This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

vGrabber [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got caught with the vGrabber toolbar, and now I can't get rid of it. I have tried to hide it, delete it, etc. but to no avail. Any ideas?
Hello aramage and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • when the window appears, underneath Output at the top change it to Minimal Output.
  • check the boxes beside LOP Check and Purity Check.
  • under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %appdata%\Microsoft\Windows\Start Menu\*.* /s
    %programdata%\Microsoft\Windows\Start Menu\*.* /s

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hello Satchfan,

Thanks for your assistance. I have included the OTL log below:

OTL logfile created on: 4/11/2012 6:28:55 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

759.52 Mb Total Physical Memory | 473.62 Mb Available Physical Memory | 62.36% Memory free
1.19 Gb Paging File | 0.95 Gb Available in Paging File | 79.66% Paging File free
Paging file location(s): C:\pagefile.sys 500 999 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.92 Gb Total Space | 35.12 Gb Free Space | 62.80% Space Free | Partition Type: NTFS

Computer Name: ANDREW-IJ5SIR06 | User Name: Andrew Ramage | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\FCA\Syslogin.exe (InfoWorks Technology Company)
PRC - C:\WINDOWS\system32\FCA\FCACheck.exe (InfoWorks Technology Company)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\system32\FCA\InfoUtil.dll ()
MOD - C:\WINDOWS\system32\FCA\infokbl.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (PCIDump) – File not found
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
DRV - (catchme) – C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\catchme.sys File not found
DRV - (ASFWHide) – C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\ASFWHide File not found
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/solidyoutube/{D7…6-1405AE5549D1}
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/s…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3059010
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "Vgrabber Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3059010&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Vgrabber Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3059010&SearchSource=13"
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=0&systemid=1&sr=0&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/17 16:42:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/04/07 20:40:56 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Extensions
[2012/04/07 20:41:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions
[2012/04/07 19:52:47 | 000,000,000 | —D | M] (Vgrabber Community Toolbar) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}
[2012/03/27 18:33:36 | 000,000,919 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\conduit.xml
[2011/10/16 16:11:16 | 000,002,378 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\search.xml
[2012/04/07 17:05:10 | 000,002,511 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\Search_Results.xml
[2012/04/07 20:40:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/03/13 15:23:13 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/03/17 16:42:20 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/18 17:10:08 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/07 17:05:10 | 000,002,511 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/13 11:03:47 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.151\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.151\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.151\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: YouTube = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/10/08 10:03:09 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCA\Syslogin.exe (InfoWorks Technology Company)
O4 - HKLM..\Run: [Info Center] C:\Program Files\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [FCACheck] C:\WINDOWS\system32\FCA\FCACheck.exe (InfoWorks Technology Company)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{34C9BC74-F812-438A-A2C3-EC0E2C7508CD}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\AutorunsDisabled\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 () -
O24 - Desktop Components:AutorunsDisabled () -
O24 - Desktop WallPaper: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/26 18:06:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/04/11 18:26:37 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2012/04/11 18:21:54 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Recent
[2012/04/07 19:52:34 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2012/04/07 19:52:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Softwrap
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Fonts
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Config
[2012/04/07 19:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Blubster
[2012/04/07 19:45:33 | 000,000,000 | —D | C] – C:\Program Files\Blubster
[2012/04/07 18:36:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess
[2012/04/07 18:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\AppData
[2012/04/07 18:18:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband
[2012/04/07 17:06:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
[2012/04/07 17:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\My Documents\My Received Files
[2012/04/07 17:02:42 | 000,000,000 | —D | C] – C:\Program Files\iMesh Applications
[2012/04/07 16:59:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\PackageAware
[2012/03/17 11:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\DriverCure
[2012/03/17 11:32:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\ParetoLogic
[2012/03/17 11:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ParetoLogic
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/04/11 18:26:58 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2012/04/11 18:24:38 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/04/11 18:06:02 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/11 18:00:48 | 000,013,066 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/04/11 18:00:13 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/04/11 16:26:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/11 03:12:17 | 000,405,342 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/04/11 03:12:17 | 000,054,560 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/04/09 23:21:36 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Google Chrome.lnk
[2012/04/07 19:48:52 | 000,002,453 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Documents\Global.sw2
[2012/04/07 19:48:21 | 000,000,000 | -H– | M] () – C:\WINDOWS\SwSys2.bmp
[2012/04/07 19:48:21 | 000,000,000 | -H– | M] () – C:\WINDOWS\SwSys1.bmp
[2012/04/07 19:45:53 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Blubster.lnk
[2012/03/24 01:20:46 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/24 01:20:45 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/18 10:22:40 | 000,836,694 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\AC.bmp
[2012/03/14 03:19:24 | 000,134,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/04/07 19:48:21 | 000,002,453 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Documents\Global.sw2
[2012/04/07 19:48:21 | 000,000,000 | -H– | C] () – C:\WINDOWS\SwSys2.bmp
[2012/04/07 19:48:21 | 000,000,000 | -H– | C] () – C:\WINDOWS\SwSys1.bmp
[2012/04/07 19:45:53 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Blubster.lnk
[2012/03/18 10:22:40 | 000,836,694 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\AC.bmp
[2012/03/17 12:31:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/02/15 23:55:33 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/15 12:29:05 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/01/15 12:29:05 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/01/15 12:29:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/01/15 12:29:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/01/15 12:29:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/08/13 21:34:45 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/07/18 17:38:05 | 000,000,120 | —- | C] () – C:\WINDOWS\Xmomaz.dat
[2010/07/18 17:38:05 | 000,000,000 | —- | C] () – C:\WINDOWS\Lguxuvubovisid.bin
[2010/05/13 03:08:02 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\MRT.INI

========== LOP Check ==========

[2012/04/07 18:36:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess
[2012/04/07 17:06:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
[2010/12/09 20:33:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2012/03/10 17:58:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2012/03/17 12:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ParetoLogic
[2011/07/24 10:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
[2012/01/17 20:54:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/12/09 20:44:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\AVG10
[2012/03/17 11:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\DriverCure
[2011/11/26 19:29:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\FK_Monitor
[2011/09/20 19:15:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Foxit Software
[2011/01/08 20:58:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\GARMIN
[2012/03/17 11:32:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\ParetoLogic
[2012/02/09 21:49:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\TeamViewer
[2012/04/07 18:18:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband
[2010/07/01 12:47:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\WinPatrol
[2012/04/11 18:06:02 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/03/08 23:08:45 | 000,001,788 | —- | M] () – C:\aaw7boot.log
[2008/11/26 18:06:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/11/27 20:30:02 | 000,000,211 | -HS- | M] () – C:\Boot.bak
[2011/08/14 21:14:29 | 000,000,282 | RHS- | M] () – C:\boot.ini
[2011/03/26 15:36:57 | 000,000,032 | —- | M] () – C:\cd11path.fil
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2012/01/15 12:49:09 | 000,010,749 | —- | M] () – C:\ComboFix.txt
[2008/11/26 18:06:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/11/26 18:06:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/01 18:23:16 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/11/26 18:06:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/03/11 18:29:12 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/10/06 21:29:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/25 19:06:50 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2011/07/25 19:06:54 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2012/04/11 18:00:03 | 524,288,000 | -HS- | M] () – C:\pagefile.sys
[2010/07/03 21:38:32 | 000,030,308 | —- | M] () – C:\TDSSKiller.2.3.2.2_03.07.2010_21.37.55_log.txt
[2010/07/03 21:52:29 | 000,029,364 | —- | M] () – C:\TDSSKiller.2.3.2.2_03.07.2010_21.51.45_log.txt
[2010/07/09 19:39:22 | 000,029,364 | —- | M] () – C:\TDSSKiller.2.3.2.2_09.07.2010_19.38.49_log.txt
[2010/07/19 20:42:05 | 000,029,364 | —- | M] () – C:\TDSSKiller.2.3.2.2_19.07.2010_20.41.32_log.txt
[2011/10/02 20:03:32 | 000,041,202 | —- | M] () – C:\TDSSKiller.2.6.2.0_02.10.2011_18.36.12_log.txt

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/03/08 16:23:06 | 000,090,112 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/03/08 16:23:06 | 000,630,784 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/03/08 16:23:06 | 000,397,312 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/10/06 21:44:52 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/11 16:41:30 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/03/09 08:17:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/09/27 21:10:36 | 038,808,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\FileFormatConverters.exe
[2010/04/10 12:13:42 | 000,563,040 | —- | M] (Google Inc.) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\googleupdatesetup.exe
[2012/01/17 20:47:08 | 069,341,552 | —- | M] (Apple Inc.) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\iTunesSetup.exe
[2012/04/11 18:26:58 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2011/03/26 15:30:28 | 037,822,435 | —- | M] (JGsoft - Just Great Software) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\SetupEn.exe
[2010/07/01 12:50:03 | 000,204,496 | —- | M] (Malwarebytes) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\StartUpLite.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-11 09:22:42

< %appdata%\Microsoft\Windows\Start Menu\*.* /s >
Invalid Environment Variable: programdata

< End of report >
Below is the Extras:

OTL Extras logfile created on: 4/11/2012 6:28:55 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

759.52 Mb Total Physical Memory | 473.62 Mb Available Physical Memory | 62.36% Memory free
1.19 Gb Paging File | 0.95 Gb Available in Paging File | 79.66% Paging File free
Paging file location(s): C:\pagefile.sys 500 999 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.92 Gb Total Space | 35.12 Gb Free Space | 62.80% Space Free | Partition Type: NTFS

Computer Name: ANDREW-IJ5SIR06 | User Name: Andrew Ramage | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh
"C:\Program Files\Blubster\Blubster.exe" = C:\Program Files\Blubster\Blubster.exe:*:Enabled:Blubster – (MP2P Technologies.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{12CAA28E-56CA-4C3D-B3F2-7311540DD410}" = TurboTax 2011
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{24AE6B5B-3D5A-488C-9224-1BEE11F75DD9}" = TurboTax 2010
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 30
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A25D130-4EC8-11E1-BEA4-B8AC6F97B88E}" = Google Earth
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver Software
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}" = Watson
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"040a_5005" = USB MassStorage CardReader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Blubster" = Blubster 3.1.1
"CCleaner" = CCleaner
"Foxit Reader_is1" = Foxit Reader 5.0
"Google Chrome" = Google Chrome
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Info Center_is1" = Info Center 1.0.0.5
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Variety Coins 8th Edition" = Variety Coins 8th Edition 8.00
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/27/2012 2:50:20 PM | Computer Name = ANDREW-IJ5SIR06 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80508007, P2 mpupdateengine, P3 am bdd,
P4 11.1.3927.0, P5 mpsigstub.exe, P6 3.0.8402.0, P7 microsoft security essentials,
P8 NIL, P9 NIL, P10 NIL.

Error - 3/27/2012 6:42:36 PM | Computer Name = ANDREW-IJ5SIR06 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 3.0.8402.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 3/27/2012 8:36:51 PM | Computer Name = ANDREW-IJ5SIR06 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759303, P2 unspecified, P3 scanfile,
P4 3.0.8402.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 3/27/2012 8:36:54 PM | Computer Name = ANDREW-IJ5SIR06 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 3.0.8402.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 4/4/2012 10:05:54 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/6/2012 1:45:20 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 10.0.6866.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/6/2012 6:42:30 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Application Error | ID = 1000
Description = Faulting application syslogin.exe, version 4.5.0.2, faulting module
unknown, version 0.0.0.0, fault address 0x3b1c2f39.

Error - 4/7/2012 8:21:40 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Application Error | ID = 1000
Description = Faulting application syslogin.exe, version 4.5.0.2, faulting module
unknown, version 0.0.0.0, fault address 0x13a5f1d9.

Error - 4/7/2012 9:50:06 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/8/2012 5:26:02 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Application Error | ID = 1000
Description = Faulting application syslogin.exe, version 4.5.0.2, faulting module
unknown, version 0.0.0.0, fault address 0x03acdb39.

[ System Events ]
Error - 3/27/2012 2:50:23 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.123.403.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8202.0 Error
code: 0x80070643 Error description: Fatal error during installation.

Error - 3/27/2012 2:50:53 PM | Computer Name = ANDREW-IJ5SIR06 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138
(Definition 1.123.489.0).

Error - 4/8/2012 1:38:58 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 4/8/2012 1:39:09 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 4/8/2012 1:39:15 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 4/8/2012 1:39:16 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 4/8/2012 1:39:21 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 4/8/2012 1:39:21 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort0.

Error - 4/8/2012 1:42:23 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 4/8/2012 1:44:58 PM | Computer Name = ANDREW-IJ5SIR06 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.


< End of report >
And finally the aswMBR file: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-04-11 18:49:24 —————————– 18:49:24.671 OS Version: Windows 5.1.2600 Service Pack 3 18:49:24.671 Number of processors: 1 586 0x204 18:49:24.671 ComputerName: ANDREW-IJ5SIR06 UserName: Andrew Ramage 18:49:26.625 Initialize success 18:55:31.125 AVAST engine defs: 12041101 19:06:21.687 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 19:06:21.687 Disk 0 Vendor: SAMSUNG_SV0602H RH100-15 Size: 57277MB BusType: 3 19:06:21.718 Disk 0 MBR read successfully 19:06:21.718 Disk 0 MBR scan 19:06:21.828 Disk 0 Windows XP default MBR code 19:06:21.875 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 57262 MB offset 63 19:06:22.031 Disk 0 scanning sectors +117274500 19:06:22.359 Disk 0 scanning C:\WINDOWS\system32\drivers 19:07:20.531 Service scanning 19:07:44.656 Service MpKslcfdee0e8 c:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{02A38F91-47DF-4626-8530-0FC12DCFDE97}\MpKslcfdee0e8.sys **LOCKED** 32 19:08:15.296 Modules scanning 19:08:38.765 Disk 0 trace - called modules: 19:08:38.781 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 19:08:38.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82fa1ab8] 19:08:38.796 3 CLASSPNP.SYS[f7736fd7] -> nt!IofCallDriver -> \Device\00000057[0x82f8ef18] 19:08:38.796 5 ACPI.sys[f768d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82fa5d98] 19:08:41.187 AVAST engine scan C:\WINDOWS 19:09:02.484 AVAST engine scan C:\WINDOWS\system32 19:18:39.015 AVAST engine scan C:\WINDOWS\system32\drivers 19:19:28.515 AVAST engine scan C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06 19:28:08.234 AVAST engine scan C:\Documents and Settings\All Users.WINDOWS 19:28:54.000 Scan finished successfully 19:53:08.734 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\MBR.dat" 19:53:08.781 The log file has been saved successfully to "C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\aswMBR.txt"
Hi aramage

First

These have all recently arrived on your computer, 2 of which are P2P-related. Can you tell me if you were aware of them all and if they are there intentionally:

C:\Program Files\Conduit
C:\Documents and Settings\All Users.WINDOWS\Documents\Softwrap (Global.sw2(
C:\Documents and Settings\All Users.WINDOWS\Documents\Fonts
C:\Documents and Settings\All Users.WINDOWS\Documents\Config
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Blubster
C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband
C:\Program Files\iMesh Applications


===========================================

Registry cleaners

I see you have DriverCure and ParetoLogic on your computer. The use of registry cleaners is not recommended.. The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in causing more problems than it fixes.

One of the malware experts, miekiemoes, has an excellent writeup here
Another excellent article by Bill Castner is located here

===========================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    DRV - (PCIDump) – File not found
    DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
    DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
    DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
    DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
    DRV - (catchme) – C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\catchme.sys File not found
    DRV - (ASFWHide) – C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\ASFWHide File not found
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3059010
    FF - prefs.js..browser.search.defaultthis.engineName: "Vgrabber Customized Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3059010&SearchSource=3&q={searchTerms}"
    FF - prefs.js..browser.search.selectedEngine: "Vgrabber Customized Web Search"
    FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3059010&SearchSource=13"
    [2012/04/07 19:52:47 | 000,000,000 | —D | M] (Vgrabber Community Toolbar) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}
    [2012/03/27 18:33:36 | 000,000,919 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\conduit.xml
    
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found
    O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===========================================

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield:

    :dir /s
    C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
    C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess
    
    :filefind
    *vGrabber*
    
    :folderfind
    *vGrabber*
    
    :Regfind
    *vGrabber*

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===========================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Logs to include in the next post:

OTL fix log
New OTL log
SystemLook.txt
CKFiles.txt


Satchfan
Hello Satchfan, Once again thanks for your help. I was aware of the Blubster program, however, i wasn't aware of the other files that you first listed. Below is the OTL fix log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Service PCIDump stopped successfully! Service PCIDump deleted successfully! File File not found not found. Service MRESP50 stopped successfully! Service MRESP50 deleted successfully! File C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found not found. Service MRENDIS5 stopped successfully! Service MRENDIS5 deleted successfully! File C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found not found. Service MREMPR5 stopped successfully! Service MREMPR5 deleted successfully! File C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found not found. Service MREMP50 stopped successfully! Service MREMP50 deleted successfully! File C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found not found. Service catchme stopped successfully! Service catchme deleted successfully! File C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\catchme.sys File not found not found. Service ASFWHide stopped successfully! Service ASFWHide deleted successfully! File C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\ASFWHide File not found not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Prefs.js: "Vgrabber Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3059010&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "Vgrabber Customized Web Search" removed from browser.search.selectedEngine Prefs.js: "http://search.conduit.com/?ctid=CT3059010&SearchSource=13" removed from browser.startup.homepage Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\searchplugin scheduled to be moved on reboot. Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\modules scheduled to be moved on reboot. Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\META-INF scheduled to be moved on reboot. Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\defaults scheduled to be moved on reboot. Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\components scheduled to be moved on reboot. Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\chrome scheduled to be moved on reboot. Folder move failed. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} scheduled to be moved on reboot. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\conduit.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5} C:\WINDOWS\Downloaded Program Files\OnlineScanner.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: All Users.WINDOWS User: Andrew Ramage ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 9032947 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 232806 bytes User: Andrew Ramage.ANDREW-IJ5SIR06 ->Temp folder emptied: 55544407 bytes ->Temporary Internet Files folder emptied: 7226393 bytes ->Java cache emptied: 7020148 bytes ->FireFox cache emptied: 51392253 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 470 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 41 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 321094 bytes ->Temporary Internet Files folder emptied: 859390 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1158187 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 687071 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 144720755 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 102066 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 265.00 mb OTL by OldTimer - Version 3.2.39.2 log created on 04122012_174405 Files\Folders moved on Reboot… C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\searchplugin folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\modules folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\META-INF folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\defaults folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\components folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\chrome folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\Content.IE5\SA8ZADAU\iframe[1].htm moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\Content.IE5\OW1TSI06\index[1].htm moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot…
Below is the new OTL log:

OTL logfile created on: 4/12/2012 6:32:23 PM - Run 3
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

759.52 Mb Total Physical Memory | 414.88 Mb Available Physical Memory | 54.62% Memory free
1.19 Gb Paging File | 0.90 Gb Available in Paging File | 75.34% Paging File free
Paging file location(s): C:\pagefile.sys 500 999 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.92 Gb Total Space | 35.28 Gb Free Space | 63.10% Space Free | Partition Type: NTFS

Computer Name: ANDREW-IJ5SIR06 | User Name: Andrew Ramage | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\FCA\Syslogin.exe (InfoWorks Technology Company)
PRC - C:\WINDOWS\system32\FCA\FCACheck.exe (InfoWorks Technology Company)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\system32\FCA\InfoUtil.dll ()
MOD - C:\WINDOWS\system32\FCA\infokbl.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKslcfdee0e8) – c:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{02A38F91-47DF-4626-8530-0FC12DCFDE97}\MpKslcfdee0e8.sys File not found
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/solidyoutube/{D7…6-1405AE5549D1}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/s…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=0&systemid=1&sr=0&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/17 16:42:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/04/07 20:40:56 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Extensions
[2012/04/12 18:27:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions
[2011/10/16 16:11:16 | 000,002,378 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\search.xml
[2012/04/07 17:05:10 | 000,002,511 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\Search_Results.xml
[2012/04/07 20:40:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ANDREW RAMAGE.ANDREW-IJ5SIR06\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X6E2LVKN.DEFAULT\EXTENSIONS\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}
[2010/03/13 15:23:13 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/03/17 16:42:20 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/18 17:10:08 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/07 17:05:10 | 000,002,511 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/13 11:03:47 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.151\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.151\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.151\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: YouTube = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/10/08 10:03:09 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCA\Syslogin.exe (InfoWorks Technology Company)
O4 - HKLM..\Run: [Info Center] C:\Program Files\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [FCACheck] C:\WINDOWS\system32\FCA\FCACheck.exe (InfoWorks Technology Company)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{34C9BC74-F812-438A-A2C3-EC0E2C7508CD}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\AutorunsDisabled\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 () -
O24 - Desktop Components:AutorunsDisabled () -
O24 - Desktop WallPaper: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/26 18:06:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/12 17:44:05 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/11 18:48:41 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\aswMBR.exe
[2012/04/11 18:26:37 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2012/04/11 18:21:54 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Recent
[2012/04/07 19:52:34 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2012/04/07 19:52:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Softwrap
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Fonts
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Config
[2012/04/07 19:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Blubster
[2012/04/07 19:45:33 | 000,000,000 | —D | C] – C:\Program Files\Blubster
[2012/04/07 18:36:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess
[2012/04/07 18:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\AppData
[2012/04/07 18:18:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband
[2012/04/07 17:06:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
[2012/04/07 17:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\My Documents\My Received Files
[2012/04/07 17:02:42 | 000,000,000 | —D | C] – C:\Program Files\iMesh Applications
[2012/04/07 16:59:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\PackageAware
[2012/03/17 11:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\DriverCure
[2012/03/17 11:32:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\ParetoLogic
[2012/03/17 11:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ParetoLogic

========== Files - Modified Within 30 Days ==========

[2012/04/12 18:32:01 | 000,458,240 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\CKScanner.exe
[2012/04/12 18:31:07 | 000,139,264 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\SystemLook.exe
[2012/04/12 18:29:12 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/12 18:24:19 | 000,013,066 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/04/12 18:23:49 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/04/11 21:47:29 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/04/11 19:53:08 | 000,000,512 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\MBR.dat
[2012/04/11 18:49:03 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\aswMBR.exe
[2012/04/11 18:26:58 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2012/04/11 16:26:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/11 03:12:17 | 000,405,342 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/04/11 03:12:17 | 000,054,560 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/04/09 23:21:36 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Google Chrome.lnk
[2012/04/07 19:48:52 | 000,002,453 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Documents\Global.sw2
[2012/04/07 19:48:21 | 000,000,000 | -H– | M] () – C:\WINDOWS\SwSys2.bmp
[2012/04/07 19:48:21 | 000,000,000 | -H– | M] () – C:\WINDOWS\SwSys1.bmp
[2012/04/07 19:45:53 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Blubster.lnk
[2012/03/24 01:20:46 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/24 01:20:45 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/18 10:22:40 | 000,836,694 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\AC.bmp
[2012/03/14 03:19:24 | 000,134,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/04/12 18:31:54 | 000,458,240 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\CKScanner.exe
[2012/04/12 18:31:00 | 000,139,264 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\SystemLook.exe
[2012/04/11 19:53:08 | 000,000,512 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\MBR.dat
[2012/04/07 19:48:21 | 000,002,453 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Documents\Global.sw2
[2012/04/07 19:48:21 | 000,000,000 | -H– | C] () – C:\WINDOWS\SwSys2.bmp
[2012/04/07 19:48:21 | 000,000,000 | -H– | C] () – C:\WINDOWS\SwSys1.bmp
[2012/04/07 19:45:53 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Blubster.lnk
[2012/03/18 10:22:40 | 000,836,694 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\AC.bmp
[2012/03/17 12:31:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/02/15 23:55:33 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/15 12:29:05 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/01/15 12:29:05 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/01/15 12:29:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/01/15 12:29:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/01/15 12:29:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/08/13 21:34:45 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/07/18 17:38:05 | 000,000,120 | —- | C] () – C:\WINDOWS\Xmomaz.dat
[2010/07/18 17:38:05 | 000,000,000 | —- | C] () – C:\WINDOWS\Lguxuvubovisid.bin
[2010/05/13 03:08:02 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\MRT.INI

< End of report >
Below is the System Look file: SystemLook 30.07.11 by jpshortstuff Log created at 19:27 on 12/04/2012 by Andrew Ramage Administrator - Elevation successful Invalid Context: dir /s No Context: C:\Documents and Settings\All Users.WINDOWS\Application Data\C213 No Context: C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess ========== filefind ========== Searching for "*vGrabber*" C:\_OTL\MovedFiles\04122012_174405\C_Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions\{b2ed7faf-72a0-46d1-9d9d-602226f5cb9f}\chrome\vgrabber.jar –a—- 713040 bytes [01:52 08/04/2012] [00:33 28/03/2012] 83BBC0C6A0CF42A89D1EB94D8CE8306F ========== folderfind ========== Searching for "*vGrabber*" No folders found. ========== Regfind ========== Searching for "*vGrabber*" No data found. -= EOF =-
Below is the ckFiles txt: CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.GANASV —– EOF —–
Thanks for the logs aramage.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\
    [2012/04/07 20:40:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
    File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ANDREW RAMAGE.ANDREW-IJ5SIR06\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X6E2LVKN.DEFAULT\EXTENSIONS\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}
    O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
    [2012/04/07 19:52:34 | 000,000,000 | —D | C] – C:\Program Files\Conduit
    [2012/04/07 19:52:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit
    [2012/04/07 17:02:42 | 000,000,000 | —D | C] – C:\Program Files\iMesh Applications
    
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}]
    [-HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}]
    
    :Files
    C:\Program Files\AVG\
    C:\Program Files\Conduit
    C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit
    C:\Program Files\iMesh Applications
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
========================================

Re-run SystemLook

Please delete SystemLook.txt from your desktop.

When you copy the script in the code box, please make sure you include the colon, (:), before dir..
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield:

    :dir /s
    C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
    C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess
    C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\AppData
    C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Logs to include in the next post:

OTL fix log
New OTL log
SystemLook.txt


Can you tell me if you have any remaining computer problems now.

Satchfan
The OTL fix log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4 not found. C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully. C:\Program Files\Mozilla Firefox\extensions folder moved successfully. Starting removal of ActiveX control Garmin Communicator Plug-In Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Garmin Communicator Plug-In\ not found. C:\Program Files\Conduit\Community Alerts folder moved successfully. C:\Program Files\Conduit folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit\Community Alerts\Log folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit\Community Alerts folder moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit folder moved successfully. C:\Program Files\iMesh Applications folder moved successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}\ not found. Registry key HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F}\ not found. ========== FILES ========== C:\Program Files\AVG\AVG9\log folder moved successfully. C:\Program Files\AVG\AVG9 folder moved successfully. C:\Program Files\AVG\AVG8\Notification folder moved successfully. C:\Program Files\AVG\AVG8\log folder moved successfully. C:\Program Files\AVG\AVG8\Icons folder moved successfully. C:\Program Files\AVG\AVG8 folder moved successfully. C:\Program Files\AVG folder moved successfully. File\Folder C:\Program Files\Conduit not found. File\Folder C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Conduit not found. File\Folder C:\Program Files\iMesh Applications not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: All Users.WINDOWS User: Andrew Ramage ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Andrew Ramage.ANDREW-IJ5SIR06 ->Temp folder emptied: 714832 bytes ->Temporary Internet Files folder emptied: 4168745 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 49184409 bytes ->Google Chrome cache emptied: 8782510 bytes ->Flash cache emptied: 615 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 14028 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 27583 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1056 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 444420 bytes Total Files Cleaned = 60.00 mb OTL by OldTimer - Version 3.2.39.2 log created on 04142012_082556 Files\Folders moved on Reboot… C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\Content.IE5\YPGA03TI\iframe[1].htm moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\Content.IE5\HWNO3MKK\index[1].htm moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\Content.IE5\8MLVZ6FV\search[1].htm moved successfully. C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot…
The new OTL log:

OTL logfile created on: 4/14/2012 8:36:53 AM - Run 4
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

759.52 Mb Total Physical Memory | 426.70 Mb Available Physical Memory | 56.18% Memory free
1.19 Gb Paging File | 0.90 Gb Available in Paging File | 75.81% Paging File free
Paging file location(s): C:\pagefile.sys 500 999 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.92 Gb Total Space | 35.66 Gb Free Space | 63.77% Space Free | Partition Type: NTFS

Computer Name: ANDREW-IJ5SIR06 | User Name: Andrew Ramage | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/04/11 18:26:58 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
PRC - [2011/10/25 13:19:50 | 001,715,872 | —- | M] (InfoWorks Technology Company) – C:\WINDOWS\system32\FCA\Syslogin.exe
PRC - [2011/10/22 22:08:14 | 000,032,416 | —- | M] (InfoWorks Technology Company) – C:\WINDOWS\system32\FCA\FCACheck.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/02 00:26:32 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/02 00:26:12 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/01/04 15:54:02 | 000,057,344 | —- | M] () – C:\WINDOWS\system32\FCA\InfoUtil.dll
MOD - [2008/10/30 13:05:48 | 000,049,152 | —- | M] () – C:\WINDOWS\system32\FCA\infokbl.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – %SystemRoot%\System32\hidserv.dll – (HidServ)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)


========== Driver Services (SafeList) ==========

DRV - [2012/03/01 22:13:58 | 000,021,504 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\libusb0.sys – (libusb0)
DRV - [2004/08/03 23:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rtl8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2002/10/30 14:24:40 | 000,953,196 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/solidyoutube/{D7…6-1405AE5549D1}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/s…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=0&systemid=1&sr=0&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/17 16:42:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/04/07 20:40:56 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Extensions
[2012/04/12 18:27:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\extensions
[2011/10/16 16:11:16 | 000,002,378 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\search.xml
[2012/04/07 17:05:10 | 000,002,511 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\Mozilla\Firefox\Profiles\x6e2lvkn.default\searchplugins\Search_Results.xml
[2010/03/13 15:23:13 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/03/17 16:42:20 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/18 17:10:08 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/07 17:05:10 | 000,002,511 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/13 11:03:47 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: YouTube = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/10/08 10:03:09 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCA\Syslogin.exe (InfoWorks Technology Company)
O4 - HKLM..\Run: [Info Center] C:\Program Files\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [FCACheck] C:\WINDOWS\system32\FCA\FCACheck.exe (InfoWorks Technology Company)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{34C9BC74-F812-438A-A2C3-EC0E2C7508CD}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\AutorunsDisabled\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 () -
O24 - Desktop Components:AutorunsDisabled () -
O24 - Desktop WallPaper: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/26 18:06:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/13 15:51:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\My Books
[2012/04/13 12:36:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\My Documents\My Digital Editions
[2012/04/13 12:23:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\Kobo
[2012/04/13 12:19:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Kobo
[2012/04/13 12:17:06 | 000,000,000 | —D | C] – C:\Program Files\Kobo
[2012/04/12 19:47:20 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Recent
[2012/04/12 17:44:05 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/11 18:48:41 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\aswMBR.exe
[2012/04/11 18:26:37 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Softwrap
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Fonts
[2012/04/07 19:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Documents\Config
[2012/04/07 19:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Blubster
[2012/04/07 19:45:33 | 000,000,000 | —D | C] – C:\Program Files\Blubster
[2012/04/07 18:36:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess
[2012/04/07 18:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\AppData
[2012/04/07 18:18:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband
[2012/04/07 17:06:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\C213
[2012/04/07 17:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\My Documents\My Received Files
[2012/04/07 16:59:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Local Settings\Application Data\PackageAware
[2012/03/17 11:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\DriverCure
[2012/03/17 11:32:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\ParetoLogic
[2012/03/17 11:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ParetoLogic

========== Files - Modified Within 30 Days ==========

[2012/04/14 08:34:12 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/14 08:29:16 | 000,013,066 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/04/14 08:28:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/04/13 15:50:10 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/04/13 12:46:50 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Google Chrome.lnk
[2012/04/13 12:19:32 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Kobo.lnk
[2012/04/12 18:32:01 | 000,458,240 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\CKScanner.exe
[2012/04/12 18:31:07 | 000,139,264 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\SystemLook.exe
[2012/04/11 19:53:08 | 000,000,512 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\MBR.dat
[2012/04/11 18:49:03 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\aswMBR.exe
[2012/04/11 18:26:58 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\OTL.exe
[2012/04/11 16:26:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/11 03:12:17 | 000,405,342 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/04/11 03:12:17 | 000,054,560 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/04/07 19:48:52 | 000,002,453 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Documents\Global.sw2
[2012/04/07 19:48:21 | 000,000,000 | -H– | M] () – C:\WINDOWS\SwSys2.bmp
[2012/04/07 19:48:21 | 000,000,000 | -H– | M] () – C:\WINDOWS\SwSys1.bmp
[2012/04/07 19:45:53 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Blubster.lnk
[2012/03/24 01:20:46 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/24 01:20:45 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/18 10:22:40 | 000,836,694 | —- | M] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\AC.bmp

========== Files Created - No Company Name ==========

[2012/04/13 12:19:32 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Kobo.lnk
[2012/04/12 18:31:54 | 000,458,240 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\CKScanner.exe
[2012/04/12 18:31:00 | 000,139,264 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\SystemLook.exe
[2012/04/11 19:53:08 | 000,000,512 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\MBR.dat
[2012/04/07 19:48:21 | 000,002,453 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Documents\Global.sw2
[2012/04/07 19:48:21 | 000,000,000 | -H– | C] () – C:\WINDOWS\SwSys2.bmp
[2012/04/07 19:48:21 | 000,000,000 | -H– | C] () – C:\WINDOWS\SwSys1.bmp
[2012/04/07 19:45:53 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Blubster.lnk
[2012/03/18 10:22:40 | 000,836,694 | —- | C] () – C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Desktop\AC.bmp
[2012/03/17 12:31:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/02/15 23:55:33 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/15 12:29:05 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/01/15 12:29:05 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/01/15 12:29:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/01/15 12:29:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/01/15 12:29:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/08/13 21:34:45 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/07/18 17:38:05 | 000,000,120 | —- | C] () – C:\WINDOWS\Xmomaz.dat
[2010/07/18 17:38:05 | 000,000,000 | —- | C] () – C:\WINDOWS\Lguxuvubovisid.bin
[2010/05/13 03:08:02 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\MRT.INI

< End of report >
The new SystemLook file: SystemLook 30.07.11 by jpshortstuff Log created at 08:48 on 14/04/2012 by Andrew Ramage Administrator - Elevation successful Invalid Context: dir /s No Context: C:\Documents and Settings\All Users.WINDOWS\Application Data\C213 No Context: C:\Documents and Settings\All Users.WINDOWS\Application Data\boost_interprocess No Context: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\AppData No Context: C:\Documents and Settings\Andrew Ramage.ANDREW-IJ5SIR06\Application Data\wincoreimband -= EOF =-
Satchfan, The computer seems to be working great. There is no evidence of the vGrabber toolbar in any of the Internet programs. Thanks for your help. Andrew

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI