This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC non responsive, slow, self rebooting.....

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, im back with my troublesome pc. I have been having problems with this pc for many years now, its just getting worse, so before i break my bank and ungrade i though id try to see what its problems are from you guys.
My pc:
  • Is permanantly non reponsive
  • Re-boots itself without prompt
  • Has disabled Malwarebytes
  • Will not get past 34% on an Eset Scan
  • Is mini dumping again which has occured many many times in past
  • I have no sound out putting from external surround speakers
  • Is unable to continue performance without crashing for more than 30 mins
  • shuts down windows and removes desk top icons and start bar etc,so i have to turn off from wall as the towers off button is non responsive
  • has started shutting down when i ask for restart then turned itself on and started loggin off, and proceeded to re start!!!
  • when ever i have tried to download anything it says there is insufficiant access or something
    {*]if i try to access internet which today ive been lucky to get on it says that the item ie chrome or IE can no longer be found and asks if i want to delete the shortcut
This is just a list of things that happened in the last 24 hrs. i have managed to update my graphics driver which seems to have relieved some problems as ive had a lucky spell today where i can visit your site as i have been constantly gettin error 503 i think when trying to access the forums.
Anyway i hope this gives some insight to my troubles and i very much look forward to any help ;)

I could not do a hi jack this log so i have mananged to do an OTL:

OTL Logfile created on: 10/07/2012 18:52:12 - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:Documents and SettingsAccess GrantedMy DocumentsDownloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 407.91 Mb Available Physical Memory | 39.86% Memory free
2.40 Gb Paging File | 1.80 Gb Available in Paging File | 74.91% Paging File free
Paging file location(s): C:pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 149.04 Gb Total Space | 81.07 Gb Free Space | 54.39% Space Free | Partition Type: NTFS

Computer Name: SN048919120306 | User Name: Access Granted | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:Documents and SettingsAccess GrantedMy DocumentsDownloadsOTL (2).exe (OldTimer Tools)
PRC - C:Program FilesSiber SystemsAI RoboFormRoboTaskBarIcon.exe (Siber Systems)
PRC - C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
PRC - C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)
PRC - C:Documents and SettingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exe (Skype Technologies S.A.)
PRC - C:Program FilesTrusteerRapportbinRapportMgmtService.exe (Trusteer Ltd.)
PRC - C:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exe (NVIDIA Corporation)
PRC - C:Program FilesOracleJavaFX 2.1 Runtimebinjqs.exe (Oracle Corporation)
PRC - C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
PRC - C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
PRC - C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleUpdate1.3.21.111GoogleCrashHandler.exe (Google Inc.)
PRC - C:program filesrealrealplayerupdaterealsched.exe (RealNetworks, Inc.)
PRC - C:Program FilesMicrosoft OfficeOffice12Groove [2011/10/25 17:10:18 | 000,000,000 | —D | M]
PRC - C:Program FilesAdobeElements 10 OrganizerPhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:Program FilesDivXDivX UpdateDivXUpdate.exe ()
PRC - C:Program FilesOnline ArmorOAui.exe (Emsi Software GmbH)
PRC - C:Program FilesOnline Armoroasrv.exe (Emsi Software GmbH)
PRC - C:Program FilesOnline ArmorOAhlp.exe (Emsi Software GmbH)
PRC - C:Program FilesOnline ArmorOAcat.exe (Emsi Software GmbH)
PRC - C:Program FilesLexmark 2600 Serieslxdnmon.exe ()
PRC - C:Program FilesLexmark 2600 SerieslxdnMsdMon.exe ()
PRC - C:WINDOWSSystem32slserv.exe (Smart Link)
PRC - C:WINDOWSExplorer.EXE (Microsoft Corporation)
PRC - C:WINDOWSSystem32lxdncoms.exe ( )
PRC - C:Program FilesCommon FilesUlead SystemsAutoDetectormonitor.exe (Ulead Systems, Inc.)
PRC - C:WINDOWSALCWZRD.EXE (RealTek Semicoductor Corp.)


========== Modules (No Company Name) ==========

MOD - C:Program FilesAVAST SoftwareAvastdefs12070900algo.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98System.Windows.Forms.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Drawingd86f2038209a4cf0d0
f5b30f6375c9b2System.Drawing.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Configuration3d5b7368bde0
f65aa15d9f46b498cc89System.Configuration.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Xml3bba1b8b0b5ef0be238b01
1cc7a0575eSystem.Xml.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32Systeme4b5afc4da43b1c576f9322f9f
2e1bfeSystem.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32mscorlibe337c89bc9f81b69d7237aa7
0e935900mscorlib.ni.dll ()
MOD - C:Program FilesDivXDivX UpdateDivXUpdateCheck.dll ()
MOD - C:Program FilesDivXDivX UpdateDivXUpdate.exe ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportlibxml2.dll ()
MOD - C:Program FilesLexmark 2600 Serieslxdnmon.exe ()
MOD - C:Program FilesLexmark 2600 SerieslxdnMsdMon.exe ()
MOD - C:Program FilesLexmark 2600 Seriesapp4r.monitor.core.dll ()
MOD - C:Program FilesLexmark 2600 Seriesapp4r.monitor.common.dll ()
MOD - C:Program FilesLexmark 2600 Seriesapp4r.devmons.mcmdevmon.dll ()
MOD - C:WINDOWSsystem32spoolprtprocsw32x86lxdndrpp.dll ()
MOD - C:Program FilesLexmark 2600 Serieslxdndrs.dll ()
MOD - C:Program FilesLexmark 2600 Serieslxdnscw.dll ()
MOD - C:Program FilesLexmark 2600 Seriesapp4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:Program FilesLexmark 2600 Serieslxdncaps.dll ()
MOD - C:Program FilesLexmark 2600 Serieslxdncnv4.dll ()
MOD - C:Program FilesCommon FilesUlead SystemsAutoDetectorDetMethod.dll ()
MOD - C:WINDOWSsystem32spooldriversw32x863lxdndatr.dll ()
MOD - C:WINDOWSsystem32spooldriversw32x863lxdncats.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MSDTC) – File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:WINDOWSSystem32MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) – C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
SRV - (Skype C2C Service) – C:Documents and SettingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exe (Skype Technologies S.A.)
SRV - (RapportMgmtService) – C:Program FilesTrusteerRapportbinRapportMgmtService.exe (Trusteer Ltd.)
SRV - (nvUpdatusService) – C:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exe (NVIDIA Corporation)
SRV - (JavaQuickStarterService) – C:Program FilesOracleJavaFX 2.1 Runtimebinjqs.exe (Oracle Corporation)
SRV - (MBAMService) – C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:APPSSKYPEUpdaterUpdater.exe (Skype Technologies)
SRV - (AdobeActiveFileMonitor10.0) – C:Program FilesAdobeElements 10 OrganizerPhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (SvcOnlineArmor) – C:Program FilesOnline Armoroasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:Program FilesOnline ArmorOAcat.exe (Emsi Software GmbH)
SRV - (SwitchBoard) – C:Program FilesCommon FilesAdobeSwitchBoardSwitchBoard.exe (Adobe Systems Incorporated)
SRV - (lxdnCATSCustConnectService) – C:WINDOWSSystem32spoolDRIVERSW32X863lxdnserv.exe ()
SRV - (SLService) – C:WINDOWSSystem32slserv.exe (Smart Link)
SRV - (lxdn_device) – C:WINDOWSSystem32lxdncoms.exe ( )
SRV - (AOL ACS) – C:PROGRA~1COMMON~1AOLACSAOLacsd.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SANDRA) – C:Program FilesSiSoftwareSiSoftware Sandra Lite 2011WNt500x86Sandra.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (AFGMp50) – System32DriversAFGMp50.sys File not found
DRV - (aswSP) – C:WINDOWSSystem32driversaswSP.sys (AVAST Software)
DRV - (aswTdi) – C:WINDOWSSystem32driversaswTdi.sys (AVAST Software)
DRV - (aswSnx) – C:WINDOWSSystem32driversaswSnx.sys (AVAST Software)
DRV - (aswMon2) – C:WINDOWSSystem32driversaswmon2.sys (AVAST Software)
DRV - (AswRdr) – C:WINDOWSSystem32driversaswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:WINDOWSSystem32driversaavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:WINDOWSSystem32driversaswFsBlk.sys (AVAST Software)
DRV - (RapportEI) – C:Program FilesTrusteerRapportbinRapportEI.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:Program FilesTrusteerRapportbinRapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:WINDOWSSystem32DriversRapportKELL.sys (Trusteer Ltd.)
DRV - (RapportIaso) – c:documents and settingsall usersapplication datatrusteerrapportstoreextsrapportmsbaselinerapportiaso.sys (Trusteer Ltd.)
DRV - (MBAMProtector) – C:WINDOWSSystem32driversmbam.sys (Malwarebytes Corporation)
DRV - (RapportCerberus_34302) – C:Documents and SettingsAll UsersApplication DataTrusteerRapportstoreextsRapportCerberus34302RapportCerberus32_34302.s
ys ()
DRV - (oahlpXX) – C:WINDOWSSystem32driversoahlp32.sys ()
DRV - (OAnet) – C:WINDOWSSystem32driversOAnet.sys (Emsisoft)
DRV - (OADevice) – C:WINDOWSSystem32driversOADriver.sys ()
DRV - (OAmon) – C:WINDOWSSystem32driversOAmon.sys (Emsisoft)
DRV - (AFGSp50) – C:WINDOWSSystem32DriversAFGSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:WINDOWSSystem32driversRtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SlNtHal) – C:WINDOWSSystem32DRIVERSSlnthal.sys (Smart Link)
DRV - (SlWdmSup) – C:WINDOWSSystem32DRIVERSSlWdmSup.sys (Smart Link)
DRV - (Slntamr) – C:WINDOWSSystem32DRIVERSslntamr.sys (Smart Link)
DRV - (NtMtlFax) – C:WINDOWSSystem32DRIVERSNtMtlFax.sys (Smart Link)
DRV - (Mtlmnt5) – C:WINDOWSSystem32DRIVERSMtlmnt5.sys (Smart Link)
DRV - (RecAgent) – C:WINDOWSSystem32DRIVERSRecAgent.sys (Smart Link)
DRV - (Mtlstrm) – C:WINDOWSSystem32DRIVERSMtlstrm.sys (Smart Link)
DRV - (HdAudAddService) – C:WINDOWSSystem32driversHdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (RTL8023) – C:WINDOWSSystem32DRIVERSRtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (vcsmpdrv) – C:WINDOWSSystem32DRIVERSvcsmpdrv.sys (H+H Software GmbH)
DRV - (wanatw) WAN Miniport (ATW) – C:WINDOWSSystem32DRIVERSwanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.co.uk/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache_TIMESTAMP = F2 2C 29 F7 5E 1A CD 01 [binary data]
IE - HKCU..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - [removed]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32_11_3_300_262.dll ()
FF - [removed]/ShockwavePlayer: C:WINDOWSsystem32AdobeDirectornp32dsw.dll (Adobe Systems, Inc.)
FF - [removed]/iTunes,version=: File not found
FF - [removed]/iTunes,version=1.0: C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()
FF - [removed]/DivX Browser Plugin,version=1.0.0: C:Program FilesDivXDivX Plus Web Playernpdivx32.dll (DivX, LLC)
FF - [removed]/DivX VOD Helper,version=1.0.0: C:Program FilesDivXDivX OVS Helpernpovshelper.dll (DivX, LLC.)
FF - [removed]/npPicasa3,version=3.0.0: C:Program FilesPicasa2npPicasa3.dll (Google, Inc.)
FF - [removed]/DTPlugin,version=10.5.1: C:WINDOWSsystem32npDeployJava1.dll (Oracle Corporation)
FF - [removed]/JavaPlugin,version=10.5.1: C:Program FilesOracleJavaFX 2.1 Runtimebinplugin2npjp2.dll (Oracle Corporation)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.1.10411.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~1MICROS~3Office14NPSPWRAP.DLL File not found
FF - [removed]/WPF,version=3.5: c:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/nppl3260;version=15.0.0.198: c:program filesrealrealplayerNetscape6nppl3260.dll (RealNetworks, Inc.)
FF - [removed]/nprjplug;version=15.0.0.198: c:program filesrealrealplayerNetscape6nprjplug.dll (RealNetworks, Inc.)
FF - [removed]/nprpchromebrowserrecordext;version=15.0.0.198: C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginMozillaPluginsnprpchromebrowserrecorde
xt.dll (RealNetworks, Inc.)
FF - [removed]/nprphtml5videoshim;version=15.0.0.198: C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginMozillaPluginsnprphtml5videoshim.dll (RealNetworks, Inc.)
FF - [removed]/nprpjplug;version=15.0.0.198: c:program filesrealrealplayerNetscape6nprpjplug.dll (RealNetworks, Inc.)
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program FilesAdobeReader 10.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - [removed]/Google Update;version=3: C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/UnityPlayer,version=1.0: C:Documents and SettingsAccess GrantedLocal SettingsApplication DataUnityWebPlayerloadernpUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt [2011/11/26 13:01:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:Program FilesDivXDivX Plus Web PlayerfirefoxDivXHTML5 [2012/01/08 17:53:02 | 000,000,000 | —D | M]
FF - [removed]: C:Program FilesAVAST SoftwareAvastWebRepFF [2012/07/01 21:19:19 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeApplication20.0.1132.47ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeApplication20.0.1132.47pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeApplication20.0.1132.47gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataPepperFlash11.2.31.144pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:WINDOWSsystem32MacromedFlashNPSWF32_11_2_202_235.dll
CHR - plugin: Skype Toolbars (Enabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionslifbcibllhkdhoafpjfnlhfpfgnpldfl5.9.0.9216_0npSkypeChr
omePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:Program FilesAdobeReader 10.0ReaderBrowsernppdf32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:Program FilesMozilla FirefoxpluginsNPOFF12.DLL
CHR - plugin: Microsoft Office 2003 (Enabled) = C:Program FilesMozilla FirefoxpluginsNPOFFICE.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:Program FilesMozilla Firefoxpluginsnppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:Program FilesMozilla Firefoxpluginsnprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginMozillaPluginsnprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program FilesMozilla Firefoxpluginsnpqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:Program FilesMozilla Firefoxpluginsnprjplug.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpdrmv2.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:Program FilesWindows Media Playernpdsplay.dll
CHR - plugin: Google Update (Enabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleUpdate1.3.21.111npGoogleUpdate3.dll
CHR - plugin: Unity Player (Enabled) = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataUnityWebPlayerloadernpUnity3D32.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginMozillaPluginsnprpchromebrowserrecorde
xt.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:Program FilesDivXDivX OVS Helpernpovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:Program FilesDivXDivX Plus Web Playernpdivx32.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:Program FilesOracleJavaFX 2.0 Runtimebinplugin2npjp2.dll
CHR - plugin: Java Deployment Toolkit [removed] (Enabled) = C:WINDOWSsystem32npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:Program FilesiTunesMozilla Pluginsnpitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:WINDOWSsystem32AdobeDirectornp32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:Program FilesMicrosoft Silverlight5.1.10411.0npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll
CHR - Extension: YouTube = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.5_0
CHR - Extension: Google Search = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR - Extension: avast! WebRep = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsicmlaeflemplmjndnaapfdbbnpncnbda7.0.1451_0
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjfmjfhklogoienhpfnppmbcbjfjnkonk1.5_0
CHR - Extension: Skype Click to Call = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionslifbcibllhkdhoafpjfnlhfpfgnpldfl6.0.0.10297_0
CHR - Extension: DivX Plus Web Player HTML5 u003Cvideou003E = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsnneajnkjbffgblleaoojgaacokifdkhm2.1.2.145_0
CHR - Extension: Gmail = C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_0

O1 HOSTS File: ([2012/01/23 22:51:28 | 000,000,027 | —- | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginIErpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:Program FilesDivXDivX Plus Web PlayerieDivXHTML5DivXHTML5.dll (DivX, LLC)
O2 - BHO: (avast! EasyPass Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesOracleJavaFX 2.1 Runtimebinssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:APPSSKYPEToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesOracleJavaFX 2.1 Runtimebinjp2ssv.dll (Oracle Corporation)
O3 - HKLM..Toolbar: (avast! EasyPass Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O3 - HKLM..Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:Program FilesOrbitdownloaderGrabPro.dll ()
O3 - HKCU..ToolbarWebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU..ToolbarWebBrowser: (avast! EasyPass Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O3 - HKCU..ToolbarWebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:Program FilesOrbitdownloaderGrabPro.dll ()
O4 - HKLM..Run: [@OnlineArmor GUI] C:Program FilesOnline ArmorOAui.exe (Emsi Software GmbH)
O4 - HKLM..Run: [AdobeAAMUpdater-1.0] C:Program FilesCommon FilesAdobeOOBEPDAppUWAUpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..Run: [AdobeCS5.5ServiceManager] "C:Program FilesCommon FilesAdobeCS5.5ServiceManagerCS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..Run: [AlcWzrd] C:WINDOWSALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..Run: [APSDaemon] C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe (Apple Inc.)
O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)
O4 - HKLM..Run: [DivXUpdate] C:Program FilesDivXDivX UpdateDivXUpdate.exe ()
O4 - HKLM..Run: [High Definition Audio Property Page Shortcut] C:WINDOWSSystem32Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..Run: [IMJPMIG8.1] C:WINDOWSIMEimjp8_1IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..Run: [lxdnamon] C:Program FilesLexmark 2600 Serieslxdnamon.exe ()
O4 - HKLM..Run: [lxdnmon.exe] C:Program FilesLexmark 2600 Serieslxdnmon.exe ()
O4 - HKLM..Run: [Malwarebytes' Anti-Malware] C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
O4 - HKLM..Run: [NvCplDaemon] C:WINDOWSSystem32NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..Run: [NvMediaCenter] C:WINDOWSSystem32nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..Run: [nwiz] C:Program FilesNVIDIA Corporationnviewnwiz.exe ()
O4 - HKLM..Run: [PHIME2002A] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..Run: [PHIME2002ASync] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..Run: [SwitchBoard] C:Program FilesCommon FilesAdobeSwitchBoardSwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..Run: [TkBellExe] C:program filesrealrealplayerupdaterealsched.exe (RealNetworks, Inc.)
O4 - HKLM..Run: [Ulead AutoDetector v2] C:Program FilesCommon FilesUlead SystemsAutoDetectormonitor.exe (Ulead Systems, Inc.)
O4 - HKCU..Run: [RoboForm] C:Program FilesSiber SystemsAI RoboFormRoboTaskBarIcon.exe (Siber Systems)
O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDrives = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O7 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:WINDOWSSystem32GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:Program FilesSiber SystemsAI RoboFormRoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html ()
O8 - Extra context menu item: Save Forms - C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html ()
O8 - Extra context menu item: Show avast! EasyPass Toolbar - C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O9 - Extra 'Tools' menuitem : Show avast! EasyPass Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll (AVAST Software)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:APPSSKYPEToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:APPSSKYPEToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = [removed] [removed]
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{5A5780F9-9298-4B3F-BBAD-FA85CF37EE1F}: DhcpNameServer = [removed] [removed]
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)
O18 - ProtocolHandlerskype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:APPSSKYPEToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) - C:WINDOWSSystem32userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:Documents and SettingsAccess GrantedLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O24 - Desktop BackupWallPaper: C:Documents and SettingsAccess GrantedLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:Program FilesOnline Armoroaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%System32appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:WINDOWSSystem32ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:WINDOWSsystem32Iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:WINDOWSsystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:WINDOWSSystem32lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:WINDOWSSystem32sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:WINDOWSSystem32tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:WINDOWSSystem32iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:WINDOWSSystem32DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:WINDOWSSystem32ff_vfw.dll ()
Drivers32: vidc.iv31 - C:WINDOWSSystem32Ir32_32.dll ()
Drivers32: vidc.iv32 - C:WINDOWSSystem32Ir32_32.dll ()
Drivers32: vidc.iv41 - C:WINDOWSSystem32ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:WINDOWSSystem32Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:WINDOWSSystem32xvidvfw.dll ()
Drivers32: vidc.yv12 - C:WINDOWSSystem32DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:WINDOWSSystem32Iyvu9_32.dll ()
Drivers32: wave1 - C:WINDOWSSystem32serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/07 15:57:59 | 000,000,000 | RH-D | C] – C:Documents and SettingsAccess GrantedRecent
[2012/07/05 20:38:10 | 000,000,000 | —D | C] – C:Program FilesESET
[2012/07/04 20:37:59 | 000,000,000 | —D | C] – C:Documents and SettingsAccess GrantedDesktopNew Folder (2)
[2012/07/02 13:26:00 | 000,000,000 | —D | C] – C:Documents and SettingsAccess GrantedLocal SettingsApplication DataCRE
[2012/07/02 12:55:31 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersApplication DataLexmark 2600 Series
[2012/07/01 21:24:24 | 000,000,000 | —D | C] – C:Documents and SettingsAccess GrantedApplication DataRoboForm
[2012/07/01 21:22:00 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsavast! EasyPass
[2012/07/01 21:21:59 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersApplication DataRoboForm
[2012/07/01 21:21:09 | 000,000,000 | —D | C] – C:Documents and SettingsAccess GrantedMy DocumentsMy Avast EasyPass Data
[2012/07/01 21:20:18 | 000,000,000 | —D | C] – C:Program FilesSiber Systems
[2012/07/01 21:20:00 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsavast! Free Antivirus
[2012/07/01 21:19:59 | 000,021,256 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswFsBlk.sys
[2012/07/01 21:19:58 | 000,353,688 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswSP.sys
[2012/07/01 21:19:53 | 000,035,928 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswRdr.sys
[2012/07/01 21:19:52 | 000,054,232 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswTdi.sys
[2012/07/01 21:19:51 | 000,721,000 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswSnx.sys
[2012/07/01 21:19:49 | 000,097,352 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswmon2.sys
[2012/07/01 21:19:49 | 000,089,624 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaswmon.sys
[2012/07/01 21:19:48 | 000,025,256 | —- | C] (AVAST Software) – C:WINDOWSSystem32driversaavmker4.sys
[2012/07/01 21:18:46 | 000,041,224 | —- | C] (AVAST Software) – C:WINDOWSavastSS.scr
[2012/07/01 21:18:44 | 000,227,648 | —- | C] (AVAST Software) – C:WINDOWSSystem32aswBoot.exe
[2012/07/01 21:18:17 | 000,000,000 | —D | C] – C:Program FilesAVAST Software
[2012/07/01 21:18:17 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersApplication DataAVAST Software
[2012/06/30 23:21:16 | 000,000,000 | -H-D | C] – C:Documents and SettingsAll UsersApplication DataCanonBJ
[2012/06/30 23:21:09 | 000,198,656 | —- | C] (CANON INC.) – C:WINDOWSSystem32CNMLM83.DLL
[2012/06/30 23:20:51 | 000,000,000 | -H-D | C] – C:WINDOWSSystem32CanonIJ Uninstaller Information
[2012/06/30 23:20:50 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsCanon MP160
[2012/06/30 23:20:45 | 000,106,496 | —- | C] (Canon Inc.) – C:WINDOWSSystem32cnco160.dll
[2012/06/30 23:20:44 | 001,302,528 | —- | C] (CANON INC.) – C:WINDOWSSystem32CNCC160.DLL
[2012/06/30 23:20:44 | 000,135,168 | —- | C] (Canon Inc.) – C:WINDOWSSystem32CNCL160.DLL
[2012/06/30 23:20:44 | 000,069,632 | —- | C] (CANON INC.) – C:WINDOWSSystem32CNCI160.DLL
[2012/06/30 23:20:39 | 000,000,000 | -H-D | C] – C:Program FilesCanonBJ
[2012/06/30 22:20:22 | 000,000,000 | —D | C] – C:Documents and SettingsAccess GrantedApplication DataLexmark Productivity Studio
[2012/06/30 22:15:38 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersLx_cats
[2012/06/30 21:54:00 | 000,087,040 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32wiafbdrv.dll
[2012/06/30 21:54:00 | 000,087,040 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcachewiafbdrv.dll
[2012/06/30 21:52:50 | 000,000,000 | —D | C] – C:Program FilesLexmark Tools for Office
[2012/06/30 21:52:03 | 001,645,320 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32gdiplus.dll
[2012/06/30 21:51:53 | 000,102,400 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdnwupd.dll
[2012/06/30 21:51:53 | 000,012,288 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdnwupd.exe
[2012/06/30 21:51:52 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsLexmark 2600 Series
[2012/06/30 21:51:36 | 000,540,672 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdnutil.dll
[2012/06/30 21:51:34 | 000,200,704 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdninsb.dll
[2012/06/30 21:51:34 | 000,147,456 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdnjswr.dll
[2012/06/30 21:51:33 | 000,176,128 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdnins.dll
[2012/06/30 21:51:33 | 000,106,496 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdninsr.dll
[2012/06/30 21:51:28 | 000,983,121 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32lxdngf.dll
[2012/06/30 21:51:27 | 000,090,112 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdncub.dll
[2012/06/30 21:51:26 | 000,077,824 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdncu.dll
[2012/06/30 21:51:26 | 000,036,864 | —- | C] (Lexmark International, Inc.) – C:WINDOWSSystem32lxdncur.dll
[2012/06/30 21:51:21 | 000,077,906 | —- | C] (Lexmark International) – C:WINDOWSSystem32LXDNcfg.dll
[2012/06/30 21:51:13 | 000,000,000 | —D | C] – C:Program FilesLexmark 2600 Series
[2012/06/24 22:24:21 | 000,000,000 | —D | C] – C:Program FilesOracle
[2012/06/24 22:24:06 | 000,143,872 | —- | C] (Oracle Corporation) – C:WINDOWSsystem32javacpl.cpl
[2012/06/24 22:23:44 | 000,143,872 | —- | C] (Oracle Corporation) – C:WINDOWSSystem32javacpl.cpl
[2012/06/24 22:23:42 | 000,227,720 | —- | C] (Oracle Corporation) – C:WINDOWSSystem32javaws.exe
[2012/06/24 22:23:34 | 000,174,064 | —- | C] (Oracle Corporation) – C:WINDOWSSystem32javaw.exe
[2012/06/24 22:23:34 | 000,174,064 | —- | C] (Oracle Corporation) – C:WINDOWSSystem32java.exe
[2012/06/16 14:29:13 | 000,000,000 | —D | C] – C:Documents and SettingsAccess GrantedMy Documents223
[2012/06/13 11:27:01 | 000,521,728 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcachejsdbgui.dll

========== Files - Modified Within 30 Days ==========

[2012/07/10 19:07:02 | 000,000,962 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-1491025595-1780334667-4173316225-1006Core.job
[2012/07/10 19:07:01 | 000,001,014 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-1491025595-1780334667-4173316225-1006UA.job
[2012/07/10 18:57:16 | 000,000,830 | —- | M] () – C:WINDOWStasksAdobe Flash Player Updater.job
[2012/07/10 18:28:44 | 000,000,332 | -H– | M] () – C:WINDOWStasksavast! Emergency Update.job
[2012/07/10 18:27:38 | 000,002,048 | –S- | M] () – C:WINDOWSbootstat.dat
[2012/07/10 18:27:36 | 1073,270,784 | -HS- | M] () – C:hiberfil.sys
[2012/07/10 12:55:15 | 000,000,284 | —- | M] () – C:WINDOWStasksAppleSoftwareUpdate.job
[2012/07/09 14:18:13 | 001,074,636 | —- | M] () – C:WINDOWSSystem32nvdrsdb0.bin
[2012/07/09 14:18:13 | 000,000,001 | —- | M] () – C:WINDOWSSystem32nvdrssel.bin
[2012/07/09 14:17:26 | 001,074,636 | —- | M] () – C:WINDOWSSystem32nvdrsdb1.bin
[2012/07/09 13:24:52 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:WINDOWSSystem32FlashPlayerApp.exe
[2012/07/09 13:24:50 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:WINDOWSSystem32FlashPlayerCPLApp.cpl
[2012/07/09 02:00:00 | 000,000,360 | —- | M] () – C:WINDOWStasksAdobeAAMUpdater-1.0-SN048919120306-Access Granted.job
[2012/07/07 12:08:48 | 000,001,324 | —- | M] () – C:WINDOWSSystem32d3d9caps.dat
[2012/07/04 20:37:43 | 000,043,604 | —- | M] () – C:Documents and SettingsAccess GrantedDesktoptoilet in the desert.jpg
[2012/07/02 16:49:08 | 000,004,982 | —- | M] () – C:Documents and SettingsAccess GrantedMy Documentscc_20120702_164902.reg
[2012/07/02 13:27:18 | 000,558,133 | —- | M] () – C:WINDOWSSystem32sqlite3.dll
[2012/07/01 21:20:00 | 000,001,692 | —- | M] () – C:Documents and SettingsAll UsersDesktopavast! Free Antivirus.lnk
[2012/07/01 21:19:50 | 000,002,625 | —- | M] () – C:WINDOWSSystem32CONFIG.NT
[2012/07/01 21:13:40 | 089,050,280 | —- | M] () – C:Documents and SettingsAccess GrantedMy Documentsavast_free_antivirus_setup.exe
[2012/07/01 21:08:43 | 000,001,945 | —- | M] () – C:WINDOWSepplauncher.mif
[2012/07/01 20:12:04 | 000,002,354 | —- | M] () – C:Documents and SettingsAccess GrantedDesktopGoogle Chrome.lnk
[2012/07/01 20:12:04 | 000,002,332 | —- | M] () – C:Documents and SettingsAccess GrantedApplication DataMicrosoftInternet ExplorerQuick LaunchGoogle Chrome.lnk
[2012/06/30 21:55:55 | 000,063,975 | —- | M] () – C:WINDOWSSystem32LexFiles.ulf
[2012/06/30 21:52:41 | 000,000,743 | —- | M] () – C:Documents and SettingsAll UsersDesktopLexmark Productivity Studio - 2600 Series.LNK
[2012/06/28 13:52:42 | 000,353,688 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswSP.sys
[2012/06/28 13:52:42 | 000,054,232 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswTdi.sys
[2012/06/28 13:52:37 | 000,721,000 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswSnx.sys
[2012/06/28 13:52:37 | 000,097,352 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswmon2.sys
[2012/06/28 13:52:37 | 000,089,624 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswmon.sys
[2012/06/28 13:52:37 | 000,035,928 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswRdr.sys
[2012/06/28 13:52:36 | 000,025,256 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaavmker4.sys
[2012/06/28 13:52:36 | 000,021,256 | —- | M] (AVAST Software) – C:WINDOWSSystem32driversaswFsBlk.sys
[2012/06/28 13:52:20 | 000,041,224 | —- | M] (AVAST Software) – C:WINDOWSavastSS.scr
[2012/06/28 13:51:49 | 000,227,648 | —- | M] (AVAST Software) – C:WINDOWSSystem32aswBoot.exe
[2012/06/24 22:23:17 | 000,174,064 | —- | M] (Oracle Corporation) – C:WINDOWSSystem32javaw.exe
[2012/06/24 22:23:17 | 000,174,064 | —- | M] (Oracle Corporation) – C:WINDOWSSystem32java.exe
[2012/06/24 22:23:17 | 000,143,872 | —- | M] (Oracle Corporation) – C:WINDOWSsystem32javacpl.cpl
[2012/06/24 11:37:32 | 000,001,158 | —- | M] () – C:WINDOWSSystem32wpa.dbl
[2012/06/14 21:20:02 | 000,013,778 | —- | M] () – C:Documents and SettingsAccess GrantedMy DocumentseBayISAPI.dll.htm
[2012/06/14 18:48:59 | 003,723,376 | —- | M] () – C:WINDOWSSystem32FNTCACHE.DAT
[2012/06/13 12:36:40 | 000,559,054 | —- | M] () – C:WINDOWSSystem32perfh009.dat
[2012/06/13 12:36:40 | 000,118,700 | —- | M] () – C:WINDOWSSystem32perfc009.dat
[2012/06/12 10:10:21 | 000,000,685 | —- | M] () – C:Documents and SettingsAll UsersDesktopCCleaner.lnk

========== Files Created - No Company Name ==========

[2012/07/09 14:14:05 | 000,010,264 | —- | C] () – C:WINDOWSSystem32nvinfo.pb
[2012/07/04 20:37:40 | 000,043,604 | —- | C] () – C:Documents and SettingsAccess GrantedDesktoptoilet in the desert.jpg
[2012/07/04 19:34:51 | 000,035,363 | —- | C] () – C:Documents and SettingsAccess GrantedDesktopCopy of spiderman.jpg
[2012/07/02 16:49:05 | 000,004,982 | —- | C] () – C:Documents and SettingsAccess GrantedMy Documentscc_20120702_164902.reg
[2012/07/02 13:29:59 | 000,558,133 | —- | C] () – C:WINDOWSSystem32sqlite3.dll
[2012/07/01 21:20:00 | 000,001,692 | —- | C] () – C:Documents and SettingsAll UsersDesktopavast! Free Antivirus.lnk
[2012/07/01 21:19:51 | 000,000,332 | -H– | C] () – C:WINDOWStasksavast! Emergency Update.job
[2012/07/01 21:13:25 | 089,050,280 | —- | C] () – C:Documents and SettingsAccess GrantedMy Documentsavast_free_antivirus_setup.exe
[2012/06/30 21:55:06 | 000,040,960 | —- | C] () – C:WINDOWSSystem32lxdnvs.dll
[2012/06/30 21:54:56 | 000,409,600 | —- | C] ( ) – C:WINDOWSSystem32lxdncoin.dll
[2012/06/30 21:54:33 | 000,061,218 | —- | C] () – C:WINDOWSSystem32lxdnprpr.chm
[2012/06/30 21:53:13 | 000,782,336 | —- | C] () – C:WINDOWSSystem32lxdndrs.dll
[2012/06/30 21:53:13 | 000,081,920 | —- | C] () – C:WINDOWSSystem32lxdncaps.dll
[2012/06/30 21:53:12 | 000,069,632 | —- | C] () – C:WINDOWSSystem32lxdncnv4.dll
[2012/06/30 21:52:41 | 000,000,743 | —- | C] () – C:Documents and SettingsAll UsersDesktopLexmark Productivity Studio - 2600 Series.LNK
[2012/06/30 21:51:37 | 000,348,160 | —- | C] () – C:WINDOWSSystem32LXDNinst.dll
[2012/06/30 21:51:36 | 000,843,776 | —- | C] ( ) – C:WINDOWSSystem32lxdnusb1.dll
[2012/06/30 21:51:36 | 000,438,272 | —- | C] ( ) – C:WINDOWSSystem32LXDNhcp.dll
[2012/06/30 21:51:36 | 000,364,544 | —- | C] ( ) – C:WINDOWSSystem32lxdninpa.dll
[2012/06/30 21:51:36 | 000,339,968 | —- | C] ( ) – C:WINDOWSSystem32lxdniesc.dll
[2012/06/30 21:51:35 | 001,101,824 | —- | C] ( ) – C:WINDOWSSystem32lxdnserv.dll
[2012/06/30 21:51:35 | 000,053,248 | —- | C] ( ) – C:WINDOWSSystem32lxdnprox.dll
[2012/06/30 21:51:34 | 000,647,168 | —- | C] ( ) – C:WINDOWSSystem32lxdnpmui.dll
[2012/06/30 21:51:34 | 000,569,344 | —- | C] ( ) – C:WINDOWSSystem32lxdnlmpm.dll
[2012/06/30 21:51:31 | 000,315,392 | —- | C] ( ) – C:WINDOWSSystem32lxdnih.exe
[2012/06/30 21:51:30 | 000,663,552 | —- | C] ( ) – C:WINDOWSSystem32lxdnhbn3.dll
[2012/06/30 21:51:29 | 000,208,896 | —- | C] () – C:WINDOWSSystem32lxdngrd.dll
[2012/06/30 21:51:25 | 000,589,824 | —- | C] ( ) – C:WINDOWSSystem32lxdncoms.exe
[2012/06/30 21:51:24 | 000,376,832 | —- | C] ( ) – C:WINDOWSSystem32lxdncomm.dll
[2012/06/30 21:51:23 | 000,851,968 | —- | C] ( ) – C:WINDOWSSystem32lxdncomc.dll
[2012/06/30 21:51:23 | 000,360,448 | —- | C] ( ) – C:WINDOWSSystem32lxdncfg.exe
[2012/06/30 21:51:21 | 000,063,975 | —- | C] () – C:WINDOWSSystem32LexFiles.ulf
[2012/06/30 21:51:21 | 000,001,633 | —- | C] () – C:WINDOWSSystem32lxdn.loc
[2012/06/14 21:19:59 | 000,013,778 | —- | C] () – C:Documents and SettingsAccess GrantedMy DocumentseBayISAPI.dll.htm
[2012/04/25 16:14:36 | 000,000,030 | —- | C] () – C:WINDOWSIedit_.INI
[2012/03/29 22:17:54 | 000,005,632 | —- | C] () – C:Documents and SettingsAccess GrantedLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/13 13:34:14 | 000,000,552 | —- | C] () – C:WINDOWSSystem32d3d8caps.dat
[2012/03/10 15:58:05 | 000,001,324 | —- | C] () – C:WINDOWSSystem32d3d9caps.dat
[2012/02/16 18:40:26 | 000,003,072 | —- | C] () – C:WINDOWSSystem32iacenc.dll
[2011/10/22 10:45:18 | 000,175,616 | —- | C] () – C:WINDOWSSystem32unrar.dll
[2011/10/22 10:45:16 | 000,000,038 | —- | C] () – C:WINDOWSavisplitter.ini
[2011/10/22 10:45:15 | 000,650,752 | —- | C] () – C:WINDOWSSystem32xvidcore.dll
[2011/10/22 10:45:14 | 000,243,200 | —- | C] () – C:WINDOWSSystem32xvidvfw.dll
[2011/10/22 10:45:13 | 000,074,752 | —- | C] () – C:WINDOWSSystem32ff_vfw.dll
[2011/09/18 15:00:39 | 009,699,328 | —- | C] () – C:Documents and SettingsAccess Grantedntuser.bak
[2011/08/08 11:34:01 | 000,001,456 | —- | C] () – C:Documents and SettingsAccess GrantedLocal SettingsApplication DataAdobe Save for Web 12.0 Prefs
[2011/07/04 23:27:06 | 000,057,864 | -H– | C] () – C:WINDOWSSystem32mlfcache.dat
[2011/06/15 22:18:30 | 001,074,636 | —- | C] () – C:WINDOWSSystem32nvdrsdb1.bin
[2011/06/15 22:18:30 | 001,074,636 | —- | C] () – C:WINDOWSSystem32nvdrsdb0.bin
[2011/06/15 22:18:30 | 000,000,001 | —- | C] () – C:WINDOWSSystem32nvdrssel.bin
[2011/06/15 22:16:07 | 002,807,708 | —- | C] () – C:WINDOWSSystem32nvdata.data
[2011/06/09 11:48:13 | 000,039,048 | —- | C] () – C:WINDOWSSystem32driversoahlp32.sys
[2011/06/09 11:48:12 | 000,205,864 | —- | C] () – C:WINDOWSSystem32driversOADriver.sys
[2011/04/27 20:05:19 | 000,056,832 | —- | C] () – C:WINDOWSSystem32Iyvu9_32.dll
[2011/02/15 22:15:37 | 000,000,158 | —- | C] () – C:Documents and SettingsAccess GrantedApplication Datawklnhst.dat
[2011/01/21 18:41:51 | 000,000,030 | —- | C] () – C:WINDOWSiedit.INI
[2011/01/19 17:36:07 | 000,000,056 | -H– | C] () – C:WINDOWSSystem32ezsidmv.dat
[2011/01/13 15:49:18 | 000,000,061 | —- | C] () – C:WINDOWSsmscfg.ini
[2011/01/13 15:46:06 | 000,003,439 | —- | C] () – C:WINDOWSmozver.dat
[2011/01/13 15:42:25 | 000,000,376 | —- | C] () – C:WINDOWSODBC.INI
[2011/01/13 15:39:24 | 000,000,514 | —- | C] () – C:WINDOWSSystem32SETUPPC.INI
[2011/01/13 15:33:42 | 000,007,584 | —- | C] () – C:WINDOWSHDReg.ini
[2011/01/13 15:32:28 | 000,000,335 | —- | C] () – C:WINDOWSnsreg.dat
[2011/01/13 15:17:47 | 000,040,448 | —- | C] () – C:WINDOWSSystem32ChCfg.exe

========== LOP Check ==========

[2011/11/05 21:31:55 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataAshampoo
[2011/06/20 14:12:18 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataAudacity
[2011/06/03 12:34:54 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataAuslogics
[2011/08/28 18:46:14 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataBoolat Games
[2011/09/06 13:27:45 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataCanon
[2011/07/04 23:26:25 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication Datachc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/04 18:25:22 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication Datacom.adobe.downloadassistant.AdobeDownloadAssistant
[2012/01/08 18:14:05 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataDDMSettings
[2011/10/19 19:38:59 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataElevatedDiagnostics
[2011/08/23 16:09:19 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication Datago
[2011/05/26 19:25:06 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataGrabPro
[2011/03/26 13:43:37 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataLeadertech
[2012/06/30 22:20:22 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataLexmark Productivity Studio
[2011/10/23 22:11:53 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataLibreOffice
[2011/06/20 15:01:06 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataNCH Swift Sound
[2011/01/20 22:04:56 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataOD2
[2011/07/15 10:33:02 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataOnlineArmor
[2011/06/23 12:20:04 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataOpenCandy
[2011/10/23 22:56:23 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataOpenOffice.org
[2012/02/16 18:58:29 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataOracle
[2012/06/24 10:01:42 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataOrbit
[2011/09/16 22:55:51 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataPhotoScape
[2011/05/26 16:39:49 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataProgSense
[2011/09/18 08:54:02 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataQuickScan
[2012/07/01 21:24:24 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataRoboForm
[2011/10/17 22:15:48 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataSpotify
[2011/10/17 20:30:25 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataSystweak
[2011/02/15 22:16:30 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataTemplate
[2011/09/14 21:18:05 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataTP
[2011/06/20 10:18:10 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataTrusteer
[2011/01/19 22:45:33 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataUlead Systems
[2011/05/31 12:33:21 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication DataWinPatrol
[2011/09/14 21:32:13 | 000,000,000 | —D | M] – C:Documents and SettingsAccess GrantedApplication Data{90140011-0061-0409-0000-0000000FF1CE}
[2011/02/18 16:23:09 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAffinegy
[2011/11/05 21:08:28 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Dataashampoo
[2012/07/01 21:18:17 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAVAST Software
[2012/06/30 23:21:16 | 000,000,000 | -H-D | M] – C:Documents and SettingsAll UsersApplication DataCanonBJ
[2011/02/24 18:17:55 | 000,000,000 | -H-D | M] – C:Documents and SettingsAll UsersApplication DataCommon Files
[2011/09/14 21:54:43 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataEasybits GO
[2012/07/02 12:55:31 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataLexmark 2600 Series
[2011/06/09 11:39:33 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataMFAData
[2011/06/20 17:16:10 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNCH Swift Sound
[2011/01/13 15:37:56 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataOD2
[2011/06/09 12:16:56 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataOnlineArmor
[2011/11/01 19:18:28 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Dataregid.1986-12.com.adobe
[2012/07/01 21:21:59 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataRoboForm
[2012/07/02 16:50:06 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataTEMP
[2011/06/20 10:16:48 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataTrusteer
[2011/01/13 15:39:38 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataUlead Systems
[2011/01/13 15:33:12 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataViewpoint
[2011/09/14 21:16:33 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataVirtualized Applications
[2011/04/25 22:49:17 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataVirtualizedApplications
[2011/08/07 22:07:47 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataZylom
[2011/01/30 15:09:20 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/10 18:28:44 | 000,000,332 | -H– | M] () – C:WINDOWSTasksavast! Emergency Update.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%*.* >
[2011/01/13 15:28:50 | 000,000,210 | RHS- | M] () – C:BOOT.BAK
[2011/06/15 21:47:21 | 000,000,281 | -HS- | M] () – C:BOOT.INI
[2004/08/04 15:00:00 | 000,260,272 | RHS- | M] () – C:cmldr
[2011/09/21 09:53:43 | 000,509,099 | —- | M] () – C:DeQuarantine.txt
[2011/01/13 16:07:20 | 000,006,569 | —- | M] () – C:DWNLOG.TXT
[2011/11/02 20:51:55 | 000,011,149 | —- | M] () – C:HCT.Log
[2012/07/10 18:27:36 | 1073,270,784 | -HS- | M] () – C:hiberfil.sys
[2011/01/13 15:31:40 | 000,000,000 | RHS- | M] () – C:IO.SYS
[2011/01/13 15:33:19 | 000,000,886 | -H– | M] () – C:IPH.PH
[2011/09/19 13:39:24 | 000,026,004 | —- | M] () – C:JavaRa.log
[2011/04/27 23:55:48 | 005,748,345 | —- | M] () – C:Lemmings.log
[2011/01/13 16:07:20 | 000,006,569 | —- | M] () – C:MCDLOG.TXT
[2011/01/13 15:31:40 | 000,000,000 | RHS- | M] () – C:MSDOS.SYS
[2004/08/04 15:00:00 | 000,047,564 | —- | M] () – C:NTDETECT.COM
[2011/01/29 20:01:49 | 000,250,048 | —- | M] () – C:NTLDR
[2012/07/10 18:27:34 | 1609,801,728 | -HS- | M] () – C:pagefile.sys
[2012/07/04 21:46:45 | 000,011,614 | —- | M] () – C:profile_43.txt
[2012/06/24 18:39:38 | 000,016,234 | —- | M] () – C:RootRepeal report 06-24-12 (18-39-38).txt
[2011/01/13 16:07:20 | 000,000,000 | —- | M] () – C:UPDFLOP.TAG

< %systemroot%Fonts*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:WINDOWSFontsGlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:WINDOWSFontsGlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:WINDOWSFontsGlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:WINDOWSFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2004/08/10 17:58:22 | 000,000,067 | -HS- | M] () – C:WINDOWSFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2006/09/13 05:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:WINDOWSsystem32spoolprtprocsw32x86CNMPD83.DLL
[2006/09/13 05:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:WINDOWSsystem32spoolprtprocsw32x86CNMPP83.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86filterpipelineprintproc.dll
[2009/08/13 07:02:22 | 000,147,968 | —- | M] () – C:WINDOWSsystem32spoolprtprocsw32x86lxdndrpp.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86printfilterpipelinesvc.exe

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2012/06/28 13:52:20 | 000,041,224 | —- | M] (AVAST Software) – C:WINDOWSavastSS.scr

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >
[2004/08/10 17:46:06 | 000,094,208 | —- | M] () – C:WINDOWSSystem32configdefault.sav
[2004/08/10 17:46:06 | 000,634,880 | —- | M] () – C:WINDOWSSystem32configsoftware.sav
[2004/08/10 17:46:06 | 000,847,872 | —- | M] () – C:WINDOWSSystem32configsystem.sav

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >
[2011/01/29 20:05:59 | 000,000,272 | -HS- | M] () – C:Documents and SettingsAll UsersStart Menudesktop.ini

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2011/01/29 20:18:17 | 000,000,119 | -HS- | M] () – C:Documents and SettingsAccess GrantedApplication DataMicrosoftInternet ExplorerQuick Launchdesktop.ini
[2004/08/10 18:04:54 | 000,000,079 | —- | M] () – C:Documents and SettingsAccess GrantedApplication DataMicrosoftInternet ExplorerQuick LaunchShow Desktop.scf

< %USERPROFILE%Desktop*.exe >
[2012/01/17 11:51:33 | 004,713,472 | —- | M] (AVAST Software) – C:Documents and SettingsAccess GrantedDesktopaswMBR.exe
[2011/09/19 19:43:21 | 016,897,824 | —- | M] (Sun Microsystems, Inc.) – C:Documents and SettingsAccess GrantedDesktopjre-6u27-windows-i586.exe
[2012/01/17 21:05:57 | 000,080,384 | —- | M] () – C:Documents and SettingsAccess GrantedDesktopMBRCheck.exe
[2011/01/19 17:29:52 | 001,029,000 | —- | M] (Skype Technologies S.A.) – C:Documents and SettingsAccess GrantedDesktopSkypeSetup.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2012-06-13 11:39:12

========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:Documents and SettingsAll UsersApplication DataTEMP:5C321E34

< End of report >

OTL Extras logfile created on: 10/07/2012 18:52:13 - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:Documents and SettingsAccess GrantedMy DocumentsDownloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 407.91 Mb Available Physical Memory | 39.86% Memory free
2.40 Gb Paging File | 1.80 Gb Available in Paging File | 74.91% Paging File free
Paging file location(s): C:pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 149.04 Gb Total Space | 81.07 Gb Free Space | 54.39% Space Free | Partition Type: NTFS

Computer Name: SN048919120306 | User Name: Access Granted | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:Documents and SettingsAccess GrantedLocal SettingsApplication DataGoogleChromeApplicationchrome.exe (Google Inc.)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
https [open] – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:PROGRA~1MI1933~1Office12ONENOTE.EXE "%L" [2012/02/21 21:30:39 | 000,000,000 | —D | M]
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewall]

[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallDomainProfile]

[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallStandardProfile]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]
"C:Program FilesVirgin Broadband WirelessWireless Manager.exe" = C:Program FilesVirgin Broadband WirelessWireless Manager.exe:LocalSubNet:Enabled:Wireless Manager – (Affinegy LLC)

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"%ProgramFiles%AOL 9.0aol.exe" = %ProgramFiles%AOL 9.0aol.exe:*:Enabled:AOL
"C:Program FilesVirgin Broadband WirelessWireless Manager.exe" = C:Program FilesVirgin Broadband WirelessWireless Manager.exe:LocalSubNet:Enabled:Wireless Manager – (Affinegy LLC)
"C:Program FilesOrbitdownloaderorbitdm.exe" = C:Program FilesOrbitdownloaderorbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:Program FilesOrbitdownloaderorbitnet.exe" = C:Program FilesOrbitdownloaderorbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:Program FilesMozilla Firefoxfirefox.exe" = C:Program FilesMozilla Firefoxfirefox.exe:*:Enabled:Firefox
"C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe" = C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:WINDOWSsystem32lxdncoms.exe" = C:WINDOWSsystem32lxdncoms.exe:*:Enabled:2600 Series Server – ( )
"C:Program FilesLexmark 2600 Serieslxdnmon.exe" = C:Program FilesLexmark 2600 Serieslxdnmon.exe:*:Enabled:Printer Device Monitor – ()
"C:WINDOWSsystem32spooldriversw32x863lxdnpswx.exe" = C:WINDOWSsystem32spooldriversw32x863lxdnpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:WINDOWSsystem32spooldriversw32x863lxdntime.exe" = C:WINDOWSsystem32spooldriversw32x863lxdntime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:Program FilesLexmark 2600 SeriesDiagnosticsLXDNdiag.exe" = C:Program FilesLexmark 2600 SeriesDiagnosticsLXDNdiag.exe:*:Enabled: – ()
"C:Program FilesLexmark 2600 Serieslxdnlscn.exe" = C:Program FilesLexmark 2600 Serieslxdnlscn.exe:*:Enabled: – ()
"C:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exe" = C:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160" = Canon MP160
"{11D08055-939C-432b-98C3-E072478A0CD7}" = PSE10 STI Installer
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22D3A614-482C-444A-932C-9DA1B8ECDFD2}" = Elements 10 Organizer
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A065EA0-0EEC-4E94-A2A0-40812576C122}" = Ulead PhotoImpact 10 SE
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}" = Macromedia Shockwave Player
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92482FB3-C05B-41C6-89E7-75D985602A6E}" = System Requirements Lab
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.27
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E1845F1C-068C-F8F4-D31D-D3540D47C453}" = Adobe Download Assistant
"{E1CFE7F3-A062-4904-AA05-084E5C27F499}" = Auctonic
"{EE549AF9-8FAA-4584-83B2-ECF1BC9DC1FF}" = Adobe Photoshop Elements 10
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"2B0D8F3C-18AD-4D8E-879A-74A867C5C3CB_is1" = Wireless Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop Elements 10" = Adobe Photoshop Elements 10
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AI RoboForm" = avast! EasyPass
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"DivX Setup" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"ie8" = Windows Internet Explorer 8
"Indeo® software" = Indeo® software
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.8.0 (Full)
"Lexmark 2600 Series" = Lexmark 2600 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OnlineArmor_is1" = Online Armor 5.0
"Orbit_is1" = Orbit Downloader
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"Rapport_msi" = Rapport
"SpywareBlaster_is1" = SpywareBlaster 4.6
"SystemRequirementsLab" = System Requirements Lab
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 05/07/2012 15:31:53 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 05/07/2012 15:33:13 | Computer Name = SN048919120306 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 05/07/2012 17:50:03 | Computer Name = SN048919120306 | Source = JavaQuickStarterService | ID = 1
Description =

Error - 07/07/2012 07:16:40 | Computer Name = SN048919120306 | Source = JavaQuickStarterService | ID = 1
Description =

Error - 07/07/2012 20:52:54 | Computer Name = SN048919120306 | Source = MBAMService | ID = 131073
Description =

Error - 07/07/2012 20:52:54 | Computer Name = SN048919120306 | Source = MBAMService | ID = 131073
Description =

Error - 08/07/2012 06:17:53 | Computer Name = SN048919120306 | Source = JavaQuickStarterService | ID = 1
Description =

Error - 08/07/2012 17:16:05 | Computer Name = SN048919120306 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 08/07/2012 20:45:42 | Computer Name = SN048919120306 | Source = MBAMService | ID = 131073
Description =

Error - 08/07/2012 20:45:42 | Computer Name = SN048919120306 | Source = MBAMService | ID = 131073
Description =

[ OSession Events ]
Error - 02/10/2011 06:21:16 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 6644
seconds with 240 seconds of active time. This session ended with a crash.

Error - 09/10/2011 11:48:29 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 865
seconds with 480 seconds of active time. This session ended with a crash.

Error - 15/11/2011 06:45:39 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1302
seconds with 1140 seconds of active time. This session ended with a crash.

Error - 02/07/2012 10:05:43 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 87885
seconds with 0 seconds of active time. This session ended with a crash.

Error - 05/07/2012 16:09:44 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 31048
seconds with 60 seconds of active time. This session ended with a crash.

Error - 07/07/2012 20:23:46 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 47019
seconds with 60 seconds of active time. This session ended with a crash.

Error - 08/07/2012 20:45:20 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 51818
seconds with 0 seconds of active time. This session ended with a crash.

Error - 09/07/2012 11:41:24 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12516
seconds with 60 seconds of active time. This session ended with a crash.

Error - 10/07/2012 12:01:52 | Computer Name = SN048919120306 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 82920
seconds with 6720 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/07/2012 07:12:52 | Computer Name = SN048919120306 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.3 on
the Network Card with network address 001485778F4D.

Error - 10/07/2012 07:14:12 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.

Error - 10/07/2012 12:01:52 | Computer Name = SN048919120306 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file '83241984.cvr' on the volume 'HarddiskVolume1'. It has
stopped monitoring the volume.

Error - 10/07/2012 12:14:59 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdnCATSCustConnectService
service to connect.

Error - 10/07/2012 12:14:59 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The lxdnCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/07/2012 12:18:49 | Computer Name = SN048919120306 | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3
00000000, parameter4 00000000.

Error - 10/07/2012 13:12:52 | Computer Name = SN048919120306 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000009A'
while processing the file 'NOD4935.tmp' on the volume 'HarddiskVolume1'. It has
stopped monitoring the volume.

Error - 10/07/2012 13:28:25 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdnCATSCustConnectService
service to connect.

Error - 10/07/2012 13:28:25 | Computer Name = SN048919120306 | Source = Service Control Manager | ID = 7000
Description = The lxdnCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/07/2012 13:32:47 | Computer Name = SN048919120306 | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3
00000000, parameter4 00000000.


< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


Because you have indicated that you are losing desktop icons when your system is crashing, I would like you to download and run this tool first:

Please download the most current version of Unhide from here.
Save it to desktop and run it. In your reply let me know if that brings back you icons, files and start menu items. This program will also remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run.


Then I'd like you to do this:
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    
    :Files
    xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
    xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
    xcopy %Temp%\smtmp\3 "%AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar" /H /I /S /Y /C
    xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C
    
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log

There is a type of infection that causes desktop icons to disappear (actually to be hidden). If they are not handled properly before running other tools, it can be a big mess after the fact. If you don't have that particular infection, we aren't going to cause any problems by running these tools and the fix, but it's better to be safe now, than sorry later :)


Then, let's see if we can't get some improvement on the other issues you are having:

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing antying, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi Doris thankyou for your reply sorry i havent got back to you sooner i was having trouble getting online. i couldnt run the unhide program at first as it said there was insufficient permissions, however i ran otl then unhide which ran ok then. I have included the combo fix log:


ComboFix 12-07-14.01 - Access Granted 15/07/2012 16:54:23.9.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.460 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\system32\avgfwdx.dll
c:\windows\system32\sqlite3.dll
c:\windows\UA000091.DLL
.
.
((((((((((((((((((((((((( Files Created from 2012-06-15 to 2012-07-15 )))))))))))))))))))))))))))))))
.
.
2012-07-15 12:33 . 2012-07-15 12:33 ——– d—–w- C:\_OTL
2012-07-14 22:30 . 2012-07-15 12:43 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-07-05 19:38 . 2012-07-05 19:38 ——– d—–w- c:\program files\ESET
2012-07-02 12:26 . 2012-07-02 12:26 ——– d—–w- c:\documents and settings\Access Granted\Local Settings\Application Data\CRE
2012-07-02 11:55 . 2012-07-02 11:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Lexmark 2600 Series
2012-07-01 20:24 . 2012-07-01 20:24 ——– d—–w- c:\documents and settings\Access Granted\Application Data\RoboForm
2012-07-01 20:21 . 2012-07-01 20:21 ——– d—–w- c:\documents and settings\All Users\Application Data\RoboForm
2012-07-01 20:20 . 2012-07-01 20:20 ——– d—–w- c:\program files\Siber Systems
2012-07-01 20:19 . 2012-06-28 12:52 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-01 20:19 . 2012-06-28 12:52 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-01 20:19 . 2012-06-28 12:52 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-01 20:19 . 2012-06-28 12:52 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-01 20:19 . 2012-06-28 12:52 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-01 20:19 . 2012-06-28 12:52 97352 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-01 20:19 . 2012-06-28 12:52 89624 —-a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-01 20:19 . 2012-06-28 12:52 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-01 20:18 . 2012-06-28 12:52 41224 —-a-w- c:\windows\avastSS.scr
2012-07-01 20:18 . 2012-06-28 12:51 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-07-01 20:18 . 2012-07-01 20:18 ——– d—–w- c:\program files\AVAST Software
2012-07-01 20:18 . 2012-07-01 20:18 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-06-30 22:21 . 2012-06-30 22:21 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2012-06-30 22:21 . 2008-04-03 04:00 198656 —-a-w- c:\windows\system32\CNMLM83.DLL
2012-06-30 22:21 . 2006-09-13 04:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP83.DLL
2012-06-30 22:21 . 2006-09-13 04:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD83.DLL
2012-06-30 22:20 . 2012-06-30 22:20 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2012-06-30 22:20 . 2006-06-29 13:29 106496 —-a-w- c:\windows\system32\cnco160.dll
2012-06-30 22:20 . 2008-01-30 10:12 1302528 —-a-w- c:\windows\system32\CNCC160.DLL
2012-06-30 22:20 . 2008-01-30 10:12 69632 —-a-w- c:\windows\system32\CNCI160.DLL
2012-06-30 22:20 . 2006-05-26 09:54 135168 —-a-w- c:\windows\system32\CNCL160.DLL
2012-06-30 22:20 . 2012-06-30 22:20 ——– d–h–w- c:\program files\CanonBJ
2012-06-30 21:20 . 2012-06-30 21:20 ——– d—–w- c:\documents and settings\Access Granted\Application Data\Lexmark Productivity Studio
2012-06-30 21:15 . 2012-07-02 17:55 ——– d—–w- c:\documents and settings\All Users\Lx_cats
2012-06-30 20:55 . 2008-03-31 13:47 40960 —-a-w- c:\windows\system32\lxdnvs.dll
2012-06-30 20:54 . 2009-10-20 11:59 409600 —-a-w- c:\windows\system32\lxdncoin.dll
2012-06-30 20:54 . 2009-08-13 06:02 147968 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdndrpp.dll
2012-06-30 20:54 . 2001-08-17 21:36 87040 —-a-w- c:\windows\system32\wiafbdrv.dll
2012-06-30 20:54 . 2001-08-17 21:36 87040 —-a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2012-06-30 20:53 . 2009-07-23 13:49 782336 —-a-w- c:\windows\system32\lxdndrs.dll
2012-06-30 20:53 . 2009-05-14 07:46 81920 —-a-w- c:\windows\system32\lxdncaps.dll
2012-06-30 20:53 . 2007-10-02 08:51 69632 —-a-w- c:\windows\system32\lxdncnv4.dll
2012-06-30 20:52 . 2012-06-30 20:52 ——– d—–w- c:\program files\Lexmark Tools for Office
2012-06-30 20:52 . 2007-06-27 23:52 1645320 —-a-w- c:\windows\system32\gdiplus.dll
2012-06-24 21:24 . 2012-06-24 21:24 ——– d—–w- c:\program files\Oracle
2012-06-24 21:24 . 2012-06-24 21:23 143872 —-a-w- c:\windows\system32javacpl.cpl
2012-06-24 21:23 . 2012-05-04 18:29 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-06-24 10:35 . 2012-06-24 10:35 ——– d—–w- c:\windows\system32\wbem\Repository
2012-06-19 16:35 . 2012-06-19 16:35 4967624 —-a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 12:57 . 2011-10-31 15:50 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-12 12:57 . 2011-05-18 15:22 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 12:46 . 2011-09-17 15:27 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-13 13:19 . 2004-08-10 16:38 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-08 20:42 . 2012-06-08 20:42 65720 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2012-06-05 15:50 . 2009-08-19 17:07 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-10 16:38 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2004-08-10 16:38 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 14:19 . 2009-08-06 19:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2009-08-06 19:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2004-08-10 16:56 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2004-08-10 16:56 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2004-08-10 16:56 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2009-08-06 19:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2009-08-06 19:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2004-08-10 16:56 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2004-08-10 16:56 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2004-08-10 16:37 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2009-08-06 19:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2004-08-10 16:56 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2004-08-10 16:56 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 14:18 . 2011-01-21 11:23 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 14:18 . 2011-01-21 11:23 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 14:18 . 2011-01-21 11:23 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-10 16:37 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-10 16:38 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 10:18 . 2012-03-13 13:35 4373248 —-a-w- c:\windows\system32\nv4_disp.dll
2012-05-15 10:18 . 2012-02-08 16:39 17543168 —-a-w- c:\windows\system32\nvcompiler.dll
2012-05-15 10:18 . 2011-10-19 18:08 883008 —-a-w- c:\windows\system32\nvgenco32.dll
2012-05-15 10:18 . 2011-10-19 18:08 1000768 —-a-w- c:\windows\system32\nvdispco32.dll
2012-05-15 10:18 . 2011-01-13 15:03 2445120 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-05-15 10:18 . 2011-01-13 15:03 2359808 —-a-w- c:\windows\system32\nvapi.dll
2012-05-15 10:18 . 2011-01-13 15:03 6012928 —-a-w- c:\windows\system32\nvcuda.dll
2012-05-15 10:18 . 2011-01-13 15:03 14014656 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-05-15 10:18 . 2011-01-13 15:03 65536 —-a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:18 . 2011-01-13 15:03 2530624 —-a-w- c:\windows\system32\nvcuvid.dll
2012-05-15 10:18 . 2011-01-13 15:03 18771968 —-a-w- c:\windows\system32\nvoglnt.dll
2012-05-15 09:40 . 2012-03-13 13:38 54272 —-a-w- c:\windows\system32\nvwddi.dll
2012-05-15 09:40 . 2012-03-13 13:39 143680 —-a-w- c:\windows\system32\nvcolor.exe
2012-05-15 09:40 . 2012-03-13 13:39 15504192 —-a-w- c:\windows\system32\nvcpl.dll
2012-05-15 09:40 . 2012-03-13 13:39 164160 —-a-w- c:\windows\system32\nvsvc32.exe
2012-05-15 09:40 . 2012-03-13 13:39 108352 —-a-w- c:\windows\system32\nvmctray.dll
2012-05-11 14:42 . 2004-08-10 16:37 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2004-08-10 16:37 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-10 16:37 385024 ——w- c:\windows\system32\html.iec
2012-05-04 18:29 . 2012-02-08 16:48 772504 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-05-04 18:29 . 2011-05-03 11:57 687504 —-a-w- c:\windows\system32\deployJava1.dll
2012-05-04 13:12 . 2004-08-10 16:38 2192640 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2069120 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2004-08-10 16:54 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-05-02 00:46 . 2012-05-02 00:46 4472832 —-a-w- c:\windows\system32\GPhotos.scr
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-06-28 12:51 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-07-01 96056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2011-06-10 2477544]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-21 2807808]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-11-26 296056]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2007-08-02 95504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2010-02-04 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2010-02-04 16040]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-06-28 4273976]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
c:\documents and settings\Access Granted\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2011-5-31 337264]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 17:06 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2006-03-15 23:07 421888 —-a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 17:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-09-21 09:24 86016 —-a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 14:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Manager]
2007-10-16 17:57 585728 —-a-w- c:\program files\Virgin Broadband Wireless\Wireless Manager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL ACS"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\APPS\\SKYPE\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\Diagnostics\\LXDNdiag.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnlscn.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [08/06/2012 21:42 65720]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [01/07/2012 21:19 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [01/07/2012 21:19 353688]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [09/06/2011 11:48 205864]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [09/06/2011 11:48 39048]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [09/06/2011 11:48 25192]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [09/06/2011 11:48 29464]
R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [18/01/2012 14:50 228208]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [08/06/2012 21:42 71480]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [08/06/2012 21:42 166840]
R1 vcsmpdrv;vcsmpdrv;c:\windows\system32\drivers\vcsmpdrv.sys [13/01/2011 15:42 49024]
R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [14/09/2011 23:06 169624]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [01/07/2012 21:19 21256]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [17/09/2011 16:27 655944]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [14/05/2012 22:24 1262400]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [09/06/2011 11:48 381512]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [08/06/2012 21:42 976728]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [17/09/2011 16:27 22344]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [14/07/2012 23:30 40776]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [30/06/2012 21:54 94208]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [19/06/2012 17:32 3048136]
S2 SkypeUpdate;Skype Updater;c:\apps\SKYPE\Updater\Updater.exe [29/02/2012 09:50 158856]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [09/06/2011 11:48 4326472]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [31/10/2011 16:50 250056]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
S3 RapportIaso;RapportIaso;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys [03/05/2012 23:27 21520]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13:37 517096]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-10-31 12:57]
.
2012-07-09 c:\windows\Tasks\AdobeAAMUpdater-1.0-SN048919120306-Access Granted.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-06-16 16:43]
.
2012-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-07-15 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-01 12:51]
.
2012-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1491025595-1780334667-4173316225-1006Core.job
- c:\documents and settings\Access Granted\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-28 13:08]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1491025595-1780334667-4173316225-1006UA.job
- c:\documents and settings\Access Granted\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-28 13:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
TCP: DhcpNameServer = [removed] [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-15 17:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-15 17:13:35
ComboFix-quarantined-files.txt 2012-07-15 16:13
.
Pre-Run: 86,292,733,952 bytes free
Post-Run: 86,636,224,512 bytes free
.
- - End Of File - - 2F86F1AEA4C7B2B050FE0CAF5B9C8B32
I can see that AVG was at one time installed on your machine, as Combofix has uninstalled some leftover firewall files. These leftover files could have been causing conflicts (especially permissions issues), even though you didn't have the program installed on your machine at this time. If you have not done so yet, please reboot your machine fully and see how the machine is behaving now. Have you noticed any improvements at this point or are you still expreiencing the same problems that you had noted previously?
its still really really sluggish, with non responsive messages asking me if i want to wait for page or kill it, and yet again another "send error report". Although considering what it was like i must say it is more reactive, it installed updates aswell which may have helped, i did reboot before, and it did start without any problems yet previously i couldn't even get on the start page. Do you think it is more of a build up of data rather than any malware etc? do you think the avg data would prevent eset from completing a scan? would it be advisable to try and complete one now to test wether its any better? :)
The remnants of AVG on the machine definitely could have affected previous ESET scans. But before we do that again, lets be sure we get all your Windows Updates. If it has been a very long time since your machine was behaving, there could be many Windows Updates that need to be applied. Some of the slowness could be a result of these downloading in the background. Since they build upon each other, some may not be available until others are installed. Just because some installed, there could be more to be done. You may not even realize they are happening if they are larger ones.

Let's be sure all of these are done before we move on because they could slow down or affect what we are doing. That could also be why your pages are loading slowly since those downloads affect your internet bandwidth. Depending on your internet connection, they "could" possibly be affecting what's going on. I'm not 100% sure they are, but let's eliminate that from the equation and be sure they are not part of what's going on.

It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Please go ahead and check to ensure all the critical ones are installed before we move on. Let me know when they are, and then we will move ahead with the next steps.
Hi Doris, I have had to update you about my pc via my phone. I can not open up a windows page, when I can it goes into a blue screen, I now can not open a window at all, it states its a "bad image", I can not open tsk mgr and my icons have gone off my start menu. The text saying "start" on the bottom panel has gone too. I have a laptop I can download any software you require me to using that
I saw earlier that things were better but obviously have gotten worse. Can you please confirm that you did not make any other changes other than doing critical Windows Updates? Did you apply the optional updates as well or just the critical ones? (This can sometimes cause issues).

Please try the following and tell me if you are able to boot successfully and if your icons are there.


Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account

    Please see if your icons are on the desktop and try browsing the internet. Please be aware you are not protected while you are doing this. Just try for a brief few minutes and let me know if the system behaves normally.
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.
Hi Doris i have no safemode or recovery on my harddrive as it was replaced last year and they didnt put them on. i am back online however after leaving the pc for sometime,i have double checked i have all the microsoft updates which i do. At first i though i had hardware issues but pretty much everything in the pc has been replaced,when i first boot up it works ok hence why i wrote it was working well, but after a short period of time it starts crashing etc, so im stumped to be honest.
Well, I'm not seeing anything in the logs at this point that would lead me to believe you have any malware on the machine, but that doesn't mean there isn't any on there. I'd like to try to get Malwareybytes working again and to get that ESET scan but I'm not sure if we will be able to or not. I'm leaning towards a hardware conflict or a possibly a .dll issue (which can be very pesky to track down), but I'm not quite ready to say that just yet. Let's see if we can get Malwarebytes working first.

If you can, let's see if we can get the current version of Malwarebytes (which you indicated was not working anyway) unintstalled. Then using your other laptop, to download the current version (which was just recently released) and transfer it to the computer in question via USB/flash drive and follow the directions listed below. The quickscan shouldn't take too long and let's hope we can get a report before it decides to act up. Let me know how this goes.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



Also, did you add any new hardware such as a new monitor, scanner or printer (or anything like that) to this computer any time recently? Anything where you might have had to install a new device and/or some software to go along with it?

Is the laptop that you'll be using to download the program on the same internet connection or is it on a different connection? That may also help point us in the right direction. If this computer happens to be the only one on that connection perhaps we have a modem issue and not a computer one. I'm grasping at straws here but they are questions worth asking.
Hi, i managed to use Malwarebytes via usb memory stick as instructed, it ran the scan and was still in progress after some 3hrs and disappeared but It has produced a notepad log however which detects no malicious items. I had installed 2 printers which quite possibly could cause conflicts but i did have problems with pc prior to the installations. I have however tried to remove the canon driver and my Online Armor has detected a Keylogger (DelDrv.exe). I am unable to use the pc again so am contacting you via the laptop (which after eset scan has detected 3 virus', and has Babylon toolbar and media finder infestations. So either way im pretty infected lol. I have a Virgin Media Super Hub with a 60mg connection which both laptop and pc are connected however the laptop has no issues other than the above mentioned which i have since deleted, bar the babylon toolbar which is impenetrable, but i think my problems did start once i received this new modem and it got worse ever since probably since i installed the printer driver.
OK let's give something else a try before we tackle anything else just yet. Being that BOTH your computers had reasonable amounts of issues, I'd like to reset your Virgin Media Super Hub router and see if we can then find any resolution to this. (When we finish with the PC we can make sure your laptop is clean as well but it is too difficult to work on two machines at the same time, and since it is currently working let's deal with it separately). Routers can become infected so I'd like to rule it out as a possible source of the problem.

By the way, that file isn't a keylogger (it's a false positive). It's just part of the Canon software. You don' t need to worry about that.



I would like to have you reset your router. Most routers have a reset pin hole on the back.

1. With the unit on, place an straightend paperclip into the hole on the back on the unit labeled Reset.
2. Hold the paperclip/reset down for 10 seconds and then release it.
3. The unit will reboot on its own.
4. As soon as the lights stop blinking, the unit is ready.
5. You may need to reinstall the router to regain your internet access.

Note: If you changed your password, it will be gone so refer to your user's guide for your router.

If you have not already done so after doing this, please go into your router's settings and change the default password to a stronger one.


Then I'd like you to re-run Combofix on the PC by doing the following:

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal.

Double click ComboFix.exe to run it. It will prompt you that an update is available - please allow it to update.

Follow all prompts. Post the C:\ComboFix.txt when it has completed.

How is the machine behaving now?
hi, when i try to access the internet the page can not load and a warning box appears stating Your preferences can not be read, im beginning to give up with the pc and wondering if doing a total windows recovery and take it back to its original settings would be better, i can back up my photos and have no relevant data other the pictures. i have taken the log of the combo fix by using the usb stick:

ComboFix 12-07-19.02 - Access Granted 19/07/2012 22:05:12.10.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.377 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\isRS-000.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-06-19 to 2012-07-19 )))))))))))))))))))))))))))))))
.
.
2012-07-15 12:33 . 2012-07-15 12:33 ——– d—–w- C:\_OTL
2012-07-05 19:38 . 2012-07-05 19:38 ——– d—–w- c:\program files\ESET
2012-07-02 12:26 . 2012-07-02 12:26 ——– d—–w- c:\documents and settings\Access Granted\Local Settings\Application Data\CRE
2012-07-02 11:55 . 2012-07-02 11:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Lexmark 2600 Series
2012-07-01 20:24 . 2012-07-01 20:24 ——– d—–w- c:\documents and settings\Access Granted\Application Data\RoboForm
2012-07-01 20:21 . 2012-07-01 20:21 ——– d—–w- c:\documents and settings\All Users\Application Data\RoboForm
2012-07-01 20:20 . 2012-07-01 20:20 ——– d—–w- c:\program files\Siber Systems
2012-07-01 20:19 . 2012-06-28 12:52 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-01 20:19 . 2012-06-28 12:52 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-01 20:19 . 2012-06-28 12:52 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-01 20:19 . 2012-06-28 12:52 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-01 20:19 . 2012-06-28 12:52 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-01 20:19 . 2012-06-28 12:52 97352 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-01 20:19 . 2012-06-28 12:52 89624 —-a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-01 20:19 . 2012-06-28 12:52 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-01 20:18 . 2012-06-28 12:52 41224 —-a-w- c:\windows\avastSS.scr
2012-07-01 20:18 . 2012-06-28 12:51 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-07-01 20:18 . 2012-07-01 20:18 ——– d—–w- c:\program files\AVAST Software
2012-07-01 20:18 . 2012-07-01 20:18 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-06-30 22:21 . 2008-04-03 04:00 198656 —-a-w- c:\windows\system32\CNMLM83.DLL
2012-06-30 22:21 . 2006-09-13 04:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP83.DLL
2012-06-30 22:21 . 2006-09-13 04:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD83.DLL
2012-06-30 21:20 . 2012-06-30 21:20 ——– d—–w- c:\documents and settings\Access Granted\Application Data\Lexmark Productivity Studio
2012-06-30 21:15 . 2012-07-02 17:55 ——– d—–w- c:\documents and settings\All Users\Lx_cats
2012-06-30 20:55 . 2008-03-31 13:47 40960 —-a-w- c:\windows\system32\lxdnvs.dll
2012-06-30 20:54 . 2009-10-20 11:59 409600 —-a-w- c:\windows\system32\lxdncoin.dll
2012-06-30 20:54 . 2009-08-13 06:02 147968 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdndrpp.dll
2012-06-30 20:54 . 2001-08-17 21:36 87040 —-a-w- c:\windows\system32\wiafbdrv.dll
2012-06-30 20:54 . 2001-08-17 21:36 87040 —-a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2012-06-30 20:53 . 2009-07-23 13:49 782336 —-a-w- c:\windows\system32\lxdndrs.dll
2012-06-30 20:53 . 2009-05-14 07:46 81920 —-a-w- c:\windows\system32\lxdncaps.dll
2012-06-30 20:53 . 2007-10-02 08:51 69632 —-a-w- c:\windows\system32\lxdncnv4.dll
2012-06-30 20:52 . 2012-06-30 20:52 ——– d—–w- c:\program files\Lexmark Tools for Office
2012-06-30 20:52 . 2007-06-27 23:52 1645320 —-a-w- c:\windows\system32\gdiplus.dll
2012-06-24 21:24 . 2012-06-24 21:24 ——– d—–w- c:\program files\Oracle
2012-06-24 21:24 . 2012-06-24 21:23 143872 —-a-w- c:\windows\system32javacpl.cpl
2012-06-24 21:23 . 2012-05-04 18:29 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-06-24 10:35 . 2012-06-24 10:35 ——– d—–w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 12:57 . 2011-10-31 15:50 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-12 12:57 . 2011-05-18 15:22 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 12:46 . 2011-09-17 15:27 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-13 13:19 . 2004-08-10 16:38 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-08 20:42 . 2012-06-08 20:42 65720 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2012-06-05 15:50 . 2009-08-19 17:07 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-10 16:38 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 16:35 . 2011-01-21 11:23 222448 —-a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32 . 2004-08-10 16:38 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 14:19 . 2009-08-06 19:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2009-08-06 19:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2004-08-10 16:56 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2004-08-10 16:56 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2004-08-10 16:56 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2009-08-06 19:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2009-08-06 19:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2004-08-10 16:56 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2004-08-10 16:56 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2004-08-10 16:37 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2009-08-06 19:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2004-08-10 16:56 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2004-08-10 16:56 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 14:18 . 2011-01-21 11:23 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 14:18 . 2011-01-21 11:23 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-10 16:37 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-10 16:38 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 10:18 . 2012-03-13 13:35 4373248 —-a-w- c:\windows\system32\nv4_disp.dll
2012-05-15 10:18 . 2012-02-08 16:39 17543168 —-a-w- c:\windows\system32\nvcompiler.dll
2012-05-15 10:18 . 2011-10-19 18:08 883008 —-a-w- c:\windows\system32\nvgenco32.dll
2012-05-15 10:18 . 2011-10-19 18:08 1000768 —-a-w- c:\windows\system32\nvdispco32.dll
2012-05-15 10:18 . 2011-01-13 15:03 2445120 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-05-15 10:18 . 2011-01-13 15:03 2359808 —-a-w- c:\windows\system32\nvapi.dll
2012-05-15 10:18 . 2011-01-13 15:03 6012928 —-a-w- c:\windows\system32\nvcuda.dll
2012-05-15 10:18 . 2011-01-13 15:03 14014656 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-05-15 10:18 . 2011-01-13 15:03 65536 —-a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:18 . 2011-01-13 15:03 2530624 —-a-w- c:\windows\system32\nvcuvid.dll
2012-05-15 10:18 . 2011-01-13 15:03 18771968 —-a-w- c:\windows\system32\nvoglnt.dll
2012-05-15 09:40 . 2012-03-13 13:38 54272 —-a-w- c:\windows\system32\nvwddi.dll
2012-05-15 09:40 . 2012-03-13 13:39 143680 —-a-w- c:\windows\system32\nvcolor.exe
2012-05-15 09:40 . 2012-03-13 13:39 15504192 —-a-w- c:\windows\system32\nvcpl.dll
2012-05-15 09:40 . 2012-03-13 13:39 164160 —-a-w- c:\windows\system32\nvsvc32.exe
2012-05-15 09:40 . 2012-03-13 13:39 108352 —-a-w- c:\windows\system32\nvmctray.dll
2012-05-11 14:42 . 2004-08-10 16:37 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2004-08-10 16:37 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-10 16:37 385024 ——w- c:\windows\system32\html.iec
2012-05-04 18:29 . 2012-02-08 16:48 772504 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-05-04 18:29 . 2011-05-03 11:57 687504 —-a-w- c:\windows\system32\deployJava1.dll
2012-05-04 13:12 . 2004-08-10 16:38 2192640 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2069120 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2004-08-10 16:54 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-05-02 00:46 . 2012-05-02 00:46 4472832 —-a-w- c:\windows\system32\GPhotos.scr
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-15_16.09.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-19 15:05 . 2012-07-19 15:05 16384 c:\windows\temp\Perflib_Perfdata_744.dat
+ 2012-07-19 13:55 . 2005-10-20 12:02 163328 c:\windows\ERDNT\AutoBackup\19-07-2012\ERDNT.EXE
+ 2012-07-18 12:45 . 2005-10-20 12:02 163328 c:\windows\ERDNT\AutoBackup\18-07-2012\ERDNT.EXE
+ 2012-07-16 09:54 . 2005-10-20 12:02 163328 c:\windows\ERDNT\AutoBackup\16-07-2012\ERDNT.EXE
+ 2012-07-19 13:55 . 2012-07-19 13:55 1318912 c:\windows\ERDNT\AutoBackup\19-07-2012\Users\00000002\UsrClass.dat
+ 2012-07-18 12:45 . 2012-07-18 12:45 1318912 c:\windows\ERDNT\AutoBackup\18-07-2012\Users\00000002\UsrClass.dat
+ 2012-07-16 09:54 . 2012-07-16 09:54 1318912 c:\windows\ERDNT\AutoBackup\16-07-2012\Users\00000002\UsrClass.dat
+ 2012-07-19 13:55 . 2012-07-19 13:55 13778944 c:\windows\ERDNT\AutoBackup\19-07-2012\Users\00000001\ntuser.dat
+ 2012-07-18 12:45 . 2012-07-18 12:45 13778944 c:\windows\ERDNT\AutoBackup\18-07-2012\Users\00000001\ntuser.dat
+ 2012-07-16 09:54 . 2012-07-16 09:54 13778944 c:\windows\ERDNT\AutoBackup\16-07-2012\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-06-28 12:51 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-07-01 96056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2011-06-10 2477544]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-21 2807808]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-11-26 296056]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2007-08-02 95504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2010-02-04 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2010-02-04 16040]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-06-28 4273976]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
c:\documents and settings\Access Granted\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2011-5-31 337264]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2011-04-06 354720]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 17:06 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2006-03-15 23:07 421888 —-a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 17:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-09-21 09:24 86016 —-a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 14:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Manager]
2007-10-16 17:57 585728 —-a-w- c:\program files\Virgin Broadband Wireless\Wireless Manager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL ACS"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\APPS\\SKYPE\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\Diagnostics\\LXDNdiag.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnlscn.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [08/06/2012 21:42 65720]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [01/07/2012 21:19 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [01/07/2012 21:19 353688]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [09/06/2011 11:48 205864]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [09/06/2011 11:48 39048]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [09/06/2011 11:48 25192]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [09/06/2011 11:48 29464]
R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [18/01/2012 14:50 228208]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [08/06/2012 21:42 71480]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [08/06/2012 21:42 166840]
R1 vcsmpdrv;vcsmpdrv;c:\windows\system32\drivers\vcsmpdrv.sys [13/01/2011 15:42 49024]
R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [14/09/2011 23:06 169624]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [01/07/2012 21:19 21256]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [17/09/2011 16:27 655944]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [14/05/2012 22:24 1262400]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [09/06/2011 11:48 381512]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [08/06/2012 21:42 976728]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [17/09/2011 16:27 22344]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [30/06/2012 21:54 94208]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [19/06/2012 17:32 3048136]
S2 SkypeUpdate;Skype Updater;c:\apps\SKYPE\Updater\Updater.exe [29/02/2012 09:50 158856]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [09/06/2011 11:48 4326472]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [31/10/2011 16:50 250056]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
S3 RapportIaso;RapportIaso;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys [03/05/2012 23:27 21520]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13:37 517096]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - MBAMSwissArmy
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-10-31 12:57]
.
2012-07-16 c:\windows\Tasks\AdobeAAMUpdater-1.0-SN048919120306-Access Granted.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-06-16 16:43]
.
2012-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-07-19 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-01 12:51]
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1491025595-1780334667-4173316225-1006Core.job
- c:\documents and settings\Access Granted\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-28 13:08]
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1491025595-1780334667-4173316225-1006UA.job
- c:\documents and settings\Access Granted\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-28 13:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
TCP: DhcpNameServer = [removed] [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-19 22:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-19 22:28:57
ComboFix-quarantined-files.txt 2012-07-19 21:28
ComboFix2.txt 2012-07-15 16:13
.
Pre-Run: 85,911,048,192 bytes free
Post-Run: 85,923,028,992 bytes free
.
- - End Of File - - D94AAC711D49C9F8F1C38EE3E4A94079
Sometimes, when you have a stubborn infection, if there are no other relevant files on the computer, the best bet is a complete restore. In this case, if you have only pictures, it sounds like that would indeed be the fastest way to fix the problem. I can see from your previous attempts here that you have had issues for quite some time and have put a lot of effort into trying to fix it. It could be that you have a hardware issue as well. A complete restore will certainly tell you if that is the case. I can still see that pesky AVG registry entry on there as well, which should have been removed. A restore will certainly take care of that as well. Since you are amenable to doing it, I would say that would be your best bet. It will probably save you a lot of headaches on this machine.
i think it would definately be the best bet however it would be the last of many restores i have done to this pc. I am also concerned that as i do not have any safemode I may not also have no recovery console as i can not restore to last known good configuration either. i may even invest in simply buying a new laptop as this pc is very old regardless of the hardware that has been replaced, it has been troublesome since i bought it. I would however like to check the laptop i am currently using as it has had a brand new harddrive put in and has avast protection but malware etc is still getting through and this babylon search engine drives us insane. Would i need to open up a new case or can we continue from here? I would also like to thank you for your time as it is much appreciated :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI