This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ads on bottom left/right of every website visited [Closed]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

im trying to get rid of these little boxed ads that seem to appear on every site i visit. some are in the shape of an ipod with text ads and others are square boxes usually with insurance ads. i know its not part of sites like gmail or groupon or something to show ads such as these since they are hovering over the site. i ran virus scans, spybot, and replaced the hosts file but doesnt seem to be helping. Please see my log from DDS below. Thank you. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 12:42:58.78 on Sat 10/20/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_35 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2038.713 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Microsoft Security Client\NisSrv.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Citrix\ICA Client\concentr.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Sony\VAIO Center Access Bar\VCAB.exe C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe C:\Program Files\Citrix\ICA Client\wfcrun32.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Epson Software\Event Manager\EEventManager.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Users\akshara\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Users\akshara\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe C:\Program Files\iPod\bin\iPodService.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\akshara\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\akshara\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\msiexec.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\akshara\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . mDefault_Page_URL = hxxp://www.sony.com/vaiopeople uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421; BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Skytel] Skytel.exe mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [VAIO Center Access Bar] "c:\program files\sony\vaio center access bar\VCAB.exe" mRun: [VAIOCameraUtility] "c:\program files\sony\vaio camera utility\VCUServe.exe" mRun: [VAIOSecurity] "c:\program files\sony\vaio security center\VSC.exe" 1 mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEVENT~1.EXE mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" StartupFolder: c:\users\akshara\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\akshara\appdata\roaming\dropbox\bin\Dropbox.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL Hosts: 149.5.18.173 www.google-analytics.com. Hosts: 149.5.18.173 ad-emea.doubleclick.net. Hosts: 149.5.18.173 www.statcounter.com. Hosts: 108.163.215.51 www.google-analytics.com. Hosts: 108.163.215.51 ad-emea.doubleclick.net. . Note: multiple HOSTS entries found. Please refer to Attach.txt . ================= FIREFOX =================== . FF - ProfilePath - c:\users\akshara\appdata\roaming\mozilla\firefox\profiles\crketjqa.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q= FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npicaN.dll FF - plugin: c:\users\akshara\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\users\akshara\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\akshara\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_287.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552] R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2009-9-8 65584] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-12-10 239168] R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2012-7-5 374184] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2012-6-8 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2012-10-20 47640] R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 99272] R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-1-3 11032] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-10-20 1153368] R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-9-12 287824] R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2007-5-3 73472] R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2007-5-3 43904] R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2007-8-3 9344] R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2007-5-3 31104] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-5-3 807424] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-9-30 250808] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464] S3 ICScsiSV;Image Converter SCSI Service;c:\program files\sony\image converter 3\ICScsiSV.exe [2010-6-14 75952] S3 IcVzMonLauncher;IcVzMonLauncher;c:\program files\sony\image converter 3\IcVzMonLauncher.exe [2010-6-14 67760] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-9-9 129976] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2011-4-11 77184] S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2011-4-11 25600] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224] S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2011-4-11 112640] S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\sony\vaio media integrated server\UCLS.exe [2010-6-14 745472] S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\sony\vaio media integrated server\platform\SV_Httpd.exe [2010-6-14 397312] S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\sony\vaio media integrated server\platform\UPnPFramework.exe [2010-6-14 1089536] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-9-30 1343400] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpffontcache_v0400.exe –> c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [?] . =============== Created Last 30 ================ . 2012-10-20 16:36:39 ——– d—–w- c:\users\akshara\appdata\local\LogMeIn 2012-10-20 16:36:35 52128 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2012-10-20 16:36:34 30624 —-a-w- c:\windows\system32\LMIport.dll 2012-10-20 16:36:33 83392 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-10-20 16:36:33 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys 2012-10-20 16:36:29 87456 —-a-w- c:\windows\system32\LMIinit.dll 2012-10-20 16:36:24 ——– d—–w- c:\progra~2\LogMeIn 2012-10-20 16:36:08 ——– d—–w- c:\program files\LogMeIn 2012-10-20 15:52:53 740784 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8b9644a8-6e3d-463d-b445-63d6ee2449a2}\gapaengine.dll 2012-10-20 15:52:30 6918632 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{62ad5c39-cbaf-4726-a4ab-cbb20afaf6ab}\mpengine.dll 2012-10-20 15:42:36 ——– d—–w- c:\program files\Spybot - Search & Destroy 2012-10-20 15:42:36 ——– d—–w- c:\progra~2\Spybot - Search & Destroy 2012-10-13 20:20:53 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-10-13 20:19:21 ——– d—–w- c:\program files\iPod 2012-10-13 20:18:48 ——– d—–w- c:\progra~2\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-10-13 20:18:47 ——– d—–w- c:\program files\iTunes 2012-10-13 20:08:24 2048 —-a-w- c:\windows\system32\tzres.dll 2012-10-13 20:08:00 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-10-13 20:06:52 1159680 —-a-w- c:\windows\system32\crypt32.dll 2012-10-13 20:06:51 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-13 20:06:51 103936 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-13 20:05:45 1211760 —-a-w- c:\windows\system32\drivers\ntfs.sys 2012-10-13 20:03:05 3968880 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-10-13 20:03:05 3914096 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-10-13 19:58:24 6980552 ——w- c:\progra~2\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-10-01 13:05:50 805376 —-a-w- c:\windows\system32\FntCache.dll 2012-10-01 13:05:49 739840 —-a-w- c:\windows\system32\d2d1.dll 2012-10-01 07:01:01 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-10-01 07:01:00 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-10-01 07:01:00 194048 —-a-w- c:\program files\internet explorer\IEShims.dll 2012-10-01 07:01:00 140936 —-a-w- c:\program files\internet explorer\sqmapi.dll 2012-10-01 02:26:50 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys 2012-09-30 19:49:15 ——– d—–w- c:\users\akshara\appdata\local\Macromedia 2012-09-30 17:37:21 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-30 17:28:49 398336 —-a-w- c:\windows\system32\TVWizudlg.exe 2012-09-30 17:28:49 140288 —-a-w- c:\windows\system32\igfxtvcx.dll 2012-09-30 17:23:46 ——– d—–w- c:\windows\system32\Wat 2012-09-30 16:30:21 ——– d—–w- c:\windows\system32\appmgmt 2012-09-30 16:18:36 5120 —-a-w- c:\windows\system32\wmi.dll 2012-09-30 16:18:36 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-09-30 16:18:36 159232 —-a-w- c:\windows\system32\imagehlp.dll 2012-09-29 20:23:11 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-29 20:23:11 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-29 20:23:01 311808 —-a-w- c:\windows\system32\drivers\srv.sys 2012-09-29 20:23:01 310272 —-a-w- c:\windows\system32\drivers\srv2.sys 2012-09-29 20:23:01 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys 2012-09-29 20:21:58 75776 —-a-w- c:\windows\system32\psisrndr.ax 2012-09-29 20:20:59 372736 —-a-w- c:\program files\common files\system\ado\msadox.dll 2012-09-29 20:19:51 2342400 —-a-w- c:\windows\system32\msi.dll 2012-09-29 20:07:12 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2012-09-29 20:06:55 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-09-29 20:06:54 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-09-29 19:58:02 477168 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-09-29 19:54:51 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-09-29 19:54:34 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-09-29 19:54:23 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-09-29 19:54:23 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-09-29 19:53:27 ——– d—–w- c:\users\akshara\appdata\local\Diagnostics . ==================== Find3M ==================== . 2012-10-13 19:55:05 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-29 19:57:50 473072 —-a-w- c:\windows\system32\deployJava1.dll 2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-21 20:12:27 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-08-21 17:01:22 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-08-20 17:40:31 169984 —-a-w- c:\windows\system32\winsrv.dll 2012-08-20 17:40:01 293376 —-a-w- c:\windows\system32\KernelBase.dll 2012-08-20 17:37:58 271360 —-a-w- c:\windows\system32\conhost.exe 2012-08-20 15:33:28 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-08-20 15:33:28 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-08-20 15:33:28 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-08-20 15:33:28 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-08-10 23:56:14 542208 —-a-w- c:\windows\system32\kerberos.dll 2012-08-02 16:57:20 490496 —-a-w- c:\windows\system32\d3d10level9.dll . ============= FINISH: 12:44:06.00 ===============
Hi zek, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Let's see if this will stop the ads.

Download OTL to your desktop.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
ipconfig /flushdns /c

:Commands
[resethosts]
[createrestorepoint]
[reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log.

Next

Open OTL if it's still not open after the reboot.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • OTL fix log
  • both OTL logs from the scan
Ads still there?
Hi oldman960,

Thank you for your help in trying to resolve this issue. I went to couple of sites and noticed that the ads are still there; if you would like I can post up a screenshot if that might help. I have completed the steps to the letter on your post; please see the logs pasted below.

OTL Fix Log:

========== SERVICES/DRIVERS ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\akshara\Desktop\cmd.bat deleted successfully.
C:\Users\akshara\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 10212012_111558

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

================================================================================
==================================
================================================================================
==================================

BOTH OTL LOGS FROM THE SCAN:

OTL:

OTL logfile created on: 10/21/2012 11:23:30 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\akshara\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 52.91% Memory free
3.98 Gb Paging File | 2.82 Gb Available in Paging File | 70.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50.78 Gb Total Space | 21.14 Gb Free Space | 41.64% Space Free | Partition Type: NTFS
Drive F: | 91.13 Gb Total Space | 48.11 Gb Free Space | 52.79% Space Free | Partition Type: NTFS

Computer Name: AKSHARA-PC | User Name: akshara | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\akshara\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Users\akshara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Center Access Bar\VCAB.exe (Sony Electronics, Inc.)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll ()
MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\libglesv2.dll ()
MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\libegl.dll ()
MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\avutil-51.dll ()
MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\avformat-54.dll ()
MOD - C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\avcodec-54.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\Epson Software\Event Manager\Assistants\Scan Assistant\ScanEngine.dll ()
MOD - C:\Program Files\Epson Software\Event Manager\Assistants\Scan Assistant\Satwain.dll ()
MOD - C:\Program Files\Sony\VAIO Camera Utility\VCULib.dll ()


========== Services (SafeList) ==========

SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe File not found
SRV - (SBSDWSCService) – C:\Program Files\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NisSrv) – C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (ICScsiSV) – C:\Program Files\Sony\Image Converter 3\ICScsiSV.exe (Sony Corporation)
SRV - (IcVzMonLauncher) – C:\Program Files\Sony\Image Converter 3\IcVzMonLauncher.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 3\IcVzMon.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-UCLS-UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-UCLS-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-UCLS-HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (dtsoftbus01) – C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (LMIRfsClientNP) – C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\System32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (ctxusbm) – C:\Windows\System32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (SFEP) – C:\Windows\System32\drivers\SFEP.sys (Sony Corporation)
DRV - (SonyImgF) – C:\Windows\System32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (WimFltr) – C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (ti21sony) – C:\Windows\System32\drivers\ti21sony.sys (Texas Instruments)
DRV - (SNC) – C:\Windows\System32\drivers\SonyNC.sys (Sony Corporation)
DRV - (regi) – C:\Windows\System32\drivers\regi.sys (InterVideo)
DRV - (DMICall) – C:\Windows\System32\drivers\DMICall.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
IE - HKLM\..\SearchScopes,DefaultScope = {077DE1EC-B4F5-4258-AEF7-569FD62A6590}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{077DE1EC-B4F5-4258-AEF7-569FD62A6590}: "URL" = http://search.aol.com/aolcom/search?query=…onType=sny_ie7;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=Z134&install;_date=20111108
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.ask.com/?l=dis&o;=14196
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {29238212-B172-435B-9C62-477D76B81283}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{29238212-B172-435B-9C62-477D76B81283}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\..\SearchScopes\{7ABD5EFD-88A6-E9CE-80AE-DBCA8C52F41C}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:2.5
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\akshara\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\akshara\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\akshara\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\akshara\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/13 16:04:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/13 16:04:38 | 000,000,000 | —D | M]

[2012/09/09 18:40:27 | 000,000,000 | —D | M] (No name found) – C:\Users\akshara\AppData\Roaming\Mozilla\Extensions
[2012/09/09 18:40:32 | 000,000,000 | —D | M] (No name found) – C:\Users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\extensions
[2008/01/19 01:49:12 | 000,004,804 | —- | M] () (No name found) – C:\Users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\extensions\[removed]
[2011/11/07 20:23:57 | 000,001,945 | —- | M] () – C:\Users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\searchplugins\bing-zugo.xml
[2012/09/29 15:58:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/29 15:58:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/09/09 14:31:06 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/09/13 00:05:42 | 000,124,240 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2009/09/13 00:06:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2009/09/13 00:06:32 | 000,091,480 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2009/09/13 00:06:28 | 000,022,360 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2009/09/13 00:08:36 | 000,406,864 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2009/09/13 00:06:24 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012/02/27 01:47:09 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
[2012/02/27 01:47:09 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\akshara\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\akshara\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\akshara\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\akshara\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/23 15:54:56 | 000,001,395 | RHS- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 149.5.18.173 www.google-analytics.com.
O1 - Hosts: 149.5.18.173 ad-emea.doubleclick.net.
O1 - Hosts: 149.5.18.173 www.statcounter.com.
O1 - Hosts: 108.163.215.51 www.google-analytics.com.
O1 - Hosts: 108.163.215.51 ad-emea.doubleclick.net.
O1 - Hosts: 108.163.215.51 www.statcounter.com.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [VAIO Center Access Bar] c:\program files\sony\VAIO Center Access Bar\VCAB.exe (Sony Electronics, Inc.)
O4 - HKLM..\Run: [VAIOCameraUtility] C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
O4 - HKLM..\Run: [VAIOSecurity] C:\Program Files\Sony\VAIO Security Center\VSC.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\akshara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\akshara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF0F21D0-C3F5-48BB-BB45-47F56CF825B4}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\VAIO Azure Float Wallpaper 1280x720.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\VAIO Azure Float Wallpaper 1280x720.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/21 11:15:58 | 000,000,000 | —D | C] – C:\_OTL
[2012/10/21 11:14:42 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\akshara\Desktop\OTL.exe
[2012/10/20 12:36:39 | 000,000,000 | —D | C] – C:\Users\akshara\AppData\Local\LogMeIn
[2012/10/20 12:36:34 | 000,030,624 | —- | C] (LogMeIn, Inc.) – C:\Windows\System32\LMIport.dll
[2012/10/20 12:36:33 | 000,083,392 | —- | C] (LogMeIn, Inc.) – C:\Windows\System32\LMIRfsClientNP.dll
[2012/10/20 12:36:33 | 000,047,640 | —- | C] (LogMeIn, Inc.) – C:\Windows\System32\drivers\LMIRfsDriver.sys
[2012/10/20 12:36:29 | 000,087,456 | —- | C] (LogMeIn, Inc.) – C:\Windows\System32\LMIinit.dll
[2012/10/20 12:36:24 | 000,000,000 | —D | C] – C:\ProgramData\LogMeIn
[2012/10/20 12:36:08 | 000,000,000 | —D | C] – C:\Program Files\LogMeIn
[2012/10/20 12:22:06 | 000,895,464 | —- | C] (Oracle Corporation) – C:\Users\akshara\Desktop\jre-7u9-windows-i586-iftw.exe
[2012/10/20 11:42:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/10/20 11:42:36 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/10/20 11:42:36 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2012/10/13 22:38:46 | 000,000,000 | —D | C] – C:\Users\akshara\AppData\Roaming\WinRAR
[2012/10/13 22:38:46 | 000,000,000 | —D | C] – C:\Users\akshara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/10/13 22:38:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/10/13 22:37:59 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/10/13 16:21:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/10/13 16:19:21 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/10/13 16:18:48 | 000,000,000 | —D | C] – C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/10/13 16:18:47 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/10/13 16:08:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/10/13 16:07:52 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2012/10/13 16:07:52 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/10/13 16:07:51 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012/10/13 16:07:51 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012/10/13 16:07:51 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/13 16:07:51 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/13 16:07:51 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/13 16:07:51 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012/10/13 16:07:51 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012/10/13 16:07:51 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012/10/13 16:07:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/13 16:07:50 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012/10/13 16:07:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012/10/13 16:04:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/10/13 16:03:35 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/10/13 16:03:05 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/10/13 16:03:05 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/10/01 09:05:49 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/10/01 03:01:01 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/10/01 03:00:59 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/10/01 03:00:58 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/10/01 03:00:58 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/10/01 03:00:58 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/10/01 03:00:56 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/10/01 03:00:56 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/10/01 03:00:54 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/09/30 22:26:50 | 000,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2012/09/30 22:26:49 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2012/09/30 22:26:45 | 000,148,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2012/09/30 22:26:45 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2012/09/30 15:49:15 | 000,000,000 | —D | C] – C:\Users\akshara\AppData\Local\Macromedia
[2012/09/30 13:37:21 | 000,696,760 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/09/30 13:28:49 | 000,398,336 | —- | C] (Intel® Corporation) – C:\Windows\System32\TVWizudlg.exe
[2012/09/30 13:23:46 | 000,000,000 | —D | C] – C:\Windows\System32\Wat
[2012/09/30 12:30:21 | 000,000,000 | —D | C] – C:\Windows\System32\appmgmt
[2012/09/30 12:17:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/09/30 12:17:42 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/09/30 12:17:41 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/09/30 12:17:41 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/09/30 12:17:41 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/09/30 12:17:41 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/09/30 12:17:41 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/09/30 12:17:41 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/09/30 12:17:41 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/09/30 12:17:41 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/09/30 12:17:41 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/09/30 12:17:41 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/09/30 12:17:41 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/09/30 12:17:41 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/09/30 12:17:41 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/09/30 12:17:41 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/09/30 12:17:41 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/09/30 12:17:40 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/09/30 12:17:40 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/09/30 12:17:40 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/09/30 12:17:40 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/09/30 12:17:40 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/09/30 12:17:40 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/09/30 12:17:40 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/09/30 12:17:39 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/09/30 12:17:39 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/09/30 12:17:39 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/09/30 12:17:39 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/09/30 12:17:39 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/09/29 16:23:11 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2012/09/29 16:22:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2012/09/29 16:22:43 | 000,240,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2012/09/29 16:22:43 | 000,187,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012/09/29 16:22:21 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2012/09/29 16:22:20 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2012/09/29 16:22:19 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/09/29 16:22:18 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2012/09/29 16:22:18 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/09/29 16:22:11 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OxpsConverter.exe
[2012/09/29 16:21:58 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2012/09/29 16:21:58 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2012/09/29 16:21:56 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2012/09/29 16:21:50 | 000,919,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorets.dll
[2012/09/29 16:21:31 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2012/09/29 16:21:28 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2012/09/29 16:21:00 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
[2012/09/29 16:20:55 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/09/29 16:20:54 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/09/29 16:20:50 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2012/09/29 16:20:50 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2012/09/29 16:20:49 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2012/09/29 16:20:49 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2012/09/29 16:20:49 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2012/09/29 16:20:49 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2012/09/29 16:20:46 | 000,191,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSCOVER.exe
[2012/09/29 16:20:36 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2012/09/29 16:20:31 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2012/09/29 16:20:21 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2012/09/29 16:20:18 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2012/09/29 16:20:07 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/09/29 16:20:07 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/09/29 16:20:05 | 000,850,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2012/09/29 16:20:05 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CPFilters.dll
[2012/09/29 16:20:04 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2012/09/29 16:20:00 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2012/09/29 16:19:47 | 000,490,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2012/09/29 16:19:41 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browcli.dll
[2012/09/29 16:19:39 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webio.dll
[2012/09/29 16:19:39 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sspisrv.dll
[2012/09/29 16:19:38 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcjt32.dll
[2012/09/29 16:19:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbctrac.dll
[2012/09/29 16:19:38 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2012/09/29 16:19:38 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccu32.dll
[2012/09/29 16:19:38 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccr32.dll
[2012/09/29 16:19:37 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/09/29 16:19:36 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2012/09/29 16:19:36 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2012/09/29 16:19:35 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2012/09/29 16:19:26 | 001,077,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/09/29 16:19:23 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2012/09/29 16:19:23 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2012/09/29 16:19:16 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2012/09/29 16:19:15 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2012/09/29 16:07:12 | 000,219,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2012/09/29 16:06:55 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcore.dll
[2012/09/29 15:58:02 | 000,477,168 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/09/29 15:54:51 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2012/09/29 15:54:51 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2012/09/29 15:54:34 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2012/09/29 15:54:34 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2012/09/29 15:54:34 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2012/09/29 15:54:23 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2012/09/29 15:54:23 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2012/09/29 15:53:27 | 000,000,000 | —D | C] – C:\Users\akshara\AppData\Local\Diagnostics
[1 C:\Users\akshara\Desktop\*.tmp files -> C:\Users\akshara\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/21 11:28:00 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2058305492-2997592224-2038688142-1005UA.job
[2012/10/21 11:25:50 | 000,011,104 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/21 11:25:50 | 000,011,104 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/21 11:18:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/21 11:18:00 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2012/10/21 11:16:54 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2058305492-2997592224-2038688142-1005Core.job
[2012/10/21 11:14:50 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\akshara\Desktop\OTL.exe
[2012/10/21 11:12:44 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/20 12:42:49 | 000,625,664 | —- | M] () – C:\Users\akshara\Desktop\dds.scr
[2012/10/20 12:36:26 | 000,001,024 | —- | M] () – C:\.rnd
[2012/10/20 12:33:15 | 018,900,992 | —- | M] () – C:\Users\akshara\Desktop\LogMeIn.msi
[2012/10/20 12:23:05 | 000,895,464 | —- | M] (Oracle Corporation) – C:\Users\akshara\Desktop\jre-7u9-windows-i586-iftw.exe
[2012/10/20 12:05:47 | 000,635,850 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/10/20 12:05:47 | 000,111,392 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/10/20 11:42:56 | 000,001,220 | —- | M] () – C:\Users\akshara\Desktop\Spybot - Search & Destroy.lnk
[2012/10/13 16:21:03 | 000,001,753 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/10/13 15:57:18 | 000,002,324 | —- | M] () – C:\Users\akshara\Desktop\Google Chrome.lnk
[2012/10/13 15:57:18 | 000,002,201 | —- | M] () – C:\Users\akshara\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/10/13 15:55:05 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/10/13 15:55:05 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/10/01 03:02:43 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/09/30 13:29:07 | 000,001,411 | —- | M] () – C:\Users\akshara\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/09/30 13:26:32 | 000,446,216 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/09/30 12:17:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/09/30 12:17:42 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/09/30 12:17:41 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/09/30 12:17:41 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/09/30 12:17:41 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/09/30 12:17:41 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/09/30 12:17:41 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/09/30 12:17:41 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/09/30 12:17:41 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/09/30 12:17:41 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/09/30 12:17:41 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/09/30 12:17:41 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/09/30 12:17:41 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/09/30 12:17:41 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/09/30 12:17:41 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012/09/30 12:17:41 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/09/30 12:17:41 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/09/30 12:17:41 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/09/30 12:17:41 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/09/30 12:17:40 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/09/30 12:17:40 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/09/30 12:17:40 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/09/30 12:17:40 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/09/30 12:17:40 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/09/30 12:17:40 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/09/30 12:17:40 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/09/30 12:17:39 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/09/30 12:17:39 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/09/30 12:17:39 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/09/30 12:17:39 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/09/29 15:57:51 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/09/29 15:57:51 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/09/29 15:57:51 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/09/29 15:57:50 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/09/29 15:57:50 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[1 C:\Users\akshara\Desktop\*.tmp files -> C:\Users\akshara\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/20 12:42:44 | 000,625,664 | —- | C] () – C:\Users\akshara\Desktop\dds.scr
[2012/10/20 12:36:25 | 000,001,024 | —- | C] () – C:\.rnd
[2012/10/20 12:36:16 | 000,000,958 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2012/10/20 12:32:45 | 018,900,992 | —- | C] () – C:\Users\akshara\Desktop\LogMeIn.msi
[2012/10/20 11:42:56 | 000,001,220 | —- | C] () – C:\Users\akshara\Desktop\Spybot - Search & Destroy.lnk
[2012/10/13 16:21:03 | 000,001,753 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/30 13:37:22 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/30 13:28:49 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2012/09/30 12:17:41 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2012/09/09 19:16:45 | 000,000,418 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2012/09/09 18:49:15 | 000,021,924 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2012/03/10 20:04:47 | 000,000,016 | —- | C] () – C:\Windows\System32\crt.dat
[2012/03/10 20:04:44 | 000,295,053 | —- | C] () – C:\Windows\System32\shimg.dll
[2012/02/16 04:26:52 | 000,000,000 | —- | C] () – C:\Windows\EEventManager.INI
[2012/02/03 23:45:49 | 000,073,220 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2012/02/03 23:45:49 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2012/02/03 23:45:49 | 000,029,114 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2012/02/03 23:45:49 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2012/02/03 23:45:49 | 000,021,021 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2012/02/03 23:45:49 | 000,015,670 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2012/02/03 23:45:49 | 000,013,280 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2012/02/03 23:45:49 | 000,010,673 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2012/02/03 23:45:49 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2012/02/03 23:45:49 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2012/02/03 23:45:49 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2012/02/03 23:45:49 | 000,001,137 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2012/02/03 23:45:49 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2012/02/03 23:45:49 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2012/02/03 23:45:49 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2012/02/03 23:45:49 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2011/12/04 20:27:06 | 000,000,000 | —- | C] () – C:\Users\akshara\AppData\Roaming\wklnhst.dat
[2011/08/18 21:03:37 | 000,001,880 | —- | C] () – C:\Users\akshara\LookAndFeel.java
[2011/08/18 21:01:54 | 000,004,926 | —- | C] () – C:\Users\akshara\MRHouse.java
[2011/07/12 23:46:47 | 000,000,056 | —- | C] () – C:\Windows\System32\ezsidmv.dat
[2010/12/23 15:24:52 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/11/20 17:29:34 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/20 17:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2010/08/20 02:39:33 | 000,018,789 | —- | C] () – C:\Users\akshara\ebay.jpg
[2010/08/19 17:58:03 | 000,029,064 | —- | C] () – C:\Users\akshara\viewer.png
[2010/08/18 23:46:50 | 000,031,231 | —- | C] () – C:\Users\akshara\despicable-me-int-trailer.jpg
[2010/08/18 23:36:26 | 000,007,893 | —- | C] () – C:\Users\akshara\logo.png
[2010/08/02 22:41:23 | 000,000,310 | —- | C] () – C:\Users\akshara\Public - Shortcut.lnk
[2010/07/29 19:09:43 | 000,008,743 | —- | C] () – C:\Users\akshara\sofa.jpg
[2010/07/28 03:02:28 | 000,008,020 | —- | C] () – C:\Users\akshara\comp.jpg
[2010/07/28 03:01:14 | 000,080,204 | —- | C] () – C:\Users\akshara\ethics.jpg
[2010/07/28 03:00:18 | 000,010,838 | —- | C] () – C:\Users\akshara\num.jpg
[2010/07/28 02:58:48 | 000,006,808 | —- | C] () – C:\Users\akshara\physics6.jpg
[2010/07/28 02:56:13 | 000,007,585 | —- | C] () – C:\Users\akshara\physics.jpeg
[2010/07/28 02:55:17 | 000,006,428 | —- | C] () – C:\Users\akshara\books.jpeg

========== ZeroAccess Check ==========

[2011/11/18 16:23:34 | 000,002,048 | -HS- | M] () – C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\@
[2011/11/18 16:23:34 | 000,000,000 | -HSD | M] – C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\L
[2012/09/09 21:26:10 | 000,000,000 | -HSD | M] – C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\U
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 17:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/09 18:39:51 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\Azureus
[2012/09/09 18:39:52 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\BOXEE
[2012/09/09 18:39:56 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\DAEMON Tools Lite
[2012/10/21 11:19:40 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\Dropbox
[2012/09/09 18:39:58 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\Epson
[2012/09/09 18:40:01 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\FrostWire
[2010/06/17 16:40:23 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\GetRightToGo
[2012/09/09 18:40:01 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\ICAClient
[2012/09/09 18:40:01 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\InterVideo
[2012/09/09 18:40:01 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\Jason Robitaille
[2012/09/09 18:40:32 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\OpenOffice.org
[2012/09/09 19:18:07 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\Synaptics
[2012/09/09 18:40:39 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\Template
[2012/09/09 18:40:39 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\TP
[2012/10/13 19:00:26 | 000,000,000 | —D | M] – C:\Users\akshara\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/10/20 12:36:26 | 000,001,024 | —- | M] () – C:\.rnd
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 17:29:06 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2012/09/09 22:00:50 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/10/21 11:18:00 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2005/01/03 09:37:18 | 000,000,017 | —- | M] () – C:\initrd.pam
[2012/04/08 06:19:03 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/14 16:39:38 | 000,000,344 | —- | M] () – C:\IPH.PH
[2007/01/15 21:13:14 | 000,000,068 | —- | M] () – C:\kernel.pam
[2012/04/08 06:19:03 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/10/21 11:18:09 | 2137,448,448 | -HS- | M] () – C:\pagefile.sys
[2010/06/14 20:41:11 | 000,000,000 | —- | M] () – C:\ProgramData.LOG1
[2010/06/14 20:41:11 | 000,000,000 | —- | M] () – C:\ProgramData.LOG2
[2012/09/09 00:44:02 | 000,138,878 | —- | M] () – C:\TDSSKiller.2.8.8.0_09.09.2012_00.35.59_log.txt
[2012/09/09 00:52:36 | 000,125,158 | —- | M] () – C:\TDSSKiller.2.8.8.0_09.09.2012_00.49.49_log.txt
[2012/09/09 02:13:37 | 000,135,524 | —- | M] () – C:\TDSSKiller.2.8.8.0_09.09.2012_02.10.38_log.txt
[2010/06/14 18:04:27 | 000,390,438 | —- | M] () – C:\vcredist_x86.log

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2012/07/05 18:09:54 | 000,052,128 | —- | M] (LogMeIn, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\LMIproc.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 17:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2012/10/20 12:23:05 | 000,895,464 | —- | M] (Oracle Corporation) – C:\Users\akshara\Desktop\jre-7u9-windows-i586-iftw.exe
[2012/10/21 11:14:50 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\akshara\Desktop\OTL.exe
[1 C:\Users\akshara\Desktop\*.tmp files -> C:\Users\akshara\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-13 21:15:22

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2011/04/11 22:15:49 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2011/04/11 22:15:49 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 17:29:20 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2011/04/11 22:15:39 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2011/04/11 22:15:39 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.ZIP >
[2009/06/03 22:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_b1148f09c82553c5\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_b1a52ddae13ca4f0\iexplore.exe
[2012/09/30 12:17:42 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2010/11/20 17:29:33 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/09/30 12:17:43 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/09/30 12:17:43 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: SERVICES >
[2006/09/18 17:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\$INPLACE.~TR\Machine\DATA\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2011/04/11 22:15:38 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2011/04/11 22:15:38 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2012/06/23 15:21:23 | 000,000,313 | —- | M] () MD5=88D77F7E3835E66E8141A68B61E1251F – C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\JBAC82PY\mochiads.com\services.mochiads.com.sol

< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2011/04/11 22:15:37 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2011/04/11 22:15:37 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 03:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2011/04/11 22:15:49 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2011/04/11 22:15:49 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 17:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 17:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2011/04/11 22:15:37 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2011/04/11 22:15:37 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2011/04/11 22:15:38 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2011/04/11 22:15:38 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< End of report >

================================================================================
=======
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++++
================================================================================
=======

EXTRAS LOG:

OTL Extras logfile created on: 10/21/2012 11:23:30 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\akshara\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 52.91% Memory free
3.98 Gb Paging File | 2.82 Gb Available in Paging File | 70.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50.78 Gb Total Space | 21.14 Gb Free Space | 41.64% Space Free | Partition Type: NTFS
Drive F: | 91.13 Gb Total Space | 48.11 Gb Free Space | 52.79% Space Free | Partition Type: NTFS

Computer Name: AKSHARA-PC | User Name: akshara | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{765FA195-1ADD-4052-ACF4-20E86482B184}" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"{A9FEFB96-5D0B-4136-AD8C-9049B5643894}" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"{D1A7AC3C-23F3-4990-80F9-BCA4ABD4C067}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{FB2BD274-7038-426C-9E3D-8D7AFC263AFD}" = dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{932F4949-9179-49B5-B33A-4ECB4CD591A4}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"TCP Query User{FD9401CD-7BAE-41D7-B159-C1E8E60C0BB5}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{BA810BCC-6391-46A9-9A61-79EC66299152}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{F0999ECB-9894-4063-B0A7-28A301605A8C}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{009E7FB7-1775-4D89-8956-F5C9A1C019FC}" = DSD Playback Plug-in
"{0312BD0D-A1FE-4E1A-9208-D436F566D867}" = VAIO Azure Float Wallpaper
"{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}" = Citrix online plug-in (Web)
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility
"{1B500D37-E7CF-480B-8054-8A563594EC4E}" = VAIO OOBE
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{22461A1C-BD68-4D90-9897-1DB146D55ECB}" = LogMeIn
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java™ 6 Update 35
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{337CBC16-F6F3-411A-9A3F-DB21C57BFDFD}" = Simple Start Entice
"{3A23120C-CD83-4CE6-B451-C5C998052522}" = Battery Care Function
"{3B203763-8CA0-4A62-AFFD-44F7F7C8889A}" = VAIO Video & Photo Suite
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{428A6DA3-FD56-44AE-B602-15DCCD6A7515}" = VAIO AV Mode Launcher
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 3
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{500162A0-4DD5-460A-BAFD-895AAE48C532}" = VAIO Media Content Collection 6.0
"{500C3FDC-5E5F-485F-BDF5-2C445839CBE0}" =
"{55392E52-1AAD-44C4-BE49-258FFE72434F}" = Citrix online plug-in (USB)
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 6.0
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 6.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5E343EF6-D27C-4CFC-9FAE-9AAFB541BCEE}" = VAIO Photo 2007
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}" = VAIO Video & Photo Suite
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D2576EC-A0E9-418A-A09A-409933A3B6F4}" = VAIO Camera Capture Utility
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 6.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7D716354-2C08-48DC-9AC5-957348048817}" = VAIO Help And Support
"{812424AC-A8B5-44E6-8D48-07E939D1AD9A}" = Citrix online plug-in (HDX)
"{82D5BACA-3619-4D34-99DB-3A65CFB4DA33}" = DSD Direct
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91208A47-5D08-4C79-986F-1931940F51BB}" = QuickBooks Product Listing Service
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 6.0
"{AFB6AFBA-88B1-48A7-AF52-BA59BA5F183B}" = Image Converter 3
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BABC878D-BB64-4688-9A88-1D9E88F339A9}" = VAIO Productivity Center
"{C299F969-AE3D-4679-ADF5-682A186CE62E}" = VAIO Center Access Bar
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CF53CF7C-D996-43EB-9904-DBED57C25625}" = Citrix online plug-in (DV)
"{CFED0AE3-6D93-4745-B8A0-F3410B493CC4}" = VAIO Security Center
"{D36E4755-83B9-4B10-BE51-0AC5B9F43C1F}" = VAIO Media
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{D6651810-8439-4F25-BACC-5FB66D4B1A63}" = VAIO Media Registration Tool
"{DFD30824-6BD0-34E1-ABE8-308AD3CBB9A0}" = Google Talk Plugin
"{E6707034-D7A4-49B1-94D0-F5AACE46F06C}" = Instant Mode
"{E74F7423-77CB-4F6A-A44D-604E1010FE50}" = VAIO Entertainment Center
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" =
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"332CCC08910F1AE2E4D90D25DEDE87E3EF797832" = Windows Driver Package - Palm (WinUSB) Palm Devices (10/09/2009 1.0.1)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"BOXEE" = Boxee
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_104D0200" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DAEMON Tools Lite" = DAEMON Tools Lite
"EPSON NX110 Series" = EPSON NX110 Series Printer Uninstall
"EPSON Scanner" = EPSON Scan
"HDMI" = Intel® Graphics Media Accelerator Driver
"HTC_WModemDriver" = WModem Driver Installer
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-13-24-01
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TVWiz" = Intel® TV Wizard
"uTorrent" = µTorrent
"VAIO Service Utility" = VAIO Service Utility
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR 4.20 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/13/2012 10:41:29 PM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/20/2012 11:56:03 AM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/20/2012 11:56:03 AM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/20/2012 12:02:38 PM | Computer Name = akshara-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/20/2012 12:02:38 PM | Computer Name = akshara-PC | Source = Application Error | ID = 1000
Description = Faulting application name: VAIO-SUTOOL.exe, version: 1.1.1.3, time
stamp: 0x4500969c Faulting module name: AcGenral.DLL, version: 6.1.7601.17514, time
stamp: 0x4ce7b6ff Exception code: 0xc00000fd Fault offset: 0x000221ed Faulting process
id: 0x9b4 Faulting application start time: 0x01cdaedc5036c3d2 Faulting application
path: C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe Faulting module
path: C:\Windows\AppPatch\AcGenral.DLL Report Id: 919dd680-1acf-11e2-a8e5-0013a9f0def8

Error - 10/20/2012 12:02:53 PM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/21/2012 11:18:46 AM | Computer Name = akshara-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/21/2012 11:18:49 AM | Computer Name = akshara-PC | Source = Application Error | ID = 1000
Description = Faulting application name: VAIO-SUTOOL.exe, version: 1.1.1.3, time
stamp: 0x4500969c Faulting module name: AcGenral.DLL, version: 6.1.7601.17514, time
stamp: 0x4ce7b6ff Exception code: 0xc00000fd Fault offset: 0x000221ed Faulting process
id: 0xa8c Faulting application start time: 0x01cdaf9f5b0d6995 Faulting application
path: C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe Faulting module
path: C:\Windows\AppPatch\AcGenral.DLL Report Id: 9d2240b7-1b92-11e2-bcf6-0013a9f0def8

Error - 10/21/2012 11:19:14 AM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/21/2012 11:21:38 AM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/21/2012 11:21:38 AM | Computer Name = akshara-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL".
Dependent
Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

[ System Events ]
Error - 10/13/2012 4:09:55 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 10/13/2012 4:10:55 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Apple Mobile Device service,
but this action failed with the following error: %%1056

Error - 10/13/2012 4:53:26 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7003
Description = The VAIO Entertainment Database Service service depends the following
service: MSSQL$VAIO_VEDB. This service might not be installed.

Error - 10/13/2012 4:53:26 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7001
Description = The VAIO Entertainment File Import Service service depends on the
VAIO Entertainment Database Service service which failed to start because of the
following error: %%1075

Error - 10/13/2012 5:18:13 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7003
Description = The VAIO Entertainment Database Service service depends the following
service: MSSQL$VAIO_VEDB. This service might not be installed.

Error - 10/13/2012 5:18:13 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7001
Description = The VAIO Entertainment File Import Service service depends on the
VAIO Entertainment Database Service service which failed to start because of the
following error: %%1075

Error - 10/20/2012 12:02:25 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7003
Description = The VAIO Entertainment Database Service service depends the following
service: MSSQL$VAIO_VEDB. This service might not be installed.

Error - 10/20/2012 12:02:25 PM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7001
Description = The VAIO Entertainment File Import Service service depends on the
VAIO Entertainment Database Service service which failed to start because of the
following error: %%1075

Error - 10/21/2012 11:18:38 AM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7003
Description = The VAIO Entertainment Database Service service depends the following
service: MSSQL$VAIO_VEDB. This service might not be installed.

Error - 10/21/2012 11:18:38 AM | Computer Name = akshara-PC | Source = Service Control Manager | ID = 7001
Description = The VAIO Entertainment File Import Service service depends on the
VAIO Entertainment Database Service service which failed to start because of the
following error: %%1075


< End of report >
Hi zek,

That didn't work as expected. We'll have to do a little tweak first.

Download the attached file, zek.zip and save it to your desktop. Extract the contents to your desktop.
  • you should now have a file named Takeownership.reg it has an icon like this [external image: Posted Image]
  • right click it and click merge
  • accept any warning you might recieve
  • reboot the computer
Let me know if you recieve any error message.

Next

Click on the Windows Explorer icon on the taskbar
  • When it opens click the Organize button
  • click folder and search options
  • click the View tab
  • check Show hidden files, folders and drives
  • uncheck hide extentions for known file types
  • uncheck hide protected operating system files (recommended)
  • click apply, click ok

Navigate to C:\windows\system32\drivers\etc

  • Locate Hosts (it's an extentionless file)
  • Right click it. You will now have a new right click menu item, take ownership . Click it.
  • right click on the file again and click rename
  • rename it to Hosts.old
Reboot your computer.

Next

Rerun the OTL fix

:Services

:Files
ipconfig /flushdns /c

:Commands
[resethosts]
[createrestorepoint]
[reboot]

Please post the OTL fix log.

Ads still there?

📎zek.zip
Thank you very much for your help; it looks like we finally got rid of the ads! I went to a couple of sites that i saw them pop up at constantly and I dont see them anymore. Please see the attached log:

========== SERVICES/DRIVERS ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\akshara\Desktop\cmd.bat deleted successfully.
C:\Users\akshara\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 10212012_174838
Hi zek,

That seemed to work but there are signs of another infections.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. If after running combofix you recieve an message "Illegal operation attempted on a registery key that has been marked for deletion" or similar reboot the computer.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
Sorry for the late reply; went on vacation for a bit and then had to deal with a hurricane :) Please see the attached log as requested and advise as necessary. Thanks again for your help! ComboFix 12-10-31.03 - akshara 10/31/2012 19:54:07.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2038.1154 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\searchplugins\bing-zugo.xml c:\users\akshara\Logo.png c:\windows\system32\crt.dat c:\windows\system32\drivers\etc\hosts.txt c:\windows\system32\shimg.dll c:\windows\system32\URTTemp c:\windows\system32\URTTemp\regtlib.exe . . ((((((((((((((((((((((((( Files Created from 2012-10-01 to 2012-11-01 ))))))))))))))))))))))))))))))) . . 2012-11-01 00:03 . 2012-11-01 00:04 ——– d—–w- c:\users\akshara\AppData\Local\temp 2012-11-01 00:03 . 2012-11-01 00:03 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-21 16:18 . 2012-10-12 05:56 6918632 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2F6608EC-7020-4F24-99BF-4AA47E9BD9ED}\mpengine.dll 2012-10-21 15:15 . 2012-10-21 15:15 ——– d—–w- C:\_OTL 2012-10-20 16:36 . 2012-10-20 16:36 ——– d—–w- c:\users\akshara\AppData\Local\LogMeIn 2012-10-20 16:36 . 2012-07-05 22:09 52128 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll 2012-10-20 16:36 . 2012-07-05 22:09 30624 —-a-w- c:\windows\system32\LMIport.dll 2012-10-20 16:36 . 2012-07-05 22:10 83392 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-10-20 16:36 . 2012-06-08 16:06 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys 2012-10-20 16:36 . 2012-07-05 22:09 87456 —-a-w- c:\windows\system32\LMIinit.dll 2012-10-20 16:36 . 2012-10-31 23:45 ——– d—–w- c:\programdata\LogMeIn 2012-10-20 16:36 . 2012-10-20 16:36 ——– d—–w- c:\program files\LogMeIn 2012-10-20 15:52 . 2012-10-13 19:58 740784 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8B9644A8-6E3D-463D-B445-63D6EE2449A2}\gapaengine.dll 2012-10-20 15:52 . 2012-10-12 05:56 6918632 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-10-20 15:42 . 2012-10-20 16:00 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2012-10-20 15:42 . 2012-10-20 15:45 ——– d—–w- c:\program files\Spybot - Search & Destroy 2012-10-13 20:20 . 2012-08-21 17:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-10-13 20:19 . 2012-10-13 20:19 ——– d—–w- c:\program files\iPod 2012-10-13 20:18 . 2012-10-13 20:20 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-10-13 20:18 . 2012-10-13 20:20 ——– d—–w- c:\program files\iTunes 2012-10-13 20:08 . 2012-09-14 18:28 2048 —-a-w- c:\windows\system32\tzres.dll 2012-10-13 20:08 . 2012-08-24 16:57 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-10-13 20:06 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\system32\crypt32.dll 2012-10-13 20:06 . 2012-06-02 04:36 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-13 20:06 . 2012-06-02 04:36 103936 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-13 20:05 . 2012-08-31 17:18 1211760 —-a-w- c:\windows\system32\drivers\ntfs.sys 2012-10-13 20:03 . 2012-08-30 17:12 3968880 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-10-13 20:03 . 2012-08-30 17:12 3914096 —-a-w- c:\windows\system32\ntoskrnl.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-13 19:55 . 2012-09-30 17:37 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-13 19:55 . 2011-11-19 18:59 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-30 16:17 . 2012-09-30 16:17 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-09-30 16:17 . 2012-09-30 16:17 161792 —-a-w- c:\windows\system32\msls31.dll 2012-09-30 16:17 . 2012-09-30 16:17 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-09-30 16:17 . 2012-09-30 16:17 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-09-30 16:17 . 2012-09-30 16:17 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-09-30 16:17 . 2012-09-30 16:17 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-09-30 16:17 . 2012-09-30 16:17 367104 —-a-w- c:\windows\system32\html.iec 2012-09-30 16:17 . 2012-09-30 16:17 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-09-30 16:17 . 2012-09-30 16:17 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-09-30 16:17 . 2012-09-30 16:17 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-09-30 16:17 . 2012-09-30 16:17 152064 —-a-w- c:\windows\system32\wextract.exe 2012-09-30 16:17 . 2012-09-30 16:17 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-09-30 16:17 . 2012-09-30 16:17 11776 —-a-w- c:\windows\system32\mshta.exe 2012-09-30 16:17 . 2012-09-30 16:17 101888 —-a-w- c:\windows\system32\admparse.dll 2012-09-30 16:17 . 2012-09-30 16:17 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-09-29 19:57 . 2012-09-29 19:58 477168 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-09-29 19:57 . 2010-06-14 23:34 473072 —-a-w- c:\windows\system32\deployJava1.dll 2012-09-09 23:20 . 2011-12-10 21:12 239168 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2012-08-31 02:03 . 2012-08-31 02:03 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2012-08-31 02:03 . 2012-03-21 00:44 99272 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-08-24 06:59 . 2012-10-01 07:00 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51 . 2012-10-01 07:00 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51 . 2012-10-01 07:00 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47 . 2012-10-01 07:00 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47 . 2012-10-01 07:01 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43 . 2012-10-01 07:01 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-22 17:16 . 2012-09-29 20:22 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-22 17:16 . 2012-09-29 20:23 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-08-22 17:16 . 2012-09-29 20:22 240496 —-a-w- c:\windows\system32\drivers\netio.sys 2012-08-22 17:16 . 2012-09-29 20:22 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-08-21 20:12 . 2012-09-29 20:22 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-08-21 17:01 . 2010-06-15 03:06 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2009-09-13 04:05 . 2009-09-13 04:05 124240 —-a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll 2009-09-13 04:06 . 2009-09-13 04:06 13136 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll 2009-09-13 04:06 . 2009-09-13 04:06 70488 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll 2009-09-13 04:06 . 2009-09-13 04:06 91480 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll 2009-09-13 04:06 . 2009-09-13 04:06 22360 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll 2009-09-13 04:07 . 2009-09-13 04:07 255312 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll 2009-09-13 04:06 . 2009-09-13 04:06 31064 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll 2009-09-13 04:06 . 2009-09-13 04:06 40280 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll 2009-08-14 18:33 . 2009-08-14 18:33 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll 2009-09-13 04:06 . 2009-09-13 04:06 23896 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll 2012-09-09 18:31 . 2011-05-24 19:48 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2010-11-20 144384] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-03-31 2221352] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680] "Skytel"="Skytel.exe" [2007-04-06 1822720] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2009-09-13 103768] "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176] "VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-03-06 36864] "VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768] "VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [2007-03-14 2322432] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-06-08 63048] . c:\users\akshara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\akshara\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2007-04-24 00:19 98304 —-a-w- c:\windows\System32\VESWinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup backupExtension=.CommonStartup path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0] 2008-06-12 05:43 640376 —-a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher] 2008-06-12 09:25 37232 —-a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2012-08-28 01:32 59280 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] 2011-11-10 09:17 3514176 —-a-w- c:\program files\DAEMON Tools Lite\DTLite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON NX110 Series] 2008-09-26 11:00 199680 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIFBA.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2010-12-06 09:01 136176 —-atw- c:\users\akshara\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2012-09-10 03:30 421776 —-a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2012-04-19 00:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-01-18 18:02 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 ICScsiSV;Image Converter SCSI Service;c:\program files\Sony\Image Converter 3\ICScsiSV.exe [x] R3 IcVzMonLauncher;IcVzMonLauncher;c:\program files\Sony\Image Converter 3\IcVzMonLauncher.exe [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [x] R3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [x] R3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [x] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x] S2 regi;regi;c:\windows\system32\drivers\regi.sys [x] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [x] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x] S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [x] S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [x] S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\DRIVERS\SonyImgF.sys [x] S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-10-31 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-30 19:55] . 2012-10-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2058305492-2997592224-2038688142-1005Core.job - c:\users\akshara\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-06 09:01] . 2012-10-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2058305492-2997592224-2038688142-1005UA.job - c:\users\akshara\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-06 09:01] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421; IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q;= FF - ExtSQL: 2012-09-29 15:58; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} . - - - - ORPHANS REMOVED - - - - . WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe MSConfigStartUp-QuickBooks Simple Start - c:\program files\Intuit\SimpleStartEntice\entice.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97, 02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7 "{1374A200-8F9E-56F4-AB74-655BC426D972}"=hex:51,66,7a,6c,4c,1d,38,12,6e,a1,67, 17,ac,c1,9a,13,d4,62,26,1b,c1,78,9d,66 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 "{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90, 43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a "{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f, aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04 "{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0, b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84, f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:90,b7,9c,f6,79,51,cd,01 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-31 20:11:15 ComboFix-quarantined-files.txt 2012-11-01 00:11 . Pre-Run: 23,170,551,808 bytes free Post-Run: 23,184,502,784 bytes free . - - End Of File - - 2EE4B5533367143279C730DB9DF87CCD

Attachments:

Hi zek,

Glad you made it through ok.

You have some old java installed. Click start > Control panel. Under programs click uninstall a program and uninstall

Java™ SE Runtime Environment 6
Java™ 6 Update 20


Do not uninstall Java™ 6 Update 35


Next

Click your start button > Control Panel
]
  • Use the drop down menu beside view by and change it to small icons
  • locate java (32bit) in the list and click on it
  • when the java console opens click the update tab
  • Click update now
Decline any other installs that may be offered.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\@
C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\L
C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\U
C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • OTL fix log
  • MBAM log
Everything still ok.
malwarebytes didnt find anything :) malware bytes log: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.02.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 akshara :: AKSHARA-PC [administrator] 11/2/2012 12:24:14 AM mbam-log-2012-11-02 (00-24-14).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 204868 Time elapsed: 5 minute(s), 54 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ————————————————————————————————————————- OTL log: All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\@ moved successfully. C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\L folder moved successfully. C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76}\U folder moved successfully. C:\Windows\Installer\{5c2b86a6-8e4f-e4f9-1f54-e5e828665a76} folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: akshara ->Temp folder emptied: 949345 bytes ->Temporary Internet Files folder emptied: 415106 bytes ->Java cache emptied: 43773 bytes ->FireFox cache emptied: 107738554 bytes ->Google Chrome cache emptied: 201364907 bytes ->Flash cache emptied: 96538 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 296.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 11022012_001001 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hi zek,

One more scan to check for remnants.


As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

Please post the ESET log if there was one.
here is the ESET log looks like it found a couple of threats: C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Intuit\Adobe\sanmxpdch.dll a variant of Win32/Kryptik.ALUZ trojan C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I63T8CF6\q[1].htm HTML/Iframe.B.Gen virus C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I63T8CF6\US_468X60_20111115[1].htm HTML/Iframe.B.Gen virus C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ICJ8YL9A\q[1].htm HTML/Iframe.B.Gen virus C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IFDA8USE\US_468X60_20111115[1].htm HTML/Iframe.B.Gen virus C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WJU9W1VX\q[1].htm HTML/Iframe.B.Gen virus C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WJU9W1VX\q[2].htm HTML/Iframe.B.Gen virus C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\f2d5a10-25f156a5 Java/Exploit.Agent.NBR trojan C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\3eac6f9e-3d84eb7c a variant of Java/Exploit.Agent.NCD trojan C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\3eac6f9e-4601091b Java/Exploit.Agent.NBS trojan C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\6ccc6074-5c21b158 Java/Exploit.CVE-2011-3544.AU trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0001.dta Win32/Olmarik.AWO trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0002.dta Win64/Olmarik.AD trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0003.dta Win32/Olmarik.AYH trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0004.dta Win64/Olmarik.AG trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0005.dta a variant of Win32/Rootkit.Kryptik.LH trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0006.dta Win64/Olmarik.AF trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0010.dta Win32/Olmarik.AWO trojan C:\TDSSKiller_Quarantine\09.09.2012_00.36.01\mbr0000\tdlfs0000\tsk0011.dta Win64/Olmarik.X trojan C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Default\aadggcdcgdgbdigddjdgdbdhdedhdide\background.html Win32/BHO.OEI trojan C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Default\aadggcdcgdgbdigddjdgdbdhdedhdide\ContentScript.js Win32/BHO.OEI trojan C:\Users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\extensions\[removed] JS/Redirector.NCA trojan
Hi zek,

Most of the detections are quarantined files and intemporary locations.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\TDSSKiller_Quarantine
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Intuit\Adobe\sanmxpdch.dll
C:\Users\akshara\AppData\Roaming\Mozilla\Firefox\Profiles\crketjqa.default\extensions\[removed] 
C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Default\aadggcdcgdgbdigddjdgdbdhdedhdide\ContentScript.js
C:\Users\akshara\AppData\Local\Google\Chrome\User Data\Default\Default\aadggcdcgdgbdigddjdgdbdhdedhdide\background.html 
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I63T8CF6\q[1].htm
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I63T8CF6\US_468X60_20111115[1].htm 
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ICJ8YL9A\q[1].htm
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IFDA8USE\US_468X60_20111115[1].htm 
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WJU9W1VX\q[1].htm
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WJU9W1VX\q[2].htm
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\f2d5a10-25f156a5
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\3eac6f9e-3d84eb7c
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\3eac6f9e-4601091b
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\6ccc6074-5c21b158

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log.

Any issues?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI