This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

btsearch.name

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I have a problem with this btsearch. It keeps changing my home page and comes up on all search's. I have run a malware bytes and removed all infections but it still happens. Please help.
This is the hijackthis stuff.

Thanks for your help, John

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:13:06 AM, on 7/2/2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Novatel Wireless\MobiLink3\MobiLink3.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Documents and Settings\Admin\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Expat Shield\bin\openvpnas.exe
C:\Program Files\Expat Shield\HssWPR\hsssrv.exe
C:\Program Files\Expat Shield\bin\hsswd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Expat Shield\bin\openvpntray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.expatshield.com/g/?c=h
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Expat Shield Class - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files\Expat Shield\HssIE\ExpatIE.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [MobiLink 3] C:\Program Files\Novatel Wireless\MobiLink3\MobiLink3.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Admin\Application Data\Dropbox\bin\Dropbox.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://yahoouk.oberon-media.com/Gameshell/…ronGameHost.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E29B5748-40C5-428F-80AF-294752983CB2}: NameServer = 209.121.225.11 209.91.107.11
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Expat Shield Service (ExpatShieldService) - Unknown owner - C:\Program Files\Expat Shield\bin\openvpnas.exe
O23 - Service: Expat Shield Routing Service (ExpatSrv) - AnchorFree Inc. - C:\Program Files\Expat Shield\HssWPR\hsssrv.exe
O23 - Service: Expat Shield Tray Service (ExpatTrayService) - Unknown owner - C:\Program Files\Expat Shield\bin\ExpatTrayService.EXE
O23 - Service: Expat Shield Monitoring Service (ExpatWd) - Unknown owner - C:\Program Files\Expat Shield\bin\hsswd.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NovaCore SDK Service (NvtlService) - Unknown owner - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
O23 - Service: Spybot S&D 2 Live Protection Service (SDHookService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11883 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi mowman, thanks for getting back so fast. Here's the log for tdsskiller, it was all clean. I'll do the otl one next, Thanks 12:11:38.0421 2320 TDSS rootkit removing tool [removed] Jun 29 2012 17:54:22 12:11:39.0796 2320 ============================================================ 12:11:39.0796 2320 Current date / time: 2012/07/02 12:11:39.0796 12:11:39.0796 2320 SystemInfo: 12:11:39.0796 2320 12:11:39.0796 2320 OS Version: 5.1.2600 ServicePack: 2.0 12:11:39.0796 2320 Product type: Workstation 12:11:39.0796 2320 ComputerName: ADMIN-3C 12:11:39.0796 2320 UserName: Admin 12:11:39.0796 2320 Windows directory: C:\WINDOWS 12:11:39.0796 2320 System windows directory: C:\WINDOWS 12:11:39.0796 2320 Processor architecture: Intel x86 12:11:39.0796 2320 Number of processors: 2 12:11:39.0796 2320 Page size: 0x1000 12:11:39.0796 2320 Boot type: Normal boot 12:11:39.0796 2320 ============================================================ 12:11:42.0359 2320 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 12:11:42.0375 2320 ============================================================ 12:11:42.0375 2320 \Device\Harddisk0\DR0: 12:11:42.0375 2320 MBR partitions: 12:11:42.0375 2320 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x7530462 12:11:42.0390 2320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x75304E0, BlocksNum 0x7530462 12:11:42.0406 2320 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xEA60981, BlocksNum 0x3FB427F 12:11:42.0406 2320 ============================================================ 12:11:42.0453 2320 C: <-> \Device\Harddisk0\DR0\Partition0 12:11:42.0500 2320 D: <-> \Device\Harddisk0\DR0\Partition1 12:11:42.0515 2320 E: <-> \Device\Harddisk0\DR0\Partition2 12:11:42.0515 2320 ============================================================ 12:11:42.0515 2320 Initialize success 12:11:42.0515 2320 ============================================================ 12:11:46.0812 0812 ============================================================ 12:11:46.0812 0812 Scan started 12:11:46.0812 0812 Mode: Manual; 12:11:46.0812 0812 ============================================================ 12:11:47.0375 0812 Abiosdsk - ok 12:11:47.0390 0812 abp480n5 - ok 12:11:47.0453 0812 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 12:11:47.0468 0812 ACPI - ok 12:11:47.0484 0812 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 12:11:47.0500 0812 ACPIEC - ok 12:11:47.0500 0812 adpu160m - ok 12:11:47.0546 0812 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 12:11:47.0562 0812 aec - ok 12:11:47.0593 0812 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys 12:11:47.0593 0812 AFD - ok 12:11:47.0609 0812 Aha154x - ok 12:11:47.0625 0812 aic78u2 - ok 12:11:47.0640 0812 aic78xx - ok 12:11:47.0656 0812 Alerter (c7ae0fd3867db0d42b03b73c18f3d671) C:\WINDOWS\system32\alrsvc.dll 12:11:47.0656 0812 Alerter - ok 12:11:47.0671 0812 ALG (f1958fbf86d5c004cf19a5951a9514b7) C:\WINDOWS\System32\alg.exe 12:11:47.0687 0812 ALG - ok 12:11:47.0687 0812 AliIde - ok 12:11:47.0703 0812 amsint - ok 12:11:47.0781 0812 Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 12:11:47.0781 0812 Apple Mobile Device - ok 12:11:47.0812 0812 AppMgmt (9c3c12975c97119412802b181fbeeffe) C:\WINDOWS\System32\appmgmts.dll 12:11:47.0828 0812 AppMgmt - ok 12:11:47.0968 0812 AR5416 (864160f5f4fbdd97b6a686854bfebd86) C:\WINDOWS\system32\DRIVERS\athw.sys 12:11:48.0031 0812 AR5416 - ok 12:11:48.0046 0812 asc - ok 12:11:48.0062 0812 asc3350p - ok 12:11:48.0078 0812 asc3550 - ok 12:11:48.0109 0812 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 12:11:48.0109 0812 AsyncMac - ok 12:11:48.0140 0812 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 12:11:48.0140 0812 atapi - ok 12:11:48.0156 0812 Atdisk - ok 12:11:48.0187 0812 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 12:11:48.0203 0812 Atmarpc - ok 12:11:48.0234 0812 AudioSrv (db66db626e4882ebef55f136f12c1829) C:\WINDOWS\System32\audiosrv.dll 12:11:48.0234 0812 AudioSrv - ok 12:11:48.0281 0812 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 12:11:48.0281 0812 audstub - ok 12:11:48.0796 0812 AVGIDSAgent (ba60fd7a64b9759a14c0fba4a9ed4c7b) C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe 12:11:49.0000 0812 AVGIDSAgent - ok 12:11:49.0109 0812 AVGIDSDriver (1074f787080068c71303b61fae7e7ca4) C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys 12:11:49.0109 0812 AVGIDSDriver - ok 12:11:49.0125 0812 AVGIDSFilter (61a7e0b02f82cff3db2445bbe50b3589) C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys 12:11:49.0125 0812 AVGIDSFilter - ok 12:11:49.0156 0812 AVGIDSHX (d63d83659eedf60b3a3e620281a888e5) C:\WINDOWS\system32\DRIVERS\avgidshx.sys 12:11:49.0171 0812 AVGIDSHX - ok 12:11:49.0187 0812 AVGIDSShim (baf975b72062f53d327788e99d64197e) C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys 12:11:49.0187 0812 AVGIDSShim - ok 12:11:49.0234 0812 Avgldx86 (dda6a2a18841e4c9172bb85958b8d948) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 12:11:49.0250 0812 Avgldx86 - ok 12:11:49.0265 0812 Avgmfx86 (ccdd61545aaea265977e4b1efdc74e8c) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 12:11:49.0265 0812 Avgmfx86 - ok 12:11:49.0281 0812 Avgrkx86 (1fd90b28d2c3100bf4500199c8ad6358) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 12:11:49.0296 0812 Avgrkx86 - ok 12:11:49.0343 0812 Avgtdix (1263f2554ace925c237a40b4c568d815) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 12:11:49.0359 0812 Avgtdix - ok 12:11:49.0468 0812 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files\AVG\AVG2012\avgwdsvc.exe 12:11:49.0484 0812 avgwd - ok 12:11:49.0515 0812 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 12:11:49.0515 0812 Beep - ok 12:11:49.0593 0812 BITS (2c69ec7e5a311334d10dd95f338fccea) C:\WINDOWS\system32\qmgr.dll 12:11:49.0609 0812 BITS - ok 12:11:49.0687 0812 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 12:11:49.0703 0812 Bonjour Service - ok 12:11:49.0750 0812 Browser (e3cfccdda4edd1d0dc9168b2e18f27b8) C:\WINDOWS\System32\browser.dll 12:11:49.0750 0812 Browser - ok 12:11:49.0828 0812 btaudio (2c04f295f7f40eb46f7accd3f6cdef4a) C:\WINDOWS\system32\drivers\btaudio.sys 12:11:49.0875 0812 btaudio - ok 12:11:49.0906 0812 BTDriver (2f9f111d31aa3fbbe5781d829a4524e6) C:\WINDOWS\system32\DRIVERS\btport.sys 12:11:49.0906 0812 BTDriver - ok 12:11:50.0000 0812 btwdins (80349cb09ddc2f99e16d0f8919e2dca3) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 12:11:50.0031 0812 btwdins - ok 12:11:50.0062 0812 BTWDNDIS (485020a1e1fc5c51a800ca69c618d881) C:\WINDOWS\system32\DRIVERS\btwdndis.sys 12:11:50.0078 0812 BTWDNDIS - ok 12:11:50.0109 0812 btwhid (949eca9c56f657c06d3166d51f3226c7) C:\WINDOWS\system32\DRIVERS\btwhid.sys 12:11:50.0109 0812 btwhid - ok 12:11:50.0140 0812 BTWUSB (6b622612fe21b59faee2ca4385959778) C:\WINDOWS\system32\Drivers\btwusb.sys 12:11:50.0140 0812 BTWUSB - ok 12:11:50.0171 0812 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 12:11:50.0187 0812 cbidf2k - ok 12:11:50.0218 0812 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 12:11:50.0218 0812 CCDECODE - ok 12:11:50.0218 0812 cd20xrnt - ok 12:11:50.0250 0812 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 12:11:50.0250 0812 Cdaudio - ok 12:11:50.0296 0812 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 12:11:50.0296 0812 Cdfs - ok 12:11:50.0328 0812 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 12:11:50.0343 0812 Cdrom - ok 12:11:50.0359 0812 Changer - ok 12:11:50.0390 0812 CiSvc (3192bd04d032a9c4a85a3278c268a13a) C:\WINDOWS\system32\cisvc.exe 12:11:50.0390 0812 CiSvc - ok 12:11:50.0421 0812 ClipSrv (c8dec22c4137d7a90f8bdf41ca4b82ae) C:\WINDOWS\system32\clipsrv.exe 12:11:50.0421 0812 ClipSrv - ok 12:11:50.0453 0812 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 12:11:50.0453 0812 CmBatt - ok 12:11:50.0453 0812 CmdIde - ok 12:11:50.0484 0812 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys 12:11:50.0484 0812 Compbatt - ok 12:11:50.0500 0812 COMSysApp - ok 12:11:50.0531 0812 Cpqarray - ok 12:11:50.0562 0812 CryptSvc (10654f9ddcea9c46cfb77554231be73b) C:\WINDOWS\System32\cryptsvc.dll 12:11:50.0562 0812 CryptSvc - ok 12:11:50.0578 0812 dac2w2k - ok 12:11:50.0593 0812 dac960nt - ok 12:11:50.0640 0812 DcomLaunch (5c83a4408604f737717ab96371201680) C:\WINDOWS\system32\rpcss.dll 12:11:50.0671 0812 DcomLaunch - ok 12:11:50.0687 0812 Dhcp (cb6ca3e5261d65f6f809eed23bf167aa) C:\WINDOWS\System32\dhcpcsvc.dll 12:11:50.0703 0812 Dhcp - ok 12:11:50.0734 0812 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 12:11:50.0734 0812 Disk - ok 12:11:50.0750 0812 dmadmin - ok 12:11:50.0875 0812 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 12:11:50.0906 0812 dmboot - ok 12:11:50.0921 0812 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 12:11:50.0937 0812 dmio - ok 12:11:50.0984 0812 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 12:11:50.0984 0812 dmload - ok 12:11:51.0015 0812 dmserver (1639d9964c9e1b2ecca95c8217d3e70d) C:\WINDOWS\System32\dmserver.dll 12:11:51.0015 0812 dmserver - ok 12:11:51.0078 0812 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 12:11:51.0078 0812 DMusic - ok 12:11:51.0093 0812 Dnscache (7379de06fd196e396a00aa97b990c00d) C:\WINDOWS\System32\dnsrslvr.dll 12:11:51.0093 0812 Dnscache - ok 12:11:51.0109 0812 dpti2o - ok 12:11:51.0125 0812 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 12:11:51.0125 0812 drmkaud - ok 12:11:51.0156 0812 ERSvc (67dff7bbbd0e80aab7b3cf061448db8a) C:\WINDOWS\System32\ersvc.dll 12:11:51.0171 0812 ERSvc - ok 12:11:51.0203 0812 Eventlog (c6ce6eec82f187615d1002bb3bb50ed4) C:\WINDOWS\system32\services.exe 12:11:51.0218 0812 Eventlog - ok 12:11:51.0250 0812 EventSystem (acd36a2dd7d1e9d8a060aa651dc07e63) C:\WINDOWS\system32\es.dll 12:11:51.0265 0812 EventSystem - ok 12:11:51.0375 0812 ExpatShieldService (507942b5bfdbb8efd0e03bde9f72bc86) C:\Program Files\Expat Shield\bin\openvpnas.exe 12:11:51.0406 0812 ExpatShieldService - ok 12:11:51.0453 0812 ExpatSrv (2cfea9c337b699aca38487e8a7438f35) C:\Program Files\Expat Shield\HssWPR\hsssrv.exe 12:11:51.0484 0812 ExpatSrv - ok 12:11:51.0515 0812 ExpatTrayService (1034f1285e474fcbb850afd2dc712837) C:\Program Files\Expat Shield\bin\ExpatTrayService.EXE 12:11:51.0531 0812 ExpatTrayService - ok 12:11:51.0531 0812 ExpatWd - ok 12:11:51.0578 0812 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 12:11:51.0593 0812 Fastfat - ok 12:11:51.0625 0812 FastUserSwitchingCompatibility (e7518dc542d3ebdcb80edd98462c7821) C:\WINDOWS\System32\shsvcs.dll 12:11:51.0640 0812 FastUserSwitchingCompatibility - ok 12:11:51.0656 0812 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 12:11:51.0671 0812 Fdc - ok 12:11:51.0703 0812 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 12:11:51.0703 0812 Fips - ok 12:11:51.0718 0812 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 12:11:51.0718 0812 Flpydisk - ok 12:11:51.0765 0812 FltMgr (54fd90f0038f07920cb9fb6591bde82f) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 12:11:51.0781 0812 FltMgr - ok 12:11:51.0796 0812 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 12:11:51.0796 0812 Fs_Rec - ok 12:11:51.0828 0812 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 12:11:51.0828 0812 Ftdisk - ok 12:11:51.0875 0812 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 12:11:51.0890 0812 GEARAspiWDM - ok 12:11:51.0906 0812 GMSIPCI - ok 12:11:51.0953 0812 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 12:11:51.0953 0812 Gpc - ok 12:11:52.0015 0812 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 12:11:52.0015 0812 HDAudBus - ok 12:11:52.0093 0812 helpsvc (8827911a8c37e40c027cbfc88e69d967) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 12:11:52.0093 0812 helpsvc - ok 12:11:52.0125 0812 HidServ (9376e6893e52b368abc6255bf54f0b28) C:\WINDOWS\System32\hidserv.dll 12:11:52.0156 0812 HidServ - ok 12:11:52.0171 0812 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 12:11:52.0187 0812 HidUsb - ok 12:11:52.0203 0812 hpn - ok 12:11:52.0234 0812 HssDrv (06c9c9de9ab51daa5a83a838c7a58adf) C:\WINDOWS\system32\DRIVERS\HssDrv.sys 12:11:52.0250 0812 HssDrv - ok 12:11:52.0312 0812 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys 12:11:52.0328 0812 HTTP - ok 12:11:52.0343 0812 HTTPFilter (064d8581adf77c25133e7d751d917d83) C:\WINDOWS\System32\w3ssl.dll 12:11:52.0359 0812 HTTPFilter - ok 12:11:52.0375 0812 i2omgmt - ok 12:11:52.0406 0812 i2omp - ok 12:11:52.0453 0812 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 12:11:52.0453 0812 i8042prt - ok 12:11:52.0937 0812 ialm (0f68e2ec713f132ffb19e45415b09679) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 12:11:53.0140 0812 ialm - ok 12:11:53.0453 0812 igfx (d0bf041acf103ba66987db95480a6a0f) C:\WINDOWS\system32\DRIVERS\igdkmd32.sys 12:11:53.0531 0812 igfx - ok 12:11:53.0703 0812 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 12:11:53.0718 0812 Imapi - ok 12:11:53.0750 0812 ImapiService (fa788520bcac0f5d9d5cde5615c0d931) C:\WINDOWS\system32\imapi.exe 12:11:53.0750 0812 ImapiService - ok 12:11:53.0765 0812 ini910u - ok 12:11:54.0187 0812 IntcAzAudAddService (12cd9f66b64b25cbe18f1bb2c6f54832) C:\WINDOWS\system32\drivers\RtkHDAud.sys 12:11:54.0390 0812 IntcAzAudAddService - ok 12:11:54.0437 0812 IntelIde - ok 12:11:54.0468 0812 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 12:11:54.0468 0812 intelppm - ok 12:11:54.0500 0812 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 12:11:54.0500 0812 Ip6Fw - ok 12:11:54.0531 0812 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 12:11:54.0546 0812 IpFilterDriver - ok 12:11:54.0546 0812 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 12:11:54.0562 0812 IpInIp - ok 12:11:54.0593 0812 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 12:11:54.0593 0812 IpNat - ok 12:11:54.0718 0812 iPod Service (e6be7a41a28d8f2db174957454d32448) C:\Program Files\iPod\bin\iPodService.exe 12:11:54.0765 0812 iPod Service - ok 12:11:54.0812 0812 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 12:11:54.0828 0812 IPSec - ok 12:11:54.0859 0812 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 12:11:54.0859 0812 IRENUM - ok 12:11:54.0890 0812 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 12:11:54.0906 0812 isapnp - ok 12:11:54.0953 0812 JavaQuickStarterService (126a16f569122ae00ad3d12ef831d651) C:\Program Files\Java\jre6\bin\jqs.exe 12:11:54.0968 0812 JavaQuickStarterService - ok 12:11:55.0000 0812 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 12:11:55.0015 0812 Kbdclass - ok 12:11:55.0031 0812 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 12:11:55.0031 0812 kbdhid - ok 12:11:55.0078 0812 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 12:11:55.0093 0812 kmixer - ok 12:11:55.0140 0812 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 12:11:55.0140 0812 KSecDD - ok 12:11:55.0171 0812 lanmanserver (93d32468d34e000cb3407947d1d6e22a) C:\WINDOWS\System32\srvsvc.dll 12:11:55.0187 0812 lanmanserver - ok 12:11:55.0218 0812 lanmanworkstation (2c0a7b2ae9c26f2c163627679b42783c) C:\WINDOWS\System32\wkssvc.dll 12:11:55.0234 0812 lanmanworkstation - ok 12:11:55.0250 0812 lbrtfdc - ok 12:11:55.0281 0812 LmHosts (b3eff6d938c572e90a07b3d87a3c7657) C:\WINDOWS\System32\lmhsvc.dll 12:11:55.0296 0812 LmHosts - ok 12:11:55.0328 0812 Messenger (95fd808e4ac22aba025a7b3eac0375d2) C:\WINDOWS\System32\msgsvc.dll 12:11:55.0328 0812 Messenger - ok 12:11:55.0437 0812 Microsoft Office Groove Audit Service (fafe367d032ed82e9332b4c741a20216) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 12:11:55.0437 0812 Microsoft Office Groove Audit Service - ok 12:11:55.0468 0812 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 12:11:55.0468 0812 mnmdd - ok 12:11:55.0515 0812 mnmsrvc (f6415361201915b9fe3896b0e4e724ff) C:\WINDOWS\system32\mnmsrvc.exe 12:11:55.0515 0812 mnmsrvc - ok 12:11:55.0562 0812 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 12:11:55.0578 0812 Modem - ok 12:11:55.0578 0812 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 12:11:55.0593 0812 Mouclass - ok 12:11:55.0609 0812 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 12:11:55.0625 0812 mouhid - ok 12:11:55.0640 0812 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 12:11:55.0640 0812 MountMgr - ok 12:11:55.0687 0812 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 12:11:55.0687 0812 MozillaMaintenance - ok 12:11:55.0703 0812 mraid35x - ok 12:11:55.0734 0812 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 12:11:55.0734 0812 MRxDAV - ok 12:11:55.0812 0812 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 12:11:55.0843 0812 MRxSmb - ok 12:11:55.0875 0812 MSDTC (c7c3d89eb0a6f3dba622ea737fa335b1) C:\WINDOWS\system32\msdtc.exe 12:11:55.0890 0812 MSDTC - ok 12:11:55.0906 0812 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 12:11:55.0906 0812 Msfs - ok 12:11:55.0906 0812 MSIServer - ok 12:11:55.0953 0812 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 12:11:55.0953 0812 MSKSSRV - ok 12:11:55.0968 0812 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 12:11:55.0968 0812 MSPCLOCK - ok 12:11:55.0984 0812 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 12:11:55.0984 0812 MSPQM - ok 12:11:56.0031 0812 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 12:11:56.0031 0812 mssmbios - ok 12:11:56.0062 0812 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 12:11:56.0062 0812 MSTEE - ok 12:11:56.0093 0812 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 12:11:56.0093 0812 Mup - ok 12:11:56.0125 0812 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 12:11:56.0125 0812 NABTSFEC - ok 12:11:56.0171 0812 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 12:11:56.0187 0812 NDIS - ok 12:11:56.0218 0812 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 12:11:56.0218 0812 NdisIP - ok 12:11:56.0250 0812 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12:11:56.0250 0812 NdisTapi - ok 12:11:56.0296 0812 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 12:11:56.0312 0812 Ndisuio - ok 12:11:56.0359 0812 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 12:11:56.0359 0812 NdisWan - ok 12:11:56.0390 0812 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 12:11:56.0406 0812 NDProxy - ok 12:11:56.0421 0812 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 12:11:56.0437 0812 NetBIOS - ok 12:11:56.0484 0812 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 12:11:56.0484 0812 NetBT - ok 12:11:56.0515 0812 NetDDE (05afb5ad06462257bea7495283c86d50) C:\WINDOWS\system32\netdde.exe 12:11:56.0531 0812 NetDDE - ok 12:11:56.0531 0812 NetDDEdsdm (05afb5ad06462257bea7495283c86d50) C:\WINDOWS\system32\netdde.exe 12:11:56.0531 0812 NetDDEdsdm - ok 12:11:56.0562 0812 Netlogon (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe 12:11:56.0562 0812 Netlogon - ok 12:11:56.0609 0812 Netman (dab9e6c7105d2ef49876fe92c524f565) C:\WINDOWS\System32\netman.dll 12:11:56.0625 0812 Netman - ok 12:11:56.0671 0812 Nla (4e74af063c3271fbea20dd940cfd1184) C:\WINDOWS\System32\mswsock.dll 12:11:56.0687 0812 Nla - ok 12:11:56.0703 0812 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 12:11:56.0703 0812 Npfs - ok 12:11:56.0750 0812 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 12:11:56.0781 0812 Ntfs - ok 12:11:56.0781 0812 NtLmSsp (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe 12:11:56.0781 0812 NtLmSsp - ok 12:11:56.0843 0812 NtmsSvc (b62f29c00ac55a761b2e45877d85ea0f) C:\WINDOWS\system32\ntmssvc.dll 12:11:56.0859 0812 NtmsSvc - ok 12:11:56.0890 0812 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 12:11:56.0890 0812 Null - ok 12:11:56.0953 0812 NvtlRmNet (1344d8f661aee2a988d9f001ffb5a9f2) C:\WINDOWS\system32\DRIVERS\nvtlrmnet.sys 12:11:56.0968 0812 NvtlRmNet - ok 12:11:57.0156 0812 NvtlService (d0e679c3a6266ad1f041a90bd3c10843) C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe 12:11:57.0156 0812 NvtlService - ok 12:11:57.0203 0812 NvtlUSBModem (44a5a089c3e826d7bb6d9a10eaf93a42) C:\WINDOWS\system32\DRIVERS\nvtlusbmdm.sys 12:11:57.0218 0812 NvtlUSBModem - ok 12:11:57.0250 0812 NvtlUSBPort (44a5a089c3e826d7bb6d9a10eaf93a42) C:\WINDOWS\system32\DRIVERS\nvtlusbser.sys 12:11:57.0265 0812 NvtlUSBPort - ok 12:11:57.0312 0812 NvtlUSBPort2 (44a5a089c3e826d7bb6d9a10eaf93a42) C:\WINDOWS\system32\DRIVERS\nvtlusbser2.sys 12:11:57.0312 0812 NvtlUSBPort2 - ok 12:11:57.0375 0812 NWADI (c87b011485670e5c10df8d9064c7a14f) C:\WINDOWS\system32\DRIVERS\NWADIenum.sys 12:11:57.0390 0812 NWADI - ok 12:11:57.0406 0812 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 12:11:57.0406 0812 NwlnkFlt - ok 12:11:57.0421 0812 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 12:11:57.0421 0812 NwlnkFwd - ok 12:11:57.0546 0812 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 12:11:57.0578 0812 odserv - ok 12:11:57.0640 0812 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 12:11:57.0656 0812 ose - ok 12:11:57.0703 0812 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\drivers\Parport.sys 12:11:57.0718 0812 Parport - ok 12:11:57.0750 0812 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 12:11:57.0750 0812 PartMgr - ok 12:11:57.0781 0812 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 12:11:57.0781 0812 ParVdm - ok 12:11:57.0828 0812 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\WINDOWS\system32\Drivers\PCASp50.sys 12:11:57.0828 0812 PCASp50 - ok 12:11:57.0859 0812 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 12:11:57.0859 0812 PCI - ok 12:11:57.0875 0812 PCIDump - ok 12:11:57.0890 0812 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 12:11:57.0890 0812 PCIIde - ok 12:11:57.0937 0812 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 12:11:57.0937 0812 Pcmcia - ok 12:11:57.0953 0812 PDCOMP - ok 12:11:57.0968 0812 PDFRAME - ok 12:11:57.0984 0812 PDRELI - ok 12:11:58.0000 0812 PDRFRAME - ok 12:11:58.0015 0812 perc2 - ok 12:11:58.0031 0812 perc2hib - ok 12:11:58.0093 0812 PlugPlay (c6ce6eec82f187615d1002bb3bb50ed4) C:\WINDOWS\system32\services.exe 12:11:58.0109 0812 PlugPlay - ok 12:11:58.0125 0812 PolicyAgent (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe 12:11:58.0125 0812 PolicyAgent - ok 12:11:58.0171 0812 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 12:11:58.0187 0812 PptpMiniport - ok 12:11:58.0203 0812 ProtectedStorage (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe 12:11:58.0203 0812 ProtectedStorage - ok 12:11:58.0218 0812 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 12:11:58.0234 0812 PSched - ok 12:11:58.0265 0812 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 12:11:58.0265 0812 Ptilink - ok 12:11:58.0312 0812 PxHelp20 (b572ed0c3e6165643fa116af20425a54) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys 12:11:58.0312 0812 PxHelp20 - ok 12:11:58.0328 0812 ql1080 - ok 12:11:58.0343 0812 Ql10wnt - ok 12:11:58.0343 0812 ql12160 - ok 12:11:58.0359 0812 ql1240 - ok 12:11:58.0375 0812 ql1280 - ok 12:11:58.0406 0812 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 12:11:58.0406 0812 RasAcd - ok 12:11:58.0437 0812 RasAuto (44db7a9bdd2fb58747d123fbf1d35adb) C:\WINDOWS\System32\rasauto.dll 12:11:58.0453 0812 RasAuto - ok 12:11:58.0468 0812 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 12:11:58.0468 0812 Rasl2tp - ok 12:11:58.0500 0812 RasMan (41a3c11e3517c962c9b44893bcec3b34) C:\WINDOWS\System32\rasmans.dll 12:11:58.0500 0812 RasMan - ok 12:11:58.0515 0812 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 12:11:58.0515 0812 RasPppoe - ok 12:11:58.0531 0812 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 12:11:58.0531 0812 Raspti - ok 12:11:58.0562 0812 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 12:11:58.0578 0812 Rdbss - ok 12:11:58.0578 0812 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 12:11:58.0578 0812 RDPCDD - ok 12:11:58.0625 0812 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 12:11:58.0640 0812 rdpdr - ok 12:11:58.0671 0812 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 12:11:58.0687 0812 RDPWD - ok 12:11:58.0718 0812 RDSessMgr (729798e0933076b8fcfcd9934698f164) C:\WINDOWS\system32\sessmgr.exe 12:11:58.0718 0812 RDSessMgr - ok 12:11:58.0750 0812 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 12:11:58.0765 0812 redbook - ok 12:11:58.0796 0812 RemoteAccess (3046db917e3cfa040632799dd9b14865) C:\WINDOWS\System32\mprdim.dll 12:11:58.0796 0812 RemoteAccess - ok 12:11:58.0843 0812 RemoteRegistry (3151427db7d87107d1c5be58fac53960) C:\WINDOWS\system32\regsvc.dll 12:11:58.0843 0812 RemoteRegistry - ok 12:11:58.0859 0812 RpcLocator (793f04a09b15e7c6c11dbdffaf06c0ab) C:\WINDOWS\system32\locator.exe 12:11:58.0875 0812 RpcLocator - ok 12:11:58.0921 0812 RpcSs (5c83a4408604f737717ab96371201680) C:\WINDOWS\system32\rpcss.dll 12:11:58.0937 0812 RpcSs - ok 12:11:58.0968 0812 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe 12:11:58.0984 0812 RSVP - ok 12:11:59.0015 0812 SamSs (84885f9b82f4d55c6146ebf6065d75d2) C:\WINDOWS\system32\lsass.exe 12:11:59.0015 0812 SamSs - ok 12:11:59.0046 0812 SCardSvr (25d8de134df108e3dbc8d7d23b1aa58e) C:\WINDOWS\System32\SCardSvr.exe 12:11:59.0062 0812 SCardSvr - ok 12:11:59.0125 0812 Schedule (92360854316611f6cc471612213c3d92) C:\WINDOWS\system32\schedsvc.dll 12:11:59.0125 0812 Schedule - ok 12:11:59.0218 0812 SDHookDriver (f182946b2557283a34aa6c0325141e47) C:\Program Files\Spybot - Search & Destroy 2\SDHookDrv32.sys 12:11:59.0218 0812 SDHookDriver - ok 12:11:59.0250 0812 SDHookService (e9850746f7fcf8443bbc94729fee59ce) C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe 12:11:59.0250 0812 SDHookService - ok 12:11:59.0359 0812 SDScannerService (c610da7829f50495df8586ce800bc86d) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe 12:11:59.0406 0812 SDScannerService - ok 12:11:59.0531 0812 SDUpdateService (e915b09a55404837c0c78ed89ef607f5) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe 12:11:59.0593 0812 SDUpdateService - ok 12:11:59.0687 0812 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 12:11:59.0687 0812 Secdrv - ok 12:11:59.0734 0812 seclogon (b1e0ce09895376871746f36dc5773b4f) C:\WINDOWS\System32\seclogon.dll 12:11:59.0734 0812 seclogon - ok 12:11:59.0750 0812 SENS (dfd9870cf39c791d86c4c209da9fa919) C:\WINDOWS\system32\sens.dll 12:11:59.0765 0812 SENS - ok 12:11:59.0812 0812 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys 12:11:59.0812 0812 Serial - ok 12:11:59.0828 0812 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 12:11:59.0828 0812 Sfloppy - ok 12:11:59.0890 0812 SharedAccess (36cc8c01b5e50163037bef56cb96deff) C:\WINDOWS\System32\ipnathlp.dll 12:11:59.0921 0812 SharedAccess - ok 12:11:59.0968 0812 ShellHWDetection (e7518dc542d3ebdcb80edd98462c7821) C:\WINDOWS\System32\shsvcs.dll 12:11:59.0968 0812 ShellHWDetection - ok 12:11:59.0984 0812 Simbad - ok 12:12:00.0125 0812 SkypeUpdate (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files\Skype\Updater\Updater.exe 12:12:00.0125 0812 SkypeUpdate - ok 12:12:00.0187 0812 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 12:12:00.0187 0812 SLIP - ok 12:12:00.0203 0812 Sparrow - ok 12:12:00.0234 0812 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 12:12:00.0234 0812 splitter - ok 12:12:00.0281 0812 Spooler (7435b108b935e42ea92ca94f59c8e717) C:\WINDOWS\system32\spoolsv.exe 12:12:00.0296 0812 Spooler - ok 12:12:00.0343 0812 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 12:12:00.0359 0812 sr - ok 12:12:00.0406 0812 srservice (92bdf74f12d6cbec43c94d4b7f804838) C:\WINDOWS\system32\srsvc.dll 12:12:00.0421 0812 srservice - ok 12:12:00.0453 0812 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys 12:12:00.0468 0812 Srv - ok 12:12:00.0531 0812 SSDPSRV (4b8d61792f7175bed48859cc18ce4e38) C:\WINDOWS\System32\ssdpsrv.dll 12:12:00.0546 0812 SSDPSRV - ok 12:12:00.0609 0812 stisvc (d9f6c4f6b1e188adafc42b561d9bc2e6) C:\WINDOWS\system32\wiaservc.dll 12:12:00.0656 0812 stisvc - ok 12:12:00.0703 0812 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 12:12:00.0703 0812 streamip - ok 12:12:00.0734 0812 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 12:12:00.0750 0812 swenum - ok 12:12:00.0796 0812 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 12:12:00.0796 0812 swmidi - ok 12:12:00.0812 0812 SwPrv - ok 12:12:00.0828 0812 symc810 - ok 12:12:00.0843 0812 symc8xx - ok 12:12:00.0859 0812 sym_hi - ok 12:12:00.0875 0812 sym_u3 - ok 12:12:00.0921 0812 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 12:12:00.0921 0812 sysaudio - ok 12:12:00.0984 0812 SysmonLog (8b54aa346d1b1b113ffaa75501b8b1b2) C:\WINDOWS\system32\smlogsvc.exe 12:12:01.0000 0812 SysmonLog - ok 12:12:01.0031 0812 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\WINDOWS\system32\DRIVERS\taphss.sys 12:12:01.0046 0812 taphss - ok 12:12:01.0093 0812 TapiSrv (eb4a4187d74a8efdcbea3ea2cb1bdfbd) C:\WINDOWS\System32\tapisrv.dll 12:12:01.0109 0812 TapiSrv - ok 12:12:01.0171 0812 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys 12:12:01.0203 0812 Tcpip - ok 12:12:01.0234 0812 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 12:12:01.0234 0812 TDPIPE - ok 12:12:01.0281 0812 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 12:12:01.0281 0812 TDTCP - ok 12:12:01.0328 0812 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 12:12:01.0328 0812 TermDD - ok 12:12:01.0390 0812 TermService (b60c877d16d9c880b952fda04adf16e6) C:\WINDOWS\System32\termsrv.dll 12:12:01.0406 0812 TermService - ok 12:12:01.0468 0812 Themes (e7518dc542d3ebdcb80edd98462c7821) C:\WINDOWS\System32\shsvcs.dll 12:12:01.0468 0812 Themes - ok 12:12:01.0515 0812 TlntSvr (37db0a7d097310e8b4de803fc3119c78) C:\WINDOWS\system32\tlntsvr.exe 12:12:01.0515 0812 TlntSvr - ok 12:12:01.0515 0812 TosIde - ok 12:12:01.0562 0812 TrkWks (6d9ac544b30f96c57f8206566c1fb6a1) C:\WINDOWS\system32\trkwks.dll 12:12:01.0562 0812 TrkWks - ok 12:12:01.0593 0812 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 12:12:01.0609 0812 Udfs - ok 12:12:01.0609 0812 ultra - ok 12:12:01.0640 0812 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 12:12:01.0656 0812 Update - ok 12:12:01.0687 0812 upnphost (0546477bde979e33294fe97f6b3de84a) C:\WINDOWS\System32\upnphost.dll 12:12:01.0687 0812 upnphost - ok 12:12:01.0718 0812 UPS (3f5df65b0758675f95a2d43918a740a3) C:\WINDOWS\System32\ups.exe 12:12:01.0718 0812 UPS - ok 12:12:01.0750 0812 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys 12:12:01.0781 0812 USBAAPL - ok 12:12:01.0796 0812 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 12:12:01.0796 0812 usbccgp - ok 12:12:01.0828 0812 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 12:12:01.0828 0812 usbehci - ok 12:12:01.0859 0812 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 12:12:01.0859 0812 usbhub - ok 12:12:01.0890 0812 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 12:12:01.0890 0812 usbscan - ok 12:12:01.0921 0812 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 12:12:01.0921 0812 usbstor - ok 12:12:01.0953 0812 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 12:12:01.0953 0812 usbuhci - ok 12:12:01.0984 0812 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys 12:12:01.0984 0812 usbvideo - ok 12:12:02.0093 0812 usnsvc (03e7b81702fcc9d9b2b15541a0799750) C:\Program Files\MSN Messenger\usnsvc.dll 12:12:02.0109 0812 usnsvc - ok 12:12:02.0140 0812 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 12:12:02.0156 0812 VgaSave - ok 12:12:02.0156 0812 ViaIde - ok 12:12:02.0203 0812 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 12:12:02.0203 0812 VolSnap - ok 12:12:02.0265 0812 VSS (3ee00364ae0fd8d604f46cbaf512838a) C:\WINDOWS\System32\vssvc.exe 12:12:02.0296 0812 VSS - ok 12:12:02.0343 0812 W32Time (2b281958f5d0cf99ed626e3ef39d5c8d) C:\WINDOWS\system32\w32time.dll 12:12:02.0359 0812 W32Time - ok 12:12:02.0375 0812 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 12:12:02.0390 0812 Wanarp - ok 12:12:02.0390 0812 WDICA - ok 12:12:02.0437 0812 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 12:12:02.0453 0812 wdmaud - ok 12:12:02.0500 0812 WebClient (5d0a442864bfbf3b19dcca4cd29f6e99) C:\WINDOWS\System32\webclnt.dll 12:12:02.0500 0812 WebClient - ok 12:12:02.0593 0812 winmgmt (f399242a80c4066fd155efa4cf96658e) C:\WINDOWS\system32\wbem\WMIsvc.dll 12:12:02.0609 0812 winmgmt - ok 12:12:02.0687 0812 WmdmPmSN (c086483e3dba8c1c0a687ec8d5b3d4c1) C:\WINDOWS\system32\mspmsnsv.dll 12:12:02.0687 0812 WmdmPmSN - ok 12:12:02.0781 0812 Wmi (1aff244ca134956c54474f4e2433e4ce) C:\WINDOWS\System32\advapi32.dll 12:12:02.0843 0812 Wmi - ok 12:12:02.0890 0812 WmiApSrv (ba8cecc3e813e1f7c441b20393d4f86c) C:\WINDOWS\system32\wbem\wmiapsrv.exe 12:12:02.0890 0812 WmiApSrv - ok 12:12:02.0937 0812 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 12:12:02.0937 0812 WS2IFSL - ok 12:12:02.0984 0812 wscsvc (4d59daa66c60858cdf4f67a900f42d4a) C:\WINDOWS\system32\wscsvc.dll 12:12:03.0000 0812 wscsvc - ok 12:12:03.0031 0812 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 12:12:03.0031 0812 WSTCODEC - ok 12:12:03.0093 0812 WZCSVC (5a91e6feab9f901302fa7ff768c0120f) C:\WINDOWS\System32\wzcsvc.dll 12:12:03.0125 0812 WZCSVC - ok 12:12:03.0171 0812 xmlprov (eef46dab68229a14da3d8e73c99e2959) C:\WINDOWS\System32\xmlprov.dll 12:12:03.0187 0812 xmlprov - ok 12:12:03.0359 0812 YahooAUService (dd0042f0c3b606a6a8b92d49afb18ad6) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 12:12:03.0390 0812 YahooAUService - ok 12:12:03.0453 0812 yksvc (b074b1ee465a3292636858323d176402) C:\WINDOWS\System32\yk51x86.dll 12:12:03.0468 0812 yksvc - ok 12:12:03.0515 0812 yukonwxp (7578410b1512fad9c485b134561e8b78) C:\WINDOWS\system32\DRIVERS\yk51x86.sys 12:12:03.0531 0812 yukonwxp - ok 12:12:03.0640 0812 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 12:12:04.0703 0812 \Device\Harddisk0\DR0 - ok 12:12:04.0718 0812 Boot (0x1200) (71e50b1008dbe20a8766d46cb1d983fe) \Device\Harddisk0\DR0\Partition0 12:12:04.0718 0812 \Device\Harddisk0\DR0\Partition0 - ok 12:12:04.0750 0812 Boot (0x1200) (75d9ebb029d616a83587d5f257a47ae7) \Device\Harddisk0\DR0\Partition1 12:12:04.0750 0812 \Device\Harddisk0\DR0\Partition1 - ok 12:12:04.0781 0812 Boot (0x1200) (f1fc82cc1e2d19f12c0276db6715eec9) \Device\Harddisk0\DR0\Partition2 12:12:04.0781 0812 \Device\Harddisk0\DR0\Partition2 - ok 12:12:04.0781 0812 ============================================================ 12:12:04.0781 0812 Scan finished 12:12:04.0781 0812 ============================================================ 12:12:04.0796 2080 Detected object count: 0 12:12:04.0796 2080 Actual detected object count: 0
Hi mowman, heres the OTL log. John

OTL logfile created on: 7/2/2012 12:26:24 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.36 Mb Total Physical Memory | 228.36 Mb Available Physical Memory | 22.51% Memory free
2.39 Gb Paging File | 1.46 Gb Available in Paging File | 61.34% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 58.59 Gb Total Space | 7.43 Gb Free Space | 12.68% Space Free | Partition Type: NTFS
Drive D: | 58.59 Gb Total Space | 58.36 Gb Free Space | 99.59% Space Free | Partition Type: NTFS
Drive E: | 31.85 Gb Total Space | 31.78 Gb Free Space | 99.77% Space Free | Partition Type: NTFS

Computer Name: ADMIN-3C | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Admin\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Expat Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Expat Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Novatel Wireless\MobiLink3\MobiLink3.exe (Novatel Wireless Inc.)
PRC - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Expat Shield\bin\hsswd.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Expat Shield\bin\openvpntray.exe ()
MOD - C:\Program Files\Expat Shield\bin\lang\gui-eng.dll ()
MOD - C:\Program Files\Expat Shield\bin\openvpnas.exe ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlGps.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlFile.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlEnc.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlDiag.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlConn.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlActv.dll ()
MOD - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Expat Shield\bin\hsswd.exe ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Expat Shield\bin\libidn-11.dll ()
MOD - C:\Program Files\Expat Shield\bin\libssl32.dll ()
MOD - C:\Program Files\Expat Shield\bin\libeay32.dll ()
MOD - C:\WINDOWS\system32\btwicons.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtGui4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtCore4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtXmlPatterns4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtNetwork4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtXml4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\Imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\Imageformats\qico4.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (SDHookService) – C:\Program Files\Spybot File not found
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ExpatTrayService) – C:\Program Files\Expat Shield\bin\ExpatTrayService.exe ()
SRV - (ExpatShieldService) – C:\Program Files\Expat Shield\bin\openvpnas.exe ()
SRV - (ExpatSrv) – C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (ExpatWd) – C:\Program Files\Expat Shield\bin\hsswd.exe ()
SRV - (yksvc) – C:\WINDOWS\system32\yk51x86.dll (Marvell)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SDHookDriver) – C:\Program Files\Spybot File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (GMSIPCI) – F:\INSTALL\GMSIPCI.SYS File not found
DRV - (Changer) – File not found
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NvtlRmNet) – C:\WINDOWS\system32\drivers\nvtlrmnet.sys (Novatel Wireless Inc.)
DRV - (NvtlUSBPort2) – C:\WINDOWS\system32\drivers\nvtlusbser2.sys (Novatel Wireless Inc.)
DRV - (NvtlUSBPort) – C:\WINDOWS\system32\drivers\nvtlusbser.sys (Novatel Wireless Inc.)
DRV - (NvtlUSBModem) – C:\WINDOWS\system32\drivers\nvtlusbmdm.sys (Novatel Wireless Inc.)
DRV - (HssDrv) – C:\WINDOWS\system32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.expatshield.com/g/?c=h
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {B8B0DB17-5356-41D9-82A2-9531B67EE0A5}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{57A9124A-87B0-488D-956D-890995E5690F}: "URL" = http://rover.ebay.com/rover/1/710-61977-23…e={searchTerms}
IE - HKCU\..\SearchScopes\{8A3B0DFC-7F07-45BC-802B-95EAC432A9BF}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\..\SearchScopes\{b167b83b-348e-4f8a-a00d-693f28ede787}: "URL" = http://search.expatshield.com/g/results.ph…q={searchTerms}
IE - HKCU\..\SearchScopes\{B8B0DB17-5356-41D9-82A2-9531B67EE0A5}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;fr=chr-yie8
IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://toolbar.inbox.com/search/dispatcher…0757&lng;=en
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb119/?searc…1RujH5&i;=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Expat Shield Private Search"
FF - prefs.js..browser.startup.homepage: "http://www.btsearch.name/"
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource;=2&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{DFD1337D-AA7C-4A6D-9B18-561D4C511F4A}: C:\Documents and Settings\Admin\Local Settings\Application Data\{DFD1337D-AA7C-4A6D-9B18-561D4C511F4A} [2011/08/14 04:56:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/06/12 14:35:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/15 20:02:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/16 03:07:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010/05/22 06:27:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Admin\Application Data\Mozilla\Extensions
[2010/05/22 06:27:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Admin\Application Data\Mozilla\Extensions\[removed]
[2012/06/12 02:45:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\extensions
[2012/05/23 22:01:19 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/05 20:35:35 | 000,000,000 | —D | M] ("Torrent") – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\extensions\[removed]
[2012/02/15 19:00:39 | 000,002,203 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\searchplugins\MyStart Search.xml
[2012/03/21 22:59:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/20 17:52:21 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/03/21 22:59:40 | 000,000,000 | —D | M] (Expat Shield Helper (Please allow this installation)) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/08/07 20:05:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2011/08/07 20:05:56 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/05/16 03:07:46 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/05/16 03:07:39 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/05/16 03:07:39 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/05/16 03:07:39 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/05/16 03:07:39 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/05/16 03:07:39 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/05/16 03:07:39 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Expat Shield Class) - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files\Expat Shield\HssIE\ExpatIE.dll (AnchorFree Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED File not found
O4 - HKCU..\Run: [MobiLink 3] C:\Program Files\Novatel Wireless\MobiLink3\MobiLink3.exe (Novatel Wireless Inc.)
O4 - HKCU..\Run: [Mobilink3] File not found
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - Startup: C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Admin\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Risk/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://yahoouk.oberon-media.com/Gameshell/…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E29B5748-40C5-428F-80AF-294752983CB2}: NameServer = 209.121.225.11 209.91.107.11
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/26 01:58:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{9ae19d03-7c0f-11e1-837e-00245401a172}\Shell - "" = AutoRun
O33 - MountPoints2\{9ae19d03-7c0f-11e1-837e-00245401a172}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{9ae19d03-7c0f-11e1-837e-00245401a172}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ActionSportDrives.html
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/02 12:11:11 | 002,134,616 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Admin\Desktop\TDSSKiller.exe
[2012/07/02 00:08:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
[2012/07/01 23:49:47 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2012/06/24 02:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/06/24 02:20:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/06/24 02:19:59 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/24 02:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/06/24 02:18:00 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/06/16 14:36:45 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/06/12 16:00:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\123abc.exe
[2012/06/12 16:00:03 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/06/12 16:00:03 | 000,000,000 | —D | C] – C:\Program Files\123abc.exe
[2012/06/12 14:35:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2012/06/08 05:25:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\My Documents\OneNote Notebooks
[2012/06/06 01:19:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Desktop\Geogaddi
[2012/06/06 01:00:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\Dropbox
[2012/06/06 00:58:46 | 000,000,000 | —D | C] – C:\Program Files\Dropbox
[2012/06/06 00:58:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Dropbox
[2012/06/06 00:57:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Dropbox
[2012/06/05 22:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\CRE
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/02 12:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2012/07/02 04:44:40 | 100,932,387 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/07/02 04:38:11 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F96075BF-9DAB-4C77-BE0D-8B9AF29A9980}.job
[2012/07/02 00:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2012/07/02 00:08:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
[2012/07/01 23:50:12 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2012/07/01 23:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2012/07/01 22:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2012/07/01 10:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2012/07/01 04:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2012/07/01 03:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2012/07/01 02:30:44 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2012/07/01 02:27:30 | 000,000,294 | —- | M] () – C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2012/07/01 02:27:29 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2012/07/01 02:27:28 | 000,000,310 | -HS- | M] () – C:\WINDOWS\tasks\Lsxs.job
[2012/07/01 02:27:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/01 02:27:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/29 17:54:52 | 002,134,616 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Admin\Desktop\TDSSKiller.exe
[2012/06/29 06:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2012/06/29 05:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2012/06/28 15:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2012/06/28 02:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2012/06/28 01:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2012/06/27 21:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2012/06/27 20:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2012/06/27 19:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2012/06/27 18:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2012/06/27 18:06:05 | 000,116,997 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/06/27 17:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2012/06/26 19:36:02 | 000,033,758 | —- | M] () – C:\Documents and Settings\Admin\Local Settings\Application Data\dt.dat
[2012/06/24 16:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2012/06/24 02:21:47 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/24 00:56:51 | 000,002,137 | —- | M] () – C:\Documents and Settings\Admin\Desktop\iTunes.lnk
[2012/06/16 14:36:48 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/16 14:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2012/06/13 07:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2012/06/13 01:48:21 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2012/06/12 16:00:09 | 000,000,674 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/12 14:35:47 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/06/11 13:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2012/06/09 22:13:14 | 000,060,928 | —- | M] () – C:\Documents and Settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/08 05:25:58 | 000,000,947 | —- | M] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/06/06 11:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2012/06/06 01:00:33 | 000,000,994 | —- | M] () – C:\Documents and Settings\Admin\Desktop\Dropbox.lnk
[2012/06/06 00:59:03 | 000,001,024 | —- | M] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Dropbox.lnk
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/26 19:36:02 | 000,033,758 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\dt.dat
[2012/06/24 02:21:47 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/12 16:00:09 | 000,000,674 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/08 05:25:58 | 000,000,947 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/06/06 01:11:28 | 000,000,719 | —- | C] () – C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2012/06/06 01:00:33 | 000,000,994 | —- | C] () – C:\Documents and Settings\Admin\Desktop\Dropbox.lnk
[2012/06/06 00:59:03 | 000,001,024 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Dropbox.lnk
[2012/01/17 18:43:47 | 000,017,408 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\WebpageIcons.db
[2012/01/04 23:22:01 | 000,014,530 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\365ca37cy33q13173681bwfcor3m531tll1kl15165h
[2012/01/04 23:22:01 | 000,014,530 | -HS- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\365ca37cy33q13173681bwfcor3m531tll1kl15165h
[2011/08/14 04:57:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Fcuro.bin
[2011/08/14 04:56:59 | 000,000,120 | —- | C] () – C:\WINDOWS\Cbenife.dat
[2011/08/07 21:34:59 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2011/08/02 15:20:16 | 000,060,928 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/01 13:51:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/27 15:30:10 | 000,013,492 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\us3c2x41oq335o4iu5d88rk4fkf4t40vst1b
[2011/07/27 15:30:10 | 000,013,492 | -HS- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\us3c2x41oq335o4iu5d88rk4fkf4t40vst1b
[2011/04/20 03:15:21 | 000,000,013 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2011/04/17 22:28:13 | 000,000,037 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2011/04/17 22:28:13 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2010/07/25 13:09:25 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat

========== LOP Check ==========

[2012/03/21 15:33:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\AbiSuite
[2012/02/19 02:51:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\AVG2012
[2012/06/06 01:27:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\calibre
[2010/08/07 11:57:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/08/22 19:20:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\CyberDefender
[2012/07/01 02:30:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\Dropbox
[2011/04/19 23:38:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\Oberon Media
[2010/05/24 07:02:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\Playrix Entertainment
[2011/08/18 16:34:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\PriceGong
[2010/08/08 14:45:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\SpinTop
[2011/08/07 20:08:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\Tior
[2011/08/03 17:17:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Admin\Application Data\WinBatch
[2012/02/15 19:02:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\100
[2012/02/19 03:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/02/19 02:51:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/04/26 22:39:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hssff
[2012/02/15 19:02:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2012/07/02 12:05:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/05/30 20:03:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2011/04/20 01:10:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2011/04/17 22:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2012/02/18 04:16:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/26 12:25:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLAN
[2010/05/25 05:09:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/02 00:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2012/04/13 09:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2012/07/01 10:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2012/06/06 11:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2012/07/02 12:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2012/06/11 13:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2012/06/16 14:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2012/06/28 15:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2012/06/24 16:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2012/06/27 17:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2012/06/27 18:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2012/06/28 01:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2012/06/27 19:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2012/06/27 20:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2012/06/27 21:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2012/07/01 22:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2012/07/01 23:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2012/06/28 02:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2012/07/01 03:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2012/07/01 04:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2012/06/29 05:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2012/06/29 06:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2012/06/13 07:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2012/04/13 08:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2012/07/01 02:30:44 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
[2012/07/01 02:27:28 | 000,000,310 | -HS- | M] () – C:\WINDOWS\Tasks\Lsxs.job
[2012/07/01 02:27:30 | 000,000,294 | —- | M] () – C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
[2012/07/01 02:27:29 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
[2012/07/02 04:38:11 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F96075BF-9DAB-4C77-BE0D-8B9AF29A9980}.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/08/04 16:17:58 | 003,148,200 | -H– | M] (Safer-Networking Ltd.) MD5=1B5F8B17F6E5A65394E6EB761A2D381C – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe
[2004/08/03 19:56:50 | 001,032,192 | -H– | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\explorer.exe
[2004/08/03 19:56:50 | 001,032,192 | -H– | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\123abc.exe\Chameleon\svchost.exe
[2004/08/03 19:56:58 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\system32\dllcache\svchost.exe
[2004/08/03 19:56:58 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/03 19:56:58 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\system32\dllcache\userinit.exe
[2004/08/03 19:56:58 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/03 19:56:58 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/03 19:56:58 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\winlogon.exe
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\123abc.exe\Chameleon\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA7FE636
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2430E4FC
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5095D8B1
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2

< End of report >
Hi, heres the Extra. log. John

OTL Extras logfile created on: 7/2/2012 12:26:24 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.36 Mb Total Physical Memory | 228.36 Mb Available Physical Memory | 22.51% Memory free
2.39 Gb Paging File | 1.46 Gb Available in Paging File | 61.34% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 58.59 Gb Total Space | 7.43 Gb Free Space | 12.68% Space Free | Partition Type: NTFS
Drive D: | 58.59 Gb Total Space | 58.36 Gb Free Space | 99.59% Space Free | Partition Type: NTFS
Drive E: | 31.85 Gb Total Space | 31.78 Gb Free Space | 99.77% Space Free | Partition Type: NTFS

Computer Name: ADMIN-3C | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Disabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 21
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{30C2FCD0-FF7B-4FFA-8DDE-43A22E01A1E7}" = Rhapsody Player Engine
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{6D12EC75-E7D3-4EAD-AB10-E1F3AFF94AA6}" = AVG 2012
"{6DE18AB5-540B-4981-87D5-6CF7E923D983}_is1" = MyCleanPC Registry Cleaner
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A837109-E671-470D-B489-F1EBE471D220}" = Windows Live Messenger
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{355EFB0F-D42B-4E8F-9BC8-42513EC417D9}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support
"{9FAD990A-82BF-44F8-ADF9-0DB7FA48B934}" = MobiLink 3
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy 2
"{B5E88F7C-E626-4ACF-971C-986CD532E839}" = calibre
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C6A09671-93A6-4548-9FAE-3BF21EB9C921}" = AVG 2012
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{E8222F5B-FE5E-43BF-9540-B9FB4C38EB1A}" = Novatel 3G-4G Mobile Broadband Drivers
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F41D14-E0DD-4FB4-AA09-A14225C769BD}" = Atheros WLAN Client
"{F652D238-5F29-42D5-BAF3-0115EF977EC2}" = Windows Live Sign-in Assistant
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AbiWord2" = AbiWord 2.9.2
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2012
"BFlix" = BFlix
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ExpatShield" = Expat Shield 2.24
"Fishdom" = Fishdom
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Marvell Miniport Driver" = Marvell Miniport Driver
"MobiLink 3" = MobiLink 3
"Mozilla Firefox 12.0 (x86 en-GB)" = Mozilla Firefox 12.0 (x86 en-GB)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Total Video Converter 3.12_is1" = Total Video Converter 3.12 080330
"VLC media player" = VLC media player 1.0.3
"Winamp" = Winamp (remove only)
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/28/2012 9:54:49 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30564531

Error - 6/28/2012 10:48:19 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/28/2012 10:48:19 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2282

Error - 6/28/2012 10:48:19 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2282

Error - 6/29/2012 12:37:09 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/29/2012 12:37:09 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2438

Error - 6/29/2012 12:37:09 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2438

Error - 6/29/2012 1:37:50 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/29/2012 1:37:50 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2343

Error - 6/29/2012 1:37:50 AM | Computer Name = ADMIN-3C | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2343

[ System Events ]
Error - 6/11/2012 12:52:21 PM | Computer Name = ADMIN-3C | Source = NvtlRmNet | ID = 4000
Description = USBIF_InitializeUSB failed.

Error - 6/11/2012 1:03:01 PM | Computer Name = ADMIN-3C | Source = NvtlRmNet | ID = 4000
Description = USBIF_InitializeUSB failed.

Error - 6/11/2012 1:17:00 PM | Computer Name = ADMIN-3C | Source = Schedule | ID = 7901
Description = The At19.job command failed to start due to the following error: %%2147942402

Error - 6/11/2012 2:34:02 PM | Computer Name = ADMIN-3C | Source = NvtlRmNet | ID = 4000
Description = USBIF_InitializeUSB failed.

Error - 6/11/2012 3:17:00 PM | Computer Name = ADMIN-3C | Source = Schedule | ID = 7901
Description = The At21.job command failed to start due to the following error: %%2147942402

Error - 6/11/2012 4:50:12 PM | Computer Name = ADMIN-3C | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 10.1.0.165 on the
Network
Card with network address 00265E372987.

Error - 6/11/2012 4:51:00 PM | Computer Name = ADMIN-3C | Source = NvtlRmNet | ID = 4000
Description = USBIF_InitializeUSB failed.

Error - 6/11/2012 5:17:00 PM | Computer Name = ADMIN-3C | Source = Schedule | ID = 7901
Description = The At23.job command failed to start due to the following error: %%2147942402

Error - 6/11/2012 6:17:00 PM | Computer Name = ADMIN-3C | Source = Schedule | ID = 7901
Description = The At24.job command failed to start due to the following error: %%2147942402

Error - 6/11/2012 7:17:00 PM | Computer Name = ADMIN-3C | Source = Schedule | ID = 7901
Description = The At1.job command failed to start due to the following error: %%2147942402


< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    
    IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb119/?searc…1RujH5&i=26
    FF - prefs.js..browser.startup.homepage: "http://www.btsearch.name/"
    [2012/02/15 19:00:39 | 000,002,203 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\searchplugins\MyStart Search.xml
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - HKCU..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED File not found
    O4 - HKCU..\Run: [Mobilink3] File not found
    O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
    @Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA7FE636
    @Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2430E4FC
    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5095D8B1
    @Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )











Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi mowman, heres the OTL log,

OTL logfile created on: 7/2/2012 4:09:12 PM - Run 2
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Documents and Settings\Admin\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.36 Mb Total Physical Memory | 83.27 Mb Available Physical Memory | 8.21% Memory free
2.39 Gb Paging File | 1.29 Gb Available in Paging File | 54.21% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 58.59 Gb Total Space | 7.41 Gb Free Space | 12.64% Space Free | Partition Type: NTFS
Drive D: | 58.59 Gb Total Space | 58.36 Gb Free Space | 99.59% Space Free | Partition Type: NTFS
Drive E: | 31.85 Gb Total Space | 31.78 Gb Free Space | 99.77% Space Free | Partition Type: NTFS

Computer Name: ADMIN-3C | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Admin\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Expat Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Expat Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Novatel Wireless\MobiLink3\MobiLink3.exe (Novatel Wireless Inc.)
PRC - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Expat Shield\bin\hsswd.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Expat Shield\bin\openvpntray.exe ()
MOD - C:\Program Files\Expat Shield\bin\lang\gui-eng.dll ()
MOD - C:\Program Files\Expat Shield\bin\openvpnas.exe ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlGps.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlFile.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlEnc.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlDiag.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlConn.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\NvtlActv.dll ()
MOD - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Expat Shield\bin\hsswd.exe ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Expat Shield\bin\libidn-11.dll ()
MOD - C:\Program Files\Expat Shield\bin\libssl32.dll ()
MOD - C:\Program Files\Expat Shield\bin\libeay32.dll ()
MOD - C:\WINDOWS\system32\btwicons.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtGui4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtCore4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtXmlPatterns4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtNetwork4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\QtXml4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\Imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Novatel Wireless\MobiLink3\Imageformats\qico4.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\qcap.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (SDHookService) – C:\Program Files\Spybot File not found
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ExpatTrayService) – C:\Program Files\Expat Shield\bin\ExpatTrayService.exe ()
SRV - (ExpatShieldService) – C:\Program Files\Expat Shield\bin\openvpnas.exe ()
SRV - (ExpatSrv) – C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (ExpatWd) – C:\Program Files\Expat Shield\bin\hsswd.exe ()
SRV - (yksvc) – C:\WINDOWS\system32\yk51x86.dll (Marvell)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SDHookDriver) – C:\Program Files\Spybot File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (GMSIPCI) – F:\INSTALL\GMSIPCI.SYS File not found
DRV - (Changer) – File not found
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NvtlRmNet) – C:\WINDOWS\system32\drivers\nvtlrmnet.sys (Novatel Wireless Inc.)
DRV - (NvtlUSBPort2) – C:\WINDOWS\system32\drivers\nvtlusbser2.sys (Novatel Wireless Inc.)
DRV - (NvtlUSBPort) – C:\WINDOWS\system32\drivers\nvtlusbser.sys (Novatel Wireless Inc.)
DRV - (NvtlUSBModem) – C:\WINDOWS\system32\drivers\nvtlusbmdm.sys (Novatel Wireless Inc.)
DRV - (HssDrv) – C:\WINDOWS\system32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.expatshield.com/g/?c=h
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {B8B0DB17-5356-41D9-82A2-9531B67EE0A5}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{57A9124A-87B0-488D-956D-890995E5690F}: "URL" = http://rover.ebay.com/rover/1/710-61977-23…e={searchTerms}
IE - HKCU\..\SearchScopes\{8A3B0DFC-7F07-45BC-802B-95EAC432A9BF}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\..\SearchScopes\{b167b83b-348e-4f8a-a00d-693f28ede787}: "URL" = http://search.expatshield.com/g/results.ph…q={searchTerms}
IE - HKCU\..\SearchScopes\{B8B0DB17-5356-41D9-82A2-9531B67EE0A5}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;fr=chr-yie8
IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://toolbar.inbox.com/search/dispatcher…0757&lng;=en
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb119/?searc…1RujH5&i;=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Expat Shield Private Search"
FF - prefs.js..browser.startup.homepage: "http://www.btsearch.name/"
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource;=2&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{DFD1337D-AA7C-4A6D-9B18-561D4C511F4A}: C:\Documents and Settings\Admin\Local Settings\Application Data\{DFD1337D-AA7C-4A6D-9B18-561D4C511F4A} [2011/08/14 04:56:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/06/12 14:35:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/15 20:02:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/16 03:07:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010/05/22 06:27:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Admin\Application Data\Mozilla\Extensions
[2010/05/22 06:27:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Admin\Application Data\Mozilla\Extensions\[removed]
[2012/06/12 02:45:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\extensions
[2012/05/23 22:01:19 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/05 20:35:35 | 000,000,000 | —D | M] ("Torrent") – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\extensions\[removed]
[2012/02/15 19:00:39 | 000,002,203 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\searchplugins\MyStart Search.xml
[2012/03/21 22:59:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/20 17:52:21 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/03/21 22:59:40 | 000,000,000 | —D | M] (Expat Shield Helper (Please allow this installation)) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/08/07 20:05:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2011/08/07 20:05:56 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/05/16 03:07:46 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/05/16 03:07:39 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/05/16 03:07:39 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/05/16 03:07:39 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/05/16 03:07:39 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/05/16 03:07:39 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/05/16 03:07:39 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Expat Shield Class) - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files\Expat Shield\HssIE\ExpatIE.dll (AnchorFree Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED File not found
O4 - HKCU..\Run: [MobiLink 3] C:\Program Files\Novatel Wireless\MobiLink3\MobiLink3.exe (Novatel Wireless Inc.)
O4 - HKCU..\Run: [Mobilink3] File not found
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - Startup: C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Admin\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Risk/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://yahoouk.oberon-media.com/Gameshell/…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E29B5748-40C5-428F-80AF-294752983CB2}: NameServer = 207.219.69.11 216.218.29.11
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/26 01:58:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{9ae19d03-7c0f-11e1-837e-00245401a172}\Shell - "" = AutoRun
O33 - MountPoints2\{9ae19d03-7c0f-11e1-837e-00245401a172}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{9ae19d03-7c0f-11e1-837e-00245401a172}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ActionSportDrives.html
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/02 12:11:11 | 002,134,616 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Admin\Desktop\TDSSKiller.exe
[2012/07/02 00:08:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
[2012/07/01 23:49:47 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2012/06/24 02:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/06/24 02:20:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/06/24 02:19:59 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/24 02:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/06/24 02:18:00 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/06/16 14:36:45 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/06/12 16:00:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\123abc.exe
[2012/06/12 16:00:03 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/06/12 16:00:03 | 000,000,000 | —D | C] – C:\Program Files\123abc.exe
[2012/06/12 14:35:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2012/06/08 05:25:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\My Documents\OneNote Notebooks
[2012/06/06 01:19:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Desktop\Geogaddi
[2012/06/06 01:00:33 | 000,000,000 | R–D | C] – C:\Documents and Settings\Admin\My Documents\Dropbox
[2012/06/06 00:58:46 | 000,000,000 | —D | C] – C:\Program Files\Dropbox
[2012/06/06 00:58:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Start Menu\Programs\Dropbox
[2012/06/06 00:57:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Application Data\Dropbox
[2012/06/05 22:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Admin\Local Settings\Application Data\CRE
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/02 16:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2012/07/02 15:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2012/07/02 13:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2012/07/02 12:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2012/07/02 04:44:40 | 100,932,387 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/07/02 04:38:11 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F96075BF-9DAB-4C77-BE0D-8B9AF29A9980}.job
[2012/07/02 00:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2012/07/02 00:08:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
[2012/07/01 23:50:12 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Admin\Desktop\OTL.exe
[2012/07/01 23:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2012/07/01 22:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2012/07/01 10:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2012/07/01 04:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2012/07/01 03:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2012/07/01 02:30:44 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2012/07/01 02:27:30 | 000,000,294 | —- | M] () – C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2012/07/01 02:27:29 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2012/07/01 02:27:28 | 000,000,310 | -HS- | M] () – C:\WINDOWS\tasks\Lsxs.job
[2012/07/01 02:27:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/01 02:27:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/29 17:54:52 | 002,134,616 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Admin\Desktop\TDSSKiller.exe
[2012/06/29 06:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2012/06/29 05:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2012/06/28 02:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2012/06/28 01:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2012/06/27 21:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2012/06/27 20:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2012/06/27 19:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2012/06/27 18:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2012/06/27 18:06:05 | 000,116,997 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/06/27 17:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2012/06/26 19:36:02 | 000,033,758 | —- | M] () – C:\Documents and Settings\Admin\Local Settings\Application Data\dt.dat
[2012/06/24 02:21:47 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/24 00:56:51 | 000,002,137 | —- | M] () – C:\Documents and Settings\Admin\Desktop\iTunes.lnk
[2012/06/16 14:36:48 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/16 14:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2012/06/13 07:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2012/06/13 01:48:21 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2012/06/12 16:00:09 | 000,000,674 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/12 14:35:47 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/06/09 22:13:14 | 000,060,928 | —- | M] () – C:\Documents and Settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/08 05:25:58 | 000,000,947 | —- | M] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/06/06 11:17:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2012/06/06 01:00:33 | 000,000,994 | —- | M] () – C:\Documents and Settings\Admin\Desktop\Dropbox.lnk
[2012/06/06 00:59:03 | 000,001,024 | —- | M] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Dropbox.lnk
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/26 19:36:02 | 000,033,758 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\dt.dat
[2012/06/24 02:21:47 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/12 16:00:09 | 000,000,674 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/08 05:25:58 | 000,000,947 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/06/06 01:11:28 | 000,000,719 | —- | C] () – C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2012/06/06 01:00:33 | 000,000,994 | —- | C] () – C:\Documents and Settings\Admin\Desktop\Dropbox.lnk
[2012/06/06 00:59:03 | 000,001,024 | —- | C] () – C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Dropbox.lnk
[2012/01/17 18:43:47 | 000,017,408 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\WebpageIcons.db
[2012/01/04 23:22:01 | 000,014,530 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\365ca37cy33q13173681bwfcor3m531tll1kl15165h
[2012/01/04 23:22:01 | 000,014,530 | -HS- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\365ca37cy33q13173681bwfcor3m531tll1kl15165h
[2011/08/14 04:57:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Fcuro.bin
[2011/08/14 04:56:59 | 000,000,120 | —- | C] () – C:\WINDOWS\Cbenife.dat
[2011/08/07 21:34:59 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2011/08/02 15:20:16 | 000,060,928 | —- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/01 13:51:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/27 15:30:10 | 000,013,492 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\us3c2x41oq335o4iu5d88rk4fkf4t40vst1b
[2011/07/27 15:30:10 | 000,013,492 | -HS- | C] () – C:\Documents and Settings\Admin\Local Settings\Application Data\us3c2x41oq335o4iu5d88rk4fkf4t40vst1b
[2011/04/20 03:15:21 | 000,000,013 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2011/04/17 22:28:13 | 000,000,037 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2011/04/17 22:28:13 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2010/07/25 13:09:25 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat

========== Custom Scans ==========

< :Services >

< >

< :Otl >

< >

< IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb119/?searc…1RujH5&i;=26 >

< FF - prefs.js..browser.startup.homepage: "http://www.btsearch.name/" >

< [2012/02/15 19:00:39 | 000,002,203 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\searchplugins\MyStart Search.xml >
Invalid Switch: 15 19:00:39 | 000,002,203 | —- | M] () – C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\searchplugins\MyStart Search.xml

< O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. >

< O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. >

< O4 - HKCU..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED File not found >

< O4 - HKCU..\Run: [Mobilink3] File not found >

< O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found >

< @Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA7FE636 >

< @Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2430E4FC >

< @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5095D8B1 >

< @Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2 >

< >

< >

< :Commands >

< [emptytemp] >

< [Reboot] >

========== Alternate Data Streams ==========

@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA7FE636
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2430E4FC
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5095D8B1
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2

< End of report >
Hi mowman, having trouble with the combofix. It runs and then it says windows cant close the program, then closes and I cant find a log for it. John
You need to redo the OTL fix I gave you,copy paste in the box the script then click Run Fix not run scan.

The combofix log should be located at C:/Combofix.txt
Clicked the correct button this time. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found. Prefs.js: "http://www.btsearch.name/" removed from browser.startup.homepage C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\p7yf7s7u.default\searchplugins\MyStart Search.xml moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BitTorrent deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mobilink3 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:FA7FE636 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:2430E4FC deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:5095D8B1 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2 deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Admin ->Temp folder emptied: 244174600 bytes ->Temporary Internet Files folder emptied: 54743913 bytes ->Java cache emptied: 242319 bytes ->FireFox cache emptied: 50302048 bytes ->Flash cache emptied: 27226 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 3928682 bytes ->Flash cache emptied: 798 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 529729514 bytes ->Java cache emptied: 80060 bytes ->Flash cache emptied: 41586 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2142714 bytes %systemroot%\System32 .tmp files removed: 4109841 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 134916492 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 115090 bytes RecycleBin emptied: 11637575 bytes Total Files Cleaned = 988.00 mb OTL by OldTimer - Version 3.2.53.1 log created on 07022012_185246 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hi mowman, combofix runs and gives me a same windows message, I cant find any text but I do have an empty combofix file, C:\combofix\cmd.3xe. When I open it, it is just a black box with a little script. But I cant do anything with it. John
Forget about combofix for now.



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.







Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/





Also tell me how the computer is running now.
Hi, the mbam log, Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.07.02.04 Windows XP Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.18702 Admin :: ADMIN-3C [administrator] 7/2/2012 8:02:46 PM mbam-log-2012-07-02 (20-02-46).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 194650 Time elapsed: 4 minute(s), 35 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi mowman, just done the eset scan and its come up no threats found. There is no list of threats come up and I cant see a export to text button. John

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI