This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:Blank [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my Google Chrome browser has been hijacked by About:Blank - every time I try to open a site, it opens, and then goes blank.
I have attached the OTL, Hijack and DDS files below (and in subsequent posts).
Hopefully this is a fairly common problem, and easily remedied.
Thank you,

OTL logfile created on: 25/10/2012 22:22:41 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.54% Memory free
6.73 Gb Paging File | 6.32 Gb Available in Paging File | 93.88% Paging File free
Paging file location(s): J:\pagefile.sys 5000 5000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 108.43 Gb Free Space | 74.66% Space Free | Partition Type: NTFS
Drive J: | 74.46 Gb Total Space | 69.47 Gb Free Space | 93.30% Space Free | Partition Type: NTFS
Drive L: | 931.51 Gb Total Space | 123.47 Gb Free Space | 13.25% Space Free | Partition Type: NTFS

Computer Name: CHICPC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Disk Speedup\DSUDefragSrv.exe (Systweak Inc., (www.systweak.com))
PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Services (SafeList) ==========

SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe File not found
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe File not found
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (WajamUpdater) – C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (DSUDiskOptimizer) – C:\Program Files\Disk Speedup\DSUDefragSrv.exe (Systweak Inc., (www.systweak.com))
SRV - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (RapportIaso) – c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (ntcdrdrv) – system32\DRIVERS\ntcdrdrv.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (ManyCam) – system32\DRIVERS\ManyCam.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (Cdr4_2K) – File not found
DRV - (catchme) – C:\DOCUME~1\chic\LOCALS~1\Temp\catchme.sys File not found
DRV - (82311) – globalroot\C:\WINDOWS\system32\drivers\82311.sys File not found
DRV - (79612) – globalroot\C:\WINDOWS\system32\drivers\79612.sys File not found
DRV - (78928) – globalroot\C:\WINDOWS\system32\drivers\78928.sys File not found
DRV - (74636) – globalroot\C:\WINDOWS\system32\drivers\74636.sys File not found
DRV - (735E) – globalroot\C:\WINDOWS\system32\drivers\735E.sys File not found
DRV - (73513) – globalroot\C:\WINDOWS\system32\drivers\73513.sys File not found
DRV - (725F) – globalroot\C:\WINDOWS\system32\drivers\725F.sys File not found
DRV - (6824) – globalroot\C:\WINDOWS\system32\drivers\6824.sys File not found
DRV - (6064) – globalroot\C:\WINDOWS\system32\drivers\6064.sys File not found
DRV - (5834) – globalroot\C:\WINDOWS\system32\drivers\5834.sys File not found
DRV - (48426) – globalroot\C:\WINDOWS\system32\drivers\48426.sys File not found
DRV - (4481D) – globalroot\C:\WINDOWS\system32\drivers\4481D.sys File not found
DRV - (4363) – globalroot\C:\WINDOWS\system32\drivers\4363.sys File not found
DRV - (2993) – globalroot\C:\WINDOWS\system32\drivers\2993.sys File not found
DRV - (2004) – globalroot\C:\WINDOWS\system32\drivers\2004.sys File not found
DRV - (1964) – globalroot\C:\WINDOWS\system32\drivers\1964.sys File not found
DRV - (19336) – globalroot\C:\WINDOWS\system32\drivers\19336.sys File not found
DRV - (19310) – globalroot\C:\WINDOWS\system32\drivers\19310.sys File not found
DRV - (1844) – globalroot\C:\WINDOWS\system32\drivers\1844.sys File not found
DRV - (1803) – globalroot\C:\WINDOWS\system32\drivers\1803.sys File not found
DRV - (1703C) – globalroot\C:\WINDOWS\system32\drivers\1703C.sys File not found
DRV - (165D) – globalroot\C:\WINDOWS\system32\drivers\165D.sys File not found
DRV - (1655) – globalroot\C:\WINDOWS\system32\drivers\1655.sys File not found
DRV - (1643) – globalroot\C:\WINDOWS\system32\drivers\1643.sys File not found
DRV - (1613F) – globalroot\C:\WINDOWS\system32\drivers\1613F.sys File not found
DRV - (16130) – globalroot\C:\WINDOWS\system32\drivers\16130.sys File not found
DRV - (16017) – globalroot\C:\WINDOWS\system32\drivers\16017.sys File not found
DRV - (148D) – globalroot\C:\WINDOWS\system32\drivers\148D.sys File not found
DRV - (1484) – globalroot\C:\WINDOWS\system32\drivers\1484.sys File not found
DRV - (12115) – globalroot\C:\WINDOWS\system32\drivers\12115.sys File not found
DRV - (12032) – globalroot\C:\WINDOWS\system32\drivers\12032.sys File not found
DRV - (1202A) – globalroot\C:\WINDOWS\system32\drivers\1202A.sys File not found
DRV - (117F) – globalroot\C:\WINDOWS\system32\drivers\117F.sys File not found
DRV - (1083) – globalroot\C:\WINDOWS\system32\drivers\1083.sys File not found
DRV - (100D) – globalroot\C:\WINDOWS\system32\drivers\100D.sys File not found
DRV - (MpKsledf26030) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{64F6E675-6396-4B2D-8926-876CD33774CA}\MpKsledf26030.sys (Microsoft Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (SmartDefragDriver) – C:\WINDOWS\system32\drivers\SmartDefragDriver.sys ()
DRV - (andnetndis) – C:\WINDOWS\system32\drivers\lgandnetndis.sys (LG Electronics Inc.)
DRV - (AndNetGps) – C:\WINDOWS\system32\drivers\lgandnetgps.sys (LG Electronics Inc.)
DRV - (ANDNetModem) – C:\WINDOWS\system32\drivers\lgandnetmodem.sys (LG Electronics Inc.)
DRV - (AndNetDiag) – C:\WINDOWS\system32\drivers\lgandnetdiag.sys (LG Electronics Inc.)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (s716unic) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\system32\drivers\BTHidMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {CF739809-1C6C-47C0-85B9-569DBB141420}
IE - HKLM\..\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}: "URL" = http://uk.search.yahoo.com/search?ei=UTF-8…p={searchTerms}
IE - HKLM\..\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}: "URL" = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKLM\..\SearchScopes\{749F5CD3-7B4D-4349-B510-0586016EE61C}: "URL" = http://uk.news.search.yahoo.com/search/new…p={searchTerms}
IE - HKLM\..\SearchScopes\{8EA8ADF6-B3CF-4CBD-A630-741A82BD8448}: "URL" = http://uk.local.yahoo.com/search.html?p={s…GugiXML&cs;=
IE - HKLM\..\SearchScopes\{8FE0B69C-E812-4CDA-B67D-14DA6B88C324}: "URL" = http://uk.search.yahoo.com/search/dir?ei=U…p={searchTerms}
IE - HKLM\..\SearchScopes\{B4E9D89A-5ECB-4D73-B42B-B0EF5BF2DDA5}: "URL" = http://shopping.yahoo.co.uk/ctl/do/search?…y={searchTerms}
IE - HKLM\..\SearchScopes\{C9201B62-6575-4C97-BE89-44B460C2E5F0}: "URL" = http://uk.search.yahoo.com/search/video?ei…p={searchTerms}
IE - HKLM\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirec…erms}&crm;=1
IE - HKLM\..\SearchScopes\{CF74A3B6-1C71-4192-9F84-885EEBCE8AA1}: "URL" = http://uk.search.yahoo.com/search/audio?ei…p={searchTerms}
IE - HKLM\..\SearchScopes\{E903FDC2-77F8-4E45-9476-AC74FFBDEA6F}: "URL" = http://uk.search.yahoo.com/search/images?e…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0F82FEE6-B232-0661-52CB-1B2546B28F18}
IE - HKCU\..\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}: "URL" = http://uk.search.yahoo.com/search?ei=UTF-8…p={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}: "URL" = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…z=1I7ADBS_en-GB
IE - HKCU\..\SearchScopes\{9B0FE47C-BED4-44E4-8C07-D7F906B08B5A}: "URL" = http://www.ask.com/web?q={searchTerms}&…=1690&l;=dir
IE - HKCU\..\SearchScopes\{9BE63AD6-4299-4920-B628-B11D2D83B9CC}: "URL" = http://uk.search.yahoo.com/search?fr=chr-g…p={searchTerms}
IE - HKCU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirec…erms}&crm;=1
IE - HKCU\..\SearchScopes\{F0816BF4-5A7B-4C14-9FAE-563F3DEAD1CD}: "URL" = http://www.buzqo.com/s/?q={searchTerms}&am;…eferrer:source}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledAddons: {dd05fd3d-18df-4ce4-ae53-e795339c5f01}:1.21
FF - prefs.js..extensions.enabledAddons: {EEE6C361-6118-11DC-9C72-001320C79847}:[removed]
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.9rc3
FF - prefs.js..extensions.enabledAddons: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120910
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://search.sweetim.com/search.asp?src=2&crg;=3.1010000.10009&q;="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.sweetim.com/search.asp?src=2&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: G:\Program Files\iTunes\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2303: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2361: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1465: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\chic\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/12 22:33:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/18 05:49:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/18 05:49:22 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2012/10/25 22:17:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2012/10/25 22:17:43 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2012/02/05 20:11:54 | 000,000,000 | —D | M] (TVU Web Player) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2012/10/25 22:17:42 | 000,530,225 | —- | M] () (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2011/08/18 20:36:50 | 000,090,116 | —- | M] () (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
[2012/10/25 06:24:35 | 000,169,792 | —- | M] () (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2009/04/11 15:17:33 | 000,000,681 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/07/11 19:04:02 | 000,000,633 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\startsear.xml
[2012/10/19 18:52:03 | 000,003,915 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\sweetim.xml
[2011/08/03 21:36:01 | 000,001,386 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\yahoo-zugo.xml
[2012/04/25 06:24:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/24 18:49:05 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2012/04/21 02:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\mozilla firefox\plugins\npBBCPlugin.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011/10/03 10:14:54 | 000,083,456 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2012/04/21 02:18:25 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/21 02:18:25 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.twitter.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://www.twitter.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BBC iPlayer Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = G:\Program Files\bin\new_plugin\npjp2.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: iTunes Application Detector (Enabled) = G:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: VLC Web Plugin (Enabled) = g:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - Extension: WOT = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.3.6_0\
CHR - Extension: YouTube = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Slinky Elegant = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln\19.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: http://www.miniclip.com/games/en/ = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ganlfmllnoladlbocpgloiambgjcfcgo\2012.1.20.54959_0\
CHR - Extension: Fast save = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbdmalcpfacdgmkafcdhlohodkmdcgng\1.1_0\
CHR - Extension: Wajam = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: WOT = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.3.6_0\
CHR - Extension: YouTube = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Slinky Elegant = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln\19.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: http://www.miniclip.com/games/en/ = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ganlfmllnoladlbocpgloiambgjcfcgo\2012.1.20.54959_0\
CHR - Extension: Fast save = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbdmalcpfacdgmkafcdhlohodkmdcgng\1.1_0\
CHR - Extension: Wajam = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/12/06 06:59:52 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon;) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe File not found
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AshSnap] C:\Program Files\Ashampoo\Ashampoo Snap 6\ashsnap.exe (Ashampoo Media GmbH & Co. KG)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKCU\..Trusted Domains: adobe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: course-source.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: epautotest.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: learndirect.co.uk ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: learndirect-business.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: mindleaders.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: thirdforce.com ([]* in Trusted sites)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CD82845A-4D7A-45CC-9EF0-8828228EA642}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E350DD9B-A2A9-4B8D-8944-A6BF1661A59E}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\chic\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\chic\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | R–D | M] - L:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | R— | M] () - L:\AUTORUN.FCB – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave8 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/25 22:21:12 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2012/10/25 21:25:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SweetIM
[2012/10/25 06:27:45 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\Ashampoo Snap 6
[2012/10/25 06:24:08 | 000,000,000 | —D | C] – C:\i386\Programs\Wajam
[2012/10/25 06:24:04 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\Wajam
[2012/10/25 06:23:59 | 000,000,000 | —D | C] – C:\Program Files\Wajam
[2012/10/19 18:51:36 | 000,000,000 | —D | C] – C:\Program Files\SweetIM
[2012/10/19 18:49:44 | 000,000,000 | —D | C] – C:\Program Files\ExpressFiles
[2012/10/19 18:49:44 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\ExpressFiles
[2012/09/29 10:25:12 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\default
[2012/09/28 06:24:12 | 000,000,000 | —D | C] – C:\i386\Programs\Ashampoo
[2009/08/17 17:46:25 | 008,046,393 | —- | C] (Moyea Software Co., LTD ) – C:\Documents and Settings\chic\FLV to Video Converter2.0.1.0-Setup.exe
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2006/07/09 22:20:16 | 003,167,744 | —- | C] (Citrix Online) – C:\Documents and Settings\chic\gosetup.exe

========== Files - Modified Within 30 Days ==========

[2012/10/25 22:21:15 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2012/10/25 22:20:48 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/10/25 22:17:22 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/25 22:17:21 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/25 22:15:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2012/10/25 22:11:13 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/25 22:11:11 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/25 22:11:10 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\Express FilesUpdate.job
[2012/10/25 22:10:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/25 22:10:36 | 2145,538,048 | -HS- | M] () – C:\hiberfil.sys
[2012/10/25 21:52:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/25 19:27:07 | 000,000,658 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/25 14:03:52 | 000,122,880 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/25 06:27:39 | 000,000,851 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Snap 6.lnk
[2012/10/25 06:27:39 | 000,000,833 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Snap 6.lnk
[2012/10/25 04:15:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2012/10/25 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2012/10/24 12:26:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/10 21:23:25 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/06 06:27:54 | 000,000,860 | —- | M] () – C:\Documents and Settings\chic\Desktop\YouTube DL.lnk
[2012/10/01 13:31:13 | 000,001,733 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\5gtyns2mwr3.crx
[2012/09/29 19:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/09/28 06:24:12 | 000,000,786 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 11.lnk
[2012/09/28 06:24:12 | 000,000,786 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 11.lnk

========== Files Created - No Company Name ==========

[2012/10/25 06:27:39 | 000,000,851 | —- | C] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Snap 6.lnk
[2012/10/25 06:27:39 | 000,000,833 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Snap 6.lnk
[2012/10/19 18:49:54 | 000,000,290 | —- | C] () – C:\WINDOWS\tasks\Express FilesUpdate.job
[2012/10/01 13:31:13 | 000,001,733 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\5gtyns2mwr3.crx
[2012/09/28 06:24:12 | 000,000,786 | —- | C] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 11.lnk
[2012/09/28 06:24:12 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 11.lnk
[2012/07/07 15:31:19 | 001,074,636 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2012/07/07 15:31:19 | 001,074,636 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2012/07/07 15:31:19 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2012/07/07 15:30:41 | 002,807,708 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2012/01/14 10:34:25 | 000,000,874 | —- | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/10/20 22:01:12 | 000,002,404 | —- | C] () – C:\WINDOWS\System32\ASOROSet.bin
[2011/10/10 05:27:00 | 000,000,000 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\{FA8E2894-B67D-4D46-8D71-333C38DF5C23}
[2011/09/04 15:57:36 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/09/04 15:57:36 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/08/09 10:48:53 | 000,013,304 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2011/08/09 10:48:53 | 000,011,860 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[2011/07/10 11:56:16 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/07/10 11:56:15 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/05/30 14:08:48 | 000,000,079 | —- | C] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/28 08:55:55 | 000,112,952 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/04/03 10:41:37 | 000,002,528 | —- | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | —- | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/11 21:13:21 | 000,001,024 | —- | C] () – C:\Documents and Settings\chic\.rnd
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2007/11/28 06:09:52 | 000,000,696 | —- | C] () – C:\Documents and Settings\chic\PCTuneUp.config
[2007/07/11 22:06:05 | 000,000,127 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2006/12/30 23:59:04 | 000,000,020 | —- | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/01/28 15:51:23 | 019,866,702 | —- | C] () – C:\Documents and Settings\chic\fm5.fm
[2005/12/04 00:14:05 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/24 23:45:56 | 000,122,880 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2004/08/10 14:09:48 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 01:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 13:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 01:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2012/10/25 22:05:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/11/19 13:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2011/04/23 17:50:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2012/03/14 09:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\explauncher
[2012/06/09 22:20:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011/09/20 19:42:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/05/10 07:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2011/07/02 17:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2012/09/08 10:11:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2012/09/08 10:16:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/02/20 22:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2012/10/25 21:25:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SweetIM
[2011/10/21 06:34:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Systweak
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2011/12/19 19:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/12/25 23:57:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2011/12/01 19:03:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2012/03/04 14:22:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\BeNaughtyChat
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2011/07/28 05:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2012/02/12 22:34:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DDMSettings
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2012/10/19 18:49:58 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ExpressFiles
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/11/06 12:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/07/10 11:56:15 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2011/07/02 17:29:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\muvee Technologies
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2011/07/02 17:26:20 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Nikon
[2012/01/28 19:00:58 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\OnLive App
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2012/05/27 12:24:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Oracle
[2012/02/20 22:08:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Cleaners
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2012/02/20 22:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PCPro
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2011/11/21 23:17:19 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2012/10/25 17:39:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Systweak
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/08/24 21:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TreeCardGames
[2012/10/16 22:51:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\uTorrent
[2012/03/04 13:38:05 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vcards
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2012/10/06 06:28:24 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\YouTubeFreeDownloader

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/04 06:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 12:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 11:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 06:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/10/25 21:46:40 | 000,055,880 | —- | M] () MD5=E44182F1F4C5CEF583731AF7204DF4AA – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SC_ >
[2004/08/04 06:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.ZIP >
[2009/06/03 22:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CHM >
[2004/08/04 06:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 06:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 09:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 06:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/29 08:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/19 06:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 07:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 12:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/25 06:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2012/04/22 07:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\WINDOWS\ie7updates\KB2722913-IE7\iexplore.exe
[2012/07/03 11:57:55 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0F06AE8613FE66FF4C02A0C27D0DC7EF – C:\WINDOWS\ie7updates\KB2744842-IE7\iexplore.exe
[2007/04/24 15:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/19 06:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 09:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2011/12/16 12:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie7updates\KB2675157-IE7\iexplore.exe
[2011/10/31 11:32:32 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=1C5DA2D9EA2A59D0D5C116FA3A5A21AA – C:\WINDOWS\$hf_mig$\KB2618444-IE7\SP3QFE\iexplore.exe
[2008/08/23 06:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 16:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2010/06/17 16:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\SoftwareDistribution\Download\bd4a8ed1ff18ce602cf240d9190152b0\sp3gdr\iexplore.exe
[2008/04/22 08:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 12:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 09:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 09:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2011/10/31 11:46:00 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=2E34CF22B5862AB02786F0819B9FD819 – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2012/08/26 07:40:35 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=326B5461CCD7DB0CD6B126ADEB28667A – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/26 07:40:35 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=326B5461CCD7DB0CD6B126ADEB28667A – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/08/27 06:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 11:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2009/06/29 09:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 11:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/28 07:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2012/02/29 12:01:00 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=50BA6A230D743A4D33BFFA2FA1113055 – C:\WINDOWS\ie7updates\KB2699988-IE7\iexplore.exe
[2006/10/17 14:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 14:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 11:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/14 01:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/07/03 11:35:40 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=5A120ED9A6327241A69241A3D854AB21 – C:\WINDOWS\$hf_mig$\KB2722913-IE7\SP3QFE\iexplore.exe
[2007/10/10 09:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 10:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 09:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2011/08/17 12:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\erdnt\cache\iexplore.exe
[2011/08/17 12:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\ie7updates\KB2618444-IE7\iexplore.exe
[2008/02/22 10:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 12:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/28 07:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 09:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 19:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2011/06/20 12:29:11 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=993F33696EF219C306BF9BBA34D85073 – C:\WINDOWS\ie7updates\KB2586448-IE7\iexplore.exe
[2007/04/24 15:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/15 08:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 05:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 15:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/06/17 15:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\SoftwareDistribution\Download\bd4a8ed1ff18ce602cf240d9190152b0\sp3qfe\iexplore.exe
[2010/04/16 12:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/23 06:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/04/21 11:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\ie7updates\KB2559049-IE7\iexplore.exe
[2010/12/20 11:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/28 05:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 10:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/25 06:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 12:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 09:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/23 06:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2011/08/17 11:34:43 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=CB0AFAF9E5C5FE70EC7087E71275DD33 – C:\WINDOWS\$hf_mig$\KB2586448-IE7\SP3QFE\iexplore.exe
[2012/04/22 07:32:36 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=CE2379FC341C65CAD88FF8264A791AB5 – C:\WINDOWS\$hf_mig$\KB2699988-IE7\SP3QFE\iexplore.exe
[2009/12/18 08:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/28 07:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 11:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/12/16 11:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe
[2011/06/20 11:38:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DE0F15DD275A36C3E67DC1E36F958F3A – C:\WINDOWS\$hf_mig$\KB2559049-IE7\SP3QFE\iexplore.exe
[2012/02/29 11:34:48 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DF642AABFDACE36E3B4329091A07DE87 – C:\WINDOWS\$hf_mig$\KB2675157-IE7\SP3QFE\iexplore.exe
[2011/02/14 12:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 13:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 12:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 06:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/23 06:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 11:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 12:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 06:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
[2012/08/26 07:32:43 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=F516E1F811AC01F5DA1D486051069A7C – C:\WINDOWS\$hf_mig$\KB2744842-IE7\SP3QFE\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 14:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/10/25 21:47:05 | 000,081,044 | —- | M] () MD5=D4F81388E58493B32650D16BE9DF06BC – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CNF >
[2005/11/27 10:46:49 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\chic\My Documents\My Webs\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2009/02/06 12:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 01:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 01:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 06:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\i386\services.exe
[2004/08/04 06:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SERVICES.LNK >
[2008/02/02 00:00:15 | 000,001,602 | —- | M] () MD5=FA42047000D028B48AD9EC8F757A6915 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/04 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 06:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2005/11/24 22:47:54 | 000,000,735 | —- | M] () – C:\892.cin
[2010/06/02 21:33:44 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 11:18:33 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/06/05 06:54:17 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/12/06 07:05:30 | 000,019,821 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/11/03 03:45:47 | 000,003,291 | —- | M] () – C:\data
[2006/01/17 11:43:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2005/11/17 20:51:24 | 000,005,148 | R— | M] () – C:\dell.sdr
[2011/07/28 05:04:17 | 000,059,013 | —- | M] () – C:\dlcd.log
[2010/10/25 20:43:22 | 000,009,432 | —- | M] () – C:\dlcdscan.log
[2009/02/18 22:37:03 | 000,003,532 | —- | M] () – C:\drmHeader.bin
[2006/01/29 14:07:03 | 000,013,312 | —- | M] () – C:\dvb.GRF
[2006/01/28 20:59:03 | 000,008,192 | —- | M] () – C:\dvb4.GRF
[2010/02/21 13:11:54 | 000,000,157 | —- | M] () – C:\error.txt
[2012/10/25 22:10:36 | 2145,538,048 | -HS- | M] () – C:\hiberfil.sys
[2011/10/30 22:52:21 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2005/11/24 22:18:42 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\IO.SYS
[2005/11/17 21:11:23 | 000,000,897 | —- | M] () – C:\IPH.PH
[2010/05/07 19:49:49 | 000,029,887 | —- | M] () – C:\log.txt
[2006/10/08 20:03:52 | 000,000,036 | —- | M] () – C:\mediamp3.dat
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/27 22:24:22 | 000,250,048 | RHS- | M] () – C:\ntldr
[2006/02/25 15:44:24 | 000,184,320 | —- | M] () – C:\PlayerHost.dll
[2008/06/24 18:14:29 | 000,003,021 | —- | M] () – C:\rollback.ini
[2007/11/08 20:03:17 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
[2011/12/06 06:39:21 | 000,077,466 | —- | M] () – C:\TDSSKiller.2.6.21.0_06.12.2011_05.38.02_log.txt
[2012/07/10 19:22:47 | 000,000,111 | —- | M] () – C:\UnInstallService.bat

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/10/02 09:47:51 | 000,001,738 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/27 22:36:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2008/06/23 18:36:24 | 000,773,120 | —- | M] () – C:\WINDOWS\system32\NEROINSTAEC43759.DB

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/24 21:16:36 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/10/25 22:21:15 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2009/05/03 09:04:25 | 003,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\chic\Desktop\procexp.exe
[2010/09/14 17:28:00 | 000,102,400 | —- | M] () – C:\Documents and Settings\chic\Desktop\Snippy.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2010/05/20 15:27:26 | 000,013,023 | —- | M] () – C:\WINDOWS\VX1000.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-25 21:06:14

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream

< End of report >
OTL Extras logfile created on: 25/10/2012 22:22:41 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.54% Memory free
6.73 Gb Paging File | 6.32 Gb Available in Paging File | 93.88% Paging File free
Paging file location(s): J:\pagefile.sys 5000 5000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 108.43 Gb Free Space | 74.66% Space Free | Partition Type: NTFS
Drive J: | 74.46 Gb Total Space | 69.47 Gb Free Space | 93.30% Space Free | Partition Type: NTFS
Drive L: | 931.51 Gb Total Space | 123.47 Gb Free Space | 13.25% Space Free | Partition Type: NTFS

Computer Name: CHICPC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP" = 135:TCP:*:Enabled:TCP Port 135
"5985:TCP" = 5985:TCP:*:Enabled:Windows Remote Management
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kontiki\KService.exe" = C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service – (Kontiki Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe – (Microsoft Corporation)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe" = C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe:LocalSubNet:Enabled:HP Device Setup – (Hewlett-Packard Co.)
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Disabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe" = C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe:*:Enabled:BT Broadband Desktop Help – (Alcatel-Lucent)
"C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" = C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe:*:Enabled:BT Broadband Desktop Help Notifier – (Alcatel-Lucent)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"G:\Program Files\bin\javaw.exe" = G:\Program Files\bin\javaw.exe:*:Enabled:Java™ Platform SE binary
"C:\Program Files\TVUPlayer\TVUPlayer.exe" = C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component – (TVU networks)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"G:\Program Files\iTunes\iTunes.exe" = G:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
"K:\Program Files\iTunes\iTunes.exe" = K:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:\Program Files\Java\jre7\bin\javaw.exe" = C:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Oracle Corporation)
"C:\Program Files\ExpressFiles\expressdl.exe" = C:\Program Files\ExpressFiles\expressdl.exe:*:Enabled:Express Files
"C:\Program Files\ExpressFiles\ExpressFiles.exe" = C:\Program Files\ExpressFiles\ExpressFiles.exe:*:Enabled:Express Files
"C:\Documents and Settings\chic\Local Settings\temp\toolbar16242984.exe" = C:\Documents and Settings\chic\Local Settings\temp\toolbar16242984.exe:*:Enabled:InHouseSDM Setup – (SweetIM Technologies Ltd.)
"C:\WINDOWS\system32\msiexec.exe" = C:\WINDOWS\system32\msiexec.exe:*:Enabled:UpdateManagerSetup – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0354C0B5-AA35-49D8-B7B7-1CF3412465DD}" = DataCastComponent
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}" = Search Settings 1.2.1
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F6D55D8-89AA-4C1D-BC4C-ACBBDE8BE57A}" = Serif PhotoPlus 8.0
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1D3C662A-F6C6-4767-A788-7AA43A9A1317}" = ARTEuro
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java™ 7 Update 5
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{39CEE1F2-12B6-4C50-9131-04BFCA110578}" = PowerCinema NE for Everio
"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10
"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Photo Premium 10
"{4442AB48-DEC4-4B39-B067-1F75BF8017E7}" = Creative Centrale
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{496F4FDB-A4A5-4AB1-89C2-7B4FFD37F9F1}" = HP Deskjet 1050 J410 series Basic Device Software
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}" = HP Deskjet 1050 J410 series Help
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7390478C-8581-415E-92E9-2997D9306B81}" = PC Connectivity Solution
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90240409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Resource Kit
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95774351-6087-3A3B-8CA8-70BEE49D2BD5}" = Google Gears
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A7894110-9C15-43EF-89E9-060363290188}" = Samsung PC Studio
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free YouTube Downloader 3.3.115
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC7EE5F1-0DE4-4256-8E43-92B73C8E6019}" = LG Bluetooth Drivers
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.27
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{BEA3FF0E-D040-4D9A-B939-9AEB28C2EC64}" = HP Deskjet 1050 J410 series Product Improvement Study
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB481CC-F57C-4397-81A0-DADD22257047}" = Sound Blaster Live! 24-bit
"{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D466F3D9-510C-4729-B7D4-2E70490E4CDF}" = BBC iPlayer Download Manager
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D95CD7BE-A894-4F6C-B9DF-578C3CB411D4}" = VLC
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{DAB5C521-80B2-48C3-B0DA-326A1B331F55}" = GoToAssist Corporate
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E72019B8-1287-4093-BE9B-1CFA7BA1A8D2}" = Windows Desktop Search 3.01
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"{F8650CB3-89F1-4AE0-81AC-917423C58DB8}" = Serif PhotoPlus Association File Formats
"{FC7E771F-8170-4573-825D-EDB6723C804F}_is1" = Disk Speedup
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382" = Windows Driver Package - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0)
"3D Billiard_is1" = 3D Billiards 1.36
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"Amazon Kindle" = Amazon Kindle
"Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10 v.10.0.15
"Ashampoo Burning Studio 11_is1" = Ashampoo Burning Studio 11 v.11.0.4
"Ashampoo Snap 6_is1" = Ashampoo Snap 6 v.6.0.1
"ATI Display Driver" = ATI Display Driver
"BBC iPlayer Download Manager" = BBC iPlayer Download Manager
"BT Broadband Desktop Help" = BT Broadband Desktop Help
"CC Network Video Client" = CC Network Video Client
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Creative Centrale" = Creative Centrale
"Defraggler" = Defraggler (remove only)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup" = DivX Setup
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"ERUNT_is1" = ERUNT 1.1j
"Foxit Reader" = Foxit Reader
"Google Chrome" = Google Chrome
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IEAK5" = Microsoft Internet Explorer Administration Kit 5
"iLivid" = iLivid
"Indeo® software" = Indeo® software
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"LG PC Suite IV" = LG PC Suite IV
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PictureItPrem_v10" = Microsoft Photo Premium 10
"PROSet" = Intel® PRO Network Connections Drivers
"RarZilla Free Unrar" = RarZilla Free Unrar
"Revo Uninstaller" = Revo Uninstaller 1.94
"Smart Defrag 2_is1" = Smart Defrag 2
"Spotify" = Spotify
"TVUPlayer" = TVUPlayer [removed]
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV
"VLC media player" = VLC media player 2.0.2
"vShare.tv plugin" = vShare.tv plugin 1.3
"Wajam" = Wajam
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.2
"winusb0100" = Microsoft WinUsb 1.0
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"YouTube Free Downloader" = YouTube Free Downloader
"ZENMXUG" = Creative ZEN MX Documentation
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CNET TechTracker" = CNET TechTracker
"f031ef6ac137efc5" = Dell Driver Download Manager
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 07/10/2012 10:11:19 | Computer Name = CHICPC | Source = MsiInstaller | ID = 11327
Description = Product: swMSM – Error 1327.Invalid Drive: F:\

Error - 19/10/2012 13:52:11 | Computer Name = CHICPC | Source = Application Error | ID = 1000
Description = Faulting application revouninstaller.exe, version 1.9.4.0, faulting
module revouninstaller.exe, version 1.9.4.0, fault address 0x0007cbc6.

Error - 24/10/2012 10:09:14 | Computer Name = CHICPC | Source = MsiInstaller | ID = 11324
Description = Product: swMSM – Error 1324.The path My Pictures contains an invalid
character.

Error - 25/10/2012 14:05:24 | Computer Name = CHICPC | Source = Avira Antivirus | ID = 4118
Description =

Error - 25/10/2012 16:24:15 | Computer Name = CHICPC | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80070005 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 25/10/2012 16:24:15 | Computer Name = CHICPC | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x80040206.

[ OSession Events ]
Error - 17/11/2008 19:32:11 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 10/04/2009 11:57:43 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 02/05/2009 15:11:19 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 19/06/2009 17:58:10 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 25/10/2012 16:36:25 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7034
Description = The DNS Client service terminated unexpectedly. It has done this
1 time(s).

Error - 25/10/2012 16:36:28 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7031
Description = The Windows Driver Foundation - User-mode Driver Framework service
terminated unexpectedly. It has done this 1 time(s). The following corrective
action will be taken in 120000 milliseconds: Restart the service.

Error - 25/10/2012 16:44:38 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The COMODO Internet Security Helper Service service failed to start
due to the following error: %%3

Error - 25/10/2012 16:44:38 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The Bonjour Service service failed to start due to the following error:
%%2

Error - 25/10/2012 16:44:38 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The 5.0M MPEG4 DV Video Capture service failed to start due to the
following error: %%1058

Error - 25/10/2012 16:44:38 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The Cdralw2k service failed to start due to the following error: %%1058

Error - 25/10/2012 17:11:00 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The COMODO Internet Security Helper Service service failed to start
due to the following error: %%3

Error - 25/10/2012 17:11:00 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The Bonjour Service service failed to start due to the following error:
%%2

Error - 25/10/2012 17:11:00 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The 5.0M MPEG4 DV Video Capture service failed to start due to the
following error: %%1058

Error - 25/10/2012 17:11:00 | Computer Name = CHICPC | Source = Service Control Manager | ID = 7000
Description = The Cdralw2k service failed to start due to the following error: %%1058


< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:55:19, on 25/10/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17114)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Disk Speedup\DSUDefragSrv.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wajam\Updater\WajamUpdater.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Zune\ZuneBusEnum.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\chic\Desktop\OTL.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\chic\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [AshSnap] C:\Program Files\Ashampoo\Ashampoo Snap 6\ashsnap.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O15 - Trusted Zone: *.adobe.com
O15 - Trusted Zone: *.course-source.net
O15 - Trusted Zone: *.epautotest.com
O15 - Trusted Zone: *.learndirect-business.com
O15 - Trusted Zone: *.learndirect.co.uk
O15 - Trusted Zone: *.mindleaders.com
O15 - Trusted Zone: *.thirdforce.com
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: DSUDiskOptimizer - Systweak Inc., (www.systweak.com) - C:\Program Files\Disk Speedup\DSUDefragSrv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: WajamUpdater - Wajam - C:\Program Files\Wajam\Updater\WajamUpdater.exe

–
End of file - 10826 bytes
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 22:56:48.75 on 25/10/2012 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 10.5.1 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2046.1339 [GMT 1:00] . AV: PC Cleaner Pro *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB} AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Creative\Shared Files\CTDevSrv.exe C:\Program Files\Disk Speedup\DSUDefragSrv.exe C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Wajam\Updater\WajamUpdater.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Zune\ZuneBusEnum.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\GoogleCrashHandler.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\chic\Desktop\OTL.exe C:\WINDOWS\notepad.exe C:\WINDOWS\notepad.exe C:\Documents and Settings\chic\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local; uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll BHO: HistoryTriggerBHO Class: {21a88cb9-84d2-4020-a2d1-b25a21034884} - c:\program files\lg electronics\lg pc suite iv\linkair\LinkAirBrowserHelper.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll BHO: Wajam: {a7a6995d-6ee1-4fd1-a258-49395d5bf99c} - c:\program files\wajam\ie\priam_bho.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll BHO: SweetPacks Browser Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll TB: SweetPacks Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\chic\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE" uRun: [AshSnap] c:\program files\ashampoo\ashampoo snap 6\ashsnap.exe mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [SweetIM] c:\program files\sweetim\messenger\SweetIM.exe dRunOnce: [RunNarrator] Narrator.exe uPolicies-explorer: NoResolveTrack = 1 (0x1) uPolicies-explorer: NoInstrumentation = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000 IE: MediaManager tool grab multimedia file - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} Trusted Zone: adobe.com Trusted Zone: course-source.net Trusted Zone: epautotest.com Trusted Zone: learndirect-business.com Trusted Zone: learndirect.co.uk Trusted Zone: mindleaders.com Trusted Zone: thirdforce.com DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/E/1/F/E1F6B9B3-49AA-42BB-9115-D9FB57768CC2/wmavax.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: {81559C35-8464-49F7-BB0E-07A383BEF910} - No File SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\chic\applic~1\mozilla\firefox\profiles\a8kz582u.default\ FF - prefs.js: browser.search.selectedEngine - Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&crg=3.1010000.10009&q= FF - plugin: c:\documents and settings\chic\local settings\application data\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL FF - plugin: c:\program files\common files\motive\npMotive.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npvsharetvplg.dll FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll FF - plugin: c:\program files\tvuplayer\npTVUAx.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\windows\system32\adobe\director\np32dsw_1167637.dll FF - plugin: c:\windows\system32\adobe\director\np32dsw_1168638.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_257.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll FF - plugin: c:\windows\system32\npwmsdrm.dll FF - plugin: g:\program files\bin\new_plugin\npdeployJava1.dll . —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064] R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-7-10 13496] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576] R1 MpKsledf26030;MpKsledf26030;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{64f6e675-6396-4b2d-8926-876cd33774ca}\MpKsledf26030.sys [2012-10-25 29904] R2 DSUDiskOptimizer;DSUDiskOptimizer;c:\program files\disk speedup\DSUDefragSrv.exe [2011-10-21 668472] R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-10 55152] R2 WajamUpdater;WajamUpdater;c:\program files\wajam\updater\WajamUpdater.exe [2012-10-5 109064] R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160] R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496] R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928] R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664] S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys –> c:\windows\system32\drivers\ntcdrdrv.sys [?] S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [2005-12-19 514155] S2 cmdAgent;COMODO Internet Security Helper Service;"c:\program files\comodo\comodo internet security\cmdagent.exe" –> c:\program files\comodo\comodo internet security\cmdagent.exe [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944] S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [2005-11-24 14974] S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2011-5-10 14336] S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-5-10 20736] S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-5-10 20096] S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2011-5-10 25088] S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [2011-5-10 23168] S3 AndNetGps;LGE AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys [2011-5-10 22272] S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [2011-5-10 28032] S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys [2011-5-10 70016] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-12-30 16512] S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000] S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [2005-12-25 18432] S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [2005-12-25 19328] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-3 36608] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176] S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [2005-5-11 52384] S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [2005-5-11 6096] S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [2005-5-11 87456] S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [2005-5-11 79248] S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [2005-5-11 77072] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys –> c:\windows\system32\drivers\ManyCam.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 129976] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 RapportIaso;RapportIaso;\??\c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys –> c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys [?] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-10 14336] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2011-8-5 268512] S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-4-3 233472] . =============== Created Last 30 ================ . 2012-10-25 21:10:57 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{64f6e675-6396-4b2d-8926-876cd33774ca}\MpKsledf26030.sys 2012-10-25 20:25:57 ——– d—–w- c:\docume~1\alluse~1\applic~1\SweetIM 2012-10-25 05:24:04 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\Wajam 2012-10-25 05:23:59 ——– d—–w- c:\program files\Wajam 2012-10-25 04:03:41 6918632 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{64f6e675-6396-4b2d-8926-876cd33774ca}\mpengine.dll 2012-10-24 22:06:46 6918632 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-10-19 17:51:36 ——– d—–w- c:\program files\SweetIM 2012-10-19 17:49:44 ——– d—–w- c:\program files\ExpressFiles 2012-10-19 17:49:44 ——– d—–w- c:\docume~1\chic\applic~1\ExpressFiles . ==================== Find3M ==================== . 2012-10-25 21:17:22 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-25 21:17:21 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-23 14:17:06 2404 —-a-w- c:\windows\system32\ASOROSet.bin 2012-08-27 19:12:39 832512 —-a-w- c:\windows\system32\wininet.dll 2012-08-27 19:12:36 1830912 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-27 19:12:35 78336 —-a-w- c:\windows\system32\ieencode.dll 2012-08-27 19:12:34 17408 —-a-w- c:\windows\system32\corpol.dll 2012-08-24 13:53:22 177664 —-a-w- c:\windows\system32\wintrust.dll 2012-08-21 13:33:26 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-08-21 12:58:09 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe . ============= FINISH: 22:57:35.18 ===============

Attachments:

Hello Declan and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested


Hopefully this is a fairly common problem

It is for those who use torrents and other practices that download rubbish bundled with other rubbish. ;)

P2P - I see you have P2P software, (uTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Uninstall the following programs, if present:

iLivid
Search Settings 1.2.1


To remove them:
  • click on Start, Settings, Control Panel
  • double-click Add or Remove Programs (it may take time for the list to appear, so be patient)
  • scroll down the list and look for any of the above entries:
  • if they are present, click on the program name and then on Remove.
===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.

Please run OTL again and send a new log.

Please include the following in your next post :

ADWCleaner log
aswMBR log
new OTL log.


Thanks

Satchfan
Hello Satchfan, thank you for the quick response, and thank you for the kind words - I had intended removing the uTorrent before contacting you, to save you from rebuking me :)

I couldn't remove the search121 program using AddRemove as it resulted in this error message, "Error 1316. A network error occurred while attempting to read from the file C:\Windows\Installer\SearchSettings.msi". I removed it using RevoUninstaller.

Please find below the requested files -

# AdwCleaner v2.005 - Logfile created 10/26/2012 at 15:55:29
# Updated 14/10/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : chic - CHICPC
# Boot Mode : Normal
# Running from : C:\Documents and Settings\chic\desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : WajamUpdater

***** [Files / Folders] *****

Deleted on reboot : C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
File Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\Ask.xml
File Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\Startsear.xml
File Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\SweetIm.xml
File Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\yahoo-zugo.xml
File Deleted : C:\Program Files\Mozilla FireFox\Components\AskSearch.js
File Deleted : C:\Program Files\Mozilla Firefox\Plugins\npvsharetvplg.dll
Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Deleted : C:\Documents and Settings\All Users\Application Data\SweetIM
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia
Folder Deleted : C:\Documents and Settings\chic\Application Data\iWin
Folder Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\Conduit
Folder Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\ConduitEngine
Folder Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\CT1043329
Folder Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
Folder Deleted : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\SweetPacksToolbarData
Folder Deleted : C:\Documents and Settings\chic\Application Data\Search Settings
Folder Deleted : C:\Documents and Settings\chic\Application Data\vghd
Folder Deleted : C:\Documents and Settings\chic\Local Settings\Application Data\Ilivid Player
Folder Deleted : C:\Documents and Settings\chic\Local Settings\Application Data\Wajam
Folder Deleted : C:\i386\Programs\Wajam
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\SweetIM
Folder Deleted : C:\Program Files\vShare.tv plugin
Folder Deleted : C:\Program Files\Wajam

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\AskToolbarInfo
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0702A2B6-13AA-4090-9E01-BCDC85DD933F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\Wajam
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Key Deleted : HKLM\Software\Search Settings
Key Deleted : HKLM\SOFTWARE\Software
Key Deleted : HKLM\Software\Wajam
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SweetIM]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll]

***** [Internet Browsers] *****

-\\ Internet Explorer v7.0.5730.11

[OK] Registry is clean.

-\\ Mozilla Firefox v16.0.1 (en-US)

Profile name : default
File : C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\prefs.js

C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\user.js … Deleted !

Deleted : user_pref("CT1043329..clientLogIsEnabled", true);
Deleted : user_pref("CT1043329..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[…]
Deleted : user_pref("CT1043329..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[…]
Deleted : user_pref("CT1043329.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT1043329.CurrentServerDate", "14-3-2011");
Deleted : user_pref("CT1043329.DialogsAlignMode", "LTR");
Deleted : user_pref("CT1043329.DialogsGetterLastCheckTime", "Mon Mar 14 2011 17:47:33 GMT+0000 (GMT Standard T[…]
Deleted : user_pref("CT1043329.DownloadReferralCookieData", "");
Deleted : user_pref("CT1043329.FirstServerDate", "14-3-2011");
Deleted : user_pref("CT1043329.FirstTimeFF3", true);
Deleted : user_pref("CT1043329.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT1043329.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT1043329.HasUserGlobalKeys", true);
Deleted : user_pref("CT1043329.Initialize", true);
Deleted : user_pref("CT1043329.InitializeCommonPrefs", true);
Deleted : user_pref("CT1043329.InstallationAndCookieDataSentCount", 2);
Deleted : user_pref("CT1043329.IsGrouping", false);
Deleted : user_pref("CT1043329.IsMulticommunity", false);
Deleted : user_pref("CT1043329.LanguagePackLastCheckTime", "Mon Mar 14 2011 17:47:33 GMT+0000 (GMT Standard Ti[…]
Deleted : user_pref("CT1043329.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT1043329.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…]
Deleted : user_pref("CT1043329.LastLogin_3.3.2.1", "Mon Mar 14 2011 17:47:33 GMT+0000 (GMT Standard Time)");
Deleted : user_pref("CT1043329.LatestVersion", "3.2.5.2");
Deleted : user_pref("CT1043329.Locale", "en-gb");
Deleted : user_pref("CT1043329.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT1043329.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT1043329.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT1043329.SearchInNewTabEnabled", true);
Deleted : user_pref("CT1043329.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT1043329.SearchInNewTabLastCheckTime", "Mon Mar 14 2011 17:47:33 GMT+0000 (GMT Standard […]
Deleted : user_pref("CT1043329.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…]
Deleted : user_pref("CT1043329.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[…]
Deleted : user_pref("CT1043329.ServiceMapLastCheckTime", "Mon Mar 14 2011 17:47:31 GMT+0000 (GMT Standard Time[…]
Deleted : user_pref("CT1043329.SettingsLastCheckTime", "Mon Mar 14 2011 17:47:31 GMT+0000 (GMT Standard Time)"[…]
Deleted : user_pref("CT1043329.SettingsLastUpdate", "1300101039");
Deleted : user_pref("CT1043329.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT1043329.ThirdPartyComponentsLastCheck", "Mon Mar 14 2011 17:47:31 GMT+0000 (GMT Standar[…]
Deleted : user_pref("CT1043329.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT1043329.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1043329");
Deleted : user_pref("CT1043329.UserID", "UN76770902784796064");
Deleted : user_pref("CT1043329.alertChannelId", "3278");
Deleted : user_pref("CT1043329.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[…]
Deleted : user_pref("CT1043329.globalFirstTimeInfoLastCheckTime", "Mon Mar 14 2011 17:47:34 GMT+0000 (GMT Stan[…]
Deleted : user_pref("CT1043329.isAppTrackingManagerOn", true);
Deleted : user_pref("CT1043329.myStuffEnabled", true);
Deleted : user_pref("CT1043329.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT1043329.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr;[…]
Deleted : user_pref("CT1043329.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT1043329.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…]
Deleted : user_pref("CT1043329.testingCtid", "");
Deleted : user_pref("CT1043329.toolbarAppMetaDataLastCheckTime", "Mon Mar 14 2011 17:47:33 GMT+0000 (GMT Stand[…]
Deleted : user_pref("CT1043329.toolbarContextMenuLastCheckTime", "Mon Mar 14 2011 17:47:33 GMT+0000 (GMT Stand[…]
Deleted : user_pref("CT2405280.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2405280.CTID", "CT2405280");
Deleted : user_pref("CT2405280.CurrentServerDate", "4-9-2010");
Deleted : user_pref("CT2405280.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2405280.DownloadReferralCookieData", "");
Deleted : user_pref("CT2405280.EMailNotifierPollDate", "Sat Sep 04 2010 08:04:35 GMT+0100 (GMT Daylight Time)"[…]
Deleted : user_pref("CT2405280.FeedLastCount1783261708582779529", 1355);
Deleted : user_pref("CT2405280.FeedPollDate129255180392415092", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392415098", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392415104", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392415110", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392415116", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392415122", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571378", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571384", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571390", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571396", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571402", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571408", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571414", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571420", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571426", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571432", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571438", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392571444", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727700", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727706", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727712", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727718", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727724", "Sat Sep 04 2010 07:34:37 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727730", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727736", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727742", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727748", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727754", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727760", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727766", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727772", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727778", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727784", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727790", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727796", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727802", "Sat Sep 04 2010 07:34:38 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727808", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727814", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727820", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727826", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727832", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727838", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727844", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727850", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727856", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727862", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727868", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727874", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727880", "Sat Sep 04 2010 07:34:39 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727886", "Sat Sep 04 2010 07:34:40 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727892", "Sat Sep 04 2010 07:34:40 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedPollDate129255180392727898", "Sat Sep 04 2010 07:34:40 GMT+0100 (GMT Daylig[…]
Deleted : user_pref("CT2405280.FeedTTL129255180392415104", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392415116", 60);
Deleted : user_pref("CT2405280.FeedTTL129255180392571420", 60);
Deleted : user_pref("CT2405280.FeedTTL129255180392571426", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392571432", 2);
Deleted : user_pref("CT2405280.FeedTTL129255180392571438", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392727700", 30);
Deleted : user_pref("CT2405280.FeedTTL129255180392727706", 5);
Deleted : user_pref("CT2405280.FeedTTL129255180392727712", 5);
Deleted : user_pref("CT2405280.FeedTTL129255180392727724", 5);
Deleted : user_pref("CT2405280.FeedTTL129255180392727736", 30);
Deleted : user_pref("CT2405280.FeedTTL129255180392727742", 30);
Deleted : user_pref("CT2405280.FeedTTL129255180392727766", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392727778", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392727784", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392727790", 15);
Deleted : user_pref("CT2405280.FeedTTL129255180392727808", 1440);
Deleted : user_pref("CT2405280.FeedTTL129255180392727838", 10);
Deleted : user_pref("CT2405280.FeedTTL129255180392727856", 5);
Deleted : user_pref("CT2405280.FirstServerDate", "25-8-2010");
Deleted : user_pref("CT2405280.FirstTime", true);
Deleted : user_pref("CT2405280.FirstTimeFF3", true);
Deleted : user_pref("CT2405280.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2405280.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2405280.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2405280.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2405280.Initialize", true);
Deleted : user_pref("CT2405280.InitializeCommonPrefs", true);
Deleted : user_pref("CT2405280.InstallationAndCookieDataSentCount", 2);
Deleted : user_pref("CT2405280.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2405280.InstalledDate", "Wed Aug 25 2010 21:59:48 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2405280.InvalidateCache", false);
Deleted : user_pref("CT2405280.IsGrouping", false);
Deleted : user_pref("CT2405280.IsMulticommunity", false);
Deleted : user_pref("CT2405280.IsOpenThankYouPage", false);
Deleted : user_pref("CT2405280.IsOpenUninstallPage", true);
Deleted : user_pref("CT2405280.LanguagePackLastCheckTime", "Sat Sep 04 2010 07:34:36 GMT+0100 (GMT Daylight Ti[…]
Deleted : user_pref("CT2405280.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2405280.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…]
Deleted : user_pref("CT2405280.LastLogin_2.7.1.3", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2405280.LatestVersion", "2.7.2.0");
Deleted : user_pref("CT2405280.Locale", "en-us");
Deleted : user_pref("CT2405280.LoginCache", 4);
Deleted : user_pref("CT2405280.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2405280.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2405280.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2405280.RadioIsPodcast", false);
Deleted : user_pref("CT2405280.RadioLastCheckTime", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2405280.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2405280.RadioLastUpdateServer", "129167775315800000");
Deleted : user_pref("CT2405280.RadioMediaID", "20503713");
Deleted : user_pref("CT2405280.RadioMediaType", "Media Player");
Deleted : user_pref("CT2405280.RadioMenuSelectedID", "EBRadioMenu_CT240528020503713");
Deleted : user_pref("CT2405280.RadioStationName", "Virgin%20Radio%20Classic%20Rock");
Deleted : user_pref("CT2405280.RadioStationURL", "hxxp://www.smgradio.com/core/audio/wmp/live.asx?service=vcbb[…]
Deleted : user_pref("CT2405280.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2405280.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[…]
Deleted : user_pref("CT2405280.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2405280.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT240[…]
Deleted : user_pref("CT2405280.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2405280.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2405280.SearchInNewTabLastCheckTime", "Sat Sep 04 2010 07:34:34 GMT+0100 (GMT Daylight […]
Deleted : user_pref("CT2405280.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…]
Deleted : user_pref("CT2405280.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[…]
Deleted : user_pref("CT2405280.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2405280.SettingsLastCheckTime", "Sat Sep 04 2010 07:34:34 GMT+0100 (GMT Daylight Time)"[…]
Deleted : user_pref("CT2405280.SettingsLastUpdate", "1282218256");
Deleted : user_pref("CT2405280.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2405280.ThirdPartyComponentsLastCheck", "Wed Aug 25 2010 21:59:47 GMT+0100 (GMT Dayligh[…]
Deleted : user_pref("CT2405280.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2405280.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId;=[…]
Deleted : user_pref("CT2405280.Uninstall", true);
Deleted : user_pref("CT2405280.UserID", "UN71322118740303342");
Deleted : user_pref("CT2405280.WeatherNetwork", "");
Deleted : user_pref("CT2405280.WeatherPollDate", "Sat Sep 04 2010 08:04:39 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2405280.WeatherUnit", "C");
Deleted : user_pref("CT2405280.alertChannelId", "799768");
Deleted : user_pref("CT2405280.clientLogIsEnabled", true);
Deleted : user_pref("CT2405280.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[…]
Deleted : user_pref("CT2405280.myStuffEnabled", true);
Deleted : user_pref("CT2405280.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2405280.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr;[…]
Deleted : user_pref("CT2405280.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2405280.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…]
Deleted : user_pref("CT2405280.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[…]
Deleted : user_pref("CT2642703.CTID", "CT2642703");
Deleted : user_pref("CT2642703.Chat.ServerLastCheckTime", "Sat Sep 04 2010 07:35:11 GMT+0100 (GMT Daylight Tim[…]
Deleted : user_pref("CT2642703.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2642703.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[…]
Deleted : user_pref("CT2642703.EMailNotifierPollDate", "Sat Sep 04 2010 08:05:11 GMT+0100 (GMT Daylight Time)"[…]
Deleted : user_pref("CT2642703.ExternalComponentPollDate129193296031660350", "Sat Sep 04 2010 07:35:10 GMT+010[…]
Deleted : user_pref("CT2642703.ExternalComponentPollDate129234866109202801", "Sat Sep 04 2010 07:35:10 GMT+010[…]
Deleted : user_pref("CT2642703.FirstTime", true);
Deleted : user_pref("CT2642703.FirstTimeFF3", true);
Deleted : user_pref("CT2642703.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2642703.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2642703.Initialize", true);
Deleted : user_pref("CT2642703.InitializeCommonPrefs", true);
Deleted : user_pref("CT2642703.InstallationAndCookieDataSentCount", 2);
Deleted : user_pref("CT2642703.InstalledDate", "Sun Aug 01 2010 08:51:26 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2642703.InvalidateCache", false);
Deleted : user_pref("CT2642703.IsGrouping", false);
Deleted : user_pref("CT2642703.IsMulticommunity", false);
Deleted : user_pref("CT2642703.IsOpenThankYouPage", true);
Deleted : user_pref("CT2642703.IsOpenUninstallPage", true);
Deleted : user_pref("CT2642703.LanguagePackLastCheckTime", "Sat Sep 04 2010 07:35:12 GMT+0100 (GMT Daylight Ti[…]
Deleted : user_pref("CT2642703.Locale", "en");
Deleted : user_pref("CT2642703.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2642703.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2642703.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2642703.RadioIsPodcast", false);
Deleted : user_pref("CT2642703.RadioLastCheckTime", "Sat Sep 04 2010 07:35:11 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2642703.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2642703.RadioLastUpdateServer", "3");
Deleted : user_pref("CT2642703.RadioMediaID", "9962");
Deleted : user_pref("CT2642703.RadioMediaType", "Media Player");
Deleted : user_pref("CT2642703.RadioMenuSelectedID", "EBRadioMenu_CT26427039962");
Deleted : user_pref("CT2642703.RadioStationName", "California%20Rock");
Deleted : user_pref("CT2642703.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT2642703.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2642703.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[…]
Deleted : user_pref("CT2642703.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2642703.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT264[…]
Deleted : user_pref("CT2642703.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2642703.SettingsLastCheckTime", "Sat Sep 04 2010 07:35:10 GMT+0100 (GMT Daylight Time)"[…]
Deleted : user_pref("CT2642703.SettingsLastUpdate", "1283150753");
Deleted : user_pref("CT2642703.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2642703.ThirdPartyComponentsLastCheck", "Sat Sep 04 2010 07:35:10 GMT+0100 (GMT Dayligh[…]
Deleted : user_pref("CT2642703.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2642703.Uninstall", true);
Deleted : user_pref("CT2642703.WeatherNetwork", "");
Deleted : user_pref("CT2642703.WeatherPollDate", "Sat Sep 04 2010 07:35:12 GMT+0100 (GMT Daylight Time)");
Deleted : user_pref("CT2642703.WeatherUnit", "C");
Deleted : user_pref("CT2642703.alertChannelId", "1035390");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1035390/1031101/UK", "\"0\"[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/3278/3278/UK", "\"0\"");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/UK", "\"0\"")[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1043329", […]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.2[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1043329",[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut;=3/13/20[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT1043329/CT1043329[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[…]
Deleted : user_pref("CommunityToolbar.EngineOwner", "CT1043329");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{04666517-d7b9-43c9-b329-cd7a30ff0079}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "nagra3");
Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT1043329");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{04666517-d7b9-43c9-b329-cd7a30ff0079}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "nagra3");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://uk.search.yahoo.com/search?fr=gre[…]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2642703,CT2405280,CT1043329,ConduitEngine");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2642703,CT2405280");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Mar 14 2011 17:47:33 GMT+00[…]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 60);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Mon Mar 14 2011 17:47:39 GMT+0000 (GMT S[…]
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon Mar 14 2011 17:47:30 GMT+0000 (GMT Stand[…]
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1291052234");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "{d54dba38-24a0-4a39-985e-ab065fc45a0b}");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Sep 04 2010 07:34:35 GMT+0100 (GMT[…]
Deleted : user_pref("CommunityToolbar.globalUserId", "b5815f04-0aa9-4b6d-9bc5-68e0b5ae35ff");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Mon Mar 14 2011 17:47:34 GMT+0000 (GMT Standa[…]
Deleted : user_pref("ConduitEngine.FirstServerDate", "03/14/2011 20");
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Mar 14 2011 17:47:35 GMT+0000 (GMT Standar[…]
Deleted : user_pref("ConduitEngine.LastLogin_3.3.2.1", "Mon Mar 14 2011 17:47:35 GMT+0000 (GMT Standard Time)"[…]
Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Mar 14 2011 17:47:35 GMT+0000 (GMT Standard Ti[…]
Deleted : user_pref("ConduitEngine.UserID", "UN90199788162487542");
Deleted : user_pref("ConduitEngine.engineLocale", "en-US");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Mar 14 2011 17:47:35 GMT+0000 (GMT S[…]
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Mon Mar 14 2011 17:47:36 GMT+0000 (GMT […]
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("browser.search.defaultengine", "Web Search");
Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Deleted : user_pref("browser.search.order.1", "Web Search");
Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Deleted : user_pref("extensions.snipit.askTbInstalled", true);
Deleted : user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13116&gct;=&g;[…]
Deleted : user_pref("keyword.URL", "hxxp://search.sweetim.com/search.asp?src=2&crg;=3.1010000.10009&q;=");
Deleted : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1351199881053");
Deleted : user_pref("sweetim.toolbar.Visibility.enable", "true");
Deleted : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Deleted : user_pref("sweetim.toolbar.cargo", "3.1010000.10009");
Deleted : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.returnValue", "hide");
Deleted : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[…]
Deleted : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Deleted : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Deleted : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff_1_6.ht[…]
Deleted : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Deleted : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[…]
Deleted : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Deleted : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[…]
Deleted : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Deleted : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handl[…]
Deleted : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Deleted : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Deleted : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Deleted : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Deleted : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[…]
Deleted : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Deleted : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Deleted : user_pref("sweetim.toolbar.mode.debug", "false");
Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.sweetim.com/search.asp?src=2&q;=");
Deleted : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Deleted : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*");
Deleted : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Deleted : user_pref("sweetim.toolbar.scripts.0.enable", "true");
Deleted : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Deleted : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Deleted : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Deleted : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*");
Deleted : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Deleted : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Deleted : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Deleted : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Deleted : user_pref("sweetim.toolbar.scripts.2.callback", "");
Deleted : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[…]
Deleted : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Deleted : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Deleted : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Deleted : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?[…]
Deleted : user_pref("sweetim.toolbar.search.external", " Deleted : user_pref("sweetim.toolbar.search.history.capacity", "10");
Deleted : user_pref("sweetim.toolbar.simapp_id", "{A2C0D7DE-1A15-11E2-AE6C-00123FB247C6}");
Deleted : user_pref("sweetim.toolbar.version", "1.6.0.3");
Deleted : user_pref("vshare.install.date", "1313696212");
Deleted : user_pref("vshare.install.finished", "1.0.0");
Deleted : user_pref("vshare.install.fresh", "false");
Deleted : user_pref("vshare.install.guid", "{38dff1b5-d534-47ba-9d5d-1438e1bcb208}");
Deleted : user_pref("vshare.install.newtab", false);

-\\ Google Chrome v [Unable to get version]

File : C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [43562 octets] - [26/10/2012 15:29:36]
AdwCleaner[S1].txt - [44306 octets] - [26/10/2012 15:55:29]

########## EOF - C:\AdwCleaner[S1].txt - [44367 octets] ##########

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-26 16:11:28
—————————–
16:11:28.281 OS Version: Windows 5.1.2600 Service Pack 3
16:11:28.281 Number of processors: 2 586 0x403
16:11:28.281 ComputerName: CHICPC UserName: chic
16:11:28.921 Initialize success
16:11:40.203 AVAST engine defs: 12102600
16:14:14.796 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-18
16:14:14.796 Disk 0 Vendor: SAMSUNG_HD160JJ/P ZM100-34 Size: 152587MB BusType: 3
16:14:14.796 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T1L0-20
16:14:14.796 Disk 1 Vendor: WDC_WD800JD-75MSA3 10.01E04 Size: 76293MB BusType: 3
16:14:14.828 Disk 0 MBR read successfully
16:14:14.828 Disk 0 MBR scan
16:14:14.859 Disk 0 unknown MBR code
16:14:14.859 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 62 MB offset 63
16:14:14.890 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 148726 MB offset 128520
16:14:14.906 Disk 0 Partition - 00 0F Extended LBA 3796 MB offset 304720920
16:14:14.937 Disk 0 scanning sectors +312496380
16:14:15.046 Disk 0 scanning C:\WINDOWS\system32\drivers
16:14:55.609 Service scanning
16:15:22.328 Service MpKsl7c92e534 C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDF528A-DE1A-4AC9-9A4B-FF70BC896091}\MpKsl7c92e534.sys **LOCKED** 32
16:15:45.656 Modules scanning
16:15:58.765 Disk 0 trace - called modules:
16:15:58.796 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
16:15:58.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ab41ab8]
16:15:58.796 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-18[0x8ab45d98]
16:15:59.312 AVAST engine scan C:\WINDOWS
16:16:21.296 AVAST engine scan C:\WINDOWS\system32
16:23:08.859 AVAST engine scan C:\WINDOWS\system32\drivers
16:24:08.531 AVAST engine scan C:\Documents and Settings\chic
16:48:21.796 File: C:\Documents and Settings\chic\My Documents\Downloads\Flash_Player_Installer.exe **INFECTED** Win32:Trojan-gen
16:52:18.515 AVAST engine scan C:\Documents and Settings\All Users
16:58:56.437 Scan finished successfully
17:01:01.968 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\chic\Desktop\MBR.dat"
17:01:01.968 The log file has been saved successfully to "C:\Documents and Settings\chic\Desktop\aswMBR.txt"

OTL logfile created on: 26/10/2012 17:05:18 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.12% Memory free
6.73 Gb Paging File | 6.15 Gb Available in Paging File | 91.41% Paging File free
Paging file location(s): J:\pagefile.sys 5000 5000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 108.42 Gb Free Space | 74.65% Space Free | Partition Type: NTFS
Drive J: | 74.46 Gb Total Space | 69.47 Gb Free Space | 93.30% Space Free | Partition Type: NTFS
Drive L: | 931.51 Gb Total Space | 123.44 Gb Free Space | 13.25% Space Free | Partition Type: NTFS

Computer Name: CHICPC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ashampoo\Ashampoo Snap 6\ashsnap.exe (Ashampoo Media GmbH & Co. KG)
PRC - L:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Disk Speedup\DSUDefragSrv.exe (Systweak Inc., (www.systweak.com))
PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Ashampoo\Ashampoo Snap 6\MouseHook.dll ()
MOD - L:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\AmvTransform.dll ()


========== Services (SafeList) ==========

SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe File not found
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe File not found
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (DSUDiskOptimizer) – C:\Program Files\Disk Speedup\DSUDefragSrv.exe (Systweak Inc., (www.systweak.com))
SRV - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (RapportIaso) – c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (ntcdrdrv) – system32\DRIVERS\ntcdrdrv.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (ManyCam) – system32\DRIVERS\ManyCam.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (Cdr4_2K) – File not found
DRV - (catchme) – C:\DOCUME~1\chic\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswMBR) – C:\DOCUME~1\chic\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (82311) – globalroot\C:\WINDOWS\system32\drivers\82311.sys File not found
DRV - (79612) – globalroot\C:\WINDOWS\system32\drivers\79612.sys File not found
DRV - (78928) – globalroot\C:\WINDOWS\system32\drivers\78928.sys File not found
DRV - (74636) – globalroot\C:\WINDOWS\system32\drivers\74636.sys File not found
DRV - (735E) – globalroot\C:\WINDOWS\system32\drivers\735E.sys File not found
DRV - (73513) – globalroot\C:\WINDOWS\system32\drivers\73513.sys File not found
DRV - (725F) – globalroot\C:\WINDOWS\system32\drivers\725F.sys File not found
DRV - (6824) – globalroot\C:\WINDOWS\system32\drivers\6824.sys File not found
DRV - (6064) – globalroot\C:\WINDOWS\system32\drivers\6064.sys File not found
DRV - (5834) – globalroot\C:\WINDOWS\system32\drivers\5834.sys File not found
DRV - (48426) – globalroot\C:\WINDOWS\system32\drivers\48426.sys File not found
DRV - (4481D) – globalroot\C:\WINDOWS\system32\drivers\4481D.sys File not found
DRV - (4363) – globalroot\C:\WINDOWS\system32\drivers\4363.sys File not found
DRV - (2993) – globalroot\C:\WINDOWS\system32\drivers\2993.sys File not found
DRV - (2004) – globalroot\C:\WINDOWS\system32\drivers\2004.sys File not found
DRV - (1964) – globalroot\C:\WINDOWS\system32\drivers\1964.sys File not found
DRV - (19336) – globalroot\C:\WINDOWS\system32\drivers\19336.sys File not found
DRV - (19310) – globalroot\C:\WINDOWS\system32\drivers\19310.sys File not found
DRV - (1844) – globalroot\C:\WINDOWS\system32\drivers\1844.sys File not found
DRV - (1803) – globalroot\C:\WINDOWS\system32\drivers\1803.sys File not found
DRV - (1703C) – globalroot\C:\WINDOWS\system32\drivers\1703C.sys File not found
DRV - (165D) – globalroot\C:\WINDOWS\system32\drivers\165D.sys File not found
DRV - (1655) – globalroot\C:\WINDOWS\system32\drivers\1655.sys File not found
DRV - (1643) – globalroot\C:\WINDOWS\system32\drivers\1643.sys File not found
DRV - (1613F) – globalroot\C:\WINDOWS\system32\drivers\1613F.sys File not found
DRV - (16130) – globalroot\C:\WINDOWS\system32\drivers\16130.sys File not found
DRV - (16017) – globalroot\C:\WINDOWS\system32\drivers\16017.sys File not found
DRV - (148D) – globalroot\C:\WINDOWS\system32\drivers\148D.sys File not found
DRV - (1484) – globalroot\C:\WINDOWS\system32\drivers\1484.sys File not found
DRV - (12115) – globalroot\C:\WINDOWS\system32\drivers\12115.sys File not found
DRV - (12032) – globalroot\C:\WINDOWS\system32\drivers\12032.sys File not found
DRV - (1202A) – globalroot\C:\WINDOWS\system32\drivers\1202A.sys File not found
DRV - (117F) – globalroot\C:\WINDOWS\system32\drivers\117F.sys File not found
DRV - (1083) – globalroot\C:\WINDOWS\system32\drivers\1083.sys File not found
DRV - (100D) – globalroot\C:\WINDOWS\system32\drivers\100D.sys File not found
DRV - (MpKsl7c92e534) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDF528A-DE1A-4AC9-9A4B-FF70BC896091}\MpKsl7c92e534.sys (Microsoft Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (SmartDefragDriver) – C:\WINDOWS\system32\drivers\SmartDefragDriver.sys ()
DRV - (andnetndis) – C:\WINDOWS\system32\drivers\lgandnetndis.sys (LG Electronics Inc.)
DRV - (AndNetGps) – C:\WINDOWS\system32\drivers\lgandnetgps.sys (LG Electronics Inc.)
DRV - (ANDNetModem) – C:\WINDOWS\system32\drivers\lgandnetmodem.sys (LG Electronics Inc.)
DRV - (AndNetDiag) – C:\WINDOWS\system32\drivers\lgandnetdiag.sys (LG Electronics Inc.)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (s716unic) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\system32\drivers\BTHidMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}: "URL" = http://uk.search.yahoo.com/search?ei=UTF-8…p={searchTerms}
IE - HKLM\..\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}: "URL" = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKLM\..\SearchScopes\{749F5CD3-7B4D-4349-B510-0586016EE61C}: "URL" = http://uk.news.search.yahoo.com/search/new…p={searchTerms}
IE - HKLM\..\SearchScopes\{8EA8ADF6-B3CF-4CBD-A630-741A82BD8448}: "URL" = http://uk.local.yahoo.com/search.html?p={s…GugiXML&cs;=
IE - HKLM\..\SearchScopes\{8FE0B69C-E812-4CDA-B67D-14DA6B88C324}: "URL" = http://uk.search.yahoo.com/search/dir?ei=U…p={searchTerms}
IE - HKLM\..\SearchScopes\{B4E9D89A-5ECB-4D73-B42B-B0EF5BF2DDA5}: "URL" = http://shopping.yahoo.co.uk/ctl/do/search?…y={searchTerms}
IE - HKLM\..\SearchScopes\{C9201B62-6575-4C97-BE89-44B460C2E5F0}: "URL" = http://uk.search.yahoo.com/search/video?ei…p={searchTerms}
IE - HKLM\..\SearchScopes\{CF74A3B6-1C71-4192-9F84-885EEBCE8AA1}: "URL" = http://uk.search.yahoo.com/search/audio?ei…p={searchTerms}
IE - HKLM\..\SearchScopes\{E903FDC2-77F8-4E45-9476-AC74FFBDEA6F}: "URL" = http://uk.search.yahoo.com/search/images?e…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}: "URL" = http://uk.search.yahoo.com/search?ei=UTF-8…p={searchTerms}
IE - HKCU\..\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}: "URL" = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…z=1I7ADBS_en-GB
IE - HKCU\..\SearchScopes\{9B0FE47C-BED4-44E4-8C07-D7F906B08B5A}: "URL" = http://www.ask.com/web?q={searchTerms}&…=1690&l;=dir
IE - HKCU\..\SearchScopes\{9BE63AD6-4299-4920-B628-B11D2D83B9CC}: "URL" = http://uk.search.yahoo.com/search?fr=chr-g…p={searchTerms}
IE - HKCU\..\SearchScopes\{F0816BF4-5A7B-4C14-9FAE-563F3DEAD1CD}: "URL" = http://www.buzqo.com/s/?q={searchTerms}&am;…eferrer:source}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.9rc3
FF - prefs.js..extensions.enabledAddons: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120910
FF - prefs.js..extensions.enabledAddons: {dd05fd3d-18df-4ce4-ae53-e795339c5f01}:1.21
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: G:\Program Files\iTunes\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2303: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2361: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1465: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\chic\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/12 22:33:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/26 15:55:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/26 15:55:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: L:\Program Files\Mozilla Firefox\components [2012/10/26 07:55:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: L:\Program Files\Mozilla Firefox\plugins

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2012/10/26 15:55:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2012/10/25 22:17:43 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2012/02/05 20:11:54 | 000,000,000 | —D | M] (TVU Web Player) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2012/10/25 22:17:42 | 000,530,225 | —- | M] () (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2011/08/18 20:36:50 | 000,090,116 | —- | M] () (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
[2012/10/26 15:25:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/24 18:49:05 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/04/21 02:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\mozilla firefox\plugins\npBBCPlugin.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll

========== Chrome ==========

CHR - homepage: http://www.twitter.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://www.twitter.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BBC iPlayer Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = G:\Program Files\bin\new_plugin\npjp2.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Documents and Settings\chic\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: iTunes Application Detector (Enabled) = G:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: VLC Web Plugin (Enabled) = g:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - Extension: WOT = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.3.6_0\
CHR - Extension: YouTube = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Slinky Elegant = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln\19.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: http://www.miniclip.com/games/en/ = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ganlfmllnoladlbocpgloiambgjcfcgo\2012.1.20.54959_0\
CHR - Extension: Fast save = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbdmalcpfacdgmkafcdhlohodkmdcgng\1.1_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: WOT = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.3.6_0\
CHR - Extension: YouTube = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Slinky Elegant = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln\19.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: http://www.miniclip.com/games/en/ = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ganlfmllnoladlbocpgloiambgjcfcgo\2012.1.20.54959_0\
CHR - Extension: Fast save = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbdmalcpfacdgmkafcdhlohodkmdcgng\1.1_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Documents and Settings\chic\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/12/06 06:59:52 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon;) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AshSnap] C:\Program Files\Ashampoo\Ashampoo Snap 6\ashsnap.exe (Ashampoo Media GmbH & Co. KG)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKCU\..Trusted Domains: adobe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: course-source.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: epautotest.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: learndirect.co.uk ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: learndirect-business.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: mindleaders.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: thirdforce.com ([]* in Trusted sites)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CD82845A-4D7A-45CC-9EF0-8828228EA642}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E350DD9B-A2A9-4B8D-8944-A6BF1661A59E}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\chic\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\chic\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | R–D | M] - L:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | R— | M] () - L:\AUTORUN.FCB – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave8 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/26 15:28:40 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\chic\Desktop\aswMBR.exe
[2012/10/25 22:53:52 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2012/10/25 22:21:12 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2012/10/25 06:27:45 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\Ashampoo Snap 6
[2012/10/19 18:49:44 | 000,000,000 | —D | C] – C:\Program Files\ExpressFiles
[2012/10/19 18:49:44 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\ExpressFiles
[2012/09/29 10:25:12 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\default
[2012/09/28 06:24:12 | 000,000,000 | —D | C] – C:\i386\Programs\Ashampoo
[2009/08/17 17:46:25 | 008,046,393 | —- | C] (Moyea Software Co., LTD ) – C:\Documents and Settings\chic\FLV to Video Converter2.0.1.0-Setup.exe
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2006/07/09 22:20:16 | 003,167,744 | —- | C] (Citrix Online) – C:\Documents and Settings\chic\gosetup.exe

========== Files - Modified Within 30 Days ==========

[2012/10/26 17:01:01 | 000,000,512 | —- | M] () – C:\Documents and Settings\chic\Desktop\MBR.dat
[2012/10/26 16:52:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 16:15:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2012/10/26 16:07:07 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/10/26 15:58:26 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 15:58:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/26 15:58:21 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\Express FilesUpdate.job
[2012/10/26 15:56:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/26 15:56:53 | 2145,538,048 | -HS- | M] () – C:\hiberfil.sys
[2012/10/26 15:28:53 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\chic\Desktop\aswMBR.exe
[2012/10/26 15:27:42 | 000,538,941 | —- | M] () – C:\Documents and Settings\chic\Desktop\adwcleaner.exe
[2012/10/26 07:55:53 | 000,000,614 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/10/26 04:15:20 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2012/10/26 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2012/10/25 22:56:13 | 000,625,664 | —- | M] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2012/10/25 22:53:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2012/10/25 22:21:15 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2012/10/25 22:17:22 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/25 22:17:21 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/25 19:27:07 | 000,000,658 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/25 14:03:52 | 000,122,880 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/25 06:27:39 | 000,000,851 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Snap 6.lnk
[2012/10/25 06:27:39 | 000,000,833 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Snap 6.lnk
[2012/10/24 12:26:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/10 21:23:25 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/06 06:27:54 | 000,000,860 | —- | M] () – C:\Documents and Settings\chic\Desktop\YouTube DL.lnk
[2012/10/01 13:31:13 | 000,001,733 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\5gtyns2mwr3.crx
[2012/09/29 19:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/09/28 06:24:12 | 000,000,786 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 11.lnk
[2012/09/28 06:24:12 | 000,000,786 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 11.lnk

========== Files Created - No Company Name ==========

[2012/10/26 17:01:01 | 000,000,512 | —- | C] () – C:\Documents and Settings\chic\Desktop\MBR.dat
[2012/10/26 15:27:53 | 000,538,941 | —- | C] () – C:\Documents and Settings\chic\Desktop\adwcleaner.exe
[2012/10/25 22:56:15 | 000,625,664 | —- | C] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2012/10/25 06:27:39 | 000,000,851 | —- | C] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Snap 6.lnk
[2012/10/25 06:27:39 | 000,000,833 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Snap 6.lnk
[2012/10/19 18:49:54 | 000,000,290 | —- | C] () – C:\WINDOWS\tasks\Express FilesUpdate.job
[2012/10/01 13:31:13 | 000,001,733 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\5gtyns2mwr3.crx
[2012/09/28 06:24:12 | 000,000,786 | —- | C] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 11.lnk
[2012/09/28 06:24:12 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 11.lnk
[2012/07/07 15:31:19 | 001,074,636 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2012/07/07 15:31:19 | 001,074,636 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2012/07/07 15:31:19 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2012/07/07 15:30:41 | 002,807,708 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2012/01/14 10:34:25 | 000,000,874 | —- | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/10/20 22:01:12 | 000,002,404 | —- | C] () – C:\WINDOWS\System32\ASOROSet.bin
[2011/10/10 05:27:00 | 000,000,000 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\{FA8E2894-B67D-4D46-8D71-333C38DF5C23}
[2011/09/04 15:57:36 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/09/04 15:57:36 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/08/09 10:48:53 | 000,013,304 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2011/08/09 10:48:53 | 000,011,860 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[2011/07/10 11:56:16 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/07/10 11:56:15 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/05/30 14:08:48 | 000,000,079 | —- | C] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/28 08:55:55 | 000,112,952 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/04/03 10:41:37 | 000,002,528 | —- | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | —- | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/11 21:13:21 | 000,001,024 | —- | C] () – C:\Documents and Settings\chic\.rnd
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2007/11/28 06:09:52 | 000,000,696 | —- | C] () – C:\Documents and Settings\chic\PCTuneUp.config
[2007/07/11 22:06:05 | 000,000,127 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2006/12/30 23:59:04 | 000,000,020 | —- | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/01/28 15:51:23 | 019,866,702 | —- | C] () – C:\Documents and Settings\chic\fm5.fm
[2005/12/04 00:14:05 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/24 23:45:56 | 000,122,880 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2004/08/10 14:09:48 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 01:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 13:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 01:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/11/19 13:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2011/04/23 17:50:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2012/03/14 09:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\explauncher
[2012/06/09 22:20:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011/09/20 19:42:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/05/10 07:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2011/07/02 17:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2012/09/08 10:11:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2012/09/08 10:16:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/02/20 22:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/10/21 06:34:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Systweak
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2011/12/19 19:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/12/25 23:57:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2011/12/01 19:03:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2012/03/04 14:22:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\BeNaughtyChat
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2011/07/28 05:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2012/02/12 22:34:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DDMSettings
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2012/10/19 18:49:58 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ExpressFiles
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/11/06 12:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/07/10 11:56:15 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2011/07/02 17:29:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\muvee Technologies
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2011/07/02 17:26:20 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Nikon
[2012/01/28 19:00:58 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\OnLive App
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2012/05/27 12:24:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Oracle
[2012/02/20 22:08:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Cleaners
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2012/02/20 22:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PCPro
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2011/11/21 23:17:19 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2012/10/25 17:39:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Systweak
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/08/24 21:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TreeCardGames
[2012/03/04 13:38:05 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vcards
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2012/10/06 06:28:24 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\YouTubeFreeDownloader

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/04 06:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 12:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 11:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 06:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/10/26 12:52:40 | 000,055,880 | —- | M] () MD5=85A5635D9182EAAADF94D4991D105F44 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SC_ >
[2004/08/04 06:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.ZIP >
[2009/06/03 22:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CHM >
[2004/08/04 06:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 06:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 09:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 06:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/29 08:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/19 06:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 07:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 12:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/25 06:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2012/04/22 07:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\WINDOWS\ie7updates\KB2722913-IE7\iexplore.exe
[2012/07/03 11:57:55 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0F06AE8613FE66FF4C02A0C27D0DC7EF – C:\WINDOWS\ie7updates\KB2744842-IE7\iexplore.exe
[2007/04/24 15:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/19 06:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 09:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2011/12/16 12:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie7updates\KB2675157-IE7\iexplore.exe
[2011/10/31 11:32:32 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=1C5DA2D9EA2A59D0D5C116FA3A5A21AA – C:\WINDOWS\$hf_mig$\KB2618444-IE7\SP3QFE\iexplore.exe
[2008/08/23 06:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 16:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2010/06/17 16:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\SoftwareDistribution\Download\bd4a8ed1ff18ce602cf240d9190152b0\sp3gdr\iexplore.exe
[2008/04/22 08:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 12:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 09:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 09:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2011/10/31 11:46:00 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=2E34CF22B5862AB02786F0819B9FD819 – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2012/08/26 07:40:35 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=326B5461CCD7DB0CD6B126ADEB28667A – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/26 07:40:35 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=326B5461CCD7DB0CD6B126ADEB28667A – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/08/27 06:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 11:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2009/06/29 09:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 11:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/28 07:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2012/02/29 12:01:00 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=50BA6A230D743A4D33BFFA2FA1113055 – C:\WINDOWS\ie7updates\KB2699988-IE7\iexplore.exe
[2006/10/17 14:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 14:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 11:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/14 01:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/07/03 11:35:40 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=5A120ED9A6327241A69241A3D854AB21 – C:\WINDOWS\$hf_mig$\KB2722913-IE7\SP3QFE\iexplore.exe
[2007/10/10 09:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 10:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 09:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2011/08/17 12:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\erdnt\cache\iexplore.exe
[2011/08/17 12:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\ie7updates\KB2618444-IE7\iexplore.exe
[2008/02/22 10:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 12:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/28 07:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 09:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 19:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2011/06/20 12:29:11 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=993F33696EF219C306BF9BBA34D85073 – C:\WINDOWS\ie7updates\KB2586448-IE7\iexplore.exe
[2007/04/24 15:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/15 08:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 05:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 15:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/06/17 15:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\SoftwareDistribution\Download\bd4a8ed1ff18ce602cf240d9190152b0\sp3qfe\iexplore.exe
[2010/04/16 12:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/23 06:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/04/21 11:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\ie7updates\KB2559049-IE7\iexplore.exe
[2010/12/20 11:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/28 05:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 10:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/25 06:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 12:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 09:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/23 06:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2011/08/17 11:34:43 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=CB0AFAF9E5C5FE70EC7087E71275DD33 – C:\WINDOWS\$hf_mig$\KB2586448-IE7\SP3QFE\iexplore.exe
[2012/04/22 07:32:36 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=CE2379FC341C65CAD88FF8264A791AB5 – C:\WINDOWS\$hf_mig$\KB2699988-IE7\SP3QFE\iexplore.exe
[2009/12/18 08:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/28 07:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 11:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/12/16 11:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe
[2011/06/20 11:38:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DE0F15DD275A36C3E67DC1E36F958F3A – C:\WINDOWS\$hf_mig$\KB2559049-IE7\SP3QFE\iexplore.exe
[2012/02/29 11:34:48 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DF642AABFDACE36E3B4329091A07DE87 – C:\WINDOWS\$hf_mig$\KB2675157-IE7\SP3QFE\iexplore.exe
[2011/02/14 12:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 13:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 12:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 06:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/23 06:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 11:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 12:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 06:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
[2012/08/26 07:32:43 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=F516E1F811AC01F5DA1D486051069A7C – C:\WINDOWS\$hf_mig$\KB2744842-IE7\SP3QFE\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 14:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui

< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CNF >
[2005/11/27 10:46:49 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\chic\My Documents\My Webs\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2009/02/06 12:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 01:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 01:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 06:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\i386\services.exe
[2004/08/04 06:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SERVICES.LNK >
[2008/02/02 00:00:15 | 000,001,602 | —- | M] () MD5=FA42047000D028B48AD9EC8F757A6915 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/04 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 06:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2005/11/24 22:47:54 | 000,000,735 | —- | M] () – C:\892.cin
[2012/10/26 15:29:50 | 000,043,562 | —- | M] () – C:\AdwCleaner[R1].txt
[2012/10/26 15:59:39 | 000,044,437 | —- | M] () – C:\AdwCleaner[S1].txt
[2010/06/02 21:33:44 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 11:18:33 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/06/05 06:54:17 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/12/06 07:05:30 | 000,019,821 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/11/03 03:45:47 | 000,003,291 | —- | M] () – C:\data
[2006/01/17 11:43:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2005/11/17 20:51:24 | 000,005,148 | R— | M] () – C:\dell.sdr
[2011/07/28 05:04:17 | 000,059,013 | —- | M] () – C:\dlcd.log
[2010/10/25 20:43:22 | 000,009,432 | —- | M] () – C:\dlcdscan.log
[2009/02/18 22:37:03 | 000,003,532 | —- | M] () – C:\drmHeader.bin
[2006/01/29 14:07:03 | 000,013,312 | —- | M] () – C:\dvb.GRF
[2006/01/28 20:59:03 | 000,008,192 | —- | M] () – C:\dvb4.GRF
[2010/02/21 13:11:54 | 000,000,157 | —- | M] () – C:\error.txt
[2012/10/26 15:56:53 | 2145,538,048 | -HS- | M] () – C:\hiberfil.sys
[2011/10/30 22:52:21 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2005/11/24 22:18:42 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\IO.SYS
[2005/11/17 21:11:23 | 000,000,897 | —- | M] () – C:\IPH.PH
[2010/05/07 19:49:49 | 000,029,887 | —- | M] () – C:\log.txt
[2006/10/08 20:03:52 | 000,000,036 | —- | M] () – C:\mediamp3.dat
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/27 22:24:22 | 000,250,048 | RHS- | M] () – C:\ntldr
[2006/02/25 15:44:24 | 000,184,320 | —- | M] () – C:\PlayerHost.dll
[2008/06/24 18:14:29 | 000,003,021 | —- | M] () – C:\rollback.ini
[2007/11/08 20:03:17 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
[2011/12/06 06:39:21 | 000,077,466 | —- | M] () – C:\TDSSKiller.2.6.21.0_06.12.2011_05.38.02_log.txt
[2012/07/10 19:22:47 | 000,000,111 | —- | M] () – C:\UnInstallService.bat

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/10/02 09:47:51 | 000,001,738 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/27 22:36:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2008/06/23 18:36:24 | 000,773,120 | —- | M] () – C:\WINDOWS\system32\NEROINSTAEC43759.DB

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/24 21:16:36 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/10/26 15:27:42 | 000,538,941 | —- | M] () – C:\Documents and Settings\chic\Desktop\adwcleaner.exe
[2012/10/26 15:28:53 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\chic\Desktop\aswMBR.exe
[2012/10/25 22:53:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2012/10/25 22:21:15 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2009/05/03 09:04:25 | 003,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\chic\Desktop\procexp.exe
[2010/09/14 17:28:00 | 000,102,400 | —- | M] () – C:\Documents and Settings\chic\Desktop\Snippy.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2010/05/20 15:27:26 | 000,013,023 | —- | M] () – C:\WINDOWS\VX1000.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-25 21:06:14

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream

< End of report >
That seems to have got rid of a load of junk. Let’s get rid of the rest.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}: "URL" = http://uk.search.yahoo.com/search?ei=UTF-8…p={searchTerms}
    IE - HKLM\..\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}: "URL" = http://startsear.ch/?aff=1&src=sp&…q={searchTerms}
    IE - HKLM\..\SearchScopes\{749F5CD3-7B4D-4349-B510-0586016EE61C}: "URL" = http://uk.news.search.yahoo.com/search/new…p={searchTerms}
    IE - HKLM\..\SearchScopes\{8EA8ADF6-B3CF-4CBD-A630-741A82BD8448}: "URL" = http://uk.local.yahoo.com/search.html?p={s…GugiXML&cs=
    IE - HKLM\..\SearchScopes\{8FE0B69C-E812-4CDA-B67D-14DA6B88C324}: "URL" = http://uk.search.yahoo.com/search/dir?ei=U…p={searchTerms}
    IE - HKLM\..\SearchScopes\{B4E9D89A-5ECB-4D73-B42B-B0EF5BF2DDA5}: "URL" = http://shopping.yahoo.co.uk/ctl/do/search?…y={searchTerms}
    IE - HKLM\..\SearchScopes\{C9201B62-6575-4C97-BE89-44B460C2E5F0}: "URL" = http://uk.search.yahoo.com/search/video?ei…p={searchTerms}
    IE - HKLM\..\SearchScopes\{CF74A3B6-1C71-4192-9F84-885EEBCE8AA1}: "URL" = http://uk.search.yahoo.com/search/audio?ei…p={searchTerms}
    IE - HKLM\..\SearchScopes\{E903FDC2-77F8-4E45-9476-AC74FFBDEA6F}: "URL" = http://uk.search.yahoo.com/search/images?e…p={searchTerms}
    IE - HKCU\..\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}: "URL" = http://uk.search.yahoo.com/search?ei=UTF-8…p={searchTerms}
    IE - HKCU\..\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}: "URL" = http://startsear.ch/?aff=1&src=sp&…q={searchTerms}
    IE - HKCU\..\SearchScopes\{9B0FE47C-BED4-44E4-8C07-D7F906B08B5A}: "URL" = http://www.ask.com/web?q={searchTerms}&…=1690&l=dir
    IE - HKCU\..\SearchScopes\{9BE63AD6-4299-4920-B628-B11D2D83B9CC}: "URL" = http://uk.search.yahoo.com/search?fr=chr-g…p={searchTerms}
    IE - HKCU\..\SearchScopes\{F0816BF4-5A7B-4C14-9FAE-563F3DEAD1CD}: "URL" = http://www.buzqo.com/s/?q={searchTerms}&am…eferrer:source}
    [2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post the OTL fix log.
===============================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    🖼Click to load external image (Posted Image)


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    🖼Click to load external image (Posted Image)


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please remember to include the OTL fix log.

Can you tell me what the situation is now

Satchfan
The situation is such that, through, Google Chrome I am able to access the site I am looking for :notworthy:
Thank you very much for that.

The 2 reports are as below.

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F82FEE6-B232-0661-52CB-1B2546B28F18}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{749F5CD3-7B4D-4349-B510-0586016EE61C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{749F5CD3-7B4D-4349-B510-0586016EE61C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EA8ADF6-B3CF-4CBD-A630-741A82BD8448}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8EA8ADF6-B3CF-4CBD-A630-741A82BD8448}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8FE0B69C-E812-4CDA-B67D-14DA6B88C324}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FE0B69C-E812-4CDA-B67D-14DA6B88C324}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B4E9D89A-5ECB-4D73-B42B-B0EF5BF2DDA5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4E9D89A-5ECB-4D73-B42B-B0EF5BF2DDA5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C9201B62-6575-4C97-BE89-44B460C2E5F0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C9201B62-6575-4C97-BE89-44B460C2E5F0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF74A3B6-1C71-4192-9F84-885EEBCE8AA1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF74A3B6-1C71-4192-9F84-885EEBCE8AA1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E903FDC2-77F8-4E45-9476-AC74FFBDEA6F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E903FDC2-77F8-4E45-9476-AC74FFBDEA6F}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00EE008B-4D1D-4702-B5E3-3F61A7C51A15}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0F82FEE6-B232-0661-52CB-1B2546B28F18}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F82FEE6-B232-0661-52CB-1B2546B28F18}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9B0FE47C-BED4-44E4-8C07-D7F906B08B5A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B0FE47C-BED4-44E4-8C07-D7F906B08B5A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BE63AD6-4299-4920-B628-B11D2D83B9CC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BE63AD6-4299-4920-B628-B11D2D83B9CC}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F0816BF4-5A7B-4C14-9FAE-563F3DEAD1CD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0816BF4-5A7B-4C14-9FAE-563F3DEAD1CD}\ not found.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\searchplugin folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\META-INF folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\lib folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\DualPackage folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\defaults folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\components folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com\chrome folder moved successfully.
C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\chic\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\chic\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78924 bytes

User: All Users

User: chic
->Temp folder emptied: 159352761 bytes
->Temporary Internet Files folder emptied: 85495996 bytes
->Java cache emptied: 2732 bytes
->FireFox cache emptied: 71139062 bytes
->Google Chrome cache emptied: 407333031 bytes
->Flash cache emptied: 662 bytes

User: Default User
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 2365914 bytes
->Temporary Internet Files folder emptied: 914738 bytes

User: UpdatusUser
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 17104447 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 265185222 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 962.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10262012_192557

Files\Folders moved on Reboot…
C:\Documents and Settings\chic\Local Settings\Temp\WCESLog.log moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


ComboFix 12-10-26.05 - chic 26/10/2012 19:53:21.16.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2046.1476 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NVSVC
——-\Service_NVSvc
.
.
((((((((((((((((((((((((( Files Created from 2012-09-26 to 2012-10-26 )))))))))))))))))))))))))))))))
.
.
2012-10-26 18:25 . 2012-10-26 18:25 ——– d—–w- C:\_OTL
2012-10-26 18:19 . 2012-10-26 18:20 ——– d—–w- c:\documents and settings\All Users\Application Data\boost_interprocess
2012-10-25 22:30 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDF528A-DE1A-4AC9-9A4B-FF70BC896091}\mpengine.dll
2012-10-25 04:03 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-10-19 17:49 . 2012-10-19 17:52 ——– d—–w- c:\program files\ExpressFiles
2012-10-19 17:49 . 2012-10-19 17:49 ——– d—–w- c:\documents and settings\chic\Application Data\ExpressFiles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-25 21:17 . 2012-04-15 11:18 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-25 21:17 . 2011-05-26 04:06 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-27 19:12 . 2004-08-10 12:51 832512 —-a-w- c:\windows\system32\wininet.dll
2012-08-27 19:12 . 2004-08-10 12:51 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-27 19:12 . 2009-06-05 08:53 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-08-27 19:12 . 2004-08-10 12:50 17408 —-a-w- c:\windows\system32\corpol.dll
2012-08-24 13:53 . 2004-08-10 12:51 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2004-08-10 12:51 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2004-08-03 22:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-21 01:19 . 2011-03-27 13:07 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-20 719672]
"AshSnap"="c:\program files\Ashampoo\Ashampoo Snap 6\ashsnap.exe" [2012-10-22 3512728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2006-11-22 20:10 151552 ——w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
2008-05-26 19:13 57344 —-a-w- c:\program files\MarkAny\ContentSafer\MaAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-18 19:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-12-18 14:26 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpBrowser.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpNotifier.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP"= 135:TCP:TCP Port 135
"5985:TCP"= 5985:TCP:Windows Remote Management
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [10/07/2011 11:56 13496]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [04/06/2010 11:55 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [01/06/2010 19:00 27576]
R2 DSUDiskOptimizer;DSUDiskOptimizer;c:\program files\Disk Speedup\DSUDefragSrv.exe [21/10/2011 06:34 668472]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/09/2009 09:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/09/2009 09:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/09/2009 09:11 12928]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [24/07/2008 20:38 47360]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [17/06/2005 12:11 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys –> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S1 MpKsl565c8c56;MpKsl565c8c56;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDF528A-DE1A-4AC9-9A4B-FF70BC896091}\MpKsl565c8c56.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDF528A-DE1A-4AC9-9A4B-FF70BC896091}\MpKsl565c8c56.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [19/12/2005 19:02 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 13:28 160944]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [24/11/2005 22:38 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [10/05/2011 07:25 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [10/05/2011 07:25 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [10/05/2011 07:25 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [10/05/2011 07:25 25088]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [10/05/2011 07:25 23168]
S3 AndNetGps;LGE AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys [10/05/2011 07:25 22272]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [10/05/2011 07:25 28032]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys [10/05/2011 07:25 70016]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [30/12/2007 20:16 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 12:42 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [25/12/2005 11:22 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [25/12/2005 11:11 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [03/04/2010 10:41 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [11/05/2005 14:12 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [11/05/2005 14:12 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [11/05/2005 14:12 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [11/05/2005 14:12 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [11/05/2005 14:12 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12/06/2011 11:15 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25/04/2012 06:25 115168]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/06/2010 18:07 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
S3 RapportIaso;RapportIaso;\??\c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys –> c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys [?]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [05/08/2011 12:30 268512]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [03/04/2010 10:41 233472]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31/12/2009 09:33 691696]
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-26 c:\windows\Tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-19 03:44]
.
2012-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2012-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2012-10-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
2012-10-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.00\MediaManager\grab.html
IE: Se&nd; to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
Trusted Zone: adobe.com
Trusted Zone: course-source.net
Trusted Zone: epautotest.com
Trusted Zone: learndirect-business.com
Trusted Zone: learndirect.co.uk
Trusted Zone: mindleaders.com
Trusted Zone: thirdforce.com
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
AddRemove-ERUNT_is1 - g:\program files\ERUNT\unins000.exe
AddRemove-vShare.tv plugin - c:\program files\vShare.tv plugin\uninst.exe
AddRemove-Xvid Video Codec 1.3.1 - g:\program files\XviD\uninstall.exe
AddRemove-YouTube Free Downloader - k:\program files\YouTube Free Downloader\Uninstall.exe
AddRemove-{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1 - g:\program files\Free YouTube Downloader\unins000.exe
AddRemove-Yahoo! BrowserPlus - c:\documents and settings\chic\Local Settings\Application Data\Yahoo!\BrowserPlus\BrowserPlusUninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-26 20:03
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2CB90BE9-3AD9-D1A2-3C33-C3A076F28F92}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacfkobdbkopgbloea"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"haigiamelfjfcnkl"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"faghdhhmmpjm"=hex:63,62,6e,6d,6a,62,6e,6b,69,63,6c,6a,64,64,64,70,6f,66,66,69,
67,65,62,65,62,63,67,6f,66,6c,69,64,6e,6f,67,6b,6a,6b,00,7e
"faghihgjhglb"=hex:6f,62,6c,6d,70,61,6d,6f,64,68,68,6b,6c,6a,64,6e,6b,6c,68,67,
6f,6a,67,6e,69,62,65,6f,6b,66,6d,6b,66,68,62,62,6e,68,66,6f,68,64,65,70,6d,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3432)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Zune\ZuneBusEnum.exe
c:\windows\system32\fxssvc.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
.
**************************************************************************
.
Completion time: 2012-10-26 20:10:37 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-26 19:10
ComboFix2.txt 2011-12-06 06:05
.
Pre-Run: 117,231,628,288 bytes free
Post-Run: 117,100,232,704 bytes free
.
- - End Of File - - F2C3288BE3A931C4EDD890FE50759127
That all looks good. If a final couple of scans are clear we should be OK to tidy up.

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Run ESET Online Scan

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - if ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
whew … eset took a wee while :) Scan reports below Satchfan. Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.10.27.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 7.0.5730.11 chic :: CHICPC [administrator] 27/10/2012 06:52:10 mbam-log-2012-10-27 (06-52-10).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 219884 Time elapsed: 10 minute(s), 39 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Documents and Settings\chic\My Documents\Pest Patrol 3.2.exe probably unknown NewHeur_PE virus C:\Documents and Settings\chic\My Documents\Downloads\cbsidlm-tr1_7-Ashampoo_Snap_6-BP2-10159926.exe Win32/DownloadAdmin.D application C:\Documents and Settings\chic\My Documents\Downloads\iLividSetupV1.exe Win32/Toolbar.SearchSuite application C:\Documents and Settings\chic\My Documents\Downloads\Senna.(2010).DVDRip.AC3.XviD-MDCTeam.avi_downloader_98828.exe probably a variant of Win32/ExpressFiles application C:\Documents and Settings\chic\My Documents\Downloads\vshare-plugin.exe Win32/TopMedia.A application L:\Downloads\asc-setup.exe a variant of Win32/Toolbar.Widgi application L:\Downloads\defragsetup.exe a variant of Win32/Toolbar.Widgi application L:\Downloads\YouTubeDownloaderSetup265.exe a variant of Win32/Toolbar.Widgi application L:\Downloads\YouTubeDownloaderSetup271.exe a variant of Win32/Toolbar.Widgi application
Those that Eset found are remnants/sources of the rubbish that has been downloaded and used on your machine. Getting rid of them should be the final step in cleaning. :)

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
C:\Documents and Settings\chic\My Documents\Pest Patrol 3.2.exe 
C:\Documents and Settings\chic\My Documents\Downloads\cbsidlm-tr1_7-Ashampoo_Snap_6-BP2-10159926.exe 
C:\Documents and Settings\chic\My Documents\Downloads\iLividSetupV1.exe
C:\Documents and Settings\chic\My Documents\Downloads\Senna.(2010).DVDRip.AC3.XviD-MDCTeam.avi_downloader_98828.exe 
C:\Documents and Settings\chic\My Documents\Downloads\vshare-plugin.exe
L:\Downloads\asc-setup.exe 
L:\Downloads\defragsetup.exe 
L:\Downloads\YouTubeDownloaderSetup265.exe
L:\Downloads\YouTubeDownloaderSetup271.exe

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

If in your reply you assure me that all is well, I’ll send final instructions and suggestions.

Satchfan
Hi Satchfan,

Everything seems fine, bit slow at times but this is probably down to the age of the PC, rather than anything else. The original query certainly seems to be resolved - thank you for that.
Below is the ComboFix text file you were looking for.

ComboFix 12-10-26.05 - chic 27/10/2012 14:11:14.18.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2046.1409 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\chic\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\chic\My Documents\Downloads\cbsidlm-tr1_7-Ashampoo_Snap_6-BP2-10159926.exe"
"c:\documents and settings\chic\My Documents\Downloads\iLividSetupV1.exe"
"c:\documents and settings\chic\My Documents\Downloads\Senna.(2010).DVDRip.AC3.XviD-MDCTeam.avi_downloader_98828.exe"
"c:\documents and settings\chic\My Documents\Downloads\vshare-plugin.exe"
"c:\documents and settings\chic\My Documents\Pest Patrol 3.2.exe"
"l:\downloads\asc-setup.exe"
"l:\downloads\defragsetup.exe"
"l:\downloads\YouTubeDownloaderSetup265.exe"
"l:\downloads\YouTubeDownloaderSetup271.exe"
.
.
((((((((((((((((((((((((( Files Created from 2012-09-27 to 2012-10-27 )))))))))))))))))))))))))))))))
.
.
2012-10-27 13:07 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9D439569-3B83-4CA9-8492-48594981E6C6}\mpengine.dll
2012-10-27 06:18 . 2012-10-27 06:18 ——– d—–w- c:\windows\LastGood
2012-10-27 06:18 . 2012-10-27 06:18 ——– d—–w- c:\program files\ESET
2012-10-26 20:06 . 2012-09-29 18:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-10-26 19:15 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-10-26 18:25 . 2012-10-26 18:25 ——– d—–w- C:\_OTL
2012-10-26 18:19 . 2012-10-27 13:08 ——– d—–w- c:\documents and settings\All Users\Application Data\boost_interprocess
2012-10-19 17:49 . 2012-10-19 17:52 ——– d—–w- c:\program files\ExpressFiles
2012-10-19 17:49 . 2012-10-19 17:49 ——– d—–w- c:\documents and settings\chic\Application Data\ExpressFiles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-25 21:17 . 2012-04-15 11:18 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-25 21:17 . 2011-05-26 04:06 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-27 19:12 . 2004-08-10 12:51 832512 —-a-w- c:\windows\system32\wininet.dll
2012-08-27 19:12 . 2004-08-10 12:51 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-27 19:12 . 2009-06-05 08:53 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-08-27 19:12 . 2004-08-10 12:50 17408 —-a-w- c:\windows\system32\corpol.dll
2012-08-24 13:53 . 2004-08-10 12:51 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2004-08-10 12:51 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2004-08-03 22:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-21 01:19 . 2011-03-27 13:07 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-20 719672]
"AshSnap"="c:\program files\Ashampoo\Ashampoo Snap 6\ashsnap.exe" [2012-10-22 3512728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2006-11-22 20:10 151552 ——w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
2008-05-26 19:13 57344 —-a-w- c:\program files\MarkAny\ContentSafer\MaAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-18 19:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-12-18 14:26 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpBrowser.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpNotifier.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP"= 135:TCP:TCP Port 135
"5985:TCP"= 5985:TCP:Windows Remote Management
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [10/07/2011 11:56 13496]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [04/06/2010 11:55 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [01/06/2010 19:00 27576]
R2 DSUDiskOptimizer;DSUDiskOptimizer;c:\program files\Disk Speedup\DSUDefragSrv.exe [21/10/2011 06:34 668472]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/09/2009 09:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/09/2009 09:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/09/2009 09:11 12928]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [24/07/2008 20:38 47360]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [17/06/2005 12:11 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys –> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [19/12/2005 19:02 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 13:28 160944]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [24/11/2005 22:38 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [10/05/2011 07:25 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [10/05/2011 07:25 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [10/05/2011 07:25 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [10/05/2011 07:25 25088]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [10/05/2011 07:25 23168]
S3 AndNetGps;LGE AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys [10/05/2011 07:25 22272]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [10/05/2011 07:25 28032]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys [10/05/2011 07:25 70016]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [30/12/2007 20:16 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 12:42 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [25/12/2005 11:22 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [25/12/2005 11:11 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [03/04/2010 10:41 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 11:07 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [11/05/2005 14:12 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [11/05/2005 14:12 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [11/05/2005 14:12 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [11/05/2005 14:12 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [11/05/2005 14:12 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12/06/2011 11:15 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25/04/2012 06:25 115168]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/06/2010 18:07 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22:37 4640000]
S3 RapportIaso;RapportIaso;\??\c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys –> c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys [?]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [05/08/2011 12:30 268512]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [03/04/2010 10:41 233472]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31/12/2009 09:33 691696]
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-26 c:\windows\Tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-19 03:44]
.
2012-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2012-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2012-10-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
2012-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.00\MediaManager\grab.html
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
Trusted Zone: adobe.com
Trusted Zone: course-source.net
Trusted Zone: epautotest.com
Trusted Zone: learndirect-business.com
Trusted Zone: learndirect.co.uk
Trusted Zone: mindleaders.com
Trusted Zone: thirdforce.com
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-27 14:19
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2CB90BE9-3AD9-D1A2-3C33-C3A076F28F92}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacfkobdbkopgbloea"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"haigiamelfjfcnkl"=hex:6b,61,66,69,63,66,63,66,63,6a,6f,6d,6e,6b,6c,6b,67,61,
68,63,63,62,00,00
"faghdhhmmpjm"=hex:63,62,6e,6d,6a,62,6e,6b,69,63,6c,6a,64,64,64,70,6f,66,66,69,
67,65,62,65,62,63,67,6f,66,6c,69,64,6e,6f,67,6b,6a,6b,00,7e
"faghihgjhglb"=hex:6f,62,6c,6d,70,61,6d,6f,64,68,68,6b,6c,6a,64,6e,6b,6c,68,67,
6f,6a,67,6e,69,62,65,6f,6b,66,6d,6b,66,68,62,62,6e,68,66,6f,68,64,65,70,6d,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3288)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-10-27 14:22:06
ComboFix-quarantined-files.txt 2012-10-27 13:22
ComboFix2.txt 2012-10-27 13:05
ComboFix3.txt 2012-10-26 19:10
ComboFix4.txt 2011-12-06 06:05
.
Pre-Run: 116,558,360,576 bytes free
Post-Run: 116,527,996,928 bytes free
.
- - End Of File - - 9A90AC010524DA39E98959E578171DD3
Good job.

As far as the slowness is concerned, Ztruker has a good article here at WTT on using "msconfig" to help combat slowness. It is worth a look and can be found here.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall OTL
  • double-click OTL.exe
  • click the CleanUp! button.
  • select Yes when the Begin cleanup Process? prompt appears.
  • if you are prompted to reboot during the cleanup, select Yes.
  • the tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Uninstall AdwCleaner
  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with Yes.
You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Update installed programs

You have old versions of Java on your computer which are vulnerable to infections.
  • uninstall any version of Java
  • install the latest version here
Next

Windows Internet Explorer 7

You should install Internet Explorer 9. It has many new and improved features. The most important of these features is that older browsers will not be able to access some of those written in the new HTML5 code and earlier browsers may not comply with security requirements of some sites including banking sites.

Go here for information and download.

===================================================

Install Spybot - Search and Destroy - Download and install Spybot Search and Destroy which provides real time spyware and hijacker protection .

You should scan your computer with the program on a regular basis as you would with your anti-virus software.

A tutorial on installing and using SS&D can be found here

===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes


If I hear nothing for 24 hours I shall assume all is well and close the topic.

Safe computing

Satchfan
Hi Satchfan, Everything seems to be fine, thank you very much for your time, effort and expertise. Can I ask one last question of you - I have Microsoft Security Essentials and now SpyBot securing my system, as well as MBAM - do I need all of this, or is it even not enough?? I will be making a contribution to the site through PayPal because of your efforts (I hope you have no problems with Internet trade :)) Take care.

Everything seems to be fine, thank you very much for your time, effort and expertise.

You're welcome.

I have Microsoft Security Essentials and now SpyBot securing my system, as well as MBAM - do I need all of this

Yes.

MSE is real-time protection against viruses. Spybot gives real-time protection against things that MSE doesn't cover and a weekly scan with Malwarebytes will pick up MANY infections that antiviruses and spyware scanners do not.

All three work well alongside each other and there are no conflicts.

I will be making a contribution to the site through PayPal because of your efforts

That's kind but don't feel obliged as we don't do this for profit.

(I hope you have no problems with Internet trade ).

PayPal is safe and there are no problems using this particular form of Internet trade. :)

Take care.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI