This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow running laptop [Closed]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

Over the past couple of months my laptop has been getting progressively slower. It is as the stage now where it is painfully slow even for the simplest operations. What I have noticed is thrashing of the hard disk. It is going what seems to be 100mph at the expense of any other operation of the laptop. After a similar problem with this computer earlier this year, I am very careful where I go and use tools such as NoScript add on on Firefox as well as M86 Security to check url's before clicking. Hopefully I can get to the bottom of what's going on. I did a scan with OTL.EXE but it only genereated the OTL.TXT file. There was no EXTRAS.TXT file generated as mentioned in http://forums.whatthetech.com/index.php?showtopic=106388.

Thanks in advance

——

OTL logfile created on: 19/09/2012 21:17:12 - Run 3
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\Phil\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19272)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1013.31 Mb Total Physical Memory | 275.56 Mb Available Physical Memory | 27.19% Memory free
2.24 Gb Paging File | 1.00 Gb Available in Paging File | 44.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 106.08 Gb Total Space | 52.01 Gb Free Space | 49.03% Space Free | Partition Type: NTFS
Drive D: | 5.71 Gb Total Space | 1.34 Gb Free Space | 23.45% Space Free | Partition Type: NTFS
Drive E: | 330.76 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive P: | 149.04 Gb Total Space | 2.74 Gb Free Space | 1.84% Space Free | Partition Type: NTFS

Computer Name: PHIL-DENISE | User Name: Phil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Phil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Phil\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe ()
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\System32\igfxTMM.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Windows\System32\btwhidcs.dll ()


========== Services (SafeList) ==========

SRV - (LiveUpdate Notice Ex) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe File not found
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (CLSched) – C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe ()
SRV - (CLCapSvc) – C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe ()
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – system32\DRIVERS\UIUSYS.SYS File not found
DRV - (speccy) – C:\Users\Phil\AppData\Local\Temp\25786b6f-14cb-48c1-974d-99019d13d4c2 File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (hwdatacard) – system32\DRIVERS\ewusbmdm.sys File not found
DRV - (cpuz135) – C:\Users\Phil\AppData\Local\Temp\cpuz135\cpuz135_x32.sys File not found
DRV - (CFcatchme) – C:\Users\Phil\AppData\Local\Temp\CFcatchme.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (klbg) – C:\Windows\System32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (cmusbnet) – C:\Windows\System32\drivers\cmusbnet.sys (Cmotech Co., Ltd)
DRV - (cmusbser) – C:\Windows\System32\drivers\cmusbser.sys (Cmotech Co.,Ltd)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (eabfiltr) – C:\Windows\System32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2418376

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\SearchScopes,DefaultScope = {989A4ABD-9CD8-4E1F-886E-4ACB4C41CCF2}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{989A4ABD-9CD8-4E1F-886E-4ACB4C41CCF2}: "URL" = http://search.yahoo.com/search?p={searchTe…-8&fr;=b2ie7
IE - HKCU\..\SearchScopes\{D78D61D8-764B-41AA-9F58-3F961CDECCF3}: "URL" = http://websearch.ask.com/redirect?client=i…00-04E104190768
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: [removed]:2.2.1.829
FF - prefs.js..extensions.enabledAddons: [removed]:2.1.2
FF - prefs.js..extensions.enabledAddons: [removed]:2.00
FF - prefs.js..extensions.enabledAddons: [removed]:4.1.2
FF - prefs.js..extensions.enabledAddons: [removed]:3.504
FF - prefs.js..extensions.enabledAddons: [removed]:6.502
FF - prefs.js..extensions.enabledAddons: {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}:1.8.1
FF - prefs.js..extensions.enabledAddons: {d37dc5d0-431d-44e5-8c91-49419370caa1}:3.1.25
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.5
FF - prefs.js..extensions.enabledItems: [removed]:2.1.2
FF - prefs.js..extensions.enabledItems: {d37dc5d0-431d-44e5-8c91-49419370caa1}:2.7.82
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:4.0.0
FF - prefs.js..extensions.enabledItems: [removed]:9.0.0.736
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Phil\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Phil\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Phil\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/07 20:50:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/19 13:28:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2011/03/21 18:37:11 | 000,000,000 | —D | M]

[2008/10/05 17:20:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Extensions
[2012/09/14 20:16:05 | 000,000,000 | —D | M] (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions
[2012/09/04 18:10:47 | 000,000,000 | —D | M] (FoxClocks) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012/09/01 20:16:06 | 000,000,000 | —D | M] (DoNotTrackPlus) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2011/06/04 17:47:13 | 000,000,000 | —D | M] (English (Australian) Dictionary) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/09/02 19:11:24 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/06/14 19:17:33 | 000,000,000 | —D | M] (M86Security Secure Browsing) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/08/28 19:12:14 | 000,230,013 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/04/29 20:08:32 | 000,141,229 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/07/22 20:27:57 | 000,049,607 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
[2012/09/14 20:16:05 | 000,527,915 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/08/30 04:56:22 | 000,007,915 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]\chrome\content\ff\view_expiry.js
[2012/01/03 16:27:44 | 000,002,333 | —- | M] () – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\searchplugins\askcom.xml
[2012/09/03 19:28:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/21 18:38:45 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/09/25 14:45:56 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/09/07 20:50:43 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/21 19:25:22 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/09/07 20:50:35 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/21 19:25:22 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/06/21 19:25:22 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/09/07 20:50:35 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/06/21 19:25:22 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - homepage: about:blank
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: about:blank
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Phil\AppData\Local\Google\Chrome\Application\21.0.1180.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Phil\AppData\Local\Google\Chrome\Application\21.0.1180.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Phil\AppData\Local\Google\Chrome\Application\21.0.1180.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Phil\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Phil\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: EXIF Viewer = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\lplmljfembbkocngnlkkdgabpnfokmnl\2.1.5_0\
CHR - Extension: EXIF Viewer = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\lplmljfembbkocngnlkkdgabpnfokmnl\2.1.9_0\
CHR - Extension: Gmail = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/05/06 09:52:08 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - Startup: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Phil\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: &Virtual; keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx (ArmHelper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{312783A5-2092-4A9A-B688-3172EEC467D7}: DhcpNameServer = 10.0.0.138
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Users\Phil\Pictures\Wallpaper\dscf5879.jpg
O24 - Desktop BackupWallPaper: C:\Users\Phil\Pictures\Wallpaper\dscf5879.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/22 05:00:07 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 23:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O32 - AutoRun File - [1999/09/02 02:15:08 | 000,000,051 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2008/12/18 05:38:46 | 000,000,013 | —- | M] () - P:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivXNetworks, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/19 21:14:50 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Users\Phil\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/09/19 21:35:00 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{262EF333-8AD9-4D3F-BAC2-9C1A14ACD25C}.job
[2012/09/19 21:13:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Phil\Desktop\OTL.exe
[2012/09/19 21:04:27 | 000,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/19 21:04:27 | 000,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/19 20:53:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/19 20:41:46 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887573329-3531065527-3000446172-1000UA.job
[2012/09/19 19:41:45 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887573329-3531065527-3000446172-1000Core.job
[2012/09/19 19:04:30 | 000,016,384 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2012/09/19 19:04:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/19 19:04:20 | 1061,236,736 | -HS- | M] () – C:\hiberfil.sys
[2012/09/18 21:25:36 | 000,005,332 | —- | M] () – C:\Windows\bthservsdp.dat
[2012/09/12 18:42:20 | 149,363,456 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/09/09 15:56:43 | 000,018,910 | —- | M] () – C:\Users\Phil\Documents\Clipboard03.jpg
[2012/09/09 15:53:07 | 000,085,027 | —- | M] () – C:\Users\Phil\Documents\Clipboard02.jpg
[2012/09/09 14:31:40 | 000,696,520 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/09/09 14:31:40 | 000,073,416 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/09/05 19:59:44 | 000,002,052 | —- | M] () – C:\Users\Phil\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/25 20:58:27 | 000,027,853 | —- | M] () – C:\Users\Phil\Documents\Clipboard01.jpg

========== Files Created - No Company Name ==========

[2012/09/09 15:56:43 | 000,018,910 | —- | C] () – C:\Users\Phil\Documents\Clipboard03.jpg
[2012/09/09 15:53:07 | 000,085,027 | —- | C] () – C:\Users\Phil\Documents\Clipboard02.jpg
[2012/08/25 20:58:27 | 000,027,853 | —- | C] () – C:\Users\Phil\Documents\Clipboard01.jpg
[2012/01/15 11:51:36 | 000,016,384 | —- | C] () – C:\Windows\System32\winets2.dll
[2011/03/22 03:19:18 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2011/03/22 03:15:46 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2011/03/22 03:15:46 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/03/21 18:38:20 | 000,116,189 | —- | C] () – C:\Windows\System32\drivers\klin.dat
[2011/03/21 18:38:19 | 000,098,168 | —- | C] () – C:\Windows\System32\drivers\klick.dat
[2009/09/27 16:03:29 | 000,000,058 | -H– | C] () – C:\ProgramData\Ts_infos.ini
[2007/08/07 06:56:45 | 000,005,676 | —- | C] () – C:\Users\Phil\AppData\Local\d3d9caps.dat
[2007/06/23 18:03:16 | 000,026,546 | —- | C] () – C:\Users\Phil\AppData\Roaming\UserTile.png
[2007/05/06 20:47:44 | 000,012,800 | —- | C] () – C:\Users\Phil\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/06 18:17:57 | 000,000,000 | —- | C] () – C:\Users\Phil\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2006/11/02 20:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

========== LOP Check ==========

[2011/03/19 22:41:01 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\92429
[2008/01/31 05:09:22 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\Beep Industries
[2012/09/19 19:08:02 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\Dropbox
[2007/05/24 13:57:21 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\Forte
[2007/12/01 09:37:18 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\FUJIFILM
[2010/07/14 21:45:32 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\IrfanView
[2008/01/31 09:05:29 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\muvee Technologies
[2008/05/10 08:45:37 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\PeerNetworking
[2011/03/28 21:10:18 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\Simple Sudoku
[2011/08/27 21:03:26 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\SpinTop
[2007/05/06 18:17:56 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\Template
[2011/09/25 19:57:05 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\Unity
[2011/02/26 16:14:13 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\WinPatrol
[2007/05/03 18:59:43 | 000,000,000 | —D | M] – C:\Users\Phil\AppData\Roaming\ZagZag

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/12/28 14:27:55 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/12/28 14:27:54 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/12/28 14:27:54 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/12/19 09:08:18 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007/12/19 09:08:16 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\ERDNT\cache\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2011/02/26 12:26:06 | 007,734,208 | —- | M] (Malwarebytes Corporation ) MD5=DF7507AAF7991CE25565CB9175B166E2 – C:\Documents and Settings\Public\Archive\utils\Security\explorer.exe
[2011/02/26 12:26:06 | 007,734,208 | —- | M] (Malwarebytes Corporation ) MD5=DF7507AAF7991CE25565CB9175B166E2 – C:\Users\Public\Archive\utils\Security\explorer.exe
[2008/12/28 14:27:55 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 17:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/18 23:33:12 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 20:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 20:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2012/09/19 19:06:50 | 000,171,478 | —- | M] () MD5=E37EA9583F6B6A701B293C2F7E7FE6A3 – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf

< MD5 for: IEXPLORE.EXE >
[2012/02/28 19:33:51 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=00A346CE3D3701EA085E87EEF746A74A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19222_none_123762452fda50e6\iexplore.exe
[2010/01/13 22:05:39 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=03EF289E8F82CBC4E492658864C7C51A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22550_none_2fb594d03344a0e4\iexplore.exe
[2011/07/23 19:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2008/10/25 09:41:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2009/09/25 14:39:07 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D5A01AA2DE47C052AF46D7EBCB003A3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16890_none_2d1a75e31d20e59f\iexplore.exe
[2009/09/25 14:38:51 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D8163DBFECAEDB9C48C5F55084BC491 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18294_none_2f04b5b11a43dbec\iexplore.exe
[2010/04/20 10:10:28 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=259E27152180B895DF395ED3E412B90E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.17037_none_2d6231791cea1fc3\iexplore.exe
[2012/05/15 16:57:00 | 000,638,048 | —- | M] (Microsoft Corporation) MD5=26B900640CE979A708FD3793FA8A6C50 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23359_none_12a791524909f5e4\iexplore.exe
[2007/09/27 15:52:58 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16512_none_2d72f0251cde4150\iexplore.exe
[2011/11/03 15:33:09 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=2A268DF89913A0E927091077878EDB3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23266_none_1299bea24914c8a9\iexplore.exe
[2009/04/10 23:27:46 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2010/12/20 23:42:20 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=4319F2A5C725D9E0B9E01744E02D32BE – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18565_none_2f262b711a2a98e5\iexplore.exe
[2007/12/18 22:01:59 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4C1528C481FFE6E4EFE4BAC7271CE251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20697_none_2dab0f0236383f55\iexplore.exe
[2008/12/28 14:26:28 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 19:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2010/01/13 22:05:56 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16945_none_2d5588d71cf3d5c4\iexplore.exe
[2011/12/15 15:36:29 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=54EF418BD99720658CCE24210799BD1A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23286_none_12841eca4925008b\iexplore.exe
[2008/01/18 23:33:14 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2008/10/25 09:41:00 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2010/04/20 10:10:10 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=67C769016A79E6FC65D1755E5D6ADAB3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22653_none_2fb897943341ea10\iexplore.exe
[2007/12/18 22:01:59 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=7023BC3AF58F0C47856AF147E290D81A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16575_none_2d35117b1d0c34fb\iexplore.exe
[2010/04/20 10:10:10 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=74E60C93D1C9A40354D839776CCF53DF – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18444_none_2f3ac9191a1b4a85\iexplore.exe
[2010/12/18 15:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2010/01/13 22:05:39 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=79B60CC26404F8FC2B351A7551D93C17 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18349_none_2f3fc8a51a16cc11\iexplore.exe
[2011/05/28 15:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2009/09/25 14:39:07 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=7FCF4E704A48D95202F3E7A1E1A21412 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21089_none_2db7bd56362e80c9\iexplore.exe
[2010/01/13 22:05:55 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21148_none_2de1fea2360ef4d5\iexplore.exe
[2006/11/02 17:45:14 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=8308F01F27DF839E0010B0F72F855E35 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16386_none_2d2b3e0d1d136ff5\iexplore.exe
[2010/04/20 10:10:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=97496AA4590CB101EF990060F7055F3D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21242_none_2ddbfecc361459f2\iexplore.exe
[2012/05/15 14:37:18 | 000,638,048 | —- | M] (Microsoft Corporation) MD5=9AC31470779A703021C337FD83D683EE – C:\Program Files\Internet Explorer\iexplore.exe
[2012/05/15 14:37:18 | 000,638,048 | —- | M] (Microsoft Corporation) MD5=9AC31470779A703021C337FD83D683EE – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19272_none_120152a93002dc9b\iexplore.exe
[2011/12/15 14:22:33 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=AB18B8902C06954F8DFBAC5C6DC7E1E8 – C:\Windows\ERDNT\cache\iexplore.exe
[2011/12/15 14:22:33 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=AB18B8902C06954F8DFBAC5C6DC7E1E8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19190_none_11e9b0573014e4a8\iexplore.exe
[2010/12/20 23:29:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B021EBF2A5344FF71A641B2EFDAF813E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22816_none_2fe6dbee331ec09f\iexplore.exe
[2009/03/09 05:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/18 14:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2007/09/27 15:52:59 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20627_none_2df6be7635ff7bbe\iexplore.exe
[2011/02/18 23:23:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=BECD30E162ACFD7A04B1F87FBBAFF70E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22857_none_2fbc9c88333e49ba\iexplore.exe
[2011/02/18 23:49:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C84ABBF7D7AF2F7D004D800D10430FF5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18602_none_2f640c0119fca261\iexplore.exe
[2011/11/03 14:23:19 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CCDB0B2D1F2E016966B1DB1097E24842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19170_none_11ff502f3004acc6\iexplore.exe
[2012/02/29 02:09:50 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CF4EFFB58D9D91E8D219C8E93BC59471 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23318_none_12d1d0b848ea6cc9\iexplore.exe
[2008/12/28 14:26:29 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2009/09/25 14:38:51 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=EBEE9E4421F35CD861107DDA0266FBB1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22475_none_2fa4f48433505a52\iexplore.exe
[2011/05/28 14:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 20:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2009/03/09 05:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/09 05:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui

< MD5 for: SERVICES >
[2006/09/19 05:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/19 05:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.CFG >
[2012/07/28 04:51:34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2008/01/18 23:33:30 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006/11/02 17:45:40 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009/04/10 23:28:00 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\ERDNT\cache\services.exe
[2009/04/10 23:28:00 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/10 23:28:00 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 20:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 20:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/03/21 23:23:27 | 000,001,688 | —- | M] () MD5=7B27BF6C41148D5F482247DAA6D72B3E – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
File not found Unable to obtain MD5 – C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
File not found Unable to obtain MD5 – C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2011/09/15 20:35:35 | 000,000,306 | —- | M] () MD5=89251669BCA24FE932BD88DC2D208003 – C:\Documents and Settings\Phil\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LBXWGAVV\mochiads.com\services.mochiads.com.sol
[2011/09/15 20:35:35 | 000,000,306 | —- | M] () MD5=89251669BCA24FE932BD88DC2D208003 – C:\Users\Phil\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LBXWGAVV\mochiads.com\services.mochiads.com.sol

< MD5 for: SERVICES.MOF >
[2006/09/19 05:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/19 05:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2006/09/19 05:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/19 05:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 20:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/19 05:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 20:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/19 05:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6000.16386_none_cd2d20a848cfd40f\services.msc
[2006/09/19 05:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 17:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/18 23:33:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/18 23:40:58 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/18 23:40:58 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 20:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.MOF >
[2006/09/19 05:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/19 05:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2006/11/02 17:46:04 | 000,614,400 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.fastprox.dll.01ca2abb5d8f0605.000a
[2008/12/28 14:26:27 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.iertutil.dll.01ca2abb5aa38ee9.0002
[2006/11/02 17:46:05 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.kerberos.dll.01ca2abb5dd1ad2d.000d
[2006/11/02 17:46:05 | 000,874,496 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.kernel32.dll.01ca2abb5bf0d2b1.0006
[2007/09/27 16:03:08 | 000,694,784 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.localspl.dll.01ca2abb5e38094f.0010
[2006/11/02 17:46:05 | 001,233,408 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.lsasrv.dll.01ca2abb5bee714b.0005
[2006/11/02 17:45:21 | 000,007,680 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.lsass.exe.01ca2abb5be4ebb3.0004
[2006/11/02 17:46:10 | 000,213,504 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.msv1_0.dll.01ca2abb5de256f7.000e
[2007/09/27 15:54:40 | 000,123,904 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.msvfw32.dll.01ca2abb5e0f9189.000f
[2006/11/02 17:46:12 | 000,545,792 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.rpcss.dll.01ca2abb5cef8853.0008
[2007/09/27 15:54:47 | 000,269,824 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.schannel.dll.01ca2abb5583ec5f.0000
[2006/11/02 17:46:12 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.secur32.dll.01ca2abb5c3379d9.0007
[2008/12/28 14:26:28 | 001,160,192 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.urlmon.dll.01ca2abb59b321ab.0001
[2006/11/02 17:46:13 | 000,168,448 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.wdigest.dll.01ca2abb5db77dcb.000c
[2008/12/28 14:26:45 | 000,826,368 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.wininet.dll.01ca2abb5b3262d1.0003
[2006/11/02 17:46:14 | 000,156,160 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.wkssvc.dll.01ca2abb5e784f11.0011
[2006/11/02 17:46:14 | 000,485,888 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.WmiPrvSD.dll.01ca2abb5d9d4e69.000b
[2006/11/02 17:46:00 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\$$DeleteMe.WmiPrvSE.exe.01ca2abb5d7bfad5.0009
[2006/12/22 05:00:07 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2012/05/06 10:01:34 | 000,012,558 | —- | M] () – C:\ComboFix.txt
[2006/09/19 05:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/03/26 02:15:19 | 000,000,000 | —- | M] () – C:\FileIn.Cns
[2008/03/26 02:15:19 | 000,000,000 | —- | M] () – C:\FileOut.Cns
[2012/09/19 19:04:20 | 1061,236,736 | -HS- | M] () – C:\hiberfil.sys
[2007/06/23 23:57:28 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/19 22:51:54 | 000,011,044 | —- | M] () – C:\log.txt
[2007/06/23 23:57:28 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/10/15 20:09:37 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2008/10/15 20:09:37 | 000,005,120 | -H– | M] () – C:\ntuser.dat.LOG1
[2008/07/18 21:07:01 | 000,000,000 | -H– | M] () – C:\ntuser.dat.LOG2
[2008/07/18 21:07:01 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{464e85aa-54b4-11dd-9e18-dbd29cfab847}.TM.blf
[2008/07/18 21:07:01 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{464e85aa-54b4-11dd-9e18-dbd29cfab847}.TMContainer00000000000000000001.regtrans-ms
[2008/07/18 21:07:01 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{464e85aa-54b4-11dd-9e18-dbd29cfab847}.TMContainer00000000000000000002.regtrans-ms
[2008/07/18 21:07:02 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{464e85ae-54b4-11dd-9e18-dbd29cfab847}.TM.blf
[2008/07/18 21:07:02 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{464e85ae-54b4-11dd-9e18-dbd29cfab847}.TMContainer00000000000000000001.regtrans-ms
[2008/07/18 21:07:02 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{464e85ae-54b4-11dd-9e18-dbd29cfab847}.TMContainer00000000000000000002.regtrans-ms
[2012/09/19 19:04:18 | 1377,107,968 | -HS- | M] () – C:\pagefile.sys
[2008/09/18 23:47:11 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2008/09/19 23:10:31 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2008/09/23 23:29:48 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2008/09/24 23:00:04 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2008/10/02 17:43:44 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2008/10/03 11:24:13 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2008/11/07 18:43:50 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2008/11/24 20:34:07 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2008/11/28 15:32:50 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2008/12/07 21:27:21 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2008/12/11 21:52:21 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2008/12/13 00:20:46 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2008/12/23 20:48:19 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2008/06/07 13:46:36 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2008/08/23 11:47:14 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2008/08/24 21:34:02 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2008/08/25 21:58:19 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2008/08/26 21:51:49 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2008/08/30 00:34:24 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2008/09/17 21:54:34 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2008/09/18 23:47:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/09/19 23:10:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/09/23 23:29:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/09/24 23:00:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/10/02 17:43:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/10/03 11:24:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/11/07 18:43:50 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/11/24 20:34:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/11/28 15:32:50 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/12/07 21:27:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/12/11 21:52:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2008/12/13 00:20:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2008/12/23 20:48:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2008/06/07 13:46:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2008/08/23 11:47:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2008/08/24 21:34:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2008/08/25 21:58:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2008/08/26 21:51:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2008/08/30 00:34:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2008/09/17 21:54:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2007/06/15 20:20:00 | 000,911,032 | —- | M] () – C:\TB.log
[2010/07/14 21:50:53 | 017,028,503 | -H– | M] () – C:\treeinfo.wc
[2008/12/28 17:03:21 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 20:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 20:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 20:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2011/03/22 03:49:35 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/19 05:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 17:46:03 | 000,070,144 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNBPP3.DLL
[2006/11/02 20:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2007/04/09 11:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/03/21 23:24:15 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 18:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 18:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 18:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 18:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 18:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/04 20:18:07 | 000,000,286 | -HS- | M] () – C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/09/19 21:13:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Phil\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-15 08:51:13

========== Alternate Data Streams ==========

@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:DA18FD1D
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:211ED887

< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
G'day Jeff, Thanks for helping out :) Here's the aswMBR.txt file: —— aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-09-20 19:27:13 —————————– 19:27:13.236 OS Version: Windows 6.0.6002 Service Pack 2 19:27:13.236 Number of processors: 2 586 0xE0C 19:27:13.236 ComputerName: PHIL-DENISE UserName: Phil 19:30:31.591 Initialize success 19:32:31.982 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 19:32:31.982 Disk 0 Vendor: ST9120821AS 7.24 Size: 114473MB BusType: 3 19:32:32.013 Disk 0 MBR read successfully 19:32:32.029 Disk 0 MBR scan 19:32:32.029 Disk 0 unknown MBR code 19:32:32.029 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 108626 MB offset 63 19:32:32.060 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 5843 MB offset 222468120 19:32:32.075 Disk 0 scanning sectors +234436545 19:32:32.153 Disk 0 scanning C:\Windows\system32\drivers 19:32:44.699 Service scanning 19:33:20.547 Modules scanning 19:34:07.474 Disk 0 trace - called modules: 19:34:07.521 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll 19:34:07.521 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8759eac8] 19:34:07.537 3 CLASSPNP.SYS[891ac8b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-2[0x86f05990] 19:34:07.552 Scan finished successfully 19:34:49.995 Disk 0 MBR has been saved successfully to "C:\Users\Phil\Desktop\MBR.dat" 19:34:50.042 The log file has been saved successfully to "C:\Users\Phil\Desktop\aswMBR.txt"
Hi,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :OTL
    PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2418376
    IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
    IE - HKCU\..\SearchScopes\{D78D61D8-764B-41AA-9F58-3F961CDECCF3}: "URL" = http://websearch.ask.com/redirect?client=i…00-04E104190768
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Ask.com"
    FF - prefs.js..browser.search.order.1: "Ask.com"
    [2012/08/28 19:12:14 | 000,230,013 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
    [2012/01/03 16:27:44 | 000,002,333 | —- | M] () – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\searchplugins\askcom.xml
    [2012/09/07 20:50:35 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
    O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
    [2007/05/06 20:47:44 | 000,012,800 | —- | C] () – C:\Users\Phil\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    :Files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-
All done as recommended. Here is the latest otl.txt file:

——

OTL logfile created on: 21/09/2012 22:46:23 - Run 4
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\Phil\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19272)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1013.31 Mb Total Physical Memory | 160.13 Mb Available Physical Memory | 15.80% Memory free
2.24 Gb Paging File | 1.14 Gb Available in Paging File | 51.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 106.08 Gb Total Space | 51.09 Gb Free Space | 48.17% Space Free | Partition Type: NTFS
Drive D: | 5.71 Gb Total Space | 1.34 Gb Free Space | 23.45% Space Free | Partition Type: NTFS
Drive E: | 330.76 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PHIL-DENISE | User Name: Phil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Phil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Phil\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe ()
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\igfxTMM.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Windows\System32\btwhidcs.dll ()


========== Services (SafeList) ==========

SRV - (LiveUpdate Notice Ex) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe File not found
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (CLSched) – C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe ()
SRV - (CLCapSvc) – C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe ()
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – system32\DRIVERS\UIUSYS.SYS File not found
DRV - (speccy) – C:\Users\Phil\AppData\Local\Temp\25786b6f-14cb-48c1-974d-99019d13d4c2 File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (hwdatacard) – system32\DRIVERS\ewusbmdm.sys File not found
DRV - (cpuz135) – C:\Users\Phil\AppData\Local\Temp\cpuz135\cpuz135_x32.sys File not found
DRV - (CFcatchme) – C:\Users\Phil\AppData\Local\Temp\CFcatchme.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (klbg) – C:\Windows\System32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (cmusbnet) – C:\Windows\System32\drivers\cmusbnet.sys (Cmotech Co., Ltd)
DRV - (cmusbser) – C:\Windows\System32\drivers\cmusbser.sys (Cmotech Co.,Ltd)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (eabfiltr) – C:\Windows\System32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {989A4ABD-9CD8-4E1F-886E-4ACB4C41CCF2}
IE - HKCU\..\SearchScopes\{989A4ABD-9CD8-4E1F-886E-4ACB4C41CCF2}: "URL" = http://search.yahoo.com/search?p={searchTe…-8&fr;=b2ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: [removed]:2.2.1.829
FF - prefs.js..extensions.enabledAddons: [removed]:2.1.2
FF - prefs.js..extensions.enabledAddons: [removed]:4.1.2
FF - prefs.js..extensions.enabledAddons: [removed]:3.504
FF - prefs.js..extensions.enabledAddons: [removed]:6.502
FF - prefs.js..extensions.enabledAddons: {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}:1.8.1
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.5
FF - prefs.js..extensions.enabledAddons: {d37dc5d0-431d-44e5-8c91-49419370caa1}:3.1.26
FF - prefs.js..extensions.enabledItems: [removed]:2.1.2
FF - prefs.js..extensions.enabledItems: {d37dc5d0-431d-44e5-8c91-49419370caa1}:2.7.82
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:4.0.0
FF - prefs.js..extensions.enabledItems: [removed]:9.0.0.736
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Phil\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Phil\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Phil\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/07 20:50:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/19 13:28:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2011/03/21 18:37:11 | 000,000,000 | —D | M]

[2008/10/05 17:20:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Extensions
[2012/09/21 21:40:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions
[2012/09/21 21:29:45 | 000,000,000 | —D | M] (FoxClocks) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012/09/01 20:16:06 | 000,000,000 | —D | M] (DoNotTrackPlus) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2011/06/04 17:47:13 | 000,000,000 | —D | M] (English (Australian) Dictionary) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/09/02 19:11:24 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/06/14 19:17:33 | 000,000,000 | —D | M] (M86Security Secure Browsing) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/04/29 20:08:32 | 000,141,229 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]
[2012/07/22 20:27:57 | 000,049,607 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
[2012/09/14 20:16:05 | 000,527,915 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/08/30 04:56:22 | 000,007,915 | —- | M] () (No name found) – C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\extensions\[removed]\chrome\content\ff\view_expiry.js
[2012/09/03 19:28:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/21 18:38:45 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/09/25 14:45:56 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/09/07 20:50:43 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/21 19:25:22 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/06/21 19:25:22 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/06/21 19:25:22 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/09/07 20:50:35 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/06/21 19:25:22 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - homepage: about:blank
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: about:blank
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Phil\AppData\Local\Google\Chrome\Application\21.0.1180.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Phil\AppData\Local\Google\Chrome\Application\21.0.1180.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Phil\AppData\Local\Google\Chrome\Application\21.0.1180.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Phil\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Phil\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: EXIF Viewer = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\lplmljfembbkocngnlkkdgabpnfokmnl\2.1.5_0\
CHR - Extension: EXIF Viewer = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\lplmljfembbkocngnlkkdgabpnfokmnl\2.1.9_0\
CHR - Extension: Gmail = C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/05/06 09:52:08 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - Startup: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Phil\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: &Virtual; keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx (ArmHelper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{312783A5-2092-4A9A-B688-3172EEC467D7}: DhcpNameServer = 10.0.0.138
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Users\Phil\Pictures\Wallpaper\dscf5879.jpg
O24 - Desktop BackupWallPaper: C:\Users\Phil\Pictures\Wallpaper\dscf5879.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/22 05:00:07 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 23:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O32 - AutoRun File - [1999/09/02 02:15:08 | 000,000,051 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/21 21:38:44 | 000,000,000 | —D | C] – C:\_OTL
[2012/09/20 19:23:07 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Phil\Desktop\aswMBR.exe
[2012/09/19 21:14:50 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Users\Phil\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/09/21 23:05:09 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{262EF333-8AD9-4D3F-BAC2-9C1A14ACD25C}.job
[2012/09/21 22:52:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/21 22:41:01 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887573329-3531065527-3000446172-1000UA.job
[2012/09/21 22:20:26 | 000,016,384 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2012/09/21 22:20:25 | 000,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/21 22:20:25 | 000,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/21 22:20:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/21 22:20:16 | 1063,313,408 | -HS- | M] () – C:\hiberfil.sys
[2012/09/21 22:18:29 | 000,005,332 | —- | M] () – C:\Windows\bthservsdp.dat
[2012/09/20 19:41:02 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887573329-3531065527-3000446172-1000Core.job
[2012/09/20 19:34:50 | 000,000,512 | —- | M] () – C:\Users\Phil\Desktop\MBR.dat
[2012/09/20 19:25:18 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Phil\Desktop\aswMBR.exe
[2012/09/19 21:13:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Phil\Desktop\OTL.exe
[2012/09/12 18:42:20 | 149,363,456 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/09/09 15:56:43 | 000,018,910 | —- | M] () – C:\Users\Phil\Documents\Clipboard03.jpg
[2012/09/09 15:53:07 | 000,085,027 | —- | M] () – C:\Users\Phil\Documents\Clipboard02.jpg
[2012/09/09 14:31:40 | 000,696,520 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/09/09 14:31:40 | 000,073,416 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/09/05 19:59:44 | 000,002,052 | —- | M] () – C:\Users\Phil\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/25 20:58:27 | 000,027,853 | —- | M] () – C:\Users\Phil\Documents\Clipboard01.jpg

========== Files Created - No Company Name ==========

[2012/09/20 19:34:49 | 000,000,512 | —- | C] () – C:\Users\Phil\Desktop\MBR.dat
[2012/09/09 15:56:43 | 000,018,910 | —- | C] () – C:\Users\Phil\Documents\Clipboard03.jpg
[2012/09/09 15:53:07 | 000,085,027 | —- | C] () – C:\Users\Phil\Documents\Clipboard02.jpg
[2012/08/25 20:58:27 | 000,027,853 | —- | C] () – C:\Users\Phil\Documents\Clipboard01.jpg
[2012/01/15 11:51:36 | 000,016,384 | —- | C] () – C:\Windows\System32\winets2.dll
[2011/03/22 03:19:18 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2011/03/22 03:15:46 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2011/03/22 03:15:46 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/03/21 18:38:20 | 000,116,189 | —- | C] () – C:\Windows\System32\drivers\klin.dat
[2011/03/21 18:38:19 | 000,098,168 | —- | C] () – C:\Windows\System32\drivers\klick.dat
[2009/09/27 16:03:29 | 000,000,058 | -H– | C] () – C:\ProgramData\Ts_infos.ini
[2007/08/07 06:56:45 | 000,005,676 | —- | C] () – C:\Users\Phil\AppData\Local\d3d9caps.dat
[2007/06/23 18:03:16 | 000,026,546 | —- | C] () – C:\Users\Phil\AppData\Roaming\UserTile.png
[2007/05/06 18:17:57 | 000,000,000 | —- | C] () – C:\Users\Phil\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2006/11/02 20:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:DA18FD1D
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:211ED887

< End of report >
Hi,

Good job!

When you originally ran OTL there was a log created Extras.txt Could you post that please?

Let me know how your system is running now as well.

Hi,

When you originally ran OTL there was a log created Extras.txt Could you post that please?


There was no Extras.txt file created in the original scan. I've just searched the hard disk and there is no file by that name anywhere on it.

Let me know how your system is running now as well.


It is running faster and the disk thrashing is not quite as pronounced as before. Not quite 100% but getting there :)
Hi,

Please open OTL.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the Extra Registry section change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open 2 notepad windows, OTL.Txt and Extra.txt. Please post the Extra.txt.
———-
G'Day Jeff,

Here is the Extras.txt file:

——

OTL Extras logfile created on: 22/09/2012 10:02:20 - Run 5
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\Phil\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19272)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1013.31 Mb Total Physical Memory | 567.76 Mb Available Physical Memory | 56.03% Memory free
2.24 Gb Paging File | 1.33 Gb Available in Paging File | 59.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 106.08 Gb Total Space | 50.99 Gb Free Space | 48.07% Space Free | Partition Type: NTFS
Drive D: | 5.71 Gb Total Space | 1.34 Gb Free Space | 23.45% Space Free | Partition Type: NTFS
Drive E: | 330.76 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive P: | 149.04 Gb Total Space | 2.73 Gb Free Space | 1.83% Space Free | Partition Type: NTFS

Computer Name: PHIL-DENISE | User Name: Phil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = batfile] – "%1" %*
.chm [@ = chm.file] – C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] – "%1" %*
.com [@ = comfile] – "%1" %*
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = exefile] – "%1" %*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\Windows\System32\mshta.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Users\Phil\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
.inf [@ = inffile] – C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*
.reg [@ = regfile] – C:\Windows\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] – "%1" /S
.txt [@ = txtfile] – C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\Windows\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12FDD819-57B5-4EEC-9EBB-789988BEBA0E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{23B181C8-13A8-460C-9BED-8EB03289E550}" = lport=2869 | protocol=6 | dir=in | app=system |
"{39C5DA99-40AA-46A6-9C71-0EAD18A87EA0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{52864F27-F61E-4C88-A777-B40E9A570355}" = lport=2869 | protocol=6 | dir=in | app=system |
"{63588FF1-461D-4370-A5C3-901885738003}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6A129ED7-1633-4C5F-8065-4159F0942543}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6BA46ECC-1CE3-48B4-AF74-B23ACC61001B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7D6E43AA-67C3-4289-89CD-B1FE8BC410CA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{82C4970D-2531-45CA-97F0-B5985627A322}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8FFB856E-AE49-46BA-93F5-D442AD046374}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{B8C3CCA1-B5D4-4178-B236-D93E0D9EAAC3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C5AE3B2A-53EF-4489-B334-543C66404989}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D7F6226A-5864-4CD0-A3BD-E84B6130B020}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DE9D769D-E24C-4AA3-AFD3-9C0A6FE532CD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0350DA5B-C08F-4919-A364-D8A80527943F}" = protocol=58 | dir=out | app=system |
"{19578B65-6D68-41EA-A273-A90C615CD53E}" = protocol=58 | dir=out | app=system |
"{1F6D5B3B-56A3-4779-8344-9EE54E095D7B}" = protocol=58 | dir=out | app=system |
"{25892A5D-66F9-42B1-BE87-6BA1EBC1DF82}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{4E573F77-9A68-4D15-960B-AE2CF3FA0BC4}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{53DB03A6-CBCF-4112-AE34-BD1BAC1BC5BE}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{5424D70C-FCD8-4433-94CA-7A194692BC3F}" = protocol=58 | dir=out | app=system |
"{59B7B5FA-9EE9-4A53-A87C-C669E462D9A3}" = protocol=58 | dir=out | app=system |
"{5A7AE59B-7062-4614-B39D-650D6C52D730}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{62C2B726-371A-4147-99B0-51C7CF605B6D}" = protocol=58 | dir=out | app=system |
"{6B92050C-8E91-4B31-BE46-98FBC9F439C8}" = protocol=58 | dir=out | app=system |
"{6FF3783D-B1D4-4AE7-AB88-98268371A20E}" = protocol=17 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{73E0E1A5-5A8E-4D4D-B72D-45BFA6E97D3A}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{74C5834E-ECFF-4FA6-9362-F610A8E2B58D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{7952C63B-606C-41BA-8F98-FA1060469C25}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{8A5CC56C-63DC-4591-AB27-A9F9C500CFF2}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{8ADC055F-671A-4EC5-AFB3-D76D1008951D}" = protocol=58 | dir=out | app=system |
"{93C63974-B8D8-4CC0-991B-58B0EFE64857}" = protocol=58 | dir=out | app=system |
"{9AF0A473-7768-43D3-BE88-5D1531090A87}" = protocol=58 | dir=out | app=system |
"{9E91E27F-EA59-4593-9497-A632A879D8D2}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{A5147B9D-8BAD-4AF8-8832-8BE17AE3BA97}" = protocol=6 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{AF649F70-8038-433E-B334-B8E7B6CE058A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{B255CF0E-6EC9-49ED-A069-8256469DC628}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{B773C481-9296-46F0-A5F7-26AB456A6444}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{C3B1735D-4572-4746-8C04-90C3B5095A52}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{CF611841-8D4A-470D-8B04-B918B8AFC1E6}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{CF7A3626-216A-46A3-998B-03740072E6A7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D2769E3C-E1F7-4A57-ADF0-589BF445EFE2}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{DB1E4E81-7707-4BB8-B3D8-83C1D5D44D9E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DC169521-4627-4A8F-9DA4-D78DE5B57BA2}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{E0F35ABE-2191-49EA-8345-E16256723525}" = protocol=58 | dir=out | app=system |
"{E194CDD2-6DA3-489B-AAD1-03964D0A71CF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F0E724D5-36D3-48F6-9213-CA9DD56E248B}" = protocol=58 | dir=out | app=system |
"{F27EEB4D-97BE-41A1-811F-183EEBD20D50}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{F91E09D0-F96D-4C6E-AC83-F383A01747AE}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"TCP Query User{825C7017-7266-4489-99D4-F2907D63BFF9}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{BDCE27A3-A5E8-44C2-8655-F37C68B13437}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{D0190EC6-A73F-43AF-A749-C54030ADCEF3}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{02383116-42A1-4BE2-ACEF-9BFAF2BEE21F}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{93C1C8A4-80F9-4F65-8255-517E8C0626A2}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{CF76B78F-1F31-4108-9365-AB4D80B31879}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02F33FB0-F7D5-4C0A-B4AD-8CE5CE230BBE}" = HP Wireless Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21E62565-8639-457C-B64C-A3FF0A8B4D80}" = HP Active Support Library
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 B9
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.0
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{5CA81D12-9EC2-4082-972B-43ECA63F41F2}" = HP Pavilion Webcam Driver for Vista v061.001.00005
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111177437}" = Mahjong Match
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111263673}" = Treasures of the Deep
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111264743}" = Four Houses
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111282737}" = Scrubbles
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99C5770C-1C90-42E7-9B74-D47CFAF14621}" = muvee autoProducer 5.0
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.3100
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}" = HP Help and Support
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{ED4905E3-2B32-4DD8-BC14-7CAFD30E9ECD}" = HP User Guide 0048
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core
"{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = ASL_HS_Installer32
"Activision_SD2UninstallKey" = Shanghai Second Dynasty
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Diary_is1" = Advanced Diary v2.1
"BVS Solitaire Collection_is1" = BVS Solitaire Collection version 2.6
"CCleaner" = CCleaner
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5045&SUBSYS_103C30B7" = Soft Data Fax Modem with SmartCP
"Defraggler" = Defraggler
"Forte Agent" = Forté Agent
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"IrfanView" = IrfanView (remove only)
"Jardinains 2!_is1" = Jardinains 2!
"Jigsaws Galore" = Jigsaws Galore
"Mahjong Escape - Ancient Japan" = Mahjong Escape - Ancient Japan
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0.1 (x86 en-GB)" = Mozilla Firefox 15.0.1 (x86 en-GB)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Simple Sudoku_is1" = Simple Sudoku 4.2
"Speccy" = Speccy
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Totalcmd" = Total Commander (Remove or Repair)
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/08/2012 8:20:52 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:52 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:53 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:53 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:53 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:54 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:57 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 5/08/2012 8:20:57 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 19/08/2012 1:35:01 | Computer Name = Phil-Denise | Source = Windows Search Service | ID = 3013
Description =

Error - 18/09/2012 9:03:49 | Computer Name = Phil-Denise | Source = RasClient | ID = 20227
Description =

Error - 21/09/2012 9:50:20 | Computer Name = Phil-Denise | Source = Application Error | ID = 1000
Description = Faulting application OTL.exe, version 3.2.64.0, time stamp 0x2a425e19,
faulting module user32.dll, version 6.0.6002.18005, time stamp 0x49e0380e, exception
code 0xc0000005, fault offset 0x0001a1c9, process id 0x404, application start time
0x01cd97fe0ffbcbea.

[ Media Center Events ]
Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:58 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

Error - 11/09/2010 6:15:59 | Computer Name = Phil-Denise | Source = Media Center Guide | ID = 0
Description = Event Info: Error creating/openning C:\ProgramData\Microsoft\eHome\EPG\tracehelper\DefaultDomain-PHIL-DENISE$.xml
(error code: 5) Process: DefaultDomain Object Name: Media Center Guide

[ System Events ]
Error - 21/09/2012 11:04:46 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:04:48 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:04:51 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:04:55 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:04:58 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:05:00 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:05:02 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:05:07 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 11:05:09 | Computer Name = Phil-Denise | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 21/09/2012 20:14:09 | Computer Name = Phil-Denise | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Hi,

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-

In your next reply please post the logs made by Malwarebytes and ESET.
G'Day Jeff, Ran the ESET can which found nothing, Below is the MBAM scan log file: —— Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.09.22.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.19272 Phil :: PHIL-DENISE [administrator] 22/09/2012 23:07:58 mbam-log-2012-09-22 (23-07-58).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 232659 Time elapsed: 19 minute(s), 46 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi,

Let's dig deeper…

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • click OK
  • Press Start Scan
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
    items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI