This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mystart by Incredibar infected - Help hugely appreciated! [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It's not too much of a problem as we're only getting rid of remnants and as you say, it's good that Malwarebytes is happy. Please run OTL again and send a new log. We'll get rid of the bits we don't want using that if ComboFix is playing up.
ok, thanks, and here is the latest OTL log




OTL logfile created on: 11/06/2012 14:53:54 - Run 3
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\James\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.68 Gb Total Physical Memory | 4.47 Gb Available Physical Memory | 78.80% Memory free
11.36 Gb Paging File | 9.95 Gb Available in Paging File | 87.64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 678.54 Gb Total Space | 603.78 Gb Free Space | 88.98% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
PRC - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWOW64\rpcnet.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 14:10:50 | 000,815,512 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010/08/10 10:06:16 | 000,975,952 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/08/10 10:06:16 | 000,305,744 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/28 23:23:24 | 000,263,936 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe


========== Modules (No Company Name) ==========

MOD - [2010/06/28 23:20:54 | 000,465,576 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2009/05/20 07:02:04 | 000,072,200 | —- | M] () – C:\Program Files (x86)\Launch Manager\CdDirIo.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe – (Live Updater Service)
SRV:64bit: - [2011/01/05 15:23:58 | 000,867,712 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) [Auto | Running] – C:\Windows\SysWOW64\rpcnet.exe – (rpcnet) Remote Procedure Call (RPC)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe – (avgfws)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [On_Demand | Stopped] – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/06/07 12:25:12 | 000,191,752 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe – (GREGService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor9.0)
SRV - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) [Auto | Running] – C:\Program Files (x86)\Launch Manager\dsiwmis.exe – (DsiWMIService)
SRV - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate) @C:\Program Files (x86)
SRV - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/04/16 15:40:02 | 000,237,568 | —- | M] (SMServer) [On_Demand | Stopped] – C:\Windows\SysWOW64\snmvtsvc.exe – (SMServer)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/14 13:56:49 | 000,283,200 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/12/20 03:46:50 | 000,029,184 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\libusb0.sys – (libusb0)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:64bit: - [2011/10/07 06:23:46 | 000,283,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (Avgldx64)
DRV:64bit: - [2011/09/13 06:30:08 | 000,037,456 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avgrkx64.sys – (Avgrkx64)
DRV:64bit: - [2011/08/08 06:08:58 | 000,046,672 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (Avgmfx64)
DRV:64bit: - [2011/07/14 06:35:47 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/07/14 06:35:47 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/07/11 01:14:36 | 000,375,376 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (Avgtdia)
DRV:64bit: - [2011/07/11 01:14:08 | 000,029,776 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV:64bit: - [2011/07/11 01:14:06 | 000,120,400 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV:64bit: - [2011/07/11 01:14:06 | 000,026,704 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV:64bit: - [2011/06/02 04:37:32 | 002,750,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2011/05/23 01:03:28 | 000,048,992 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgfwd6a.sys – (Avgfwfd)
DRV:64bit: - [2011/01/13 04:17:30 | 000,122,624 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\zghsmdm.sys – (zghsmdm)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/18 07:24:46 | 000,038,424 | —- | M] (Google Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\androidusb.sys – (androidusb)
DRV:64bit: - [2010/09/22 02:47:10 | 000,243,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2010/07/20 01:10:40 | 010,603,904 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/21 10:45:56 | 000,287,232 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/04/13 17:44:22 | 000,540,696 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/04/13 11:15:04 | 000,135,560 | —- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ETD.sys – (ETD)
DRV:64bit: - [2010/03/19 03:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 00:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 06:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/06 00:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/06 00:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/16 13:18:40 | 000,033,264 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SndTAudio.sys – (SndTAudio)
DRV - [2011/05/25 20:35:20 | 000,021,504 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\libusb0.sys – (libusb0)
DRV - [2009/07/14 02:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/01 15:33:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/04/16 14:48:53 | 000,000,000 | —D | M]

[2012/04/07 09:45:18 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions
[2012/04/07 09:45:18 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/04/18 15:34:25 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/09 13:17:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/11 09:41:38 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64F0CD7F-97D9-4C18-93BC-2553B7B7A955}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/11 14:05:37 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/11 09:41:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/06/11 09:34:47 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/06/11 09:34:47 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/06/11 09:34:47 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/06/11 09:34:43 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/06/11 09:25:20 | 004,540,367 | R— | C] (Swearware) – C:\Users\James\Desktop\ComboFix.exe
[2012/06/10 23:55:00 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/10 17:11:53 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/06/10 12:25:31 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/06/09 17:49:10 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 17:35:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/06/09 16:22:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/09 15:11:45 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/06/09 14:31:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/06/09 13:20:04 | 000,000,000 | —D | C] – C:\Users\James\Documents\Downloads
[2012/06/09 13:18:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OpenCandy
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free YouTube Downloader
[2012/06/09 13:17:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/06/09 13:17:17 | 000,000,000 | —D | C] – C:\Program Files\Web Assistant
[2012/05/31 13:09:18 | 000,000,000 | —D | C] – C:\ProgramData\Soulseek
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\SoulseekNS
[2012/05/26 13:46:20 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Joboshare
[2012/05/26 13:46:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Joboshare
[2012/05/16 21:28:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\IMinent Toolbar

========== Files - Modified Within 30 Days ==========

[2012/06/11 14:27:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001UA.job
[2012/06/11 14:09:19 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/11 14:09:19 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/11 14:07:06 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/11 14:07:06 | 000,628,808 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/11 14:07:06 | 000,110,960 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/11 14:02:10 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.dll
[2012/06/11 14:02:10 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.dll
[2012/06/11 14:02:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/11 14:02:03 | 277,901,311 | -HS- | M] () – C:\hiberfil.sys
[2012/06/11 14:01:59 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.exe
[2012/06/11 14:01:59 | 000,017,920 | —- | M] () – C:\Windows\SysNative\rpcnetp.exe
[2012/06/11 11:06:04 | 100,193,302 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/11 10:53:30 | 000,139,264 | —- | M] () – C:\Users\James\Desktop\SystemLook.exe
[2012/06/11 10:27:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001Core.job
[2012/06/11 09:41:38 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/06/11 09:25:20 | 004,540,367 | R— | M] (Swearware) – C:\Users\James\Desktop\ComboFix.exe
[2012/06/10 23:05:57 | 000,335,691 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:59 | 000,001,274 | —- | M] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/06/10 12:12:34 | 000,000,834 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/10 10:41:06 | 000,013,989 | —- | M] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/06/04 09:00:40 | 000,013,160 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\Upgrd.exe
[2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.exe
[2012/05/30 18:09:44 | 000,016,565 | —- | M] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/30 12:11:01 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\calibre - E-book management.lnk
[2012/05/29 00:44:32 | 000,625,911 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/27 16:24:04 | 000,037,480 | —- | M] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | M] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:33:49 | 000,000,866 | —- | M] () – C:\Windows\SysWow64\InstallUtil.InstallLog

========== Files Created - No Company Name ==========

[2012/06/11 10:53:33 | 000,139,264 | —- | C] () – C:\Users\James\Desktop\SystemLook.exe
[2012/06/11 09:34:47 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/06/11 09:34:47 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/06/11 09:34:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/06/11 09:34:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/06/11 09:34:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/06/10 14:18:59 | 000,001,274 | —- | C] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/05/30 18:09:43 | 000,016,565 | —- | C] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/27 16:37:50 | 000,013,989 | —- | C] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/05/27 16:24:03 | 000,037,480 | —- | C] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | C] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:27:21 | 000,000,866 | —- | C] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/08 00:26:40 | 000,000,466 | —- | C] () – C:\Windows\wininit.ini
[2012/04/08 17:03:24 | 000,155,136 | —- | C] () – C:\Windows\SysWow64\AI_ContextMenu.dll
[2012/02/17 13:58:10 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2011/09/14 13:05:44 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/09/14 13:05:44 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/09/14 13:05:44 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/09/14 13:05:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/09/14 13:05:43 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/09/14 12:14:21 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.dll
[2011/09/14 12:13:30 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.exe

< End of report >
Morning TheStrwawMan

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
    [2012/05/16 21:28:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\IMinent Toolbar
    
    :Files
    C:\Program Files (x86)\IMinent Toolbar
    C:\Program Files (x86)\Yontoo
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons 
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Coupons
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Logs to include in the next post:

OTL fix log
New OTL log


Thanks

Satchfan
Good morning and here are some logs!


OTL fix log:





All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026}\ deleted successfully.
C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\ deleted successfully.
File C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll not found.
C:\Program Files (x86)\IMinent Toolbar folder moved successfully.
========== FILES ==========
File\Folder C:\Program Files (x86)\IMinent Toolbar not found.
C:\Program Files (x86)\Yontoo folder moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons folder moved successfully.
File\Folder C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Coupons not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: James
->Temp folder emptied: 33133 bytes
->Temporary Internet Files folder emptied: 702245 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 110852654 bytes
->Flash cache emptied: 3809 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5398 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 162284 bytes

Total Files Cleaned = 107.00 mb


OTL by OldTimer - Version 3.2.48.0 log created on 06122012_085215

Files\Folders moved on Reboot…
C:\Users\James\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.

Registry entries deleted on Reboot…





New OTL:




OTL logfile created on: 12/06/2012 09:04:01 - Run 5
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\James\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.68 Gb Total Physical Memory | 4.22 Gb Available Physical Memory | 74.37% Memory free
11.36 Gb Paging File | 9.88 Gb Available in Paging File | 86.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 678.54 Gb Total Space | 603.83 Gb Free Space | 88.99% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
PRC - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWOW64\rpcnet.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 14:10:50 | 000,815,512 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010/08/10 10:06:16 | 000,975,952 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/08/10 10:06:16 | 000,305,744 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/28 23:23:24 | 000,263,936 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe


========== Modules (No Company Name) ==========

MOD - [2010/06/28 23:20:54 | 000,465,576 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2009/05/20 07:02:04 | 000,072,200 | —- | M] () – C:\Program Files (x86)\Launch Manager\CdDirIo.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe – (Live Updater Service)
SRV:64bit: - [2011/01/05 15:23:58 | 000,867,712 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) [Auto | Running] – C:\Windows\SysWOW64\rpcnet.exe – (rpcnet) Remote Procedure Call (RPC)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe – (avgfws)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [On_Demand | Stopped] – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/06/07 12:25:12 | 000,191,752 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe – (GREGService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor9.0)
SRV - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) [Auto | Running] – C:\Program Files (x86)\Launch Manager\dsiwmis.exe – (DsiWMIService)
SRV - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate) @C:\Program Files (x86)
SRV - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/04/16 15:40:02 | 000,237,568 | —- | M] (SMServer) [On_Demand | Stopped] – C:\Windows\SysWOW64\snmvtsvc.exe – (SMServer)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/14 13:56:49 | 000,283,200 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/12/20 03:46:50 | 000,029,184 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\libusb0.sys – (libusb0)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:64bit: - [2011/10/07 06:23:46 | 000,283,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (Avgldx64)
DRV:64bit: - [2011/09/13 06:30:08 | 000,037,456 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avgrkx64.sys – (Avgrkx64)
DRV:64bit: - [2011/08/08 06:08:58 | 000,046,672 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (Avgmfx64)
DRV:64bit: - [2011/07/14 06:35:47 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/07/14 06:35:47 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/07/11 01:14:36 | 000,375,376 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (Avgtdia)
DRV:64bit: - [2011/07/11 01:14:08 | 000,029,776 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV:64bit: - [2011/07/11 01:14:06 | 000,120,400 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV:64bit: - [2011/07/11 01:14:06 | 000,026,704 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV:64bit: - [2011/06/02 04:37:32 | 002,750,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2011/05/23 01:03:28 | 000,048,992 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgfwd6a.sys – (Avgfwfd)
DRV:64bit: - [2011/01/13 04:17:30 | 000,122,624 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\zghsmdm.sys – (zghsmdm)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/18 07:24:46 | 000,038,424 | —- | M] (Google Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\androidusb.sys – (androidusb)
DRV:64bit: - [2010/09/22 02:47:10 | 000,243,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2010/07/20 01:10:40 | 010,603,904 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/21 10:45:56 | 000,287,232 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/04/13 17:44:22 | 000,540,696 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/04/13 11:15:04 | 000,135,560 | —- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ETD.sys – (ETD)
DRV:64bit: - [2010/03/19 03:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 00:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 06:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/06 00:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/06 00:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/16 13:18:40 | 000,033,264 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SndTAudio.sys – (SndTAudio)
DRV - [2011/05/25 20:35:20 | 000,021,504 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\libusb0.sys – (libusb0)
DRV - [2009/07/14 02:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/01 15:33:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/04/16 14:48:53 | 000,000,000 | —D | M]

[2012/04/07 09:45:18 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions
[2012/04/07 09:45:18 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/04/18 15:34:25 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/09 13:17:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/11 09:41:38 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64F0CD7F-97D9-4C18-93BC-2553B7B7A955}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/11 14:05:37 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/11 09:41:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/06/11 09:34:47 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/06/11 09:34:47 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/06/11 09:34:47 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/06/11 09:34:43 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/06/11 09:25:20 | 004,540,367 | R— | C] (Swearware) – C:\Users\James\Desktop\ComboFix.exe
[2012/06/10 23:55:00 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/10 17:11:53 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/06/10 12:25:31 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/06/09 17:49:10 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 17:35:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/06/09 16:22:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/09 15:11:45 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/06/09 14:31:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/06/09 13:20:04 | 000,000,000 | —D | C] – C:\Users\James\Documents\Downloads
[2012/06/09 13:18:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OpenCandy
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free YouTube Downloader
[2012/06/09 13:17:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/06/09 13:17:17 | 000,000,000 | —D | C] – C:\Program Files\Web Assistant
[2012/05/31 13:09:18 | 000,000,000 | —D | C] – C:\ProgramData\Soulseek
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\SoulseekNS
[2012/05/26 13:46:20 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Joboshare
[2012/05/26 13:46:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Joboshare

========== Files - Modified Within 30 Days ==========

[2012/06/12 09:00:33 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/12 09:00:33 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/12 08:57:47 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/12 08:57:47 | 000,628,808 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/12 08:57:47 | 000,110,960 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/12 08:53:29 | 000,017,920 | —- | M] () – C:\Windows\SysNative\rpcnetp.exe
[2012/06/12 08:53:27 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.dll
[2012/06/12 08:53:27 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.dll
[2012/06/12 08:53:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/12 08:53:21 | 277,901,311 | -HS- | M] () – C:\hiberfil.sys
[2012/06/12 08:53:16 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.exe
[2012/06/12 01:14:19 | 100,224,826 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/11 15:27:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001UA.job
[2012/06/11 10:53:30 | 000,139,264 | —- | M] () – C:\Users\James\Desktop\SystemLook.exe
[2012/06/11 10:27:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001Core.job
[2012/06/11 09:41:38 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/06/11 09:25:20 | 004,540,367 | R— | M] (Swearware) – C:\Users\James\Desktop\ComboFix.exe
[2012/06/10 23:05:57 | 000,335,691 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:59 | 000,001,274 | —- | M] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/06/10 12:12:34 | 000,000,834 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/10 10:41:06 | 000,013,989 | —- | M] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/06/04 09:00:40 | 000,013,160 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\Upgrd.exe
[2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.exe
[2012/05/30 18:09:44 | 000,016,565 | —- | M] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/30 12:11:01 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\calibre - E-book management.lnk
[2012/05/29 00:44:32 | 000,625,911 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/27 16:24:04 | 000,037,480 | —- | M] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | M] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:33:49 | 000,000,866 | —- | M] () – C:\Windows\SysWow64\InstallUtil.InstallLog

========== Files Created - No Company Name ==========

[2012/06/11 10:53:33 | 000,139,264 | —- | C] () – C:\Users\James\Desktop\SystemLook.exe
[2012/06/11 09:34:47 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/06/11 09:34:47 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/06/11 09:34:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/06/11 09:34:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/06/11 09:34:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/06/10 14:18:59 | 000,001,274 | —- | C] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/05/30 18:09:43 | 000,016,565 | —- | C] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/27 16:37:50 | 000,013,989 | —- | C] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/05/27 16:24:03 | 000,037,480 | —- | C] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | C] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:27:21 | 000,000,866 | —- | C] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/08 00:26:40 | 000,000,466 | —- | C] () – C:\Windows\wininit.ini
[2012/04/08 17:03:24 | 000,155,136 | —- | C] () – C:\Windows\SysWow64\AI_ContextMenu.dll
[2012/02/17 13:58:10 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2011/09/14 13:05:44 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/09/14 13:05:44 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/09/14 13:05:44 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/09/14 13:05:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/09/14 13:05:43 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/09/14 12:14:21 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.dll
[2011/09/14 12:13:30 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.exe

< End of report >
Nearly all gone.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) =
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Logs to include in the next post:

checkup.txt
OTL fix log
New OTL log


Satchfan
Ok, I'll post the two OTL logs first:


Fix log:



All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
File R - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: James
->Temp folder emptied: 9148 bytes
->Temporary Internet Files folder emptied: 35883 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 28706717 bytes
->Flash cache emptied: 1707 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4182 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 158378 bytes

Total Files Cleaned = 28.00 mb


OTL by OldTimer - Version 3.2.48.0 log created on 06122012_122135

Files\Folders moved on Reboot…
C:\Users\James\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.

Registry entries deleted on Reboot…



New OTL log




OTL logfile created on: 12/06/2012 12:31:45 - Run 6
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\James\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.68 Gb Total Physical Memory | 4.23 Gb Available Physical Memory | 74.41% Memory free
11.36 Gb Paging File | 9.86 Gb Available in Paging File | 86.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 678.54 Gb Total Space | 603.62 Gb Free Space | 88.96% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
PRC - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWOW64\rpcnet.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 14:10:50 | 000,815,512 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010/08/10 10:06:16 | 000,975,952 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/08/10 10:06:16 | 000,305,744 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/28 23:23:24 | 000,263,936 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe


========== Modules (No Company Name) ==========

MOD - [2010/06/28 23:20:54 | 000,465,576 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2009/05/20 07:02:04 | 000,072,200 | —- | M] () – C:\Program Files (x86)\Launch Manager\CdDirIo.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe – (Live Updater Service)
SRV:64bit: - [2011/01/05 15:23:58 | 000,867,712 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) [Auto | Running] – C:\Windows\SysWOW64\rpcnet.exe – (rpcnet) Remote Procedure Call (RPC)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe – (avgfws)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [On_Demand | Stopped] – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/06/07 12:25:12 | 000,191,752 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe – (GREGService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor9.0)
SRV - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) [Auto | Running] – C:\Program Files (x86)\Launch Manager\dsiwmis.exe – (DsiWMIService)
SRV - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate) @C:\Program Files (x86)
SRV - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/04/16 15:40:02 | 000,237,568 | —- | M] (SMServer) [On_Demand | Stopped] – C:\Windows\SysWOW64\snmvtsvc.exe – (SMServer)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/14 13:56:49 | 000,283,200 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/12/20 03:46:50 | 000,029,184 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\libusb0.sys – (libusb0)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:64bit: - [2011/10/07 06:23:46 | 000,283,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (Avgldx64)
DRV:64bit: - [2011/09/13 06:30:08 | 000,037,456 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avgrkx64.sys – (Avgrkx64)
DRV:64bit: - [2011/08/08 06:08:58 | 000,046,672 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (Avgmfx64)
DRV:64bit: - [2011/07/14 06:35:47 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/07/14 06:35:47 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/07/11 01:14:36 | 000,375,376 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (Avgtdia)
DRV:64bit: - [2011/07/11 01:14:08 | 000,029,776 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV:64bit: - [2011/07/11 01:14:06 | 000,120,400 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV:64bit: - [2011/07/11 01:14:06 | 000,026,704 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV:64bit: - [2011/06/02 04:37:32 | 002,750,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2011/05/23 01:03:28 | 000,048,992 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgfwd6a.sys – (Avgfwfd)
DRV:64bit: - [2011/01/13 04:17:30 | 000,122,624 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\zghsmdm.sys – (zghsmdm)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/18 07:24:46 | 000,038,424 | —- | M] (Google Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\androidusb.sys – (androidusb)
DRV:64bit: - [2010/09/22 02:47:10 | 000,243,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2010/07/20 01:10:40 | 010,603,904 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/21 10:45:56 | 000,287,232 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/04/13 17:44:22 | 000,540,696 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/04/13 11:15:04 | 000,135,560 | —- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ETD.sys – (ETD)
DRV:64bit: - [2010/03/19 03:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 00:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 06:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/06 00:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/06 00:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/16 13:18:40 | 000,033,264 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SndTAudio.sys – (SndTAudio)
DRV - [2011/05/25 20:35:20 | 000,021,504 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\libusb0.sys – (libusb0)
DRV - [2009/07/14 02:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/01 15:33:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/04/16 14:48:53 | 000,000,000 | —D | M]

[2012/04/07 09:45:18 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions
[2012/04/07 09:45:18 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/04/18 15:34:25 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/09 13:17:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/11 09:41:38 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64F0CD7F-97D9-4C18-93BC-2553B7B7A955}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/11 14:05:37 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/11 09:41:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/06/11 09:34:47 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/06/11 09:34:47 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/06/11 09:34:47 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/06/11 09:34:43 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/06/11 09:25:20 | 004,540,367 | R— | C] (Swearware) – C:\Users\James\Desktop\ComboFix.exe
[2012/06/10 23:55:00 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/10 17:11:53 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/06/10 12:25:31 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/06/09 17:49:10 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 17:35:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/06/09 16:22:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/09 15:11:45 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/06/09 14:31:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/06/09 13:20:04 | 000,000,000 | —D | C] – C:\Users\James\Documents\Downloads
[2012/06/09 13:18:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OpenCandy
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free YouTube Downloader
[2012/06/09 13:17:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/06/09 13:17:17 | 000,000,000 | —D | C] – C:\Program Files\Web Assistant
[2012/05/31 13:09:18 | 000,000,000 | —D | C] – C:\ProgramData\Soulseek
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\SoulseekNS
[2012/05/26 13:46:20 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Joboshare
[2012/05/26 13:46:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Joboshare

========== Files - Modified Within 30 Days ==========

[2012/06/12 12:29:55 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/12 12:29:55 | 000,628,808 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/12 12:29:55 | 000,110,960 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/12 12:29:48 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/12 12:29:48 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/12 12:27:01 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001UA.job
[2012/06/12 12:22:43 | 000,017,920 | —- | M] () – C:\Windows\SysNative\rpcnetp.exe
[2012/06/12 12:22:40 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.dll
[2012/06/12 12:22:40 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.dll
[2012/06/12 12:22:38 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/12 12:22:37 | 277,901,311 | -HS- | M] () – C:\hiberfil.sys
[2012/06/12 12:22:31 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.exe
[2012/06/12 11:06:10 | 100,255,877 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/12 11:05:55 | 000,335,691 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/12 10:27:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001Core.job
[2012/06/11 10:53:30 | 000,139,264 | —- | M] () – C:\Users\James\Desktop\SystemLook.exe
[2012/06/11 10:12:24 | 000,014,416 | —- | M] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/06/11 09:41:38 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/06/11 09:25:20 | 004,540,367 | R— | M] (Swearware) – C:\Users\James\Desktop\ComboFix.exe
[2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:59 | 000,001,274 | —- | M] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/06/10 12:12:34 | 000,000,834 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/04 09:00:40 | 000,013,160 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\Upgrd.exe
[2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.exe
[2012/05/30 18:09:44 | 000,016,565 | —- | M] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/30 12:11:01 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\calibre - E-book management.lnk
[2012/05/29 00:44:32 | 000,625,911 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/27 16:24:04 | 000,037,480 | —- | M] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | M] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:33:49 | 000,000,866 | —- | M] () – C:\Windows\SysWow64\InstallUtil.InstallLog

========== Files Created - No Company Name ==========

[2012/06/11 10:53:33 | 000,139,264 | —- | C] () – C:\Users\James\Desktop\SystemLook.exe
[2012/06/11 09:34:47 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/06/11 09:34:47 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/06/11 09:34:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/06/11 09:34:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/06/11 09:34:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/06/10 14:18:59 | 000,001,274 | —- | C] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/05/30 18:09:43 | 000,016,565 | —- | C] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/27 16:37:50 | 000,014,416 | —- | C] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/05/27 16:24:03 | 000,037,480 | —- | C] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | C] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:27:21 | 000,000,866 | —- | C] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/08 00:26:40 | 000,000,466 | —- | C] () – C:\Windows\wininit.ini
[2012/04/08 17:03:24 | 000,155,136 | —- | C] () – C:\Windows\SysWow64\AI_ContextMenu.dll
[2012/02/17 13:58:10 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2011/09/14 13:05:44 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/09/14 13:05:44 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/09/14 13:05:44 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/09/14 13:05:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/09/14 13:05:43 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/09/14 12:14:21 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.dll
[2011/09/14 12:13:30 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.exe

< End of report >
And here is the Security Check (ive left antivirus disabled for these scans, i dont know if that matters on not)





Results of screen317's Security Check version 0.99.41
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
AVG Internet Security Business Edition 2012
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.61.0.1400
Java™ 6 Update 31
Java version out of date!
Adobe Reader X (10.1.3)
Google Chrome 19.0.1084.52
Google Chrome 19.0.1084.56
Google Chrome plugins…
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
AVG avgtray.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
Hi

Well that Chrome plugin for Coupon Printer Manager is persistent.

You could try this:
  • Click the "Customize and control Google Chrome" wrench icon and select "Tools" then "Extensions", or type "chrome://extensions/" into the address bar
  • Find the "Coupons.com Toolbar" entry in the list of extensions
  • Click the "Remove" button, then the "Uninstall" button to remove the toolbar
If that doesn’t work, start in safe mode and remove the following file:

C:\Users\James\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll

===============================================

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
Thanks again. The pesky Coupons extension did not show up on the list of chrome extensions, so I deleted it in safe mode as you said (I had to enable show hidden files for the AppData folder to show up though) By chance whilst looking for something else I've noticed a file C:\Windows\CouponPrinter.ocx that looks suspicious, i've left it alone, but should I delete it also in safe mode? ESET happily showed no infected items so I have no log for that. Yontoo [removed] and the Coupons thing still show up in programs and features in control panel. Just remnants I suppose, but you have to admire their tenacity!
ll looks good. Apologies for the delay but I have been a bit busy and have an early start.in the morning so now need to get some beauty sleep. I'll send a reply with some final instructions tomorrow. Satchfan
Ive been unavailable also, so that is no problem, not that any apologies are required anyway as you have been extremely helpful!
Hello again TheStrawMan

I've noticed a file C:\Windows\CouponPrinter.ocx that looks suspicious, i've left it alone, but should I delete it also in safe mode?

That file alone can do nothing without CouponPrinter being installed so is not a threat and is perfectly safe to remove.

Yontoo 1.10.0.2 and the Coupons thing still show up in programs and features in control panel.

We may be able to force a removal but if they have been partially uninstalled, it may be easiest to re-install the programs and then uninstall them in their entirety.

Apart from that, it appears that all is well with your computer.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

You can delete the SecurityCheck log and program from your desktop.

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall OTL
  • Double-click OTL.exe
  • Click the CleanUp! button.
  • Select Yes when the Begin cleanup Process? prompt appears.
  • If you are prompted to reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

You can just delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Update Java

You have an old versions on your computer which is vulnerable to infections.
  • from the Start menu, select Control Panel.
  • in Large or Small icon view, click Programs and Features. If you're using Category view, under "Programs", click Uninstall a program.
  • select any versions of Java, and Adobe Reader then click Uninstall.
Install the latest version here

===================================================

Recommended programs

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Let me know if you have any more problems.

I’ll leave this thread open for 24 hours after which I will assume that all is well and close it.

Safe computing

Satchfan
Ok, I think everything is complete. I'll try and stay free of malware in the future and thanks again, you have been very helpful!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI