This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

msdcsc.exe causing havoc - WinXP freezing on load with over 200 proces

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Tomk Eset scan results shown below. Seems to show up a few entries for a molebox infection - was beginning to think that this was wild goose chase but am kinda relieved that it seems to have found something nasty lurking in the background! Look forward to your next instructions. Cheers B – C:\Documents and Settings\Administrator\My Documents\MSDCSC\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\5D81AC31\Facebook Credit Generator[1].exe Win32/TrojanDownloader.Agent.RFE trojan C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\6JN36L41\access-denied[1].html HTML/Hoax.FastDownload.A.Gen application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\8O7ZGLC9\download-k_facebook%20credit%20generator[1].html HTML/Hoax.FastDownload.A.Gen application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\H2KC3OSP\download-k_facebook%20credit%20generator[1].html HTML/Hoax.FastDownload.A.Gen application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\OUX5O4VC\11[1].exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\My Documents\MSDCSC\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0002007.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0002008.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0002014.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0003060.exe a variant of Win32/Packed.MoleboxVS.H application C:\WINDOWS\system32\update SN\update.exe a variant of Win32/Packed.MoleboxVS.H application
Hi Tomk Please excuse if this is a duplicate post - I hit reply and my response is not showing up now. Anyway, I ran the scan with eset as instructed and the results are included below: C:\Documents and Settings\Administrator\My Documents\MSDCSC\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\5D81AC31\Facebook Credit Generator[1].exe Win32/TrojanDownloader.Agent.RFE trojan C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\6JN36L41\access-denied[1].html HTML/Hoax.FastDownload.A.Gen application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\8O7ZGLC9\download-k_facebook%20credit%20generator[1].html HTML/Hoax.FastDownload.A.Gen application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\H2KC3OSP\download-k_facebook%20credit%20generator[1].html HTML/Hoax.FastDownload.A.Gen application C:\Documents and Settings\ATHLON\Local Settings\Temporary Internet Files\Content.IE5\OUX5O4VC\11[1].exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\My Documents\MSDCSC\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe a variant of Win32/Packed.MoleboxVS.H application C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0002007.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0002008.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0002014.exe a variant of Win32/Packed.MoleboxVS.H application C:\System Volume Information\_restore{FF032F18-186E-4D9B-A900-EE19C60CB8F5}\RP0\A0003060.exe a variant of Win32/Packed.MoleboxVS.H application C:\WINDOWS\system32\update SN\update.exe a variant of Win32/Packed.MoleboxVS.H application Look forward to the next instruction Many thanks B :-)
In my experience, a molebox detection is more indicitive of pirated software rather than an infection… however, is is indicated with msdcsc.exe which is what you were originally having problems with so let's nuke it.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Administrator\My Documents\MSDCSC\msdcsc.exe
C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\ATHLON\My Documents\MSDCSC\msdcsc.exe
C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe
C:\WINDOWS\system32\update SN\update.exe


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.
Hi Tomk Sadly it looks like ComboFix is still not running properly. The same boot partition cannot be ennumerated message is still coming up when it tries to download the recovery console and after the PC restarted there's no file in the C: root for me to attach. I found an article on the Microsoft knowledgebase about rebuilding the apparently missing boot.ini file (included below). Is it worth me going through this to see if it lets us download and install the recovery console afterwards? B :-) — To resolve this issue, start the computer from the Windows XP CD, start the Recovery Console, and then use the Bootcfg.exe tool to rebuild the Boot.ini file. To do this, follow these steps: 1.Configure the computer to start from the CD-ROM or DVD-ROM drive. For information about how to do this, see your computer documentation, or contact your computer manufacturer. 2.Insert the Windows XP CD-ROM into your CD-ROM or DVD-ROM drive, and then restart your computer. 3.When you receive the "Press any key to boot from CD" message, press a key to start your computer from the Windows XP CD-ROM. 4.When you receive the "Welcome to Setup" message, press R to start the Recovery Console. 5.If you have a dual-boot or multiple-boot computer, select the installation that you have to use from the Recovery Console. 6.When you are prompted, type the administrator password, and then press ENTER. 7.At the command prompt, type bootcfg /list, and then press ENTER. The entries in your current Boot.ini file appear on the screen. 8.At the command prompt, type bootcfg /rebuild, and then press ENTER. This command scans the hard disks of the computer for Windows XP, Microsoft Windows 2000, or Microsoft Windows NT installations, and then displays the results. Follow the instructions that appear on the screen to add the Windows installations to the Boot.ini file. For example, follow these steps to add a Windows XP installation to the Boot.ini file: •When you receive a message that is similar to the following message, press Y: Total Identified Windows Installs: 1 [1] C:\Windows Add installation to boot list? (Yes/No/All) •You receive a message that is similar to the following message: Enter Load Identifier This is the name of the operating system. When you receive this message, type the name of your operating system, and then press ENTER. This is either Microsoft Windows XP Professional or Microsoft Windows XP Home Edition. •You receive a message that is similar to the following: Enter OS Load options When you receive this message, type /fastdetect, and then press ENTER. Note The instructions that appear on your screen may be different, depending on the configuration of your computer. 9.Type exit, and then press ENTER to quit Recovery Console. Your computer restarts, and the updated boot list appears when you receive the "Please select the operating system to start" message.
Forgot to mention, I followed your instructions as requested in your last post. Combofix downloaded a critical update then tried to run, that's when i got the message mentioned above. :-) B
I hate to rebuild the boot.ini file when your system is booting fine except when you try to run combofix. Let's see if you can get a log from a different tool.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
(1 of 2)

Hi Tomk

Scan results are as follows - many thanks

B

:-)

—

-OTL logfile created on: 24/06/2012 21:52:36 - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\ATHLON\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

895.23 Mb Total Physical Memory | 495.28 Mb Available Physical Memory | 55.32% Memory free
2.12 Gb Paging File | 1.81 Gb Available in Paging File | 85.30% Paging File free
Paging file location(s): c:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 274.63 Gb Free Space | 92.13% Space Free | Partition Type: NTFS

Computer Name: ATHLON-0E1DCF7F | User Name: ATHLON | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\ATHLON\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - \\?\C:\windows\System32\WBEM\WMIADAP.EXE ()
PRC - C:\WINDOWS\system32\savedump.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VPrintOnline.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCom.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\KFx.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SpiffyExt.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VPrintOnlineHelper40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\kpries40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocAcqMod.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\keml40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\DibLibIP.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\KPCDInterface.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocCamBack.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocUpdateCheck.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESSkin.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCliWicMDRW.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESEmail.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\Atlas.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaAdapter.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaPrintOnline.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\AppCore.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaControls.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\Pcd.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\IStorageMediaStore.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaCDBackup.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\UpdateChecker.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\DXRawFormatHandler.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxXML2V.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxImV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxProcV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxZipV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxFFV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxCommonV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxCmpV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxBaseV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\areaifdll.dll ()
MOD - \\?\C:\windows\System32\WBEM\WMIADAP.EXE ()
MOD - \\?\C:\windows\System32\WBEM\wbemcomn.dll ()
MOD - C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (NetTcpPortSharing) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AresChatServer) – C:\Documents and Settings\ATHLON\My Documents\Ares\chatServer.exe File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (p2pgasvc) – C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Iprip) – C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys File not found
DRV - (PxHelp20) – System32\Drivers\PxHelp20.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (nielprt) – system32\DRIVERS\nielprt.sys File not found
DRV - (NielGfx) – system32\drivers\nielgfx.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\ATHLON\LOCALS~1\Temp\catchme.sys File not found
DRV - (RapportIaso) – c:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\system32\drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportCerberus_34302) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys ()
DRV - (StarOpen) – C:\windows\System32\drivers\StarOpen.sys ()
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (ss_bmdm) – C:\WINDOWS\system32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) – C:\WINDOWS\system32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) – C:\WINDOWS\system32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (s0017mdm) – C:\WINDOWS\system32\drivers\s0017mdm.sys (MCCI Corporation)
DRV - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) – C:\WINDOWS\system32\drivers\s0017unic.sys (MCCI Corporation)
DRV - (s0017obex) – C:\WINDOWS\system32\drivers\s0017obex.sys (MCCI Corporation)
DRV - (s0017bus) Sony Ericsson Device 0017 driver (WDM) – C:\WINDOWS\system32\drivers\s0017bus.sys (MCCI Corporation)
DRV - (s0017mdfl) – C:\WINDOWS\system32\drivers\s0017mdfl.sys (MCCI Corporation)
DRV - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0017mgmt.sys (MCCI Corporation)
DRV - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) – C:\WINDOWS\system32\drivers\s0017nd5.sys (MCCI Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (optovcm) – C:\WINDOWS\system32\drivers\optovcm.sys (OPTO ELECTRONICS CO.,LTD.)
DRV - (optousb) – C:\WINDOWS\system32\drivers\optousb.sys (OPTO ELECTRONICS CO.,LTD.)
DRV - (seehcri) – C:\WINDOWS\system32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvsmu) – C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (irsir) – C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am…s={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co.uk/search?q={searchTe…z=1I7GGIT_en-GB
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2724386
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?search={s…mp;a=NWgrARojZv
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.16: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2012/02/26 18:58:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ATHLON\Application Data\Mozilla\Extensions

O1 HOSTS File: ([2012/06/09 11:22:48 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\windows\System32\nwiz.exe ()
O4 - HKLM..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe (Katherina Walensky)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky)
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\ATHLON\My Documents\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8585828F-C44E-4AF0-8896-249AB8F8B799}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\ATHLON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ATHLON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/24 21:51:02 | 000,596,992 | —- | C] (OldTimer Tools) – C:\Documents and Settings\ATHLON\Desktop\OTL.exe
[2012/06/24 21:50:43 | 000,000,000 | —D | C] – C:\windows\LastGood
[2012/06/20 22:05:28 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/20 22:04:45 | 004,563,905 | R— | C] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\ComboFix.exe
[2012/06/14 20:49:23 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\ATHLON\Desktop\aswMBR.exe
[2012/06/13 22:25:52 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\windows\System32\dllcache\jsdbgui.dll
[2012/06/13 22:24:57 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\dds.scr
[2012/06/10 14:00:35 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/06/10 14:00:24 | 000,000,000 | —D | C] – C:\windows\setupupd
[2012/06/10 13:40:24 | 000,000,000 | —D | C] – C:\windows\setup.pss
[2012/06/10 12:11:06 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/06/10 12:08:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\ATHLON\Start Menu\Programs\Administrative Tools
[2012/06/09 11:19:59 | 000,000,000 | —D | C] – C:\windows\temp
[2012/06/09 11:05:27 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 11:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Favorites
[2012/05/29 21:08:38 | 000,000,000 | —D | C] – C:\Program Files\Hijack This
[2012/05/29 20:14:07 | 000,463,914 | —- | C] (Katherina Walensky) – C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe
[2009/08/08 15:57:40 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\ATHLON\Application Data\pcouffin.sys
[5 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/24 21:56:00 | 000,000,424 | -H– | M] () – C:\windows\tasks\User_Feed_Synchronization-{D6CFB8DA-62F7-4937-9105-DA5C4CED8DE0}.job
[2012/06/24 21:52:54 | 000,433,176 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/06/24 21:52:54 | 000,068,006 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/06/24 21:51:03 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Documents and Settings\ATHLON\Desktop\OTL.exe
[2012/06/24 21:48:39 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/24 21:48:26 | 000,002,422 | —- | M] () – C:\windows\System32\wpa.dbl
[2012/06/24 21:48:22 | 000,002,048 | –S- | M] () – C:\windows\bootstat.dat
[2012/06/20 22:15:05 | 938,819,584 | —- | M] () – C:\windows\MEMORY.DMP
[2012/06/20 22:05:01 | 004,563,905 | R— | M] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\ComboFix.exe
[2012/06/20 22:02:47 | 000,002,528 | —- | M] () – C:\Documents and Settings\ATHLON\Application Data\$_hpcst$.hpc
[2012/06/17 20:28:04 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/14 22:07:22 | 000,000,512 | —- | M] () – C:\Documents and Settings\ATHLON\Desktop\MBR.dat
[2012/06/14 20:51:26 | 000,103,032 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[2012/06/14 20:49:44 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\ATHLON\Desktop\aswMBR.exe
[2012/06/13 22:49:40 | 000,001,374 | —- | M] () – C:\windows\imsins.BAK
[2012/06/13 22:25:02 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\dds.scr
[2012/06/10 13:35:00 | 000,000,868 | —- | M] () – C:\windows\tasks\Google Software Updater.job
[2012/06/10 12:56:51 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/06/10 12:56:51 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/06/10 12:49:21 | 000,002,577 | —- | M] () – C:\windows\System32\CONFIG.NT
[2012/06/09 11:22:48 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2012/06/02 15:19:44 | 000,022,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\wucltui.dll.mui
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\windows\System32\wucltui.dll
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wucltui.dll
[2012/06/02 15:19:38 | 000,219,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuaucpl.cpl
[2012/06/02 15:19:38 | 000,210,968 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuweb.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\cdm.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\windows\System32\cdm.dll
[2012/06/02 15:19:34 | 000,053,784 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuauclt.exe
[2012/06/02 15:19:34 | 000,015,384 | —- | M] (Microsoft Corporation) – C:\windows\System32\wuapi.dll.mui
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\windows\System32\wuapi.dll
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuapi.dll
[2012/06/02 15:19:18 | 001,933,848 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuaueng.dll
[2012/06/02 15:18:58 | 000,275,696 | —- | M] (Microsoft Corporation) – C:\windows\System32\mucltui.dll
[2012/06/02 15:18:58 | 000,017,136 | —- | M] (Microsoft Corporation) – C:\windows\System32\mucltui.dll.mui
[2012/05/31 14:22:09 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\crypt32.dll
[5 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/20 22:02:47 | 000,002,528 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\$_hpcst$.hpc
[2012/06/14 22:07:22 | 000,000,512 | —- | C] () – C:\Documents and Settings\ATHLON\Desktop\MBR.dat
[2012/06/10 14:00:49 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/06/09 11:05:43 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2012/06/09 11:05:43 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2012/05/29 20:14:07 | 000,001,837 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
[2012/05/29 20:14:07 | 000,001,808 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/15 23:13:27 | 000,003,072 | —- | C] () – C:\windows\System32\iacenc.dll
[2012/02/14 18:46:50 | 000,000,078 | —- | C] () – C:\windows\Hotkey.INI
[2011/04/25 16:40:15 | 000,057,344 | —- | C] () – C:\windows\System32\PyWinTypes21.dll
[2011/04/25 16:40:14 | 000,290,919 | —- | C] () – C:\windows\System32\pythoncom21.dll
[2011/04/25 16:38:16 | 000,096,768 | —- | C] () – C:\windows\SlantAdj.dll
[2011/04/25 16:38:16 | 000,003,136 | —- | C] () – C:\windows\Ade001.bin
[2011/04/25 16:38:16 | 000,000,072 | —- | C] () – C:\windows\System32\epDPE.ini
[2011/03/07 17:44:26 | 000,110,592 | —- | C] () – C:\windows\System32\FsUsbExDevice.Dll
[2011/03/07 17:44:26 | 000,036,608 | —- | C] () – C:\windows\System32\FsUsbExDisk.Sys
[2010/07/31 15:21:26 | 000,098,304 | —- | C] () – C:\windows\System32\a_jumtmp.dll
[2009/08/08 15:57:40 | 000,087,608 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\inst.exe
[2009/08/08 15:57:40 | 000,007,887 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\pcouffin.cat
[2009/08/08 15:57:40 | 000,001,144 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\pcouffin.inf
[2009/06/19 11:30:43 | 000,000,473 | —- | C] () – C:\Program Files\Shortcut to dvdSanta.lnk
[2009/04/20 18:39:53 | 000,051,712 | —- | C] () – C:\Documents and Settings\ATHLON\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/01/10 19:23:51 | 000,019,046 | -H– | C] () – C:\Documents and Settings\ATHLON\Application Data\logs.dat

========== LOP Check ==========

[2012/02/26 18:59:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2010/06/08 17:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/02/26 18:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2012/02/26 18:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM(2)
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail(2)
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Photo Notifier and Animation Creator
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickClick
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedMaxPc
[2011/10/20 16:40:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2012/02/26 18:59:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\AJ SQUARE INC
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\AVGTOOLBAR
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Canneverbe Limited
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/05/19 07:35:21 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\dclogs
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\DriverCure
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\EPSON
[2012/02/26 18:59:16 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Image Zone Express
[2012/02/26 18:59:16 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\IronCode
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\PC Suite
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Printer Info Cache
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Samsung
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Skinux
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Sony
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\SpeedMaxPc
[2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Uniblue
[2012/05/05 15:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent
[2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent(2)
[2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Vso
[2012/05/16 21:42:08 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\YourFileDownloader
[2012/06/24 21:56:00 | 000,000,424 | -H– | M] () – C:\windows\Tasks\User_Feed_Synchronization-{D6CFB8DA-62F7-4937-9105-DA5C4CED8DE0}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ATHLON\My Documents\SetupDl.exe:SummaryInformation

< End of report >
(2of 2)

Second lot of results from Extras.txt

B

:-)

—

OTL Extras logfile created on: 24/06/2012 21:52:36 - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\ATHLON\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

895.23 Mb Total Physical Memory | 495.28 Mb Available Physical Memory | 55.32% Memory free
2.12 Gb Paging File | 1.81 Gb Available in Paging File | 85.30% Paging File free
Paging file location(s): c:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 274.63 Gb Free Space | 92.13% Space Free | Partition Type: NTFS

Computer Name: ATHLON-0E1DCF7F | User Name: ATHLON | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"enablefirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"13533:TCP" = 13533:TCP:*:Enabled:BitComet 13533 TCP
"13533:UDP" = 13533:UDP:*:Enabled:BitComet 13533 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"enablefirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE" = C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE:*:Enabled:SUPERAntiSpyware Alternate Start
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server – (PeeringPortal)
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server – (PeeringPortal)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{190C7419-C254-408e-81F8-BE11FCD72A1F}" = dj_sf_software
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{47499FAF-B116-4b14-B07F-DB2C3087A06C}" = D4200_Help
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{58535A90-1788-44f5-80BB-CFF62D9CE6D5}" = HP Deskjet 8.0 Software
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6C11D561-620B-47DA-A693-4C597F3CDF40}" = EPSON Smart Panel
"{6C5D7191-140A-11D6-B5A0-0050DA208A93}" = ArcSoft PhotoImpression
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{79D78DC9-96A2-426e-B705-A1EE9536D18B}" = D4200
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A3EABC0-CA06-11D4-BF77-00104B130C19}" = EPSON TWAIN 5
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B69CC1A5-0404-11D6-ABCB-005004C21D30}" = EPSON Copy Utility
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBF71276-E8DF-4D5E-8869-3397BF04CF1C}" = ArcSoft PhotoImpression 5
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C7E154EF-D5EC-4da4-9D00-43B85967B120}" = dj_sf_ProductContext
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E42E07F5-5A90-4BA9-B55A-79FCF9EAF9B5}" = STK02N 2.3
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E7946996-87C1-447B-AF8F-D8EC94F18842}" = Samsung PC Studio
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F327A8F7-00C6-4491-9782-1DFFBB0594A2}" = dj_sf_software_req
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"ContextAdvisor" = ContextAdvisor
"dvdSanta 3.44 - Create Your Own DVD Movies!_is1" = dvdSanta 3.44
"EPSON Photo Print" = EPSON Photo Print
"GearDrivers" = GearDrivers
"Google Updater" = Google Updater
"GSpot" = GSpot Codec Information Appliance
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"Rapport_msi" = Rapport
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X-OOM Movie Clone 3" = X-OOM Movie Clone 3 uninstall
"XP Codec Pack" = XP Codec Pack

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 19/05/2012 03:25:07 | Computer Name = ATHLON-0E1DCF7F | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 09/06/2012 06:15:02 | Computer Name = ATHLON-0E1DCF7F | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 09/06/2012 06:30:41 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24017c1e.

Error - 09/06/2012 06:30:41 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24087c1e.

Error - 10/06/2012 07:23:03 | Computer Name = ATHLON-0E1DCF7F | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 10/06/2012 07:28:18 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24087c1e.

Error - 10/06/2012 07:45:12 | Computer Name = ATHLON-0E1DCF7F | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/06/2012 08:08:18 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module , version 0.0.0.0, fault address 0x00000000.

Error - 10/06/2012 08:57:25 | Computer Name = ATHLON-0E1DCF7F | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 20/06/2012 17:16:01 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24017c1e.

[ System Events ]
Error - 17/06/2012 15:06:10 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL

Error - 20/06/2012 16:55:52 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 20/06/2012 16:55:52 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL

Error - 20/06/2012 17:15:22 | Computer Name = ATHLON-0E1DCF7F | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort2, did not respond within the timeout
period.

Error - 20/06/2012 17:17:22 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 20/06/2012 17:17:22 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL

Error - 24/06/2012 16:48:47 | Computer Name = ATHLON-0E1DCF7F | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort2, did not respond within the timeout
period.

Error - 24/06/2012 16:49:11 | Computer Name = ATHLON-0E1DCF7F | Source = System Error | ID = 1003
Description = Error code 00000019, parameter1 00000020, parameter2 84018000, parameter3
84018418, parameter4 1a830000.

Error - 24/06/2012 16:50:05 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 24/06/2012 16:50:05 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL


< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am…s={searchTerms}
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2724386
    IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?search={s…mp;a=NWgrARojZv
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found
    O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe File not found
    O4 - HKLM..\Run: [NPSStartup] File not found
    O4 - HKLM..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky)
    O4 - HKCU..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky)
    O4 - Startup: C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe (Katherina Walensky)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky)
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky)
    O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\ATHLON\My Documents\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 File not found
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
    [2012/05/29 20:14:07 | 000,463,914 | —- | C] (Katherina Walensky) – C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe
    [2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\AVGTOOLBAR
    [2012/05/05 15:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent
    [2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent(2)
    @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ATHLON\My Documents\SetupDl.exe:SummaryInformation
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resultant log and give me an update as to how things are running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI