This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

OTL.txt [Solved]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 03/10/2012 08:46:31 - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Salim.CCLAPTOP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

503.37 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 21.85% Memory free
1.20 Gb Paging File | 0.82 Gb Available in Paging File | 67.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 5.01 Gb Free Space | 14.65% Space Free | Partition Type: NTFS

Computer Name: CCLAPTOP | User Name: Salim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\ESI\GIGA_HD\GIGAPan.exe (EGO SYS)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\DigitalPersona\Bin\DpHost.exe (DigitalPersona, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\quickset.exe ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Dell\QuickSet\preflibcl.dll ()
MOD - C:\Program Files\Winamp\winampa.exe ()


========== Services (SafeList) ==========

SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (WLANKEEPER) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHost.exe (DigitalPersona, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
DRV - (motmodem) – system32\DRIVERS\motmodem.sys File not found
DRV - (MotDev) – system32\DRIVERS\motodrv.sys File not found
DRV - (motccgpfl) – system32\DRIVERS\motccgpfl.sys File not found
DRV - (motccgp) – system32\DRIVERS\motccgp.sys File not found
DRV - (Micorsoft Windows Service) – C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (nmwcd) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (UsbserFilt) – C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdnsu) – C:\WINDOWS\system32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdc) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (GIGAPORTHD_AA) – C:\WINDOWS\system32\drivers\GIGAdrv.sys ()
DRV - (GIGA_01) – C:\WINDOWS\system32\drivers\GIGAWdm.sys ()
DRV - (U3sHlpDr) – C:\WINDOWS\system32\drivers\U3sHlpDr.sys ()
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (APPDRV) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Audisvgramis) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (QCMerced) – C:\WINDOWS\system32\drivers\lvcm.sys ()
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (w29n51) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (UsbdpFP) – C:\WINDOWS\system32\drivers\UsbdpFP.sys (DigitalPersona, Inc.)
DRV - (dpK00701) – C:\WINDOWS\system32\drivers\dpK00701.sys (DigitalPersona, Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IWCA) – C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (Ser2pl) – C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\..\SearchScopes\{B3FC9D01-9D84-4CC8-B3B2-CE9B5ABDCA1D}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYVerInfo.dll File not found
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\WINDOWS\cache\npyaxmpb.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{C3949AC2-4B17-43ee-B4F1-D26B9D42404D}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/09 11:22:03 | 000,000,000 | —D | M]

[2012/10/02 12:48:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Mozilla\Firefox\extensions
[2012/10/02 12:48:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2006/06/11 09:42:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2006/06/11 09:42:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2004/02/20 21:14:09 | 000,176,177 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2008/09/28 10:29:58 | 000,000,952 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - !{687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [VyuHjabc] C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\Salim.CCLAPTOP\Start Menu\Programs\Startup\GIGAPORT HD Control Panel.lnk = C:\Program Files\ESI\GIGA_HD\GIGAPan.exe (EGO SYS)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: motive.com ([pbttbc.bt] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…or/sw_promo.cab (Reg Error: Unable to open value key)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Reg Error: Unable to open value key)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Unable to open value key)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Unable to open value key)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C098F866-0293-472D-B7A6-A7CF6DAD2E36}: NameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) - C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe File not found
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{d2936f38-744d-11de-83b4-00142291334c}\Shell - "" = AutoRun
O33 - MountPoints2\{d2936f38-744d-11de-83b4-00142291334c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d2936f38-744d-11de-83b4-00142291334c}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Unable to open value key File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/03 08:44:36 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe
[2012/10/02 12:49:38 | 000,000,000 | —D | C] – C:\ac672509a795966ad5b188094c
[2012/10/02 12:49:38 | 000,000,000 | —D | C] – C:\741650c739fe17d253a851c2c6
[2012/10/02 12:49:37 | 000,000,000 | —D | C] – C:\0daa56741bb7a7c546d6b3b689e5
[2012/10/02 12:49:31 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2012/10/02 12:48:53 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2012/10/02 12:48:53 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2012/10/02 12:48:53 | 000,000,000 | —D | C] – C:\WINDOWS\Connection Wizard
[2012/10/02 12:48:52 | 000,000,000 | —D | C] – C:\WINDOWS\twain_32
[2012/10/02 12:48:49 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/10/02 12:48:45 | 000,000,000 | —D | C] – C:\Program Files\Viewpoint
[2012/10/02 12:48:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/10/02 12:48:44 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Sonic
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Motorola
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Apple Computer
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\AOL
[2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\You've Got Pictures Screensaver
[2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Yahoo!
[2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband
[2012/10/02 12:48:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\TuneUp Software
[2012/10/02 12:48:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Tanagra
[2012/10/02 12:48:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Mozilla
[2012/10/02 12:48:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Malwarebytes
[2012/10/02 12:48:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Gtek
[2012/09/06 17:34:41 | 000,157,448 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/06 17:34:41 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/06 17:34:41 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/11/03 17:32:24 | 000,457,054 | —- | C] (Winmxconex ) – C:\Program Files\Winmx_3.54.exe
[2007/07/19 18:56:23 | 000,092,064 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmmdm.sys
[2007/07/19 18:56:23 | 000,079,328 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmserd.sys
[2007/07/19 18:56:23 | 000,066,656 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmbus.sys
[2007/07/19 18:56:23 | 000,009,232 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmmdfl.sys
[2007/07/19 18:56:23 | 000,006,208 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmcmnt.sys
[2007/07/19 18:56:23 | 000,005,936 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmwhnt.sys
[2007/07/19 18:56:23 | 000,004,048 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmcr.sys
[2007/07/19 18:46:34 | 000,024,192 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Salim.CCLAPTOP\usbsermptxp.sys
[2007/07/19 18:46:34 | 000,022,768 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Salim.CCLAPTOP\usbsermpt.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/03 08:44:37 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe
[2012/10/03 08:36:01 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1975611791-2844101239-1228591925-1011.job
[2012/10/03 08:35:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/03 08:34:19 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2012/10/03 08:33:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/03 08:33:27 | 527,892,480 | -HS- | M] () – C:\hiberfil.sys
[2012/10/02 16:31:17 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/02 13:31:35 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/02 13:31:35 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/01 20:35:54 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\ReclaimerResumeInstall_Salim.job
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/01 20:35:52 | 000,000,428 | —- | C] () – C:\WINDOWS\tasks\ReclaimerResumeInstall_Salim.job
[2012/08/03 10:10:21 | 000,093,644 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\ms.exe
[2012/04/30 18:57:13 | 000,551,070 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1975611791-2844101239-1228591925-1011-0.dat
[2012/04/30 18:57:04 | 000,259,550 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/03/28 22:11:06 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2012/03/28 22:11:06 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012/03/28 22:11:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012/03/28 22:11:06 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012/02/16 06:56:18 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/06/07 12:41:14 | 000,012,860 | -HS- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\2tont435w72033v0e7808tcv1dex245
[2011/06/07 12:41:14 | 000,012,860 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2tont435w72033v0e7808tcv1dex245
[2011/04/19 12:14:50 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/02/22 08:59:12 | 000,016,026 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289552-oem50.PNF
[2009/02/22 08:59:12 | 000,009,913 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289552-oem50.inf
[2009/02/22 08:59:11 | 000,015,706 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem47.PNF
[2009/02/22 08:59:11 | 000,012,444 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem46.PNF
[2009/02/22 08:59:11 | 000,009,232 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem47.inf
[2009/02/22 08:59:11 | 000,005,960 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem46.inf
[2009/02/22 08:59:10 | 000,012,852 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem40.PNF
[2009/02/22 08:59:10 | 000,012,818 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem41.PNF
[2009/02/22 08:59:10 | 000,006,141 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem41.inf
[2009/02/22 08:59:10 | 000,005,880 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem40.inf
[2009/02/22 08:59:09 | 000,014,358 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289548-oem37.PNF
[2009/02/22 08:59:09 | 000,007,201 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289548-oem37.inf
[2007/09/26 22:22:10 | 006,548,309 | —- | C] () – C:\Documents and Settings\All Users\B.T. Express - That's What I Want For You Baby.mp3
[2007/07/19 18:56:23 | 000,015,706 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem47.PNF
[2007/07/19 18:56:23 | 000,014,022 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem37.PNF
[2007/07/19 18:56:23 | 000,012,844 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem40.PNF
[2007/07/19 18:56:23 | 000,012,706 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem41.PNF
[2007/07/19 18:56:23 | 000,012,372 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem46.PNF
[2007/07/19 18:56:23 | 000,009,913 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\MCCI_MDM.INF
[2007/07/19 18:56:23 | 000,009,232 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem47.inf
[2007/07/19 18:56:23 | 000,006,989 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\MCCI_BUS.INF
[2007/07/19 18:56:23 | 000,006,947 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867783-(null)
[2007/07/19 18:56:23 | 000,006,009 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem41.inf
[2007/07/19 18:56:23 | 000,005,877 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem40.inf
[2007/07/19 18:56:23 | 000,005,813 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem46.inf
[2007/07/19 18:56:23 | 000,004,477 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\MCCI_SDM.INF
[2007/07/19 18:55:27 | 000,009,232 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USB_MOT_BRIT.INF
[2007/07/19 18:55:27 | 000,005,960 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USB_MOT_A1000.INF
[2007/07/19 18:55:26 | 000,012,570 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867726-oem41.PNF
[2007/07/19 18:55:26 | 000,005,891 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867726-oem41.inf
[2007/07/19 18:55:25 | 000,014,318 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem37.PNF
[2007/07/19 18:55:25 | 000,012,844 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem40.PNF
[2007/07/19 18:55:25 | 000,007,195 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem37.inf
[2007/07/19 18:55:25 | 000,005,877 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem40.inf
[2007/07/19 18:46:34 | 000,007,195 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USBMOT2000.INF
[2007/07/19 18:46:34 | 000,005,891 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USBMOT2000XP.INF
[2007/07/19 18:46:34 | 000,005,877 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USB_CMCS_2000.INF
[2007/07/19 18:45:58 | 000,064,954 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867157-oem37.PNF
[2007/07/19 18:45:58 | 000,048,144 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867157-oem37.inf
[2006/12/17 12:12:46 | 000,020,480 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/12 23:17:48 | 000,066,730 | —- | C] () – C:\Program Files\2nd half.htm
[2006/12/12 20:52:38 | 002,658,841 | —- | C] () – C:\Program Files\burst-3.1.0b.exe
[2006/12/10 09:16:39 | 000,023,374 | —- | C] () – C:\Program Files\ViewpointKiller.zip
[2006/10/03 21:11:28 | 000,000,846 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Updater.ini
[2006/05/14 02:59:02 | 000,000,137 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\fusioncache.dat
[2006/01/26 04:44:03 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare

========== ZeroAccess Check ==========

[2004/08/11 18:21:56 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/04/29 05:46:52 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 13:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 01:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2007/05/22 22:14:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2007/05/22 22:16:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2012/04/30 13:14:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010/08/03 11:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2012/04/30 13:32:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/08/13 13:56:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/05/19 10:52:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/10/08 22:45:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tanagra
[2012/01/14 19:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2012/10/02 12:48:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/01/14 18:20:06 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/03/24 16:26:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/14 13:43:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/10 11:48:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/06/13 09:22:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Amazon
[2006/04/17 14:24:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Leadertech
[2012/10/02 12:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Motorola
[2006/10/16 19:36:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\MSNInstaller
[2010/08/03 11:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\NCH Swift Sound
[2012/04/30 13:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Nokia
[2012/04/30 13:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\PC Suite
[2012/04/30 15:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Samsung
[2012/10/02 12:48:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband
[2012/10/02 12:48:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Tanagra
[2012/05/01 19:35:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Temp
[2012/10/02 12:48:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\TuneUp Software
[2012/10/02 12:50:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/04 06:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 12:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/10/02 12:55:42 | 000,049,934 | —- | M] () MD5=8F4CDD98BB6331D34A9651220261D1A6 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SC_ >
[2004/08/04 06:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 06:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/29 08:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2009/04/25 06:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2009/04/25 06:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3GDR\iexplore.exe
[2009/08/27 06:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 09:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/28 07:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 14:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/14 01:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/04/14 01:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/10/28 07:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2010/02/23 06:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/04/25 06:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2009/04/25 06:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3QFE\iexplore.exe
[2010/02/23 06:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 08:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/08/27 06:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/10/03 08:36:19 | 000,089,968 | —- | M] () MD5=635ED2F1D5581A30478C50513D626A9B – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.EXE >
[2009/02/06 12:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 01:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2012/01/14 18:35:08 | 000,001,602 | —- | M] () MD5=D009F33D20281A74346CE5033DCEE6A5 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2012/04/21 15:27:02 | 000,000,351 | —- | M] () MD5=058919773E86AD96071EC3619653B22E – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Macromedia\Flash Player\#SharedObjects\9XHZEBRR\mochiads.com\services.mochiads.com.sol

< MD5 for: SERVICES.MSC >
[2004/08/04 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2004/08/11 18:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/11/02 23:14:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/11 18:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/07/19 18:53:54 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2006/01/26 04:20:38 | 000,005,184 | RH– | M] () – C:\dell.sdr
[2012/10/03 08:33:27 | 527,892,480 | -HS- | M] () – C:\hiberfil.sys
[2006/01/31 21:48:23 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/11 18:15:00 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/01/26 04:52:00 | 000,000,893 | -H– | M] () – C:\IPH.PH
[2006/09/16 16:52:14 | 000,000,062 | —- | M] () – C:\MMCD.INI
[2004/08/11 18:15:00 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/26 12:33:05 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/10/03 08:33:17 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2006/09/16 16:52:20 | 000,000,207 | —- | M] () – C:\RECache.idx
[2006/04/17 08:33:33 | 000,000,441 | —- | M] () – C:\Shortcut to My Documents.lnk

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 18:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 14:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/08/03 19:05:28 | 000,001,674 | -H– | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2006/12/12 23:17:49 | 000,066,730 | —- | M] () – C:\Program Files\2nd half.htm
[2006/12/12 20:52:44 | 002,658,841 | —- | M] () – C:\Program Files\burst-3.1.0b.exe
[2006/12/10 09:16:40 | 000,023,374 | —- | M] () – C:\Program Files\ViewpointKiller.zip
[2009/11/03 17:32:27 | 000,457,054 | —- | M] (Winmxconex ) – C:\Program Files\Winmx_3.54.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/11 18:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/11 18:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/11 18:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/06/26 12:46:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/26 13:08:22 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/11 18:20:42 | 000,000,079 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/12/29 16:50:00 | 000,380,928 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\Darkman_TMLoader_187.exe
[2012/05/03 17:55:35 | 008,577,640 | —- | M] (Motorola) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\MotoHelper_2.1.40_Driver_5.5.0.exe
[2012/05/03 19:48:03 | 025,732,000 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\Motorola_Software_Update.exe
[2012/04/30 13:13:55 | 067,525,120 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\Nokia_PC_Suite_ALL.exe
[2012/10/03 08:44:37 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-11 06:37:07

< End of report >
OTL Extras logfile created on: 03/10/2012 08:46:31 - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Salim.CCLAPTOP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

503.37 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 21.85% Memory free
1.20 Gb Paging File | 0.82 Gb Available in Paging File | 67.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 5.01 Gb Free Space | 14.65% Space Free | Partition Type: NTFS

Computer Name: CCLAPTOP | User Name: Salim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Unable to open value key File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Unable to open value key
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Unable to open value key
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\WinMX\WinMX.exe" = C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application – (Frontcode Technologies)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player – (Musiccity Co.Ltd.)
"C:\Program Files\Motorola\Software Update\msu.exe" = C:\Program Files\Motorola\Software Update\msu.exe:*:Disabled:msu
"C:\Program Files\Samsung\Kies\KiesHelper.exe" = C:\Program Files\Samsung\Kies\KiesHelper.exe:*:Disabled:Kies


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{362ADCE1-0118-4DBC-82CB-12B972735049}" = IBM USB-to-Serial
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}" = mCore
"{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}" = mIWCA
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F14EAA3B-680B-4CBE-B9DE-10FF85F757FB}" = DigitalPersona Gold Fingerprint Recognition Software 2.5.0
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"Audacity_is1" = Audacity 1.2.6
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"DivX Content Uploader" = DivX Content Uploader
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ESI- GIGA PORT HD Audio Driver Setup" = ESI- GIGA PORT HD Audio Driver
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter by MixMeister 1.0.6
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PCDJRedMobile" = PCDJ Red Mobile (remove only)
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealPlayer 15.0" = RealPlayer
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"uTorrent" = µTorrent
"uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"Winmx Community 1" = Winmx Community 1
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"XviD_is1" = XviD 1.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 07/06/2011 07:56:21 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application ipe.exe, version 5.7.0.18066, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 07/06/2011 07:59:55 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application ipe.exe, version 5.7.0.18066, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 08/06/2011 05:55:43 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ipe.exe, version 5.7.0.18066, faulting module
mshtml.dll, version 8.0.6001.19046, fault address 0x000aad54.

Error - 18/06/2011 07:15:57 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 20/06/2011 15:29:52 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/07/2011 10:45:03 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/07/2011 10:48:43 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 05/08/2011 21:58:00 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

Error - 14/08/2011 07:00:06 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

Error - 21/08/2011 09:47:12 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

[ System Events ]
Error - 19/09/2012 15:03:27 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 19/09/2012 15:26:22 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 01/10/2012 15:21:50 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 01/10/2012 15:25:49 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 01/10/2012 16:53:55 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 03:43:06 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 07:53:50 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 07:54:48 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 02/10/2012 10:55:48 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 03/10/2012 03:34:20 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3


< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:19:20, on 03/10/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\program files\real\realplayer\update\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESI\GIGA_HD\GIGAPan.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Salim.CCLAPTOP\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - !{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [VyuHjabc] C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: GIGAPORT HD Control Panel.lnk = C:\Program Files\ESI\GIGA_HD\GIGAPan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://bt.yahoo.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C098F866-0293-472D-B7A6-A7CF6DAD2E36}: NameServer = 192.168.1.1
O20 - AppInit_DLLs:
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: User Authentication Manager (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Unknown owner - C:\Program Files\Common Files\Motive\McciCMService.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 8680 bytes
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 27/01/2006 15:24:34 System Uptime: 03/10/2012 08:32:40 (1 hours ago) . Motherboard: Dell Inc. | | 0HC416 Processor: Intel® Pentium® M processor 1.70GHz | Microprocessor | 209/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 34 GiB total, 4.97 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel® PRO/Wireless 2200BG Network Connection Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27228086&REV_05\4&2FA23535&0&18F0 Manufacturer: Intel® Corporation Name: Intel® PRO/Wireless 2200BG Network Connection PNP Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27228086&REV_05\4&2FA23535&0&18F0 Service: w29n51 . Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia 2730 classic Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia 2730 classic PNP Device ID: ROOT\WPD\0000 Service: WUDFRd . ==== System Restore Points =================== . RP1403: 13/08/2012 11:03:27 - Uniblue SpeedUpMyPC installation RP1404: 13/08/2012 13:53:41 - Removed Samsung Kies RP1405: 13/08/2012 14:17:04 - Removed iTunes RP1406: 13/08/2012 14:31:46 - Removed Apple Application Support RP1407: 13/08/2012 14:35:54 - Removed Apple Mobile Device Support RP1408: 13/08/2012 14:37:16 - Removed Apple Software Update RP1409: 14/08/2012 15:05:36 - System Checkpoint RP1410: 15/08/2012 22:45:24 - System Checkpoint RP1411: 16/08/2012 22:59:54 - System Checkpoint RP1412: 18/08/2012 00:05:10 - System Checkpoint RP1413: 22/08/2012 14:27:07 - System Checkpoint RP1414: 23/08/2012 15:10:48 - System Checkpoint RP1415: 24/08/2012 15:26:33 - System Checkpoint RP1416: 25/08/2012 15:40:20 - System Checkpoint RP1417: 29/08/2012 22:14:26 - System Checkpoint RP1418: 30/08/2012 22:46:19 - System Checkpoint RP1419: 31/08/2012 23:35:51 - System Checkpoint RP1420: 02/09/2012 00:35:58 - System Checkpoint RP1421: 03/09/2012 00:47:13 - System Checkpoint RP1422: 04/09/2012 01:35:57 - System Checkpoint RP1423: 06/09/2012 17:33:36 - Installed Java™ 6 Update 35 RP1424: 01/10/2012 21:30:31 - Removed Bonjour RP1425: 01/10/2012 21:32:13 - Removed Windows Installer Clean Up RP1426: 01/10/2012 21:33:04 - Removed Windows Resource Kit Tools - SubInAcl.exe RP1427: 02/10/2012 12:47:27 - Restore Operation RP1428: 03/10/2012 08:51:27 - OTL Restore Point - 03/10/2012 08:51:04 . ==== Installed Programs ====================== . µTorrent Adobe Flash Player 11 ActiveX Adobe Reader 7.0 AiO_Scan_CDA Amazon MP3 Downloader 1.0.15 Audacity 1.2.6 Bonjour Broadcom Management Programs Conexant HDA D110 MDC V.92 Modem Dell Driver Reset Tool Dell System Restore DigitalPersona Gold Fingerprint Recognition Software 2.5.0 DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Plus DirectShow Filters DivX Web Player ESI- GIGA PORT HD Audio Driver EZ Vinyl Converter by MixMeister 1.0.6 Google Earth HighMAT Extension to Microsoft Windows XP CD Writing Wizard Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976002-v5) HP Photosmart, Officejet and Deskjet 7.0.A IBM USB-to-Serial iLivid Intel® Graphics Media Accelerator Driver for Mobile Intel® PROSet/Wireless Software Internal Network Card Power Management Internet Explorer Default Page Java 2 Runtime Environment, SE v1.4.2_03 Java Auto Updater Java™ 6 Update 33 Logitech QuickCam Software Logitech® Camera Driver mCore MCU mDrWiFi mHlpDell Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 1.1 Security Update (KB2656370) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Document Explorer 2005 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft National Language Support Downlevel APIs Microsoft Office File Validation Add-In Microsoft Office Professional Edition 2003 Microsoft Office Visio Professional 2003 Microsoft User-Mode Driver Framework Feature Pack 1.9 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 mIWA mIWCA mLogView mMHouse MotoHelper MergeModules mPfMgr mPfWiz mProSafe mSSO MSVC90_x86 MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) mToolkit mWlsSafe mXML mZConfig Nero 6 Enterprise Edition Nokia Connectivity Cable Driver OGA Notifier 2.0.0048.0 PC Connectivity Solution PCDJ Red Mobile (remove only) Picasa 3 PowerDVD QFolder QuickSet QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 Scan Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB2699988) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2685939) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2707511) Security Update for Windows XP (KB2709162) Security Update for Windows XP (KB2718523) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB975713) Switch Sound File Converter Synaptics Pointing Device Driver Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows Internet Explorer 8 (KB980302) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB2718704) Update for Windows XP (KB951978) Update for Windows XP (KB967715) Update for Windows XP (KB971029) uTorrentControl2 Toolbar VC80CRTRedist - 8.0.50727.4053 Viewpoint Media Player WebFldrs XP Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Installer Clean Up Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Resource Kit Tools - SubInAcl.exe Windows XP Service Pack 3 Winmx Community 1 WinRAR 4.01 (32-bit) XviD 1.1 final uninstall Xvid Video Codec . ==== Event Viewer Messages From Past Week ======== . 01/10/2012 20:21:50, error: Service Control Manager [7000] - The McciCMService service failed to start due to the following error: The system cannot find the path specified. . ==== End Of File ===========================
Hello dekosman and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly.

Meanwhile, can you post the other log that was produced. It is called Eztras.txt and will be on the desktop.

Can you also tell me what problems you are having.

Thanks

Satchfan
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 9:22:08.25 on 03/10/2012 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.93 [GMT 1:00] . AV: *Disabled/Outdated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\DigitalPersona\Bin\DpHost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\program files\real\realplayer\update\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ESI\GIGA_HD\GIGAPan.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Salim.CCLAPTOP\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://www.cnn.com/ mSearch Page = mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local;192.168.*.* uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\documents and settings\salim.cclaptop\local settings\application data\nsduyaul\vyuhjabc.exe BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: !{687578b9-7132-4a7a-80e4-30ee31099e03} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [VyuHjabc] c:\documents and settings\salim.cclaptop\local settings\application data\nsduyaul\vyuhjabc.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [] mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe mRun: [WinampAgent] c:\program files\winamp\winampa.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\salim~1.ccl\startm~1\programs\startup\gigapo~1.lnk - c:\program files\esi\giga_hd\GIGAPan.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe mPolicies-system: EnableLUA = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL Trusted Zone: motive.com\pbttbc.bt DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw_promo.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: {C098F866-0293-472D-B7A6-A7CF6DAD2E36} = 192.168.1.1 Notify: igfxcui - igfxdev.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll Notify: TPSvc - TPSvc.dll AppInit_DLLs: SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ============= SERVICES / DRIVERS =============== . R4 Micorsoft Windows Service;Micorsoft Windows Service;\??\c:\docume~1\salim~1.ccl\locals~1\temp\dksojwwo.sys –> c:\docume~1\salim~1.ccl\locals~1\temp\dksojwwo.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-17 250288] S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;c:\windows\system32\drivers\dpK00701.sys [2004-10-12 41856] S3 GIGA_01;Service for ESI GIGAPort HD Audio driver;c:\windows\system32\drivers\GIGAWdm.sys [2009-7-17 24504] S3 GIGAPORTHD_AA;Service for ESI GIGAPort HD Controller driver;c:\windows\system32\drivers\GIGAdrv.sys [2009-7-17 33752] S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys –> c:\windows\system32\drivers\motccgp.sys [?] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys –> c:\windows\system32\drivers\motccgpfl.sys [?] S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys –> c:\windows\system32\drivers\motodrv.sys [?] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2012-4-30 137600] S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;c:\windows\system32\drivers\UsbdpFP.sys [2004-10-12 45056] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-10-02 11:51:26 ——– d—–w- c:\windows\system32\wbem\repository\FS 2012-10-02 11:51:26 ——– d—–w- c:\windows\system32\wbem\Repository 2012-10-02 11:49:38 ——– d—–w- C:\ac672509a795966ad5b188094c 2012-10-02 11:49:38 ——– d—–w- C:\741650c739fe17d253a851c2c6 2012-10-02 11:49:37 ——– d—–w- C:\0daa56741bb7a7c546d6b3b689e5 . ==================== Find3M ==================== . 2012-10-02 12:31:35 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-02 12:31:35 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-03 09:10:22 93644 —-a-w- c:\documents and settings\salim.cclaptop\ms.exe 2009-11-03 16:32:27 457054 -c–a-w- c:\program files\Winmx_3.54.exe 2006-12-12 19:52:44 2658841 -c–a-w- c:\program files\burst-3.1.0b.exe . ============= FINISH: 9:24:47.17 ===============
Hi

Please do not start a new ropic for new posts – go to the bottom of the current, (the one you are reading), and click on “Reply”

You appear to have downloaded Tanagra and it seems to have brought a friend with it.

A couple of things before we start cleaning up:

Registry cleaners

I see you are using a “Registry Cleaner”, TuneUp software. It's not recommended to use registry cleaners/boosters.

The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, (and you are expert in the registry), I would suggest you leave the registry alone.

I strongly advise you to get rid of TuneUp and any other cleaner/optimizer/booster/tuneup/tweak type utilities that you have on this or any other computer.

One of the malware experts, miekiemoes, has an excellent write-up here
Another excellent article by Bill Castner is located here


P2P - I see you have P2P software, (uTorrent), on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    DRV - (WDICA) – File not found
    DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
    DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
    DRV - (PDRFRAME) – File not found
    DRV - (PDRELI) – File not found
    DRV - (PDFRAME) – File not found
    DRV - (PDCOMP) – File not found
    DRV - (PCIDump) – File not found
    DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
    DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
    DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
    DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
    DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
    DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
    DRV - (motmodem) – system32\DRIVERS\motmodem.sys File not found
    DRV - (MotDev) – system32\DRIVERS\motodrv.sys File not found
    DRV - (motccgpfl) – system32\DRIVERS\motccgpfl.sys File not found
    DRV - (motccgp) – system32\DRIVERS\motccgp.sys File not found
    DRV - (Micorsoft Windows Service) – C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys File not found
    DRV - (lbrtfdc) – File not found
    DRV - (Changer) – File not found
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
    IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
    IE - HKCU\..\SearchScopes\{B3FC9D01-9D84-4CC8-B3B2-CE9B5ABDCA1D}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
    O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [VyuHjabc] C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe File not found
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Unable to open value key)
    O20 - HKLM Winlogon: UserInit - (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) - C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe File not found
    O37 - HKCU\…exe [@ = exefile] – Reg Error: Unable to open value key File not found
    [2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband
    [2011/06/07 12:41:14 | 000,012,860 | -HS- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\2tont435w72033v0e7808tcv1dex245
    [2011/06/07 12:41:14 | 000,012,860 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2tont435w72033v0e7808tcv1dex245
    [2012/10/02 12:48:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the prescan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects.
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Please also include the OTL fix log and a new OTL scan log

Can you also tell me what problems you are having

Thanks

Satchfan
Hi Satcfan,
thank you so much for your prompt reply and help.
The problem with my laptop is that it refuses to get widows update and the webpage cannot be found always pops up.
There are other sites that it will not find too. Generally it is behaving slowly and unhelpful to a degree.

i have posted the Extras as requested.
Thank you again. I will now run your advice and let you have the results.

OTL Extras logfile created on: 03/10/2012 08:46:31 - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Salim.CCLAPTOP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

503.37 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 21.85% Memory free
1.20 Gb Paging File | 0.82 Gb Available in Paging File | 67.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 5.01 Gb Free Space | 14.65% Space Free | Partition Type: NTFS

Computer Name: CCLAPTOP | User Name: Salim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Unable to open value key File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Unable to open value key
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Unable to open value key
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\WinMX\WinMX.exe" = C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application – (Frontcode Technologies)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player – (Musiccity Co.Ltd.)
"C:\Program Files\Motorola\Software Update\msu.exe" = C:\Program Files\Motorola\Software Update\msu.exe:*:Disabled:msu
"C:\Program Files\Samsung\Kies\KiesHelper.exe" = C:\Program Files\Samsung\Kies\KiesHelper.exe:*:Disabled:Kies


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{362ADCE1-0118-4DBC-82CB-12B972735049}" = IBM USB-to-Serial
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}" = mCore
"{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}" = mIWCA
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F14EAA3B-680B-4CBE-B9DE-10FF85F757FB}" = DigitalPersona Gold Fingerprint Recognition Software 2.5.0
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"Audacity_is1" = Audacity 1.2.6
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"DivX Content Uploader" = DivX Content Uploader
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ESI- GIGA PORT HD Audio Driver Setup" = ESI- GIGA PORT HD Audio Driver
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter by MixMeister 1.0.6
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PCDJRedMobile" = PCDJ Red Mobile (remove only)
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealPlayer 15.0" = RealPlayer
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"uTorrent" = µTorrent
"uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"Winmx Community 1" = Winmx Community 1
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"XviD_is1" = XviD 1.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 07/06/2011 07:56:21 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application ipe.exe, version 5.7.0.18066, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 07/06/2011 07:59:55 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application ipe.exe, version 5.7.0.18066, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 08/06/2011 05:55:43 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ipe.exe, version 5.7.0.18066, faulting module
mshtml.dll, version 8.0.6001.19046, fault address 0x000aad54.

Error - 18/06/2011 07:15:57 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 20/06/2011 15:29:52 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/07/2011 10:45:03 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/07/2011 10:48:43 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 05/08/2011 21:58:00 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

Error - 14/08/2011 07:00:06 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

Error - 21/08/2011 09:47:12 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

[ System Events ]
Error - 19/09/2012 15:03:27 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 19/09/2012 15:26:22 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 01/10/2012 15:21:50 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 01/10/2012 15:25:49 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 01/10/2012 16:53:55 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 03:43:06 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 07:53:50 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 07:54:48 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 02/10/2012 10:55:48 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 03/10/2012 03:34:20 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3


< End of report >
Hi satcfan,
thank you so much.
My laptop is running slow and always gives me send a report error messages when I swich on at first or visit a web site which almost always hangs.
I cannot get widows updates!! It will not connect to.. it gives me the web page cannot be found blaa blaa.
I will follow your instructions.. but first here is the extras:
OTL Extras logfile created on: 03/10/2012 08:46:31 - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Salim.CCLAPTOP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

503.37 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 21.85% Memory free
1.20 Gb Paging File | 0.82 Gb Available in Paging File | 67.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 5.01 Gb Free Space | 14.65% Space Free | Partition Type: NTFS

Computer Name: CCLAPTOP | User Name: Salim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Unable to open value key File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Unable to open value key
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Unable to open value key
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\WinMX\WinMX.exe" = C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application – (Frontcode Technologies)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player – (Musiccity Co.Ltd.)
"C:\Program Files\Motorola\Software Update\msu.exe" = C:\Program Files\Motorola\Software Update\msu.exe:*:Disabled:msu
"C:\Program Files\Samsung\Kies\KiesHelper.exe" = C:\Program Files\Samsung\Kies\KiesHelper.exe:*:Disabled:Kies


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{362ADCE1-0118-4DBC-82CB-12B972735049}" = IBM USB-to-Serial
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}" = mCore
"{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}" = mIWCA
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F14EAA3B-680B-4CBE-B9DE-10FF85F757FB}" = DigitalPersona Gold Fingerprint Recognition Software 2.5.0
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"Audacity_is1" = Audacity 1.2.6
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"DivX Content Uploader" = DivX Content Uploader
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ESI- GIGA PORT HD Audio Driver Setup" = ESI- GIGA PORT HD Audio Driver
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter by MixMeister 1.0.6
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PCDJRedMobile" = PCDJ Red Mobile (remove only)
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealPlayer 15.0" = RealPlayer
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"uTorrent" = µTorrent
"uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"Winmx Community 1" = Winmx Community 1
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"XviD_is1" = XviD 1.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 07/06/2011 07:56:21 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application ipe.exe, version 5.7.0.18066, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 07/06/2011 07:59:55 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application ipe.exe, version 5.7.0.18066, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 08/06/2011 05:55:43 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ipe.exe, version 5.7.0.18066, faulting module
mshtml.dll, version 8.0.6001.19046, fault address 0x000aad54.

Error - 18/06/2011 07:15:57 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 20/06/2011 15:29:52 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/07/2011 10:45:03 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/07/2011 10:48:43 | Computer Name = CCLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application nero.exe, version 6.6.0.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 05/08/2011 21:58:00 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

Error - 14/08/2011 07:00:06 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

Error - 21/08/2011 09:47:12 | Computer Name = CCLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application gigapan.exe, version 1.1.0.0, faulting module
gigapan.exe, version 1.1.0.0, fault address 0x00001692.

[ System Events ]
Error - 19/09/2012 15:03:27 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 19/09/2012 15:26:22 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 01/10/2012 15:21:50 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 01/10/2012 15:25:49 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 01/10/2012 16:53:55 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 03:43:06 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 07:53:50 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 02/10/2012 07:54:48 | Computer Name = CCLAPTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 02/10/2012 10:55:48 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3

Error - 03/10/2012 03:34:20 | Computer Name = CCLAPTOP | Source = Service Control Manager | ID = 7000
Description = The McciCMService service failed to start due to the following error:
%%3


< End of report >
You have now sent 2 Extras logs which I didn't ask for as I had that log previously. I want you to run the OTL fix and follow my most recent instructions. Please let me know if you are having a problem with this. Thanks Satchfan
Sorry!
I have attached the new otl txt.

I will now run rogue killer and follow your intructions.

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Service WDICA stopped successfully!
Service WDICA deleted successfully!
File File not found not found.
Service wanatw stopped successfully!
Service wanatw deleted successfully!
File system32\DRIVERS\wanatw4.sys File not found not found.
Service USBAAPL stopped successfully!
Service USBAAPL deleted successfully!
File System32\Drivers\usbaapl.sys File not found not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
File File not found not found.
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
File File not found not found.
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
File File not found not found.
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
File File not found not found.
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
File File not found not found.
Service MRESP50a64 stopped successfully!
Service MRESP50a64 deleted successfully!
File C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found not found.
Service MRESP50 stopped successfully!
Service MRESP50 deleted successfully!
File C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found not found.
Service MRENDIS5 stopped successfully!
Service MRENDIS5 deleted successfully!
File C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found not found.
Service MREMPR5 stopped successfully!
Service MREMPR5 deleted successfully!
File C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found not found.
Service MREMP50a64 stopped successfully!
Service MREMP50a64 deleted successfully!
File C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found not found.
Service MREMP50 stopped successfully!
Service MREMP50 deleted successfully!
File C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found not found.
Service motmodem stopped successfully!
Service motmodem deleted successfully!
File system32\DRIVERS\motmodem.sys File not found not found.
Service MotDev stopped successfully!
Service MotDev deleted successfully!
File system32\DRIVERS\motodrv.sys File not found not found.
Service motccgpfl stopped successfully!
Service motccgpfl deleted successfully!
File system32\DRIVERS\motccgpfl.sys File not found not found.
Service motccgp stopped successfully!
Service motccgp deleted successfully!
File system32\DRIVERS\motccgp.sys File not found not found.
Service Micorsoft Windows Service stopped successfully!
Service\Driver key Micorsoft Windows Service not found.
File C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys File not found not found.
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
File File not found not found.
Service Changer stopped successfully!
Service Changer deleted successfully!
File File not found not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ deleted successfully.
C:\Program Files\uTorrentControl2\prxtbuTor.dll moved successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B3FC9D01-9D84-4CC8-B3B2-CE9B5ABDCA1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3FC9D01-9D84-4CC8-B3B2-CE9B5ABDCA1D}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{687578b9-7132-4a7a-80e4-30ee31099e03}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found.
File C:\Program Files\uTorrentControl2\prxtbuTor.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\VyuHjabc deleted successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Classes\exefile\ deleted successfully.
HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband folder moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\2tont435w72033v0e7808tcv1dex245 moved successfully.
C:\Documents and Settings\All Users\Application Data\2tont435w72033v0e7808tcv1dex245 moved successfully.
Folder C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Could not flush the DNS Resolver Cache: Function failed during execution.
C:\Documents and Settings\Salim.CCLAPTOP\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 83 bytes

User: LocalService

User: NetworkService

User: Salim

User: Salim.CCLAPTOP
->Flash cache emptied: 70893 bytes

User: SALIM~1~CCL

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 7864541 bytes

User: NetworkService
->Temp folder emptied: 212992 bytes
->Temporary Internet Files folder emptied: 3611767 bytes

User: Salim

User: Salim.CCLAPTOP
->Temp folder emptied: 327959298 bytes
->Temporary Internet Files folder emptied: 57310534 bytes
->Java cache emptied: 39483885 bytes
->Flash cache emptied: 0 bytes

User: SALIM~1~CCL

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2775569 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33586 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 67638874 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 484.00 mb


OTL by OldTimer - Version 3.2.70.1 log created on 10042012_100802

Files\Folders moved on Reboot…
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\EFO01B97\iframe[1].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\EFO01B97\index[1].php moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\DM3E3F53\iframe[1].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\DM3E3F53\iframe[2].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\DM3E3F53\iframe[3].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\DM3E3F53\iframe[4].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\DM3E3F53\iframe[5].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\8GV1CVUA\iframe[2].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\8GV1CVUA\iframe[3].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\8GV1CVUA\iframe[4].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\8GV1CVUA\iframe[5].htm moved successfully.
C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\Content.IE5\369JZIAE\index[1].htm moved successfully.
File move failed. C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Here is the roguekiller:
RogueKiller V8.1.1 [10/03/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Salim [Admin rights]
Mode : Scan – Date : 10/04/2012 10:29:48

¤¤¤ Bad processes : 2 ¤¤¤
[SVCHOST] svchost.exe – C:\WINDOWS\system32\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe – C:\WINDOWS\system32\svchost.exe -> KILLED [TermProc]

¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : VyuHjabc (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1975611791-2844101239-1228591925-1011[…]\Run : VyuHjabc (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> FOUND
[SHELL][SUSP PATH] HKLM\[…]\Winlogon : Userinit (c:\windows\system32\userinit.exe,,C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> FOUND
[TASK][SUSP PATH] ReclaimerResumeInstall_Salim.job : C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[41] : NtCreateKey @ 0x805737EF -> HOOKED (\??\C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys @ 0xF886B6AC)
SSDT[119] : NtOpenKey @ 0x80568FE8 -> HOOKED (\??\C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys @ 0xF886B562)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

ÿþ1

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHV2040AH +++++
— User —
[MBR] 2d36b9f740306f3243aed48bb4f3aaa5
[BSP] 6751bb20408e7fd050b2ea8fc16ec20d : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 34993 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 71826615 | Size: 3074 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt

You have now sent 2 Extras logs which I didn't ask for as I had that log previously.

I want you to run the OTL fix and follow my most recent instructions.

Please let me know if you are having a problem with this.

Thanks

Satchfan

Hi Satcfan,
Am I doing things right? Have you got all the requests?
You are doing fine.

I have the logs I need and won’t bother with a new OTL log..

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
  • close all programs
  • double-click RogueKiller.exe - Windows 7: right-click the program and select Run as Administrator'
  • after it has completed it's prescan click on the “Registry” tab
  • uncheck the following false positives


    [HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

  • make sure the other entries there are checked, then click on Delete
===================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    🖼Click to load external image (Posted Image)


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    🖼Click to load external image (Posted Image)


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Remember to also include the RogueKiller log.

Satchfan
Hi Stachfan,
I downloaded and installe combofix.
Before that i did the killer stuff.
the prescan gave me nothing so I did a scan, registory, uncheck the appropriate file and deleted.

The combo job is funny! I run, the the Licence "I agree" bit shows up and vanishes!! I did that a few times and it will show a brief widow green on black background for 1 second and vanish. However all the time it was dumping the outcome txt. to my desktop
Here are the notes for the combo job.
RogueKiller V8.1.1 [10/03/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Salim [Admin rights]
Mode : Remove – Date : 10/04/2012 12:49:57

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : VyuHjabc (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> DELETED
[SHELL][SUSP PATH] HKLM\[…]\Winlogon : Userinit (c:\windows\system32\userinit.exe,,C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> REPLACED (C:\WINDOWS\system32\userinit.exe,)
[TASK][SUSP PATH] ReclaimerResumeInstall_Salim.job : C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe -> DELETED
[STARTUP][SUSP PATH] vyuhjabc.exe @Salim.CCLAPTOP : C:\Documents and Settings\Salim.CCLAPTOP\Start Menu\Programs\Startup\vyuhjabc.exe -> DELETED
[HJ] HKLM\[…]\System : EnableLUA (0) -> REPLACED (1)
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NOT SELECTED

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[41] : NtCreateKey @ 0x805737EF -> HOOKED (\??\C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys @ 0xF886B6AC)
SSDT[119] : NtOpenKey @ 0x80568FE8 -> HOOKED (\??\C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys @ 0xF886B562)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

ÿþ1

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHV2040AH +++++
— User —
[MBR] 2d36b9f740306f3243aed48bb4f3aaa5
[BSP] 6751bb20408e7fd050b2ea8fc16ec20d : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 34993 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 71826615 | Size: 3074 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt


========================
File 1
===============
RogueKiller V8.1.1 [10/03/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Salim [Admin rights]
Mode : Scan – Date : 10/04/2012 10:29:48

¤¤¤ Bad processes : 2 ¤¤¤
[SVCHOST] svchost.exe – C:\WINDOWS\system32\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe – C:\WINDOWS\system32\svchost.exe -> KILLED [TermProc]

¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : VyuHjabc (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1975611791-2844101239-1228591925-1011[…]\Run : VyuHjabc (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> FOUND
[SHELL][SUSP PATH] HKLM\[…]\Winlogon : Userinit (c:\windows\system32\userinit.exe,,C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) -> FOUND
[TASK][SUSP PATH] ReclaimerResumeInstall_Salim.job : C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[41] : NtCreateKey @ 0x805737EF -> HOOKED (\??\C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys @ 0xF886B6AC)
SSDT[119] : NtOpenKey @ 0x80568FE8 -> HOOKED (\??\C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys @ 0xF886B562)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

ÿþ1

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHV2040AH +++++
— User —
[MBR] 2d36b9f740306f3243aed48bb4f3aaa5
[BSP] 6751bb20408e7fd050b2ea8fc16ec20d : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 78 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 160650 | Size: 34993 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 71826615 | Size: 3074 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI