Hi, the flash disinfector didnt ask me to do anything, i ran it but nothing happened so i assume it does it behind the scenes? I tried to uninstall yontoo but it said "setup initialization error"
Here are the scans:
logfile created on: 26/07/2012 11:57:51 - Run 1
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Lisa\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
766.42 Mb Total Physical Memory | 315.54 Mb Available Physical Memory | 41.17% Memory free
1.75 Gb Paging File | 0.99 Gb Available in Paging File | 56.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 196.03 Gb Free Space | 84.21% Space Free | Partition Type: NTFS
Computer Name: LISA-PC | User Name: Lisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Lisa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtscript4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtgui4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtnetwork4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtsql4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtdeclarative4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtcore4.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (KSS) – C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\Users\Lisa\AppData\Local\Temp\catchme.sys File not found
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (rtl8192se) – C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9F 0B 64 1E BB 6A CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://search.babylon.com/?q={searchTerms}…000701a04ecee4d
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Lisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Lisa\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Lisa\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
[2012/05/27 22:43:16 | 000,000,000 | —D | M] (No name found) – C:\Users\Lisa\AppData\Roaming\mozilla\Extensions
[2012/05/27 22:21:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Lisa\AppData\Roaming\mozilla\Firefox\extensions
[2012/05/27 22:21:11 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\Lisa\AppData\Roaming\mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
========== Chrome ==========
CHR - homepage:
http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Lisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Lisa\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: Gmail = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/23 13:17:32 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [KSS] C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A38CA1A-8A0F-4B64-A7D2-74F5E09F122E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/26 11:50:05 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2012/07/26 00:32:36 | 000,000,000 | —D | C] – C:\Users\Lisa\Desktop\tdsskiller
[2012/07/25 17:30:02 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/07/25 17:29:55 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Local\temp
[2012/07/25 17:24:42 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/07/24 22:53:32 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/07/23 21:31:50 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
[2012/07/23 21:30:37 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2012/07/23 21:30:37 | 000,000,000 | —D | C] – C:\Program Files\Kaspersky Lab
[2012/07/23 12:47:46 | 004,585,817 | R— | C] (Swearware) – C:\Users\Lisa\Desktop\ComboFix.exe
[2012/07/23 00:24:45 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/07/23 00:24:45 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/07/23 00:24:45 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/07/23 00:23:14 | 000,000,000 | —D | C] – C:\Qoobox
[2012/07/23 00:22:18 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/07/20 00:03:10 | 000,607,260 | R— | C] (Swearware) – C:\Users\Lisa\Desktop\dds1.scr
[2012/07/19 23:54:18 | 000,607,260 | R— | C] (Swearware) – C:\Users\Lisa\Desktop\dds.scr
[2012/07/19 22:16:49 | 000,000,000 | —D | C] – C:\Users\Lisa\Desktop\New folder
[2012/07/12 23:54:49 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/07/12 23:54:47 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/07/12 23:54:46 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/07/12 23:54:46 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/07/12 23:54:44 | 001,800,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/07/12 23:54:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/07/12 23:54:39 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/07/12 23:50:16 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/07/12 23:50:06 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browserchoice.exe
[2012/07/12 17:20:31 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2012/07/12 17:20:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2012/07/12 17:20:00 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
========== Files - Modified Within 30 Days ==========
[2012/07/26 11:50:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2012/07/26 11:49:08 | 000,132,597 | —- | M] () – C:\Users\Lisa\Desktop\Flash_Disinfector.exe
[2012/07/26 11:44:19 | 000,021,504 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 11:44:19 | 000,021,504 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 11:41:46 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/07/26 11:41:46 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/07/26 11:36:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/26 11:36:05 | 602,738,688 | -HS- | M] () – C:\hiberfil.sys
[2012/07/26 00:19:02 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
[2012/07/26 00:14:59 | 002,117,108 | —- | M] () – C:\Users\Lisa\Desktop\tdsskiller.zip
[2012/07/25 23:26:08 | 000,000,922 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
[2012/07/25 20:19:03 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
[2012/07/25 17:25:16 | 000,000,900 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
[2012/07/25 17:13:43 | 004,585,817 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\ComboFix.exe
[2012/07/25 11:02:18 | 118,992,102 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/07/24 20:17:59 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/23 21:31:19 | 000,001,047 | —- | M] () – C:\Users\Lisa\Desktop\Kaspersky Security Scan.lnk
[2012/07/23 13:17:32 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/07/19 23:57:43 | 000,607,260 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\dds1.scr
[2012/07/19 23:48:01 | 000,607,260 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\dds.scr
[2012/07/13 22:00:27 | 000,409,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/07/12 17:26:16 | 000,002,354 | —- | M] () – C:\Users\Lisa\Desktop\Google Chrome.lnk
[2012/07/10 00:30:49 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/07/03 17:21:54 | 000,054,232 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012/07/03 17:21:53 | 000,721,000 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012/07/03 17:21:53 | 000,353,688 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012/07/03 17:21:53 | 000,057,656 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012/07/03 17:21:53 | 000,044,784 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr2.sys
[2012/07/03 17:21:53 | 000,021,256 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2012/07/03 17:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/07/03 17:21:28 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2012/07/26 11:49:07 | 000,132,597 | —- | C] () – C:\Users\Lisa\Desktop\Flash_Disinfector.exe
[2012/07/26 00:14:57 | 002,117,108 | —- | C] () – C:\Users\Lisa\Desktop\tdsskiller.zip
[2012/07/24 20:17:59 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/23 21:31:50 | 000,001,047 | —- | C] () – C:\Users\Lisa\Desktop\Kaspersky Security Scan.lnk
[2012/07/23 00:24:45 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/07/23 00:24:45 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/07/23 00:24:45 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/07/23 00:24:45 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/07/23 00:24:45 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/01/30 11:51:22 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2012/01/30 01:52:01 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/20 22:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
========== LOP Check ==========
[2012/05/27 22:32:26 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Babylon
[2012/01/30 13:21:23 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\DAEMON Tools Lite
[2012/06/04 12:31:53 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Media Finder
[2012/03/11 01:42:36 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Oberon Media
[2012/06/03 19:17:54 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\uTorrent
[2012/01/30 11:51:03 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\WinBatch
[2012/07/25 17:25:16 | 000,000,900 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
[2012/07/25 23:26:08 | 000,000,922 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
[2012/05/20 13:25:39 | 000,032,638 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2012/07/25 17:29:52 | 000,010,993 | —- | M] () – C:\ComboFix.txt
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/07/26 11:36:05 | 602,738,688 | -HS- | M] () – C:\hiberfil.sys
[2012/07/26 11:36:06 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2012/07/26 00:35:33 | 000,128,282 | —- | M] () – C:\TDSSKiller.2.7.48.0_26.07.2012_00.33.41_log.txt
[2012/07/26 00:43:46 | 000,122,058 | —- | M] () – C:\TDSSKiller.2.7.48.0_26.07.2012_00.35.40_log.txt
[2012/05/27 22:43:00 | 000,003,031 | —- | M] () – C:\user.js
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 22:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/07/03 17:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/05/28 09:33:41 | 000,000,221 | -HS- | M] () – C:\Users\Lisa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/07/25 17:13:43 | 004,585,817 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\ComboFix.exe
[2012/07/26 11:49:08 | 000,132,597 | —- | M] () – C:\Users\Lisa\Desktop\Flash_Disinfector.exe
[2012/07/26 11:50:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2012/02/20 01:04:39 | 014,874,472 | —- | M] (Google Inc.) – C:\Users\Lisa\Desktop\picasa39-setup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-24 15:00:13
========== Alternate Data Streams ==========
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:EFC181EC
< End of report >
OTL Extras logfile created on: 26/07/2012 11:57:51 - Run 1
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Lisa\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
766.42 Mb Total Physical Memory | 315.54 Mb Available Physical Memory | 41.17% Memory free
1.75 Gb Paging File | 0.99 Gb Available in Paging File | 56.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 196.03 Gb Free Space | 84.21% Space Free | Partition Type: NTFS
Computer Name: LISA-PC | User Name: Lisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D9F98AE-135E-4CFB-97C7-8179661BDB50}" = lport=138 | protocol=17 | dir=in | app=system |
"{33FA33A7-C25E-4951-BE9C-21375C65CFE7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3571EA0B-A938-49B9-82E9-4B0F72AA337A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3863AC59-B673-44EE-8EED-56C4E61C7233}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3E8EA66C-6221-497E-A566-098BC99D77DA}" = rport=138 | protocol=17 | dir=out | app=system |
"{507D66F5-61DF-43CD-ACEF-EA20FF06B207}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{53F5C71F-EC6B-435B-9787-B08AEFB6A708}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5EC45837-D73C-49C3-8008-E0A525F539F0}" = lport=445 | protocol=6 | dir=in | app=system |
"{6F30B55D-7CD6-4074-9A45-48EF005675A6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F1BCBCD-110B-4BB1-B5CC-65728FC7BA2B}" = lport=139 | protocol=6 | dir=in | app=system |
"{86459B98-7401-4D28-A063-389052486C0A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8D38E741-DF92-4157-9A7B-4CBAFEEF29F0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{97076DFE-3514-4235-9AE3-CB7094AE8AA4}" = rport=137 | protocol=17 | dir=out | app=system |
"{A4B9F3E2-B051-491F-A894-439037D13C5A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7B866E4-79AB-46B9-A742-3F868B765A9A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C27F7B14-F18F-47DE-940D-6452A603ECDF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C814C4AB-E868-452E-9456-46CE80E8C972}" = lport=137 | protocol=17 | dir=in | app=system |
"{D13072AA-095D-4E80-9D71-81B3D861661D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DAE67A92-4BA1-41F5-8E5F-5D648861CF3D}" = rport=139 | protocol=6 | dir=out | app=system |
"{E9A4F9B8-31E1-4AD5-93D9-046653C6C557}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EA6CFE87-CA5D-4176-B18E-2462854ACDE1}" = rport=445 | protocol=6 | dir=out | app=system |
"{EE406BA0-40E2-4D2F-A5F6-94742DE18F55}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0672A0C3-23C9-4D93-A319-4E5A6069E2C6}" = dir=in | app=c:\users\lisa\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{06AB405E-3447-4BB8-A5F3-08C9C88073BC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1787127B-1466-4420-B749-A6077FA9C8AB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17D54D04-F530-408D-AE3C-514223A3B106}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1A8F4740-150F-4FB7-970B-631D335E78C8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{21B02CD0-3B00-4C2C-A274-68F658DA682A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2D0617E3-89FB-4D61-9AD4-0BF6AA34B403}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{369CB4BC-BE01-4481-86B8-638BA1D39359}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3C3794FD-F3ED-4689-8940-7B1F7B9AD389}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{52C63C3D-B3CE-409B-85C2-DB007039641F}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{591357A3-3A1C-4924-865F-357EBE0592CC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{639A8FC4-4463-49F4-BDF4-65CE5D517A4B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6E66E2C9-4F81-4290-AD2A-14C3017B8FEC}" = protocol=6 | dir=out | app=system |
"{7BB5DB91-36F5-49BA-8D62-04680FE6806C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{80ADEFF0-6B7D-4D99-AD7D-FE3A3A9C761D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8393EF96-1280-4C26-A73B-651E06467F4C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{90EBC870-6BF7-41B8-ACE7-5E2CA62DE3E3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{984C0526-B922-4FB1-AB19-A4DC1FF62CF2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{9BD3AEBA-73FF-48DF-892D-C44FCD6DFF33}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A863F45D-10E8-47C4-B1E1-338B6601A7DE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B9296E07-74E6-4979-B07B-98E3A4008D46}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C19B892F-19E1-431E-B576-E0CFE8E8FF3F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D2D66C9A-0B56-4525-8686-475AC263E1A0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D9A019D4-1424-43D8-9284-8718102D000C}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{F09D3EFD-FB45-4F72-AF10-7F1F23349B19}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"avast" = avast! Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"InstallWIX_{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Picasa 3" = Picasa 3
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 25/07/2012 12:08:52 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 25/07/2012 12:08:52 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4602981
Error - 25/07/2012 12:08:52 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4602981
Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4604666
Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4604666
Error - 25/07/2012 12:08:54 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 25/07/2012 12:08:54 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4605883
Error - 25/07/2012 12:08:54 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4605883
Error - 25/07/2012 12:08:56 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 25/07/2012 12:08:56 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4607224
Error - 25/07/2012 12:08:56 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4607224
Error - 25/07/2012 12:26:23 | Computer Name = Lisa-PC | Source = Google Update | ID = 20
Description =
Error - 26/07/2012 06:37:42 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 25/07/2012 08:51:02 | Computer Name = Lisa-PC | Source = atikmdag | ID = 43029
Description = Display is not active
Error - 25/07/2012 12:08:50 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Wlansvc service.
Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = atikmdag | ID = 43029
Description = Display is not active
Error - 25/07/2012 12:16:14 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 25/07/2012 12:21:11 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 25/07/2012 12:25:40 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 25/07/2012 15:11:27 | Computer Name = Lisa-PC | Source = DCOM | ID = 10010
Description =
Error - 26/07/2012 06:36:09 | Computer Name = Lisa-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter
Error - 26/07/2012 06:36:09 | Computer Name = Lisa-PC | Source = atikmdag | ID = 43029
Description = Display is not active
Error - 26/07/2012 06:36:12 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7023
Description = The Offline Files service terminated with the following error: %%3
< End of report >