDOWS\System32\mlfcache.dat
[2011/08/14 18:44:12 | 000,048,128 | —- | C] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/11 15:12:04 | 000,000,000 | —- | C] () – D:\WINDOWS\nsreg.dat
[2011/08/11 15:04:22 | 000,137,216 | —- | C] () – D:\WINDOWS\System32\OemSpi.dll
[2011/08/11 15:04:22 | 000,065,536 | —- | C] ( ) – D:\WINDOWS\System32\A3d.dll
[2011/08/11 15:04:22 | 000,053,248 | —- | C] () – D:\WINDOWS\System32\P17CPI.dll
[2011/08/11 15:04:22 | 000,008,251 | —- | C] () – D:\WINDOWS\sfsyn.ini
[2011/08/11 15:01:42 | 000,000,000 | —- | C] () – D:\WINDOWS\ativpsrm.bin
[2011/08/11 14:48:43 | 000,593,920 | —- | C] () – D:\WINDOWS\System32\ati2sgag.exe
[2011/08/11 14:48:34 | 000,887,724 | R— | C] () – D:\WINDOWS\System32\ativva6x.dat
[2011/08/11 14:48:33 | 003,107,788 | R— | C] () – D:\WINDOWS\System32\ativva5x.dat
[2011/08/11 14:48:32 | 003,107,788 | R— | C] () – D:\WINDOWS\System32\ativvaxx.dat
[2011/08/11 14:48:32 | 000,174,818 | R— | C] () – D:\WINDOWS\System32\atiicdxx.dat
[2011/08/11 14:39:09 | 000,024,825 | R— | C] () – D:\WINDOWS\System32\xfisk.ini
[2011/08/11 14:39:00 | 000,151,040 | R— | C] () – D:\WINDOWS\System32\KSXPPI32.dll
[2011/08/11 14:04:50 | 000,024,576 | R— | C] () – D:\WINDOWS\System32\AsIO.dll
[2011/08/11 14:04:50 | 000,012,400 | R— | C] () – D:\WINDOWS\System32\drivers\AsIO.sys
[2011/08/11 14:04:47 | 000,011,832 | —- | C] () – D:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2011/08/11 14:04:47 | 000,010,216 | —- | C] () – D:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2011/08/11 13:59:01 | 000,049,152 | R— | C] () – D:\WINDOWS\System32\ChCfg.exe
[2011/08/11 13:44:53 | 000,037,628 | —- | C] () – D:\WINDOWS\Ascd_log.ini
[2011/08/11 13:44:29 | 000,005,810 | R— | C] () – D:\WINDOWS\System32\drivers\ASACPI.sys
[2011/08/11 13:44:18 | 000,037,237 | —- | C] () – D:\WINDOWS\Ascd_tmp.ini
[2011/08/11 13:44:18 | 000,010,296 | —- | C] () – D:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2011/08/11 13:34:59 | 000,002,048 | –S- | C] () – D:\WINDOWS\bootstat.dat
[2011/08/11 13:29:36 | 000,021,640 | —- | C] () – D:\WINDOWS\System32\emptyregdb.dat
[2011/08/11 09:19:14 | 000,004,161 | —- | C] () – D:\WINDOWS\ODBCINST.INI
[2011/08/11 09:15:57 | 003,577,688 | —- | C] () – D:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2011/12/31 10:34:27 | 000,000,000 | —D | M] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Canon
[2011/11/29 17:54:23 | 000,000,000 | —D | M] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\DAEMON Tools Pro
[2011/11/29 21:11:12 | 000,000,000 | —D | M] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\SystemRequirementsLab
[2012/03/23 18:14:29 | 000,000,000 | —D | M] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\TestApp
[2012/02/19 10:29:56 | 000,000,000 | —D | M] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\uTorrent
[2011/11/29 21:42:39 | 000,000,000 | —D | M] – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\wargaming.net
[2011/12/30 21:59:14 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\CanonEPP
[2011/12/30 21:59:14 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\CanonIJEPPEX2
[2011/12/30 21:37:28 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\CanonIJMSetup
[2011/12/30 21:59:15 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\CanonIJSolutionMenuEX
[2011/12/30 21:37:07 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\CanonIJWSpt
[2011/11/29 09:26:25 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\DAEMON Tools Pro
[2011/12/05 09:42:58 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\regid.1986-12.com.adobe
[2012/03/23 18:40:31 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2011/08/11 15:49:17 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/03/23 18:37:20 | 000,000,424 | -H– | M] () – D:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/03/23 18:37:18 | 000,000,390 | -H– | M] () – D:\WINDOWS\Tasks\MpIdleTask.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/01/14 17:18:10 | 000,000,000 | —- | M] () – D:\AUTOEXEC.BAT
[2009/01/14 17:13:19 | 000,000,211 | -HS- | M] () – D:\boot.ini
[2008/08/31 12:12:53 | 000,009,370 | —- | M] () – D:\ComboFix.txt
[2004/09/22 22:31:28 | 000,000,000 | —- | M] () – D:\CONFIG.SYS
[2004/09/22 22:31:28 | 000,000,000 | RHS- | M] () – D:\IO.SYS
[2008/08/31 20:27:45 | 000,000,110 | —- | M] () – D:\mmcInst.log
[2004/09/22 22:31:28 | 000,000,000 | RHS- | M] () – D:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – D:\NTDETECT.COM
[2004/08/04 08:00:00 | 000,250,032 | RHS- | M] () – D:\ntldr
[2012/03/23 18:06:25 | 2145,386,496 | -HS- | M] () – D:\pagefile.sys
[2004/09/24 09:37:15 | 000,001,875 | —- | M] () – D:\PollSt.txt
[2006/06/01 16:23:25 | 000,000,079 | —- | M] () – D:\Show Desktop.scf
[2009/01/15 16:41:42 | 000,000,232 | -H– | M] () – D:\sqmdata00.sqm
[2009/01/15 16:42:23 | 000,000,232 | -H– | M] () – D:\sqmdata01.sqm
[2009/01/15 16:41:42 | 000,000,244 | -H– | M] () – D:\sqmnoopt00.sqm
[2009/01/15 16:42:23 | 000,000,244 | -H– | M] () – D:\sqmnoopt01.sqm
[2011/12/04 20:56:15 | 000,009,728 | -HS- | M] () – D:\Thumbs.db
[2008/06/07 04:35:41 | 000,000,150 | —- | M] () – D:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – D:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – D:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – D:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – D:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/08/11 13:32:10 | 000,000,067 | -HS- | M] () – D:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/08/25 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – D:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDA9.DLL
[2010/08/25 06:00:00 | 000,073,216 | —- | M] (CANON INC.) – D:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPA9.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/08/11 09:14:55 | 000,094,208 | —- | M] () – D:\WINDOWS\System32\config\default.sav
[2011/08/11 09:14:55 | 000,634,880 | —- | M] () – D:\WINDOWS\System32\config\software.sav
[2011/08/11 09:14:55 | 000,937,984 | —- | M] () – D:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/08/11 14:15:55 | 000,000,272 | -HS- | M] () – D:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/11 14:21:37 | 000,000,119 | -HS- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/11 13:38:25 | 000,000,079 | —- | M] () – D:\Documents and Settings\Alex.HOME-0F9204D933\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >
[2011/09/02 14:03:28 | 000,730,192 | —- | M] (How Inc.) – D:\Program Files\Common Files\ZugoInstaller.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-15 07:03:33

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:430C6D84

< End of report >

OTL Extras logfile created on: 3/23/2012 6:47:20 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = D:\Documents and Settings\Alex.HOME-0F9204D933
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 74.04% Memory free
5.09 Gb Paging File | 4.29 Gb Available in Paging File | 84.34% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive D: | 76.32 Gb Total Space | 15.69 Gb Free Space | 20.55% Space Free | Partition Type: NTFS
Drive I: | 641.66 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ALEX | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1"

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "D:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "c:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1"
Directory [Bridge] – D:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "c:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1"
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\Winamp\winamp.exe" = D:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp – (Nullsoft, Inc.)
"D:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = D:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"D:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = D:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"D:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = D:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"D:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = D:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\Soldier Of Fortune\SoF.exe" = C:\Program Files\Soldier Of Fortune\SoF.exe:*:Enabled:SoF
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player
"C:\Program Files\World_of_Tanks\WorldOfTanks.exe" = C:\Program Files\World_of_Tanks\WorldOfTanks.exe:*:Enabled:World of Tanks
"D:\Program Files\Icecast2 Win32\Icecast2win.exe" = D:\Program Files\Icecast2 Win32\Icecast2win.exe:*:Enabled:Icecast2win
"D:\Program Files\Java\jre6\bin\javaw.exe" = D:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{022C4B5F-4A59-48DD-08A6-6EC5832DBFFE}" = Catalyst Control Center Localization Chinese Standard
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1148CE6F-6956-6ED3-1DBF-0A0046427A3E}" = CCC Help Swedish
"{1350E13C-A031-6574-961B-367DE4721E86}" = Catalyst Control Center Graphics Light
"{14A776EF-3904-3C55-508F-BB093954391E}" = Catalyst Control Center Localization Dutch
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{19762EA5-8279-8FA8-5F16-7DEEF571E5D6}" = CCC Help Russian
"{1A90FD8B-8A64-8B83-D486-E507AEC997EF}" = Catalyst Control Center Graphics Full Existing
"{1D4C0096-98D0-5290-A5F7-AAA05121FA0A}" = CCC Help Danish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2E73FAB9-7713-D109-24DB-28339CB7A3CC}" = Catalyst Control Center Localization Norwegian
"{30517D85-B2C9-5920-77B2-6034DDC90B7C}" = CCC Help Czech
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35A6DE92-DE2E-9FBB-C919-B9CA5079116D}" = Catalyst Control Center Localization Turkish
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{39C1585C-1004-5091-180A-5AFCA3D505C2}" = Catalyst Control Center Localization Thai
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{41269776-CF11-AADD-A1A9-6E1701877F88}" = CCC Help Norwegian
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{455B46A4-17C2-DDDA-F695-7F157E2C6160}" = Catalyst Control Center Localization Danish
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E10FFCA-5C09-6E8E-4DA4-B71FFC58C435}" = CCC Help Korean
"{4E568350-98BF-A31B-4E90-B23428023916}" = Catalyst Control Center Localization Spanish
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5827D56B-9A4D-6858-95C9-28B2D46F56EB}" = CCC Help German
"{5954C9DD-80C5-27FB-67FA-1DF0B5E2565A}" = Catalyst Control Center Localization Portuguese
"{5B3A354B-C059-4861-A85B-CA46F1089E15}" = Creative USB Headsets
"{5B6844F3-8C27-C589-E519-9AAE0AC87407}" = CCC Help Dutch
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{5DC1DF0D-8B08-30D9-5F5F-857ADC69201A}" = Catalyst Control Center Graphics Full New
"{5DDBDE45-EB70-DC65-6D06-6D25906E7797}" = CCC Help Japanese
"{5E075172-D826-3CFC-51F4-C9E6CF6D0690}" = CCC Help Spanish
"{618EB4D7-7D67-9126-7D63-CA39F93673DE}" = Catalyst Control Center Graphics Previews Common
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{67F5A666-181F-8AA1-0D4E-BAD64AD43B42}" = CCC Help Chinese Standard
"{69FB4970-45D2-1EA4-F131-A95EB60FFDDF}" = CCC Help Italian
"{6A053172-1F36-0307-4CA0-6AA9317EBCC1}" = CCC Help Turkish
"{6B6F61D0-BBD0-E91F-8639-6EF30206ABD2}" = Catalyst Control Center Localization Japanese
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71389CB1-6B6D-6FC2-0B74-0357D1ADC41E}" = CCC Help Finnish
"{736D005A-96E3-3B70-836C-14C80A137862}" = CCC Help French
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{8124C5F0-D59A-DEFE-C3F7-02697D9BE53E}" = CCC Help Thai
"{82357963-7536-629A-F921-A3E72A5E124C}" = Catalyst Control Center Localization Korean
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8625D3E5-2159-3FA4-3A74-AB306360E63E}" = Catalyst Control Center Localization Russian
"{888FAC3D-87CB-AB4C-EC2C-D17E0C4418E7}" = Catalyst Control Center Localization French
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89FF3A82-A88F-4035-9E95-6E03B7BA9D9B}" = Catalyst Control Center Localization Swedish
"{8E5EDE0A-6B13-A0E2-7F00-5C2660C9F771}" = Catalyst Control Center Localization Hungarian
"{8EE7E7B0-CEA9-E3FD-A63F-B27F49E9EC42}" = CCC Help Portuguese
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{924EAD66-F854-4605-8493-696DD59A113B}" = RollerCoaster Tycoon Deluxe
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9418FEE4-28B4-96FD-C398-42654B956376}" = Skins
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{94AF0F78-E983-BD4B-1A26-80F2FBD5487C}" = Catalyst Control Center Localization Czech
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9749C770-90C4-EE5A-D3BB-287F53622104}" = Catalyst Control Center Core Implementation
"{99FC30C1-60A7-205F-1A00-367506E756F2}" = Catalyst Control Center Localization Greek
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F36EDCC-81A8-5D37-9EB1-8BF6D96CAA23}" = Catalyst Control Center Localization Finnish
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A0100CB5-E6CE-F516-59C1-28CF0195A875}" = ccc-core-preinstall
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A336E48B-A46E-81B5-936E-5A9A8D7FE3D8}" = CCC Help Hungarian
"{A4CCE9FD-4A40-5669-97B3-262672CD6C38}" = CCC Help Greek
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free YouTube Downloader 3.5.123
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B325EFE1-1301-5BC4-8788-B1C7D3702ED1}" = CCC Help Polish
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8430789-D948-0314-C36B-A7D78AB67013}" = ccc-core-static
"{CB2FFEB2-AC62-8DE2-8806-7C263437F132}" = CCC Help English
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F69BED-0B44-8D65-5834-6A74D8F83805}" = Catalyst Control Center Localization Chinese Traditional
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DD45D741-53D9-80CF-D097-31131DD9C0B0}" = CCC Help Chinese Traditional
"{DE5730BC-81FB-633F-039D-5D8C8F787EDF}" = Catalyst Control Center Localization German
"{E5FEB4A0-1480-F22B-9822-B56BA6172421}" = ccc-utility
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EFF1802C-C1F1-03EC-F3E0-51048DF0009F}" = Catalyst Control Center Localization Italian
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F9C22FF2-639F-1016-7926-9A1B06CDD516}" = Catalyst Control Center Localization Polish
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Age of Empires" = Microsoft Age of Empires
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Browser Defender_is1" = Browser Defender 4.0
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Crusader No Regret_is1" = Crusader No Regret
"Diablo" = Diablo
"Diablo II" = Diablo II
"Fraps" = Fraps (remove only)
"ie8" = Windows Internet Explorer 8
"Kingpin" = Kingpin: Life of Crime
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"mv61xxDriver" = marvell 61xx
"Network Play System (Patching)" = Network Play System (Patching)
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PS3 Media Server" = PS3 Media Server
"Soldier of Fortune Platinum" = Soldier of Fortune Platinum
"Spyware Doctor" = PC Tools Spyware Doctor 9.0
"SysInfo" = Creative System Information
"UDPixel" = UDPixel.exe
"VLC media player" = VLC media player 1.1.11
"WaveStudio 7" = Creative WaveStudio 7
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"Diablo" = Diablo
"JScreenFix" = JScreenFix
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/12/2012 5:59:14 PM | Computer Name = ALEX | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 ccc.exe, P2 2.0.0.0, P3 469cdc9c, P4 mscorlib,
P5 2.0.0.0, P6 4e154d36, P7 1164, P8 0, P9 system.objectdisposedexception, P10
NIL.

Error - 3/15/2012 6:55:21 PM | Computer Name = ALEX | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 10.0.2.4428, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/15/2012 6:55:24 PM | Computer Name = ALEX | Source = Application Hang | ID = 1001
Description = Fault bucket -1454988669.

Error - 3/23/2012 4:45:55 PM | Computer Name = ALEX | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 ccc.exe, P2 2.0.0.0, P3 469cdc9c, P4 mscorlib,
P5 2.0.0.0, P6 4e154d36, P7 1164, P8 0, P9 system.objectdisposedexception, P10
NIL.

Error - 3/23/2012 6:04:42 PM | Computer Name = ALEX | Source = SDWinSec.exe | ID = 0
Description =

Error - 3/23/2012 6:32:18 PM | Computer Name = ALEX | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8402.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 3/23/2012 6:32:24 PM | Computer Name = ALEX | Source = Microsoft Security Client | ID = 5000
Description =

Error - 3/23/2012 6:32:40 PM | Computer Name = ALEX | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240022, P2 processdownloadresults, P3
download, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials
(edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 NIL, P10 NIL.

Error - 3/23/2012 6:34:22 PM | Computer Name = ALEX | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240022, P2 processdownloadresults, P3
download, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials
(edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 NIL, P10 NIL.

Error - 3/23/2012 6:42:55 PM | Computer Name = ALEX | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8402.0, P4
0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 3/23/2012 6:04:51 PM | Computer Name = ALEX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 3/23/2012 6:05:18 PM | Computer Name = ALEX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 3/23/2012 6:06:44 PM | Computer Name = ALEX | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%3

Error - 3/23/2012 6:06:44 PM | Computer Name = ALEX | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%3

Error - 3/23/2012 6:06:47 PM | Computer Name = ALEX | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
avgio

Error - 3/23/2012 6:20:32 PM | Computer Name = ALEX | Source = PCTCore | ID = 327960
Description = The item store is corrupted: @5512.

Error - 3/23/2012 6:32:40 PM | Computer Name = ALEX | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 3/23/2012 6:32:40 PM | Computer Name = ALEX | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 3/23/2012 6:34:22 PM | Computer Name = ALEX | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 3/23/2012 6:34:22 PM | Computer Name = ALEX | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.


< End of report >


Hijack This Log
———————-
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:48:03 PM, on 3/23/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Creative\Shared Files\CTAudSvc.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Nero\Update\NASvc.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\ASUS\Six Engine\SixEngine.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\WINDOWS\system32\Rundll32.exe
D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
d:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
D:\Program Files\Microsoft Security Client\msseces.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Outlook Express\msimn.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Alex.HOME-0F9204D933\OTL.exe
D:\Documents and Settings\Alex.HOME-0F9204D933\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10…;ctid=CT3031743
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - D:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Six Engine] "D:\Program Files\ASUS\Six Engine\SixEngine.exe" -r
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [VolPanel] "c:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCSSync] "D:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [AppleSyncNotifier] D:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [APSDaemon] "D:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSC] "d:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://D:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - D:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Unknown owner - C:\Program Files\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - D:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - D:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - D:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: @D:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - D:\Program Files\Nero\Update\NASvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

–
End of file - 9848 bytes

DDS.txt scan
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:50:21.42 on Fri 03/23/2012
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2410 [GMT -4:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Creative\Shared Files\CTAudSvc.exe
svchost.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Nero\Update\NASvc.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\ASUS\Six Engine\SixEngine.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\WINDOWS\system32\Rundll32.exe
D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\WINDOWS\System32\svchost.exe -k HTTPFilter
D:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
d:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
D:\Program Files\Microsoft Security Client\msseces.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Outlook Express\msimn.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Alex.HOME-0F9204D933\OTL.exe
D:\Documents and Settings\Alex.HOME-0F9204D933\HiJackThis.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?SearchSource=10&ctid;=CT3031743
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - d:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PC Tools Browser Defender BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - d:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - d:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - d:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
uRun: [SetDefaultMIDI] MIDIDef.exe
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Six Engine] "d:\program files\asus\six engine\SixEngine.exe" -r
mRun: [StartCCC] "d:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [VolPanel] "c:\program files\creative\usb headsets\volume panel\VolPanlu.exe" /r
mRun: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [BCSSync] "d:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [AppleSyncNotifier] d:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "d:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "d:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] d:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "d:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "d:\program files\microsoft security client\msseces.exe" -hide -runkey
IE: E&xport; to Microsoft Excel - d:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - d:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - d:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: d:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - d:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~2\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 mv61xx;mv61xx;d:\windows\system32\drivers\mv61xx.sys [2008-6-23 150568]
R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [2012-3-23 331880]
R0 pctDS;PC Tools Data Store;d:\windows\system32\drivers\pctDS.sys [2012-3-23 342168]
R0 pctEFA;PC Tools Extended File Attributes;d:\windows\system32\drivers\pctEFA.sys [2012-3-23 909728]
R1 MpFilter;Microsoft Malware Protection Driver;d:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl0cf75b23;MpKsl0cf75b23;d:\documents and settings\all users.windows\application data\microsoft\microsoft antimalware\definition updates\{af5bfe65-018e-42e1-a46d-cf4bce8e48c6}\MpKsl0cf75b23.sys [2012-3-23 29904]
R1 PCTSD;PC Tools Spyware Doctor Driver;d:\windows\system32\drivers\PCTSD.sys [2012-3-23 185560]
R2 avgntflt;avgntflt;d:\windows\system32\drivers\avgntflt.sys [2011-8-11 66616]
R2 Browser Defender Update Service;Browser Defender Update Service;d:\program files\pc tools\pc tools security\bdt\BDTUpdateService.exe [2012-3-23 550864]
R2 NAUpdate;@d:\program files\nero\update\nasvc.exe,-200;d:\program files\nero\update\NASvc.exe [2011-3-4 584488]
R3 PCTBD;PC Tools Browser Defender Driver;d:\windows\system32\drivers\PCTBD.sys [2012-3-23 56840]
R3 skfilt;skfilt;d:\windows\system32\drivers\skfilt.SYS [2011-8-11 1670016]
S1 avgio;avgio;\??\c:\program files\avira\antivir desktop\avgio.sys –> c:\program files\avira\antivir desktop\avgio.sys [?]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;"c:\program files\avira\antivir desktop\sched.exe" –> c:\program files\avira\antivir desktop\sched.exe [?]
S2 AntiVirService;Avira AntiVir Guard;"c:\program files\avira\antivir desktop\avguard.exe" –> c:\program files\avira\antivir desktop\avguard.exe [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;d:\program files\common files\creative labs shared\service\CTAELicensing.exe [2011-8-11 79360]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 osppsvc;Office Software Protection Platform;d:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\pc tools\pc tools security\pctsAuxs.exe [2012-3-23 402336]
S3 sdCoreService;PC Tools Security Service;d:\program files\pc tools\pc tools security\pctsSvc.exe [2012-3-23 1117624]
S3 SwitchBoard;Adobe SwitchBoard;d:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 wmamp3DriverV32;wmamp3DriverV32;d:\windows\system32\drivers\wmamp3DriverV32.sys [2011-8-13 23608]
.
=============== Created Last 30 ================
.
2012-03-23 22:49:46 625664 —-a-w- d:\documents and settings\alex.home-0f9204d933\dds.scr
2012-03-23 22:42:57 388608 —-a-w- d:\documents and settings\alex.home-0f9204d933\HiJackThis.exe
2012-03-23 22:42:43 593920 —-a-w- d:\documents and settings\alex.home-0f9204d933\OTL.exe
2012-03-23 22:40:20 56200 —-a-w- d:\docume~1\alluse~1.win\applic~1\microsoft\microsoft antimalware\definition updates\{af5bfe65-018e-42e1-a46d-cf4bce8e48c6}\offreg.dll
2012-03-23 22:40:20 29904 —-a-w- d:\docume~1\alluse~1.win\applic~1\microsoft\microsoft antimalware\definition updates\{af5bfe65-018e-42e1-a46d-cf4bce8e48c6}\MpKsl0cf75b23.sys
2012-03-23 22:34:23 6582328 —-a-w- d:\docume~1\alluse~1.win\applic~1\microsoft\microsoft antimalware\definition updates\{af5bfe65-018e-42e1-a46d-cf4bce8e48c6}\mpengine.dll
2012-03-23 22:34:21 237072 ——w- d:\windows\system32\MpSigStub.exe
2012-03-23 22:31:57 ——– d—–w- d:\program files\Microsoft Security Client
2012-03-23 22:31:34 8068864 —-a-w- d:\documents and settings\alex.home-0f9204d933\mseinstall.exe
2012-03-23 22:21:14 ——– d—–w- d:\docume~1\alex~1.hom\locals~1\applic~1\Threat Expert
2012-03-23 22:19:57 767952 —-a-w- d:\windows\BDTSupport.dll
2012-03-23 22:19:57 56840 —-a-w- d:\windows\system32\drivers\PCTBD.sys
2012-03-23 22:19:57 149456 —-a-w- d:\windows\SGDetectionTool.dll
2012-03-23 22:19:56 2250704 —-a-w- d:\windows\PCTBDCore.dll
2012-03-23 22:19:56 1681360 —-a-w- d:\windows\PCTBDRes.dll
2012-03-23 22:18:45 253352 —-a-w- d:\windows\system32\drivers\pctgntdi.sys
2012-03-23 22:18:39 17848 —-a-w- d:\windows\system32\drivers\pctBTFix.sys
2012-03-23 22:18:32 70536 —-a-w- d:\windows\system32\drivers\pctplsg.sys
2012-03-23 22:18:23 ——– d—–w- d:\program files\PC Tools
2012-03-23 22:14:57 909728 —-a-w- d:\windows\system32\drivers\pctEFA.sys
2012-03-23 22:14:57 342168 —-a-w- d:\windows\system32\drivers\pctDS.sys
2012-03-23 22:14:54 331880 —-a-w- d:\windows\system32\drivers\PCTCore.sys
2012-03-23 22:14:54 162584 —-a-w- d:\windows\system32\drivers\PCTAppEvent.sys
2012-03-23 22:14:52 185560 —-a-w- d:\windows\system32\drivers\PCTSD.sys
2012-03-23 22:14:52 ——– d—–w- d:\program files\common files\PC Tools
2012-03-23 22:14:30 ——– d—–w- d:\docume~1\alluse~1.win\applic~1\PC Tools
2012-03-23 22:14:29 ——– d—–w- d:\docume~1\alex~1.hom\applic~1\TestApp
2012-03-23 22:14:25 3834832 —-a-w- d:\documents and settings\alex.home-0f9204d933\sdsetup.exe
2012-03-23 21:56:23 ——– d-sh–w- d:\documents and settings\alex.home-0f9204d933\PrivacIE
2012-03-07 13:21:18 ——– d-sh–w- d:\documents and settings\alex.home-0f9204d933\IETldCache
2012-03-07 04:44:54 6144 -c—-w- d:\windows\system32\dllcache\iecompat.dll
2012-03-07 04:44:34 ——– d—–w- d:\windows\ie8updates
2012-03-07 04:43:42 743424 -c—-w- d:\windows\system32\dllcache\iedvtool.dll
2012-03-07 04:43:42 602112 -c—-w- d:\windows\system32\dllcache\msfeeds.dll
2012-03-07 04:43:42 55296 -c—-w- d:\windows\system32\dllcache\msfeedsbs.dll
2012-03-07 04:43:42 247808 -c—-w- d:\windows\system32\dllcache\ieproxy.dll
2012-03-07 04:43:42 2000384 -c—-w- d:\windows\system32\dllcache\iertutil.dll
2012-03-07 04:43:42 12800 -c—-w- d:\windows\system32\dllcache\xpshims.dll
2012-03-07 04:43:42 11082240 -c—-w- d:\windows\system32\dllcache\ieframe.dll
2012-03-07 04:42:16 ——– dc-h–w- d:\windows\ie8
2012-02-29 01:15:36 ——– d—–w- d:\program files\UDPixel
.
==================== Find3M ====================
.
2012-02-29 13:53:44 414368 —-a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22:18 1860096 —-a-w- d:\windows\system32\win32k.sys
2012-01-11 19:06:47 3072 ——w- d:\windows\system32\iacenc.dll
2011-09-02 18:03:28 730192 —-a-w- d:\program files\common files\ZugoInstaller.exe
.
============= FINISH: 18:51:11.07 ===============
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} Looks like you're running 2 anti-virus programs. Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously! The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time. Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown. You could try System Restore. 1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked.
Hey Tate, I tryed a system restore and got the following error, I have never turned it off at all and up until recently my C drive was fully functional I didnt even relize I had more then one AV installed, i went to add/remove programs and dont even see it installed. I also found out then when I shut down and boot up I see my C drive but shortly after I lose access to it and my system becomes crippled and I get the pop up saying "Windows Delayed Write Fail" C:/$ft

Attachments:

That might be because it looks like everything is running from D:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt
which is weird because after I did a boot from cold I can see it fine as per my screenshot attached here is my dds log file . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 22:22:23.71 on Wed 03/28/2012 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2637 [GMT -4:00] . AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} . ============== Running Processes =============== . D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe D:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\spoolsv.exe D:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe D:\Program Files\Bonjour\mDNSResponder.exe D:\Program Files\Java\jre6\bin\jqs.exe D:\Program Files\Nero\Update\NASvc.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe D:\WINDOWS\system32\svchost.exe -k imgsvc D:\WINDOWS\system32\wuauclt.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\RTHDCPL.EXE D:\Program Files\ASUS\Six Engine\SixEngine.exe D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe D:\WINDOWS\system32\Rundll32.exe D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe D:\Program Files\iTunes\iTunesHelper.exe D:\Program Files\Common Files\Java\Java Update\jusched.exe D:\WINDOWS\system32\ctfmon.exe D:\Program Files\iPod\bin\iPodService.exe D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe D:\WINDOWS\System32\svchost.exe -k HTTPFilter D:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.conduit.com/?SearchSource=10&ctid=CT3031743 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - d:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [SetDefaultMIDI] MIDIDef.exe uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Six Engine] "d:\program files\asus\six engine\SixEngine.exe" -r mRun: [StartCCC] "d:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [VolPanel] "c:\program files\creative\usb headsets\volume panel\VolPanlu.exe" /r mRun: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [BCSSync] "d:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [AppleSyncNotifier] d:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [APSDaemon] "d:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe" mRun: [AdobeAAMUpdater-1.0] "d:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] d:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "d:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe" IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - d:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - d:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - d:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~2\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - d:\docume~1\alex~1.hom\applic~1\mozilla\firefox\profiles\ncqar016.default\ FF - prefs.js: browser.startup.homepage - www.google.ca FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: d:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: d:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: d:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: d:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 mv61xx;mv61xx;d:\windows\system32\drivers\mv61xx.sys [2008-6-23 150568] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-8-11 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-8-11 136360] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-8-11 269480] R2 avgntflt;avgntflt;d:\windows\system32\drivers\avgntflt.sys [2011-8-11 66616] R2 NAUpdate;@d:\program files\nero\update\nasvc.exe,-200;d:\program files\nero\update\NASvc.exe [2011-3-4 584488] R3 skfilt;skfilt;d:\windows\system32\drivers\skfilt.SYS [2011-8-11 1670016] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;d:\program files\common files\creative labs shared\service\CTAELicensing.exe [2011-8-11 79360] S3 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\mbamswissarmy.sys [2012-3-26 40776] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880] S3 osppsvc;Office Software Protection Platform;d:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 SwitchBoard;Adobe SwitchBoard;d:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 wmamp3DriverV32;wmamp3DriverV32;d:\windows\system32\drivers\wmamp3DriverV32.sys [2011-8-13 23608] . =============== Created Last 30 ================ . 2012-03-26 21:09:15 40776 —-a-w- d:\windows\system32\drivers\mbamswissarmy.sys 2012-03-24 22:42:27 ——– d—–w- d:\program files\Malwarebytes' Anti-Malware 2012-03-24 03:31:17 ——– d—–w- d:\windows\system32\wbem\repository\FS 2012-03-24 03:31:17 ——– d—–w- d:\windows\system32\wbem\Repository 2012-03-23 22:31:57 ——– d—–w- d:\program files\Microsoft Security Client 2012-03-23 22:18:23 ——– d—–w- d:\program files\PC Tools(2) 2012-03-23 22:14:52 ——– d—–w- d:\program files\common files\PC Tools 2012-03-23 22:14:30 ——– d—–w- d:\docume~1\alluse~1.win\applic~1\PC Tools 2012-03-23 22:14:29 ——– d—–w- d:\docume~1\alex~1.hom\applic~1\TestApp 2012-03-23 21:56:23 ——– d-sh–w- d:\documents and settings\alex.home-0f9204d933\PrivacIE 2012-03-07 13:21:18 ——– d-sh–w- d:\documents and settings\alex.home-0f9204d933\IETldCache 2012-03-07 04:44:54 6144 -c—-w- d:\windows\system32\dllcache\iecompat.dll 2012-03-07 04:44:34 ——– d—–w- d:\windows\ie8updates 2012-03-07 04:43:42 743424 -c—-w- d:\windows\system32\dllcache\iedvtool.dll 2012-03-07 04:43:42 602112 -c—-w- d:\windows\system32\dllcache\msfeeds.dll 2012-03-07 04:43:42 55296 -c—-w- d:\windows\system32\dllcache\msfeedsbs.dll 2012-03-07 04:43:42 247808 -c—-w- d:\windows\system32\dllcache\ieproxy.dll 2012-03-07 04:43:42 2000384 -c—-w- d:\windows\system32\dllcache\iertutil.dll 2012-03-07 04:43:42 12800 -c—-w- d:\windows\system32\dllcache\xpshims.dll 2012-03-07 04:43:42 11082240 -c—-w- d:\windows\system32\dllcache\ieframe.dll 2012-03-07 04:42:16 ——– dc-h–w- d:\windows\ie8 2012-02-29 01:15:36 ——– d—–w- d:\program files\UDPixel . ==================== Find3M ==================== . 2012-02-29 13:53:44 414368 —-a-w- d:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-03 09:22:18 1860096 —-a-w- d:\windows\system32\win32k.sys 2012-01-11 19:06:47 3072 ——w- d:\windows\system32\iacenc.dll 2011-09-02 18:03:28 730192 —-a-w- d:\program files\common files\ZugoInstaller.exe . ============= FINISH: 22:23:32.65 ===============

Attachments:

Please do not attach the scan results from Combofx. Use copy/paste.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
while attempting to run it with access to my C drive it crash and wont allow me to run it i got this error again (screen below) shall I reboot and run it again? Its allowing me to boot from my C drive but again I have no access to scan it, only time I can is from a cold boot up but then it just acts up

Attachments:

Please download GetPartitions from the link bellow. You must right click on the link and choose Save as…. Save it as GetPartitions.bat on your desktop

getpartitions.bat

Double click it to run it (If running Vista or Windows 7, right click on it and select "Run as an Administrator").
It will produce C:\DiskReport.txt log please post results from that log here to me.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
Click Start > Control Panel > Administrative Tools > Computer Management > Disk Management Now we need a screenshot. Hold down the Shift and Print Screen keys. Now open Paint: click Start > Accessories > Paint With Paint open, click Edit / Paste Now click File Save As and select Save As mydrives.png Attach or upload the picture
Do you have 2 hard drives installed?


I'm not sure what you have going on as everything is running from D: and not C:
You don't show a C partition.


Usually C is your boot drive and D can be a restore partition.
It looks like yours is just the opposite but onle shows D



Download aswMBR.exe ( 511KB ) to your desktop.

•Double clickaswMBR.exe to run it.

•Click Yes to the prompt to download Avast! virus definitions.
(Please be patient whilst the virus definitions download)

•With the AVscan set to Quick Scan, click the Scan button.
(Please be patient whilst your computer is scanned.)

•When the scan reports "Scan finished successfully", click Save log & save the log to your desktop.

•Click OK

•Two files will be created, aswMBR.txt & a file named MBR.dat

•Save MBR.dat to to a form of removable media. (CD, DVD, USB flash drive etc) - This is a backup of your MBR. Do not delete this file.

•NOTE: Do not click to fix anything at this stage!

•Click EXIT.

•Copy & Paste the contents of aswMBR.txt into your next reply.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-29 17:56:50 —————————– 17:56:50.234 OS Version: Windows 5.1.2600 Service Pack 3 17:56:50.234 Number of processors: 4 586 0xF0B 17:56:50.234 ComputerName: ALEX UserName: Alex 17:56:50.968 Initialize success 17:58:36.171 AVAST engine defs: 12032901 17:58:50.218 Service scanning 17:59:10.281 Service sptd D:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32 17:59:15.375 Modules scanning 17:59:30.000 Disk 0 trace - called modules: 17:59:30.015 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a6cb1e8]<< 17:59:30.015 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a5efab8] 17:59:30.015 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\Scsi\mv61xx1Port4Path0Target0Lun0[0x8a65da38] 17:59:30.015 \Driver\mv61xx[0x8a5f54b0] -> IRP_MJ_CREATE -> 0x8a6cb1e8 17:59:30.718 AVAST engine scan D:\WINDOWS 17:59:46.937 AVAST engine scan D:\WINDOWS\system32 18:02:22.093 AVAST engine scan D:\WINDOWS\system32\drivers 18:02:39.421 AVAST engine scan D:\Documents and Settings\Alex.HOME-0F9204D933 18:20:33.000 AVAST engine scan D:\Documents and Settings\All Users.WINDOWS 18:22:14.062 Scan finished successfully 18:39:03.531 The log file has been saved successfully to "K:\aswMBR.txt" 18:39:56.937 The log file has been saved successfully to "D:\Documents and Settings\Alex.HOME-0F9204D933\Desktop\aswMBR.txt"
Right click on D:\ComboFix.txt and open it with notepad. Select Edit > Select All > Edit Copy Please post the combofix.txt
Here is my combofix.txt also, did you want me to run aswMBR.exe again?

ComboFix 12-03-29.02 - Alex 03/29/2012 19:37:54.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2719 [GMT -4:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\aswCmnB.dll
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\aswCmnOS.dll
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\aswCmnS.dll
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\aswEngin.dll
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\aswScan.dll
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\msvcp71.dll
d:\docume~1\ALEX~1.HOM\LOCALS~1\Temp\_av4_\msvcr71.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\aswCmnB.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\aswCmnOS.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\aswCmnS.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\aswEngin.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\aswScan.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\msvcp71.dll
d:\documents and settings\Alex.HOME-0F9204D933\Local Settings\Temp\_av4_\msvcr71.dll
d:\documents and settings\Alex.HOME-0F9204D933\OddcastV2_DSP_For_Winamp_.exe
d:\documents and settings\Alex.HOME-0F9204D933\Recent\Thumbs.db
d:\documents and settings\Alex.HOME-0F9204D933\SoftonicDownloader_for_windows-live-messenger.exe
d:\documents and settings\Alex.HOME-0F9204D933\WINDOWS
d:\documents and settings\Alex\System
d:\documents and settings\Alex\System\win_qs8.jqx
d:\documents and settings\Alex\WINDOWS
d:\documents and settings\All Users.WINDOWS\Application Data\TEMP
d:\program files\Internet Explorer\SET8.tmp
d:\program files\Internet Explorer\SET9.tmp
d:\program files\Internet Explorer\SETA.tmp
D:\Thumbs.db
d:\windows\system32\dllcache\dlimport.exe
d:\windows\system32\SET2FA.tmp
d:\windows\system32\SET2FF.tmp
d:\windows\system32\SET306.tmp
d:\windows\system32\tmp1C.tmp
d:\windows\system32\tmp1D.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-02-28 to 2012-03-29 )))))))))))))))))))))))))))))))
.
.
2012-03-26 21:09 . 2012-03-26 21:09 40776 —-a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2012-03-24 22:42 . 2012-03-24 22:42 ——– d—–w- d:\program files\Malwarebytes' Anti-Malware
2012-03-24 19:26 . 2012-03-24 19:26 ——– d—–w- d:\documents and settings\Administrator.ALEX
2012-03-24 03:31 . 2012-03-24 03:31 ——– d—–w- d:\windows\system32\wbem\Repository
2012-03-23 22:31 . 2012-03-24 03:28 ——– d—–w- d:\program files\Microsoft Security Client
2012-03-23 22:18 . 2012-03-23 22:18 ——– d—–w- d:\program files\PC Tools(2)
2012-03-23 22:14 . 2012-03-24 03:28 ——– d—–w- d:\program files\Common Files\PC Tools
2012-03-23 22:14 . 2012-03-24 03:28 ——– d—–w- d:\documents and settings\All Users.WINDOWS\Application Data\PC Tools
2012-03-23 22:14 . 2012-03-23 22:14 ——– d—–w- d:\documents and settings\Alex.HOME-0F9204D933\Application Data\TestApp
2012-03-23 21:56 . 2012-03-23 21:56 ——– d-sh–w- d:\documents and settings\Alex.HOME-0F9204D933\PrivacIE
2012-03-07 13:21 . 2012-03-07 13:21 ——– d-sh–w- d:\documents and settings\Alex.HOME-0F9204D933\IETldCache
2012-03-07 04:44 . 2011-08-16 10:45 6144 -c—-w- d:\windows\system32\dllcache\iecompat.dll
2012-03-07 04:43 . 2011-12-18 19:46 11082240 -c—-w- d:\windows\system32\dllcache\ieframe.dll
2012-03-07 04:43 . 2011-12-17 19:46 743424 -c—-w- d:\windows\system32\dllcache\iedvtool.dll
2012-03-07 04:43 . 2011-12-17 19:46 602112 -c—-w- d:\windows\system32\dllcache\msfeeds.dll
2012-03-07 04:43 . 2011-12-17 19:46 55296 -c—-w- d:\windows\system32\dllcache\msfeedsbs.dll
2012-03-07 04:43 . 2011-12-17 19:46 247808 -c—-w- d:\windows\system32\dllcache\ieproxy.dll
2012-03-07 04:43 . 2011-12-17 19:46 2000384 -c—-w- d:\windows\system32\dllcache\iertutil.dll
2012-03-07 04:43 . 2011-12-17 19:46 12800 -c—-w- d:\windows\system32\dllcache\xpshims.dll
2012-03-07 04:42 . 2012-03-07 04:43 ——– dc-h–w- d:\windows\ie8
2012-02-29 01:15 . 2012-02-29 01:19 ——– d—–w- d:\program files\UDPixel
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-29 13:53 . 2011-08-11 19:16 414368 —-a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22 . 2004-08-04 12:00 1860096 —-a-w- d:\windows\system32\win32k.sys
2012-01-11 19:06 . 2012-02-16 00:01 3072 ——w- d:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2011-08-11 17:28 139784 —-a-w- d:\windows\system32\drivers\rdpwd.sys
2011-09-02 18:03 . 2011-11-22 16:07 730192 —-a-w- d:\program files\Common Files\ZugoInstaller.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2005-04-22 73728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"Six Engine"="d:\program files\ASUS\Six Engine\SixEngine.exe" [2008-06-03 5964800]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"P17Helper"="SPIRun.dll" [2006-07-03 10752]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"BCSSync"="d:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AppleSyncNotifier"="d:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"APSDaemon"="d:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"AdobeAAMUpdater-1.0"="d:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="d:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="d:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Winamp\\winamp.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"d:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
.
R0 mv61xx;mv61xx;d:\windows\system32\drivers\mv61xx.sys [6/23/2008 6:21 PM 150568]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R2 NAUpdate;@d:\program files\Nero\Update\NASvc.exe,-200;d:\program files\Nero\Update\NASvc.exe [3/4/2011 11:39 AM 584488]
R3 skfilt;skfilt;d:\windows\system32\drivers\skfilt.SYS [8/11/2011 2:38 PM 1670016]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;"c:\program files\Avira\AntiVir Desktop\sched.exe" –> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;d:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [8/11/2011 2:37 PM 79360]
S3 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\mbamswissarmy.sys [3/26/2012 5:09 PM 40776]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\program files\Microsoft Office\Office14\GROOVE.EXE [6/12/2011 11:15 AM 31125880]
S3 osppsvc;Office Software Protection Platform;d:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S3 SwitchBoard;Adobe SwitchBoard;d:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 2:37 PM 517096]
S3 wmamp3DriverV32;wmamp3DriverV32;d:\windows\system32\drivers\wmamp3DriverV32.sys [8/13/2011 11:09 AM 23608]
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-27 d:\windows\Tasks\AdobeAAMUpdater-1.0-HOME-0F9204D933-Alex.job
- d:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-11-12 08:44]
.
2012-03-24 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com/?SearchSource=10&ctid=CT3031743
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = [removed]
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
HKLM-Run-VolPanel - c:\program files\Creative\USB Headsets\Volume Panel\VolPanlu.exe
AddRemove-5513-1208-7298-9440 - c:\program files\JDownloader\JDUninstall.exe
AddRemove-Age of Empires - c:\program files\Age of Empires\Uninstal.exe
AddRemove-Avira AntiVir Desktop - c:\program files\Avira\AntiVir Desktop\setup.exe
AddRemove-Creative USB Headsets Windows Drivers - c:\program files\Creative\USB Headsets\Program\SETUP.EXE
AddRemove-Crusader No Regret_is1 - c:\program files\Crusader No Regret\unins000.exe
AddRemove-Fraps - c:\fraps\uninstall.exe
AddRemove-Kingpin - c:\program files\Kingpin\Uninst.isu
AddRemove-Mozilla Firefox 11.0 (x86 en-US) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-PS3 Media Server - c:\program files\PS3 Media Server\uninst.exe
AddRemove-Soldier of Fortune Platinum - c:\program files\Soldier Of Fortune\sofplat.isu
AddRemove-VLC media player - c:\program files\VideoLAN\VLC\uninstall.exe
AddRemove-WinRAR archiver - c:\program files\WinRAR\uninstall.exe
AddRemove-{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1 - c:\program files\Free YouTube Downloader\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-29 19:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
P17Helper = Rundll32 SPIRun.dll,RunDLLEntry?
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(776)
d:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2492)
d:\windows\system32\WININET.dll
d:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
d:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
d:\windows\system32\msi.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
d:\windows\system32\Ati2evxx.exe
d:\windows\system32\Ati2evxx.exe
d:\program files\Creative\Shared Files\CTAudSvc.exe
d:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
d:\program files\Bonjour\mDNSResponder.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\windows\RTHDCPL.EXE
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\windows\system32\Rundll32.exe
d:\program files\iPod\bin\iPodService.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
d:\program files\internet explorer\iexplore.exe
d:\program files\internet explorer\iexplore.exe
d:\program files\internet explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2012-03-29 19:54:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-29 23:54
ComboFix2.txt 2008-08-31 16:12
ComboFix3.txt 2008-08-31 15:39
.
Pre-Run: 15,673,241,600 bytes free
Post-Run: 16,853,364,736 bytes free
.
- - End Of File - - 1F447F345FF06CBA2399ECB774AEA056

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI