This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Audio Ads playing in the background [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Running Win 7 Home Premium

Audio Adds have been playing in the background and may stop for a while but then begin again.

I ran Super Antispyware and AVG free but the issues continues.

I ran OTL and these are the results found in the OTL output file.

Thank you for any suggestions you may have.

Bill

OTL logfile created on: 8/30/2012 2:31:50 PM - Run 1
OTL by OldTimer - Version 3.2.59.1 Folder = E:\Diagnosis_Tools
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.95 Gb Available Physical Memory | 47.83% Memory free
3.98 Gb Paging File | 2.77 Gb Available in Paging File | 69.61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.69 Gb Total Space | 438.07 Gb Free Space | 94.07% Space Free | Partition Type: NTFS
Drive D: | 7.78 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 3.84 Gb Total Space | 0.41 Gb Free Space | 10.67% Space Free | Partition Type: FAT32

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\Diagnosis_Tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://us.mg4.mail.yahoo.com/neo/launch?.rand=eh0525n3h0kuj
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E3 B7 A5 A6 4D C1 CA 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…0F-245EA768EFDC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: [removed]:3.6.9.99999
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/31 15:20:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/08/16 08:20:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/27 19:07:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/27 19:04:55 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/31 15:20:19 | 000,000,000 | —D | M]

[2010/05/02 19:33:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2010/05/02 19:33:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/08/13 15:44:07 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vdbkedoc.default\extensions
[2012/01/23 22:43:32 | 000,002,425 | —- | M] () – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vdbkedoc.default\searchplugins\askcom.xml
[2012/01/03 19:04:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/10/27 16:24:38 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2012/01/03 19:04:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/08/16 08:20:09 | 000,000,000 | —D | M] (AVG Do Not Track) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2011/09/29 02:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/11/10 06:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 20:26:50 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/10/27 17:26:47 | 000,437,925 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15060 more lines…
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Device Center\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0BDFB550-9C17-4028-8669-50167AC9D005}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/29 13:30:55 | 000,285,328 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/08/29 13:30:32 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/08/29 13:30:32 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/08/29 13:00:34 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Macromedia
[2012/08/29 12:57:21 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Owner\Desktop\run.exe.exe
[2012/08/29 11:20:18 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2012/08/28 11:15:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
[2012/08/16 08:20:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/08/15 08:42:51 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/08/15 08:42:51 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/08/15 08:42:50 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/08/15 08:42:50 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/08/15 08:42:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/08/15 08:42:49 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/08/15 08:42:49 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/08/15 08:42:49 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/08/15 08:42:49 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/08/15 08:42:49 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/08/15 08:42:49 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/08/15 08:42:48 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/08/15 08:42:48 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/08/15 06:48:54 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\srcore.dll
[2012/08/15 06:48:53 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2012/08/15 06:48:52 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2012/08/15 06:48:52 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\splwow64.exe
[2012/08/15 06:48:51 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netapi32.dll
[2012/08/15 06:48:51 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browcli.dll
[2012/08/15 06:48:51 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\browcli.dll
[2012/08/15 06:48:50 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2012/08/14 15:04:15 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\Utilities
[2012/08/14 12:30:05 | 009,232,584 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2012/08/14 11:32:17 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/08/14 11:27:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
[2012/08/14 11:27:06 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Device Center
[2012/08/11 17:09:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/08/11 17:09:40 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/08/01 21:51:51 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Recovery

========== Files - Modified Within 30 Days ==========

[2012/08/30 14:30:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/30 13:18:04 | 000,026,192 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/30 13:18:04 | 000,026,192 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/30 13:10:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/30 13:10:54 | 1601,052,672 | -HS- | M] () – C:\hiberfil.sys
[2012/08/30 11:06:50 | 105,340,250 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/08/29 13:30:56 | 000,000,350 | -H– | M] () – C:\Windows\tasks\avast! Emergency Update.job
[2012/08/29 13:30:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/08/29 11:20:18 | 000,001,268 | —- | M] () – C:\Users\Owner\Desktop\Revo Uninstaller.lnk
[2012/08/29 09:44:20 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\run.exe.exe
[2012/08/28 11:16:23 | 000,730,512 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/28 11:16:23 | 000,627,066 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/08/28 11:16:23 | 000,107,382 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/08/27 18:11:05 | 000,397,271 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/08/21 05:12:02 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/08/18 07:49:36 | 000,027,520 | —- | M] () – C:\Users\Owner\AppData\Local\dt.dat
[2012/08/16 08:20:51 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/08/15 15:31:17 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/08/15 15:31:17 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/08/15 15:30:54 | 009,232,584 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2012/08/15 15:29:11 | 000,421,592 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/15 08:42:04 | 000,000,118 | —- | M] () – C:\Windows\SysNative\MRT.INI
[2012/08/12 09:21:05 | 000,000,064 | —- | M] () – C:\ProgramData\-cBHXSZzN9M1K1W
[2012/08/12 09:20:56 | 000,000,368 | —- | M] () – C:\ProgramData\cBHXSZzN9M1K1W
[2012/08/12 08:11:45 | 000,000,064 | —- | M] () – C:\ProgramData\-cBHXSZzN9M1K1Wr
[2012/08/11 17:09:43 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk

========== Files Created - No Company Name ==========

[2012/08/29 13:30:56 | 000,000,350 | -H– | C] () – C:\Windows\tasks\avast! Emergency Update.job
[2012/08/29 13:30:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2012/08/29 11:18:53 | 000,001,268 | —- | C] () – C:\Users\Owner\Desktop\Revo Uninstaller.lnk
[2012/08/18 07:49:36 | 000,027,520 | —- | C] () – C:\Users\Owner\AppData\Local\dt.dat
[2012/08/14 11:32:19 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/11 17:09:43 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/08/01 21:51:53 | 000,000,064 | —- | C] () – C:\ProgramData\-cBHXSZzN9M1K1Wr
[2012/08/01 21:51:53 | 000,000,064 | —- | C] () – C:\ProgramData\-cBHXSZzN9M1K1W
[2012/08/01 21:51:48 | 000,000,368 | —- | C] () – C:\ProgramData\cBHXSZzN9M1K1W
[2010/11/16 09:25:47 | 000,025,634 | -HS- | C] () – C:\Users\Owner\AlbumArt_{ED3EC2EB-2BFC-4836-B3A5-A985593E5659}_Large.jpg
[2010/11/16 09:25:47 | 000,007,128 | -HS- | C] () – C:\Users\Owner\AlbumArt_{ED3EC2EB-2BFC-4836-B3A5-A985593E5659}_Small.jpg
[2010/07/11 21:49:12 | 000,008,342 | -HS- | C] () – C:\Users\Owner\AlbumArt_{44114C69-EA72-4646-B2A8-735DC64737B1}_Large.jpg
[2010/07/11 21:49:12 | 000,002,316 | -HS- | C] () – C:\Users\Owner\AlbumArt_{44114C69-EA72-4646-B2A8-735DC64737B1}_Small.jpg
[2010/07/11 21:42:09 | 000,006,364 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7F4AD87D-FD80-4180-8595-4FAB0BFBEE98}_Large.jpg
[2010/07/11 21:42:09 | 000,001,742 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7F4AD87D-FD80-4180-8595-4FAB0BFBEE98}_Small.jpg
[2010/07/11 20:53:33 | 000,010,236 | -HS- | C] () – C:\Users\Owner\AlbumArt_{479B2C6F-772E-43F9-A3FF-3EE45B538405}_Large.jpg
[2010/07/11 20:53:33 | 000,002,700 | -HS- | C] () – C:\Users\Owner\AlbumArt_{479B2C6F-772E-43F9-A3FF-3EE45B538405}_Small.jpg
[2010/06/18 08:49:51 | 000,007,011 | -HS- | C] () – C:\Users\Owner\AlbumArt_{8F88FD7F-8188-4700-8B01-6FF4A62728C5}_Large.jpg
[2010/06/18 08:49:51 | 000,001,991 | -HS- | C] () – C:\Users\Owner\AlbumArt_{8F88FD7F-8188-4700-8B01-6FF4A62728C5}_Small.jpg
[2010/06/18 07:28:27 | 003,838,885 | —- | C] () – C:\Users\Owner\762 Fleetwood Mack - Don't Stop Thinking About Tomorrow.mp3
[2010/06/18 07:28:12 | 003,077,724 | —- | C] () – C:\Users\Owner\Fleetwood Mac - Dont Stop Thinking About Tomorrow.mp3
[2010/06/18 07:27:54 | 004,010,196 | —- | C] () – C:\Users\Owner\Fleetwood Mac - Say You Love Me.mp3
[2010/06/18 07:26:46 | 003,486,616 | —- | C] () – C:\Users\Owner\Fleetwood Mac - Go Your Own Way.mp3
[2010/06/18 07:26:16 | 002,890,250 | —- | C] () – C:\Users\Owner\Yvonne Elliman - If I Cant' Have You.mp3
[2010/06/18 07:25:48 | 003,449,860 | —- | C] () – C:\Users\Owner\Sister Sledge - We Are Family.mp3
[2010/06/18 07:21:23 | 001,767,115 | —- | C] () – C:\Users\Owner\Adam-Lambert-PLAY THAT FUNKY MUSIC WHITE BOY.mp3
[2010/06/18 07:21:00 | 003,034,930 | —- | C] () – C:\Users\Owner\Adam Lambert - Kiss and Tell.mp3
[2010/06/18 07:20:53 | 005,230,344 | —- | C] () – C:\Users\Owner\Adam Lambert - I Just Love You.mp3
[2010/06/18 07:20:48 | 004,966,464 | —- | C] () – C:\Users\Owner\04. Adam Lambert - Strut.mp3
[2010/06/18 07:20:25 | 003,734,302 | —- | C] () – C:\Users\Owner\Adam Lambert Whataya Want from Me.mp3
[2010/06/14 06:22:44 | 000,015,632 | -HS- | C] () – C:\Users\Owner\AlbumArt_{36732720-2074-490E-B9EF-562830E21120}_Large.jpg
[2010/06/14 06:22:44 | 000,003,238 | -HS- | C] () – C:\Users\Owner\AlbumArt_{36732720-2074-490E-B9EF-562830E21120}_Small.jpg
[2010/05/28 13:42:40 | 000,008,677 | -HS- | C] () – C:\Users\Owner\AlbumArt_{8CFFA35D-BD7D-489A-9551-0B124C5C1A00}_Large.jpg
[2010/05/28 13:42:40 | 000,002,423 | -HS- | C] () – C:\Users\Owner\AlbumArt_{8CFFA35D-BD7D-489A-9551-0B124C5C1A00}_Small.jpg
[2010/05/28 13:28:57 | 000,010,082 | -HS- | C] () – C:\Users\Owner\AlbumArt_{04DEB875-E87B-4C0B-BAD7-5573A5F055CC}_Large.jpg
[2010/05/28 13:28:57 | 000,002,729 | -HS- | C] () – C:\Users\Owner\AlbumArt_{04DEB875-E87B-4C0B-BAD7-5573A5F055CC}_Small.jpg
[2010/05/21 07:04:27 | 000,011,919 | -HS- | C] () – C:\Users\Owner\AlbumArt_{EB8CFEB2-10E9-4DA3-A794-E6C19C90571D}_Large.jpg
[2010/05/21 07:04:27 | 000,002,729 | -HS- | C] () – C:\Users\Owner\AlbumArt_{EB8CFEB2-10E9-4DA3-A794-E6C19C90571D}_Small.jpg
[2010/05/19 19:56:51 | 000,012,435 | -HS- | C] () – C:\Users\Owner\AlbumArt_{CE669108-20C2-4168-9C37-4C2E53B44FA5}_Large.jpg
[2010/05/19 19:56:51 | 000,002,879 | -HS- | C] () – C:\Users\Owner\AlbumArt_{CE669108-20C2-4168-9C37-4C2E53B44FA5}_Small.jpg
[2010/05/19 19:37:53 | 000,010,598 | -HS- | C] () – C:\Users\Owner\AlbumArt_{C03B257A-11B7-4E53-8564-B1EBB8EC9DEF}_Large.jpg
[2010/05/19 19:37:53 | 000,002,919 | -HS- | C] () – C:\Users\Owner\AlbumArt_{C03B257A-11B7-4E53-8564-B1EBB8EC9DEF}_Small.jpg
[2010/05/19 19:34:17 | 000,029,269 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7456E1F0-A716-448B-A6E6-03BB98CA878D}_Large.jpg
[2010/05/19 19:34:17 | 000,005,798 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7456E1F0-A716-448B-A6E6-03BB98CA878D}_Small.jpg
[2010/05/19 19:31:14 | 000,008,268 | -HS- | C] () – C:\Users\Owner\AlbumArt_{81C8E287-4D72-4BB6-B9AA-FAB0114C3859}_Large.jpg
[2010/05/19 19:31:14 | 000,002,210 | -HS- | C] () – C:\Users\Owner\AlbumArt_{81C8E287-4D72-4BB6-B9AA-FAB0114C3859}_Small.jpg
[2010/05/19 19:22:00 | 000,008,412 | -HS- | C] () – C:\Users\Owner\AlbumArt_{41E88225-A345-4F9B-ABCC-68C71057C919}_Large.jpg
[2010/05/19 19:22:00 | 000,002,396 | -HS- | C] () – C:\Users\Owner\AlbumArt_{41E88225-A345-4F9B-ABCC-68C71057C919}_Small.jpg
[2010/05/19 19:01:42 | 000,010,793 | -HS- | C] () – C:\Users\Owner\AlbumArt_{294FE5DE-9D4A-4C98-B3A2-039DB80A82CC}_Large.jpg
[2010/05/19 19:01:42 | 000,002,355 | -HS- | C] () – C:\Users\Owner\AlbumArt_{294FE5DE-9D4A-4C98-B3A2-039DB80A82CC}_Small.jpg
[2010/05/19 19:01:00 | 000,013,154 | -HS- | C] () – C:\Users\Owner\AlbumArt_{77988BA7-B6C9-4448-AEE0-95E08BE3B106}_Large.jpg
[2010/05/19 19:01:00 | 000,003,159 | -HS- | C] () – C:\Users\Owner\AlbumArt_{77988BA7-B6C9-4448-AEE0-95E08BE3B106}_Small.jpg
[2010/05/19 17:47:52 | 003,377,599 | —- | C] () – C:\Users\Owner\Rascall Flats - I Was Born The Day You Kissed Me.mp3
[2010/05/19 17:47:38 | 002,883,712 | —- | C] () – C:\Users\Owner\Rascall Flatts - Kissable, Huggable, Loveable, Unbelievable.mp3
[2010/05/19 17:47:30 | 004,456,762 | —- | C] () – C:\Users\Owner\Rascal Flats - Love You Out Loud .mp3
[2010/05/19 17:47:23 | 003,527,122 | —- | C] () – C:\Users\Owner\Rascal Flatts & Allison Kraus - We've Got Tonight.mp3
[2010/05/19 17:46:46 | 003,904,418 | —- | C] () – C:\Users\Owner\Rascall Flats - Here Comes Goodbye.mp3
[2010/05/19 17:46:38 | 003,454,978 | —- | C] () – C:\Users\Owner\Rascal Flatts - Praying For Daylight(1).mp3
[2010/05/19 17:46:31 | 006,759,434 | —- | C] () – C:\Users\Owner\Rascal Flatts - Unstoppable(1).mp3
[2010/05/19 17:46:21 | 005,130,240 | —- | C] () – C:\Users\Owner\Rascall Flats - What Hurts the Most.mp3
[2010/05/19 17:46:13 | 003,917,949 | —- | C] () – C:\Users\Owner\Rascall flatts - Rascal Flats - I m moving on.mp3
[2010/05/19 17:46:05 | 003,419,576 | —- | C] () – C:\Users\Owner\Rascal Flats - Good Morning Beautiful(1).mp3
[2010/05/19 17:45:26 | 003,471,488 | —- | C] () – C:\Users\Owner\Rascall Flats - These Days.mp3
[2010/05/19 17:45:18 | 003,415,144 | —- | C] () – C:\Users\Owner\Rascal Flats - What Hurts The Most.mp3
[2010/05/19 17:45:10 | 005,628,925 | —- | C] () – C:\Users\Owner\Rascal Flats - I Melt .mp3
[2010/05/19 17:43:37 | 005,387,006 | —- | C] () – C:\Users\Owner\Little Big Town - Everything Changes.mp3
[2010/05/19 17:43:28 | 002,671,975 | —- | C] () – C:\Users\Owner\_Don't Waste My Tim.mp3
[2010/05/19 17:42:50 | 002,665,788 | —- | C] () – C:\Users\Owner\Little Big Town - Don't Waste My Time.mp3
[2010/05/19 17:42:38 | 007,559,908 | —- | C] () – C:\Users\Owner\Fox and the Hound 2 - We Go Together.mp3
[2010/05/19 17:42:27 | 003,250,681 | —- | C] () – C:\Users\Owner\busboys - the boys are back in town(1).mp3
[2010/05/19 17:41:55 | 009,840,878 | —- | C] () – C:\Users\Owner\Little Big Town - I'm With The Band.mp3
[2010/05/19 17:41:46 | 006,447,700 | —- | C] () – C:\Users\Owner\11 Boondocks.mp3
[2010/05/19 17:36:53 | 002,177,677 | —- | C] () – C:\Users\Owner\Nitty Gritty Dirt Band - Louisiana Saturday Night.mp3
[2010/05/19 17:36:23 | 003,247,629 | —- | C] () – C:\Users\Owner\Nitty Gritty Dirt Band - Fishing In The Dark.mp3
[2010/05/19 17:36:04 | 003,339,376 | —- | C] () – C:\Users\Owner\Nitty Gritty Dirt Band - Fishing In The Dark.m4a
[2010/05/19 17:34:23 | 004,921,016 | —- | C] () – C:\Users\Owner\Whitney Houston - Didn't We Almost Have It All.mp3
[2010/05/19 17:34:16 | 004,246,483 | —- | C] () – C:\Users\Owner\03 Can I have this kiss forever.m4a
[2010/05/19 17:34:07 | 003,799,168 | —- | C] () – C:\Users\Owner\Disney - Cinderella (Whitney Houston & Brandy) - Impossible .mp3
[2010/05/19 17:33:48 | 005,752,832 | —- | C] () – C:\Users\Owner\Teddy Pendergrass and Whitney Houston - Hold Me In Your Arms.mp3
[2010/05/19 17:33:35 | 003,816,429 | —- | C] () – C:\Users\Owner\Whitney Houston - Unbreak My Heart.mp3
[2010/05/19 17:33:18 | 004,689,222 | —- | C] () – C:\Users\Owner\Whitney Huston - i wanna dance with somebody.mp3
[2010/05/19 17:32:51 | 004,663,424 | —- | C] () – C:\Users\Owner\Whitney Houston - The Greatest Love of All.mp3
[2010/05/19 17:32:44 | 004,574,273 | —- | C] () – C:\Users\Owner\Whitney Houston - One Moment In Time.mp3
[2010/05/19 17:32:38 | 004,368,637 | —- | C] () – C:\Users\Owner\Whitney Houston - I Will Always Love You.mp3
[2010/05/19 17:30:35 | 003,546,428 | —- | C] () – C:\Users\Owner\Stevie Nicks - Blondie - Bette Davis Eyes.mp3
[2010/05/19 17:30:17 | 004,067,372 | —- | C] () – C:\Users\Owner\Tom Petty & Stevie Nicks - Stop Dragging My Heart Around.mp3
[2010/05/19 17:29:57 | 004,608,625 | —- | C] () – C:\Users\Owner\Fleetwood Mack Stevie Nicks - Total Eclipse of the Heart.mp3
[2010/05/19 17:29:49 | 003,793,583 | —- | C] () – C:\Users\Owner\easy listening-Fleetwood Mac - Stevie Nicks - Leather And Lace ( with Don Henley).mp3
[2010/05/19 17:29:35 | 003,488,705 | —- | C] () – C:\Users\Owner\Stevie Nicks & Fleetwood Mac - Tell Me Lies.mp3
[2010/05/19 17:29:25 | 004,087,808 | —- | C] () – C:\Users\Owner\Fleetwood Mac-Thunder Only Happens When It's Raining ~ Stevie Nicks - Fleetwoodmac.mp3
[2010/05/19 17:29:15 | 004,292,022 | —- | C] () – C:\Users\Owner\Stevie Nicks - Landslide.mp3
[2010/05/19 17:28:27 | 005,230,953 | —- | C] () – C:\Users\Owner\09-ll_cool_j-big_ole_butt.mp3
[2010/05/19 17:27:41 | 004,629,198 | —- | C] () – C:\Users\Owner\LL Cool Jay - Mama said knock you out.mp3
[2010/05/19 17:26:19 | 005,496,981 | —- | C] () – C:\Users\Owner\Michael Jackson - Jam.mp3
[2010/05/19 17:26:07 | 006,727,813 | —- | C] () – C:\Users\Owner\Micheal Jackson - Dangerous.mp3
[2010/05/19 17:25:47 | 005,865,746 | —- | C] () – C:\Users\Owner\Michael Jackson - Don't Stop 'Till Get Enough.mp3
[2010/05/19 17:25:38 | 007,276,672 | —- | C] () – C:\Users\Owner\Michael Jackson - Wanna Be Starting Something.mp3
[2010/05/19 17:25:30 | 003,833,253 | —- | C] () – C:\Users\Owner\Michael Jackson - PYT (Pretty Young Thing).mp3
[2010/05/19 17:25:22 | 003,535,468 | —- | C] () – C:\Users\Owner\Micheal Jackson - Rock With You.mp3
[2010/05/19 17:24:59 | 005,727,548 | —- | C] () – C:\Users\Owner\Michael Jackson - Thriller.mp3
[2010/05/19 17:24:53 | 004,122,977 | —- | C] () – C:\Users\Owner\Michael Jackson - Smooth Criminal.mp3
[2010/05/19 17:24:48 | 004,709,672 | —- | C] () – C:\Users\Owner\Michael Jackson - Billie Jean.mp3
[2010/05/19 17:24:42 | 004,149,610 | —- | C] () – C:\Users\Owner\Michael Jackson - Beat It.mp3
[2010/05/18 22:18:56 | 000,010,583 | -HS- | C] () – C:\Users\Owner\AlbumArt_{D7CB65FE-2056-4F50-AC35-37C610693C5C}_Large.jpg
[2010/05/18 22:18:56 | 000,002,650 | -HS- | C] () – C:\Users\Owner\AlbumArt_{D7CB65FE-2056-4F50-AC35-37C610693C5C}_Small.jpg
[2010/05/18 22:18:06 | 000,014,280 | -HS- | C] () – C:\Users\Owner\AlbumArt_{EC3057A3-B08D-4FF4-AFAA-607CA9E9A18F}_Large.jpg
[2010/05/18 22:18:06 | 000,002,876 | -HS- | C] () – C:\Users\Owner\AlbumArt_{EC3057A3-B08D-4FF4-AFAA-607CA9E9A18F}_Small.jpg
[2010/05/18 22:13:01 | 000,016,956 | -HS- | C] () – C:\Users\Owner\AlbumArt_{6235903D-80D2-4039-A1F8-A6BB46D1E2CD}_Large.jpg
[2010/05/18 22:13:01 | 000,003,128 | -HS- | C] () – C:\Users\Owner\AlbumArt_{6235903D-80D2-4039-A1F8-A6BB46D1E2CD}_Small.jpg
[2010/05/18 22:10:37 | 000,011,605 | -HS- | C] () – C:\Users\Owner\AlbumArt_{C0FF1BCE-407A-469D-A210-C0C294137DDE}_Large.jpg
[2010/05/18 22:10:37 | 000,002,977 | -HS- | C] () – C:\Users\Owner\AlbumArt_{C0FF1BCE-407A-469D-A210-C0C294137DDE}_Small.jpg
[2010/05/18 21:55:26 | 000,014,154 | -HS- | C] () – C:\Users\Owner\AlbumArt_{11EE6F3F-0FF8-4EA9-BD42-4299C2AB3D1E}_Large.jpg
[2010/05/18 21:55:26 | 000,003,435 | -HS- | C] () – C:\Users\Owner\AlbumArt_{11EE6F3F-0FF8-4EA9-BD42-4299C2AB3D1E}_Small.jpg
[2010/05/18 21:51:21 | 000,015,253 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7F8EE2CA-5219-40DC-90E3-D7F14ADD99B6}_Large.jpg
[2010/05/18 21:51:21 | 000,003,270 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7F8EE2CA-5219-40DC-90E3-D7F14ADD99B6}_Small.jpg
[2010/05/18 21:35:18 | 000,010,290 | -HS- | C] () – C:\Users\Owner\AlbumArt_{6F90D383-EB7A-42A2-93EE-693516E3A3AF}_Large.jpg
[2010/05/18 21:35:18 | 000,002,605 | -HS- | C] () – C:\Users\Owner\AlbumArt_{6F90D383-EB7A-42A2-93EE-693516E3A3AF}_Small.jpg
[2010/05/18 21:32:14 | 000,008,970 | -HS- | C] () – C:\Users\Owner\AlbumArt_{72270B1D-555B-4D47-9AF0-73D636B23DBA}_Large.jpg
[2010/05/18 21:32:14 | 000,002,064 | -HS- | C] () – C:\Users\Owner\AlbumArt_{72270B1D-555B-4D47-9AF0-73D636B23DBA}_Small.jpg
[2010/05/18 21:27:20 | 000,013,935 | -HS- | C] () – C:\Users\Owner\AlbumArt_{51548DF0-A790-4A5F-8385-503534D952DB}_Large.jpg
[2010/05/18 21:27:20 | 000,003,098 | -HS- | C] () – C:\Users\Owner\AlbumArt_{51548DF0-A790-4A5F-8385-503534D952DB}_Small.jpg
[2010/05/18 21:08:32 | 000,012,780 | -HS- | C] () – C:\Users\Owner\AlbumArt_{36FF82D2-D248-4D49-BD5F-00DA4FEA2941}_Large.jpg
[2010/05/18 21:08:32 | 000,002,671 | -HS- | C] () – C:\Users\Owner\AlbumArt_{36FF82D2-D248-4D49-BD5F-00DA4FEA2941}_Small.jpg
[2010/05/18 20:51:50 | 000,010,810 | -HS- | C] () – C:\Users\Owner\AlbumArt_{62B3B5A8-D679-45F3-B89D-1FD41762ADA7}_Large.jpg
[2010/05/18 20:51:50 | 000,002,801 | -HS- | C] () – C:\Users\Owner\AlbumArt_{62B3B5A8-D679-45F3-B89D-1FD41762ADA7}_Small.jpg
[2010/05/18 20:42:55 | 000,009,795 | -HS- | C] () – C:\Users\Owner\AlbumArt_{9805E048-C781-4D3B-806A-B6FEB1983DFB}_Large.jpg
[2010/05/18 20:42:55 | 000,002,572 | -HS- | C] () – C:\Users\Owner\AlbumArt_{9805E048-C781-4D3B-806A-B6FEB1983DFB}_Small.jpg
[2010/05/18 20:39:07 | 000,007,368 | -HS- | C] () – C:\Users\Owner\AlbumArt_{0FB88DD1-1A35-4824-8598-3A75679DA195}_Large.jpg
[2010/05/18 20:39:07 | 000,002,206 | -HS- | C] () – C:\Users\Owner\AlbumArt_{0FB88DD1-1A35-4824-8598-3A75679DA195}_Small.jpg
[2010/05/18 20:24:47 | 000,013,153 | -HS- | C] () – C:\Users\Owner\AlbumArt_{0DADC0A7-2EBD-4A83-BAC6-5563E3319D11}_Large.jpg
[2010/05/18 20:24:47 | 000,002,884 | -HS- | C] () – C:\Users\Owner\AlbumArt_{0DADC0A7-2EBD-4A83-BAC6-5563E3319D11}_Small.jpg
[2010/05/18 20:17:50 | 000,038,346 | -HS- | C] () – C:\Users\Owner\AlbumArt_{3FF4C43A-8CE8-48FE-807F-456D3AA98AD5}_Large.jpg
[2010/05/18 20:17:50 | 000,008,016 | -HS- | C] () – C:\Users\Owner\AlbumArt_{3FF4C43A-8CE8-48FE-807F-456D3AA98AD5}_Small.jpg
[2010/05/18 20:13:43 | 000,010,777 | -HS- | C] () – C:\Users\Owner\AlbumArt_{C4F4ED7D-1FD3-4EB7-AC7B-A8264F3A1368}_Large.jpg
[2010/05/18 20:13:43 | 000,002,880 | -HS- | C] () – C:\Users\Owner\AlbumArt_{C4F4ED7D-1FD3-4EB7-AC7B-A8264F3A1368}_Small.jpg
[2010/05/18 14:26:25 | 000,007,783 | -HS- | C] () – C:\Users\Owner\AlbumArt_{A158502E-D531-4BC9-966B-5CFC0EEE8D9D}_Large.jpg
[2010/05/18 14:26:25 | 000,002,230 | -HS- | C] () – C:\Users\Owner\AlbumArt_{A158502E-D531-4BC9-966B-5CFC0EEE8D9D}_Small.jpg
[2010/05/18 14:24:26 | 000,010,172 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7030BF8D-A507-4D72-9265-0849AFE084F0}_Large.jpg
[2010/05/18 14:24:26 | 000,002,382 | -HS- | C] () – C:\Users\Owner\AlbumArt_{7030BF8D-A507-4D72-9265-0849AFE084F0}_Small.jpg
[2010/05/18 14:22:59 | 000,033,277 | -HS- | C] () – C:\Users\Owner\AlbumArt_{958F72D4-87DE-409F-A9C8-D73A3CD6E717}_Large.jpg
[2010/05/18 14:22:59 | 000,007,180 | -HS- | C] () – C:\Users\Owner\AlbumArt_{958F72D4-87DE-409F-A9C8-D73A3CD6E717}_Small.jpg
[2010/05/18 14:22:17 | 000,027,687 | -HS- | C] () – C:\Users\Owner\AlbumArt_{BE83396C-E517-4C4A-AE98-BBBFFBA17D02}_Large.jpg
[2010/05/18 14:22:17 | 000,006,798 | -HS- | C] () – C:\Users\Owner\AlbumArt_{BE83396C-E517-4C4A-AE98-BBBFFBA17D02}_Small.jpg
[2010/05/18 14:20:20 | 002,002,320 | —- | C] () – C:\Users\Owner\Rob Thomas - Someday.mp3
[2010/05/18 14:19:43 | 005,684,916 | —- | C] () – C:\Users\Owner\Lady Gaga - Just Dance(Ft Akon)(1).mp3
[2010/05/18 14:19:15 | 004,253,591 | —- | C] () – C:\Users\Owner\Lady GaGa - Disco Stick.mp3
[2010/05/18 14:19:00 | 004,306,469 | —- | C] () – C:\Users\Owner\Eric Church - 11 - Hell On The Heart.mp3
[2010/05/18 14:18:35 | 005,348,259 | —- | C] () – C:\Users\Owner\34-train-hey_soul_sister.mp3
[2010/05/18 14:18:12 | 004,513,418 | —- | C] () – C:\Users\Owner\01 Break Your Heart (ft Ludacris).mp3
[2010/05/18 14:17:53 | 003,545,425 | —- | C] () – C:\Users\Owner\Carrie Underwood- i dont even know his last name.mp3
[2010/05/18 14:17:04 | 005,622,768 | —- | C] () – C:\Users\Owner\Carrie Underwood - Before He Cheats.mp3
[2010/05/18 14:16:42 | 008,825,127 | —- | C] () – C:\Users\Owner\Carrie Underwood - Cowboy Casanova(1)(1).mp3
[2010/05/18 14:16:11 | 004,460,672 | —- | C] () – C:\Users\Owner\Meranda Lambert - Kerosene.mp3
[2010/05/18 14:15:42 | 005,257,226 | —- | C] () – C:\Users\Owner\Miranda Lambert Blake Shelton - You.mp3
[2010/05/18 14:15:33 | 002,576,718 | —- | C] () – C:\Users\Owner\miranda lambert - Crazy Ex-Girlfriend.mp3
[2010/05/18 14:15:24 | 003,086,762 | —- | C] () – C:\Users\Owner\Miranda Lambert - Gunpowder & Lead.mp3
[2010/05/18 14:15:15 | 004,679,787 | —- | C] () – C:\Users\Owner\10-miranda_lambert-the_house_that_built_me.mp3
[2010/05/18 14:15:10 | 006,377,979 | —- | C] () – C:\Users\Owner\Miranda Lambert - White Liar.mp3
[2010/05/18 14:14:50 | 004,057,190 | —- | C] () – C:\Users\Owner\Taylor Swift - Sparks Fly.mp3
[2010/05/18 14:14:27 | 007,646,189 | —- | C] () – C:\Users\Owner\Taylor Swift - Today Was A Fairytale(1).mp3
[2010/05/18 14:14:20 | 008,171,791 | —- | C] () – C:\Users\Owner\Boys Like Girls ft Taylor Swift -Two Is Better Than One_2.mp3
[2010/05/18 14:06:45 | 000,008,946 | -HS- | C] () – C:\Users\Owner\AlbumArt_{2E4D4E34-7924-47C1-85AD-127C58E397A2}_Large.jpg
[2010/05/18 14:06:45 | 000,002,471 | -HS- | C] () – C:\Users\Owner\AlbumArt_{2E4D4E34-7924-47C1-85AD-127C58E397A2}_Small.jpg
[2010/05/18 14:05:21 | 008,529,371 | —- | C] () – C:\Users\Owner\Heidi Newfield - Johnny & June.mp3
[2010/05/18 14:03:35 | 000,010,373 | -HS- | C] () – C:\Users\Owner\AlbumArt_{F0D16DBA-D197-450C-BEA2-03F3572DE44E}_Large.jpg
[2010/05/18 14:03:35 | 000,002,637 | -HS- | C] () – C:\Users\Owner\AlbumArt_{F0D16DBA-D197-450C-BEA2-03F3572DE44E}_Small.jpg
[2010/05/18 14:01:07 | 000,009,154 | -HS- | C] () – C:\Users\Owner\AlbumArt_{17753215-2D2C-4F7E-897C-76F87F15C812}_Large.jpg
[2010/05/18 14:01:07 | 000,002,510 | -HS- | C] () – C:\Users\Owner\AlbumArt_{17753215-2D2C-4F7E-897C-76F87F15C812}_Small.jpg
[2010/05/18 13:57:58 | 000,012,935 | -HS- | C] () – C:\Users\Owner\AlbumArt_{BBEB83FF-97C6-4D49-997F-BC9DA94AD2BD}_Large.jpg
[2010/05/18 13:57:58 | 000,002,719 | -HS- | C] () – C:\Users\Owner\AlbumArt_{BBEB83FF-97C6-4D49-997F-BC9DA94AD2BD}_Small.jpg
[2010/05/18 13:56:39 | 005,468,160 | —- | C] () – C:\Users\Owner\Rihanna - Rude Boy (OFFICIAL NEW SINGLE 2010).mp3
[2010/05/18 13:56:03 | 000,044,980 | -HS- | C] () – C:\Users\Owner\AlbumArt_{1BD32C4D-E733-4315-9F38-E0CEE51DDD7C}_Large.jpg
[2010/05/18 13:56:03 | 000,008,502 | -HS- | C] () – C:\Users\Owner\AlbumArt_{1BD32C4D-E733-4315-9F38-E0CEE51DDD7C}_Small.jpg
[2010/05/18 13:55:43 | 000,010,497 | -HS- | C] () – C:\Users\Owner\AlbumArt_{26A0F86E-A6D7-4D2F-88F4-289B4CB9CEE1}_Large.jpg
[2010/05/18 13:55:43 | 000,002,714 | -HS- | C] () – C:\Users\Owner\AlbumArt_{26A0F86E-A6D7-4D2F-88F4-289B4CB9CEE1}_Small.jpg
[2010/05/18 13:52:55 | 000,025,634 | -HS- | C] () – C:\Users\Owner\Folder.jpg
[2010/05/18 13:52:55 | 000,007,128 | -HS- | C] () – C:\Users\Owner\AlbumArtSmall.jpg
[2010/05/18 13:49:03 | 003,829,760 | —- | C] () – C:\Users\Owner\Johnny Cash - Cadillac One Piece At A Time.mp3
[2010/05/18 13:47:26 | 002,942,976 | —- | C] () – C:\Users\Owner\Johnny Cash & June Carter - It Ain't Me, Babe.mp3
[2010/05/18 13:47:22 | 004,196,352 | —- | C] () – C:\Users\Owner\jonny cash - johnny rebel - ship those niggers back.mp3
[2010/05/18 13:46:48 | 002,207,363 | —- | C] () – C:\Users\Owner\Johnny Cash - I Fought The Law.mp3
[2010/05/18 13:46:06 | 002,740,080 | —- | C] () – C:\Users\Owner\Johnny Cash - Folsom Prison Blues.mp3
[2010/05/18 13:45:59 | 002,617,580 | —- | C] () – C:\Users\Owner\I Walk the Line.mp3
[2010/05/18 13:45:36 | 002,463,715 | —- | C] () – C:\Users\Owner\Johnny Cash - Ring of Fire.mp3
[2010/05/18 13:44:32 | 002,720,128 | —- | C] () – C:\Users\Owner\Hank Williams Jr & Sr - There's A Tear In My Bear.mp3
[2010/05/18 13:44:18 | 004,621,536 | —- | C] () – C:\Users\Owner\Kid Rock - Cadillac ###### - (with Hank Williams Jr.).mp3
[2010/05/18 13:44:15 | 002,605,734 | —- | C] () – C:\Users\Owner\Hank Williams Jr - Why Don't We Get Drunk and Screw.mp3
[2010/05/18 13:44:00 | 003,799,825 | —- | C] () – C:\Users\Owner\Hank Williams Jr. - Country State of Mind.mp3
[2010/05/18 13:43:54 | 002,125,824 | —- | C] () – C:\Users\Owner\Hank Williams Jr - Sweet Home Alabama.mp3
[2010/05/18 13:43:21 | 003,143,680 | —- | C] () – C:\Users\Owner\Hank Williams Jr. - Thank God I'm a Country Boy.mp3
[2010/05/18 13:43:16 | 003,088,465 | —- | C] () – C:\Users\Owner\David Allen Coe & Hank Williams Jr. - Were You Born An Asshole.mp3
[2010/05/18 13:43:10 | 002,644,555 | —- | C] () – C:\Users\Owner\Hank Williams Jr - Born to Boogie.mp3
[2010/05/18 13:42:51 | 004,093,337 | —- | C] () – C:\Users\Owner\Hank Williams Jr. - A Country Boy Can Survive.mp3
[2010/05/18 13:42:23 | 004,073,498 | —- | C] () – C:\Users\Owner\Charlie Daniels Band - The Legend of Wooley Swamp.mp3
[2010/05/18 13:42:08 | 003,461,527 | —- | C] () – C:\Users\Owner\Charlie Daniels Band - Devil Went Down in Georgia.mp3
[2010/05/18 13:41:26 | 004,046,076 | —- | C] () – C:\Users\Owner\Charlie Daniels Band - The Devil Went Down To Georgia II (Devil Came Back to Georgia).mp3
[2010/05/18 13:41:03 | 003,541,709 | —- | C] () – C:\Users\Owner\Charlie Daniels Band - A Few More Rednecks.mp3
[2010/05/18 13:40:35 | 009,728,147 | —- | C] () – C:\Users\Owner\Lynard Skynard - Free Bird.mp3
[2010/05/18 13:40:15 | 003,269,235 | —- | C] () – C:\Users\Owner\Lynard Skynard - Stuck In The Middle With You.mp3
[2010/05/18 13:39:53 | 002,663,768 | —- | C] () – C:\Users\Owner\Lynard Skynard - American Woman.mp3
[2010/05/18 13:39:38 | 004,948,219 | —- | C] () – C:\Users\Owner\Lynard Skynard - Saturday Night Special.mp3
[2010/05/18 13:38:52 | 003,381,908 | —- | C] () – C:\Users\Owner\Lynard Skynard - Whats Your Name.mp3
[2010/05/18 13:38:45 | 006,192,309 | —- | C] () – C:\Users\Owner\Lynard Skynard - They Call Me The Breeze.mp3
[2010/05/18 13:38:32 | 004,805,279 | —- | C] () – C:\Users\Owner\Lynard Skynard - Sweet Home Alabama.mp3
[2010/05/18 13:37:50 | 008,744,480 | —- | C] () – C:\Users\Owner\01 Our Kind of Love.m4a
[2010/05/18 13:37:23 | 005,849,248 | —- | C] () – C:\Users\Owner\Lady Antebellum - I Run To You.mp3
[2010/05/18 13:37:17 | 009,522,830 | —- | C] () – C:\Users\Owner\Lady Antebellum-01 Need You Now.mp3
[2010/05/18 13:37:08 | 006,167,220 | —- | C] () – C:\Users\Owner\Lady Antebellum - American Honey.mp3
[2010/05/18 13:35:48 | 003,216,890 | —- | C] () – C:\Users\Owner\Tick Tock - Kesha.mp3
[2010/05/18 13:35:08 | 006,690,221 | —- | C] () – C:\Users\Owner\B.o.B. feat. Bruno Mars - Nothing On You.mp3
[2010/05/18 13:34:16 | 004,957,829 | —- | C] () – C:\Users\Owner\Jason Darulo - In My Head.mp3

========== LOP Check ==========

[2011/10/27 14:52:24 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\AVG2012
[2012/08/12 19:19:10 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2012/08/12 19:25:40 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\LimeWire
[2012/08/12 19:25:10 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Singlesnet
[2010/04/14 18:34:49 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Unity
[2012/02/20 12:23:26 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WinPatrol
[2012/08/29 13:30:56 | 000,000,350 | -H– | M] () – C:\Windows\Tasks\avast! Emergency Update.job
[2012/06/03 06:34:55 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/08/30 13:10:54 | 1601,052,672 | -HS- | M] () – C:\hiberfil.sys
[2010/05/17 10:59:38 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2012/08/30 13:10:54 | 2134,736,896 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/27 21:55:35 | 000,000,221 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/08/29 09:44:20 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\run.exe.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Ok try this…

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hi,

In the run box type the following

diskmgmt.msc

When disc management opens expand it so that all drives are visible
Take a screenshot and post it here

Are you able to burn a CD on another computer ?
————-
Good job….this is a tricky one. :D

Download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Hi Jeff, Two things. 1) repair mode won't start. Get a message to use the installation disk which I don't have, so I need to make one. 2) I just got a call to attend a meeting. I'm not sure I can get back to this until later or maybe tomorrow morning. I would like to continue now but can't. Thank you for your help. Bill
Hello Jeff, I created a recovery disk and ran frst64. This is the log created. Scan result of Farbar Recovery Scan Tool Version: 30-08-2012 Ran by [removed] at 30-08-2012 21:33:50 Running from F:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe" [1464928 2012-06-26] (Microsoft Corporation) HKLM\…\Run: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe" [2004584 2012-06-26] (Microsoft Corporation) HKLM\…\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe -expressboot [384232 2012-07-12] (BillP Studios) HKLM-x32\…\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2587008 2012-04-05] (AVG Technologies CZ, s.r.o.) HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard) HKLM-x32\…\Run: [] [x] HKLM-x32\…\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot [384232 2012-07-12] (BillP Studios) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Services (Whitelisted) ====== 2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com) 2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.) ==================== Drivers (Whitelisted) =================== 0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. ) 1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [289872 2012-02-22] (AVG Technologies CZ, s.r.o.) 1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.) 0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.) 1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 3 cpuz132; \??\C:\Users\Owner\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x] 1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x] ==================== NetSvcs (Whitelisted) ================= ==================== One Month Created Files and Folders ====================== 2012-08-30 21:33 - 2012-08-30 21:33 - 00000000 ____D C:\FRST 2012-08-30 11:22 - 2012-08-29 05:44 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\iexplore.exe.exe 2012-08-29 09:30 - 2012-08-30 09:07 - 00000000 ____D C:\Users\All Users\AVAST Software 2012-08-29 09:30 - 2012-08-29 09:30 - 00000350 ___AH C:\Windows\Tasks\avast! Emergency Update.job 2012-08-29 09:30 - 2012-08-29 09:30 - 00000000 ____D C:\Program Files\AVAST Software 2012-08-29 09:30 - 2012-08-29 09:30 - 00000000 ____A C:\Windows\SysWOW64\config.nt 2012-08-29 09:30 - 2012-08-21 01:12 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe 2012-08-29 09:01 - 2012-08-29 09:01 - 04731392 ____A (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe 2012-08-29 09:00 - 2012-08-29 09:00 - 00000000 ____D C:\Users\Owner\AppData\Local\Macromedia 2012-08-29 08:57 - 2012-08-29 05:44 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\run.exe.exe 2012-08-29 07:18 - 2012-08-29 07:20 - 00001268 ____A C:\Users\Owner\Desktop\Revo Uninstaller.lnk 2012-08-28 07:30 - 2012-08-28 07:30 - 00000000 ____D C:\Users\jacob\AppData\Roaming\WinPatrol 2012-08-24 09:28 - 2012-08-24 09:28 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe 2012-08-18 03:49 - 2012-08-18 03:49 - 00027520 ____A C:\Users\Owner\AppData\Local\dt.dat 2012-08-15 04:42 - 2012-06-28 20:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-15 04:42 - 2012-06-28 20:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-15 04:42 - 2012-06-28 19:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-08-15 04:42 - 2012-06-28 19:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-15 04:42 - 2012-06-28 19:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-15 04:42 - 2012-06-28 19:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-15 04:42 - 2012-06-28 19:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-15 04:42 - 2012-06-28 19:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-15 04:42 - 2012-06-28 19:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-08-15 04:42 - 2012-06-28 19:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-08-15 04:42 - 2012-06-28 19:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-15 04:42 - 2012-06-28 19:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-15 04:42 - 2012-06-28 19:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-08-15 04:42 - 2012-06-28 19:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-08-15 04:42 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-08-15 04:42 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-08-15 04:42 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-08-15 04:42 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-08-15 04:42 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-08-15 04:42 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-08-15 04:42 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-08-15 04:42 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-08-15 04:42 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-08-15 04:42 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-08-15 04:42 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-08-15 04:42 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-08-15 04:42 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-08-15 04:42 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-08-15 02:48 - 2012-07-18 10:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-08-15 02:48 - 2012-07-04 14:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll 2012-08-15 02:48 - 2012-07-04 14:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll 2012-08-15 02:48 - 2012-07-04 14:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll 2012-08-15 02:48 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2012-08-15 02:48 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2012-08-15 02:48 - 2012-05-13 21:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll 2012-08-15 02:48 - 2012-05-05 00:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll 2012-08-15 02:48 - 2012-05-04 23:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2012-08-15 02:48 - 2012-02-10 22:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2012-08-15 02:48 - 2012-02-10 22:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe 2012-08-15 02:48 - 2012-02-10 22:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe 2012-08-15 02:48 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2012-08-14 11:04 - 2012-08-14 11:08 - 00000000 ____D C:\Users\Owner\Desktop\Utilities 2012-08-14 08:30 - 2012-08-15 11:30 - 09232584 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2012-08-14 07:32 - 2012-08-30 11:30 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-08-14 07:32 - 2012-08-15 11:31 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-08-14 07:27 - 2012-08-14 07:27 - 00000000 ____D C:\Program Files\Microsoft Device Center 2012-08-13 11:35 - 2012-08-30 17:23 - 00004343 ____A C:\Windows\setupact.log 2012-08-13 11:35 - 2012-08-13 11:35 - 00000000 ____A C:\Windows\setuperr.log 2012-08-11 13:09 - 2012-08-29 08:04 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2012-08-11 13:09 - 2012-08-11 13:09 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2012-08-11 13:09 - 2012-08-11 13:08 - 19113832 ____A (SUPERAntiSpyware.com) C:\Users\Owner\Downloads\SUPERAntiSpyware(1).exe 2012-08-01 17:51 - 2012-08-12 05:21 - 00000064 ____A C:\Users\All Users\-cBHXSZzN9M1K1W 2012-08-01 17:51 - 2012-08-12 05:20 - 00000368 ____A C:\Users\All Users\cBHXSZzN9M1K1W 2012-08-01 17:51 - 2012-08-12 04:11 - 00000064 ____A C:\Users\All Users\-cBHXSZzN9M1K1Wr ==================== 3 Months Modified Files ================================ 2012-08-30 17:23 - 2012-08-13 11:35 - 00004343 ____A C:\Windows\setupact.log 2012-08-30 17:23 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-08-30 12:08 - 2009-11-03 13:53 - 01223364 ____A C:\Windows\WindowsUpdate.log 2012-08-30 12:08 - 2009-07-13 20:45 - 00026192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-08-30 12:08 - 2009-07-13 20:45 - 00026192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-08-30 11:30 - 2012-08-14 07:32 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-08-30 09:07 - 2010-07-03 01:29 - 00072880 ____A C:\Windows\PFRO.log 2012-08-29 09:30 - 2012-08-29 09:30 - 00000350 ___AH C:\Windows\Tasks\avast! Emergency Update.job 2012-08-29 09:30 - 2012-08-29 09:30 - 00000000 ____A C:\Windows\SysWOW64\config.nt 2012-08-29 09:01 - 2012-08-29 09:01 - 04731392 ____A (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe 2012-08-29 07:20 - 2012-08-29 07:18 - 00001268 ____A C:\Users\Owner\Desktop\Revo Uninstaller.lnk 2012-08-29 05:44 - 2012-08-30 11:22 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\iexplore.exe.exe 2012-08-29 05:44 - 2012-08-29 08:57 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\run.exe.exe 2012-08-28 07:16 - 2009-07-13 21:13 - 00730512 ____A C:\Windows\System32\PerfStringBackup.INI 2012-08-24 09:28 - 2012-08-24 09:28 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe 2012-08-21 01:12 - 2012-08-29 09:30 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe 2012-08-18 03:49 - 2012-08-18 03:49 - 00027520 ____A C:\Users\Owner\AppData\Local\dt.dat 2012-08-16 04:20 - 2011-11-04 07:18 - 00000965 ____A C:\Users\Public\Desktop\AVG 2012.lnk 2012-08-15 11:31 - 2012-08-14 07:32 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-08-15 11:31 - 2011-10-27 12:16 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-08-15 11:30 - 2012-08-14 08:30 - 09232584 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2012-08-15 11:29 - 2009-07-13 20:45 - 00421592 ____A C:\Windows\System32\FNTCACHE.DAT 2012-08-15 04:42 - 2010-04-16 02:29 - 00000118 ____A C:\Windows\System32\MRT.INI 2012-08-15 04:40 - 2009-11-04 06:01 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-08-13 11:35 - 2012-08-13 11:35 - 00000000 ____A C:\Windows\setuperr.log 2012-08-12 05:21 - 2012-08-01 17:51 - 00000064 ____A C:\Users\All Users\-cBHXSZzN9M1K1W 2012-08-12 05:20 - 2012-08-01 17:51 - 00000368 ____A C:\Users\All Users\cBHXSZzN9M1K1W 2012-08-12 04:11 - 2012-08-01 17:51 - 00000064 ____A C:\Users\All Users\-cBHXSZzN9M1K1Wr 2012-08-11 13:09 - 2012-08-11 13:09 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2012-08-11 13:08 - 2012-08-11 13:09 - 19113832 ____A (SUPERAntiSpyware.com) C:\Users\Owner\Downloads\SUPERAntiSpyware(1).exe 2012-07-25 08:31 - 2012-01-03 14:39 - 00109616 ____A C:\Users\jacob\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-23 03:03 - 2010-03-11 10:54 - 00109616 ____A C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-22 12:35 - 2012-07-22 12:35 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_point64_01009.Wdf 2012-07-22 12:32 - 2012-07-22 12:32 - 00001280 ____A C:\Users\jacob\Desktop\Command Prompt.lnk 2012-07-18 10:15 - 2012-08-15 02:48 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-11 23:06 - 2009-07-13 18:34 - 00000513 ____A C:\Windows\win.ini 2012-07-04 14:16 - 2012-08-15 02:48 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll 2012-07-04 14:13 - 2012-08-15 02:48 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll 2012-07-04 14:13 - 2012-08-15 02:48 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll 2012-07-04 13:16 - 2012-08-15 02:48 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2012-07-04 13:14 - 2012-08-15 02:48 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2012-06-28 20:55 - 2012-08-15 04:42 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-28 20:09 - 2012-08-15 04:42 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-28 19:56 - 2012-08-15 04:42 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-28 19:49 - 2012-08-15 04:42 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-28 19:49 - 2012-08-15 04:42 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-28 19:48 - 2012-08-15 04:42 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-28 19:47 - 2012-08-15 04:42 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-28 19:45 - 2012-08-15 04:42 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-28 19:44 - 2012-08-15 04:42 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-28 19:43 - 2012-08-15 04:42 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-28 19:42 - 2012-08-15 04:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-28 19:40 - 2012-08-15 04:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-28 19:39 - 2012-08-15 04:42 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-28 19:35 - 2012-08-15 04:42 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-28 16:52 - 2012-08-15 04:42 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-28 16:27 - 2012-08-15 04:42 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-28 16:16 - 2012-08-15 04:42 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-28 16:09 - 2012-08-15 04:42 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-28 16:09 - 2012-08-15 04:42 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-28 16:08 - 2012-08-15 04:42 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-28 16:07 - 2012-08-15 04:42 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-28 16:06 - 2012-08-15 04:42 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-28 16:04 - 2012-08-15 04:42 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-28 16:04 - 2012-08-15 04:42 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-28 16:01 - 2012-08-15 04:42 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-28 16:01 - 2012-08-15 04:42 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-28 16:00 - 2012-08-15 04:42 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-28 15:57 - 2012-08-15 04:42 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-26 17:38 - 2012-06-26 17:38 - 00827728 ____A (Microsoft Corporation) C:\Windows\System32\msvcr100.dll 2012-06-26 17:38 - 2012-06-26 17:38 - 00770384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll 2012-06-26 17:38 - 2012-06-26 17:38 - 00607568 ____A (Microsoft Corporation) C:\Windows\System32\msvcp100.dll 2012-06-26 17:38 - 2012-06-26 17:38 - 00421200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll 2012-06-26 17:38 - 2012-06-26 17:38 - 00046176 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\point64.sys 2012-06-08 21:43 - 2012-07-11 01:58 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-08 20:41 - 2012-07-11 01:58 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-06-06 16:59 - 2012-06-06 16:59 - 01070152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX 2012-06-05 22:06 - 2012-07-11 01:58 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-05 22:06 - 2012-07-11 01:58 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-05 22:02 - 2012-07-11 01:58 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-06-05 21:05 - 2012-07-11 01:58 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-06-05 21:05 - 2012-07-11 01:58 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-06-05 21:03 - 2012-07-11 01:58 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-06-03 02:34 - 2009-07-13 21:08 - 00032588 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-06-02 14:19 - 2012-06-19 03:17 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-19 03:17 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-19 03:17 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-19 03:17 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-19 03:17 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:15 - 2012-06-19 03:17 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:15 - 2012-06-19 03:17 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 11:19 - 2012-06-19 03:17 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 11:15 - 2012-06-19 03:17 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-08-30 10:32:54 ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 2035.84 MB Available physical RAM: 1448.91 MB Total Pagefile: 2035.84 MB Available Pagefile: 1450.43 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ==================== Partitions ============================ 1 Drive c: () (Fixed) (Total:465.69 GB) (Free:437.51 GB) NTFS 2 Drive e: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.24 GB) (Free:0 GB) UDF 3 Drive f: (WMM_4GB_USB) (Removable) (Total:3.84 GB) (Free:0.41 GB) FAT32 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 5 Drive y: (System Reserved) (Fixed) (Total:0.05 GB) (Free:0.02 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 465 GB 3072 KB Disk 1 Online 3936 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 54 MB 31 KB Partition 2 Primary 465 GB 54 MB Partition 3 Primary 10 MB 465 GB ================================================================================ == Disk: 0 Partition 1 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y System Rese NTFS Partition 54 MB Healthy ================================================================================ == Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C NTFS Partition 465 GB Healthy ================================================================================ == Disk: 0 Partition 3 Type : 17 (Suspicious Type) Hidden: Yes Active: Yes There is no volume associated with this partition. ================================================================================ == Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 3935 MB 16 KB ================================================================================ == Disk: 1 Partition 1 Type : 0C Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F WMM_4GB_USB FAT32 Removable 3935 MB Healthy ================================================================================ == Last Boot: 2012-08-27 03:17 ==================== End Of Log =============================
List BCD was checked when I did the scan ListParts by Farbar Version: 10-08-2012 Ran by [removed] (administrator) on 30-08-2012 at 23:14:55 Windows 7 (X64) Running From: F:\ Language: 0409 ************************************************************ ========================= Memory info ====================== Percentage of memory in use: 24% Total physical RAM: 2035.84 MB Available physical RAM: 1540.57 MB Total Pagefile: 2035.84 MB Available Pagefile: 1539.36 MB Total Virtual: 8192 MB Available Virtual: 8191.91 MB ======================= Partitions ========================= 1 Drive c: () (Fixed) (Total:465.69 GB) (Free:437.51 GB) NTFS 2 Drive e: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.24 GB) (Free:0 GB) UDF 3 Drive f: (WMM_4GB_USB) (Removable) (Total:3.84 GB) (Free:0.4 GB) FAT32 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 5 Drive y: (System Reserved) (Fixed) (Total:0.05 GB) (Free:0.02 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 465 GB 3072 KB Disk 1 Online 3936 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 54 MB 31 KB Partition 2 Primary 465 GB 54 MB Partition 3 Primary 10 MB 465 GB ================================================================================ ====================== Disk: 0 Partition 1 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y System Rese NTFS Partition 54 MB Healthy ================================================================================ ====================== Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C NTFS Partition 465 GB Healthy ================================================================================ ====================== Disk: 0 Partition 3 Type : 17 (Suspicious Type) Hidden: Yes Active: Yes There is no volume associated with this partition. ================================================================================ ====================== Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 3935 MB 16 KB ================================================================================ ====================== Disk: 1 Partition 1 Type : 0C Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F WMM_4GB_USB FAT32 Removable 3935 MB Healthy ================================================================================ ====================== The boot configuration data store could not be opened. The system cannot find the file specified. ****** End Of Log ******

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI