This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blue Screen Trouble [Solved]

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello jdcats007

the next scan doesnt work with IE. I tried in firefox. After 20 mins I got error 2002

That may be being caused by the problems with the hard drive.

Please post a new OTL log for me to review and we'll take things from there :)
OTL logfile created on: 11/17/2012 7:01:45 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 81.39% Memory free
6.06 Gb Paging File | 5.70 Gb Available in Paging File | 93.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.13 Gb Total Space | 80.43 Gb Free Space | 58.23% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.83 Gb Free Space | 16.77% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/11/08 18:39:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\ProgramData\UpdaterService\wsupdsvc.exe /SERVICE – (UpdaterService)
SRV - File not found [Auto | Stopped] – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe /s Norton Internet Security /m C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll /prefetch:1 – (Norton Internet Security)
SRV - [2012/11/09 02:48:51 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/10/29 14:21:48 | 000,055,808 | —- | M] (PasswordBox, Inc.) [Auto | Stopped] – C:\Program Files\PasswordBox\pbbtnService.exe – (PasswordBox)
SRV - [2012/10/08 22:20:24 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/08/06 15:17:54 | 000,208,616 | —- | M] (Kaspersky Lab) [Auto | Stopped] – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe – (AVP)
SRV - [2008/10/06 10:54:52 | 000,365,952 | —- | M] () [Auto | Stopped] – C:\Program Files\SMINST\BLService.exe – (Recovery Service for Windows)
SRV - [2008/01/20 20:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS – (SRTSPX)
DRV - File not found [File_System | System | Stopped] – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS – (SRTSP)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS – (NAVEX15)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS – (NAVENG)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - [2010/01/29 00:03:58 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2009/08/06 15:17:54 | 000,224,272 | —- | M] (Kaspersky Lab) [File_System | System | Stopped] – C:\Windows\System32\drivers\klif.sys – (KLIF)
DRV - [2009/08/06 15:17:54 | 000,033,808 | —- | M] (Kaspersky Lab) [File_System | Boot | Stopped] – C:\Windows\System32\drivers\klbg.sys – (klbg)
DRV - [2008/12/20 01:01:46 | 001,093,120 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2008/07/21 17:34:36 | 000,121,872 | —- | M] (Kaspersky Lab) [Kernel | System | Stopped] – C:\Windows\System32\drivers\kl1.sys – (kl1)
DRV - [2008/07/09 17:28:26 | 000,020,496 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\System32\drivers\klim6.sys – (KLIM6)
DRV - [2008/06/29 08:52:26 | 000,112,128 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV - [2008/06/10 12:54:36 | 000,123,904 | —- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2008/06/05 10:58:42 | 000,222,208 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2008/03/13 18:02:46 | 000,026,640 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\klfltdev.sys – (KLFLTDEV)
DRV - [2008/01/20 20:23:20 | 002,225,664 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NETw3v32.sys – (NETw3v32)
DRV - [2007/10/17 17:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/18 18:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKLM\..\SearchScopes\{A23B6865-91F4-4D89-B386-7D1A3EFEF156}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPNTDF
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3198785

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 66 AA 48 54 99 C3 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…00000242c6ea9d7
IE - HKCU\..\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = Playbryte-fa-v/search/redirect/?type=default&user_id=cae7fe76-9c4e-476a-acd6-6fdd4686b491&query={searchTerms}
IE - HKCU\..\SearchScopes\{A23B6865-91F4-4D89-B386-7D1A3EFEF156}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3198785
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/?search={se…box_im2_test_v2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@vizzed.com/VizzedRGR: C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll (Vizzed.com)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/09 02:48:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\THBExt [2009/08/06 19:58:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Owner\AppData\Local\PasswordBox\Firefox [2012/09/28 09:49:26 | 000,000,000 | —D | M]

[2012/09/28 09:54:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/11/08 14:51:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions
[2012/10/29 20:28:29 | 000,000,000 | —D | M] (ooVoo toolbar, powered by Ask.com) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\[removed]
[2012/11/09 02:48:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/09 02:48:51 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 19:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 19:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT3198785
CHR - default_search_provider: suggest_url = http://search.conduit.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahilkiibpgjnonbhdfkkgjddddmapala\2.3.15.10_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Vizzed Retro Game Room Plugin (Enabled) = C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Oovoo Toolbar = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanijiojpcccpkjdjjmjghddcgcbfj\7.17.0.0_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Kingdom Rush = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckmfhhjalnddapegkbbohfaodgbnocim\1.0.7.3_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Isoball 3 = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj\1.3.0_0\
CHR - Extension: A Crack in Time and Space = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmpbeckibaikflbnegjemaegnpbgjol\1.1_0\
CHR - Extension: Mini Ninjas = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi\1.0.0.15_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/11/11 08:35:03 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
O3 - HKLM\..\Toolbar: (PasswordBox Toolbar) - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files\PasswordBox\Application\pbbtn.dll File not found
O3 - HKLM\..\Toolbar: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (PasswordBox Toolbar) - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files\PasswordBox\Application\pbbtn.dll File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [4Sync] C:\Program Files\4Sync\4Sync.exe (New IT Solutions Ltd.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{288F8038-4777-4D83-B729-FD77311C5E15}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/15 19:39:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/11/14 14:37:09 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/11/14 10:14:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/11/14 10:14:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/14 10:14:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/11/14 10:14:38 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/11/14 10:14:38 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/14 10:11:08 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Users\Owner\Desktop\mbam-setup-1.65.1.1000.exe
[2012/11/12 18:31:30 | 000,000,000 | —D | C] – C:\FRST
[2012/11/11 08:37:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\temp
[2012/11/11 08:37:04 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/11/09 17:30:42 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/11/09 17:30:42 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/11/09 17:30:42 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/11/09 17:30:31 | 000,000,000 | —D | C] – C:\Qoobox
[2012/11/09 17:30:09 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/11/09 17:28:25 | 005,000,376 | R— | C] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/11/09 02:48:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/11/08 19:14:57 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/11/08 18:38:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/11/08 15:17:16 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\LavasoftStatistics
[2012/11/08 15:13:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Ad-Aware Antivirus
[2012/11/07 15:36:36 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/10/29 20:28:55 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\ooVoo Details
[2012/10/29 20:27:57 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2012/10/29 20:26:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2012/10/29 20:26:45 | 000,000,000 | —D | C] – C:\Program Files\ooVoo
[2012/10/23 08:28:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/10/23 08:27:48 | 000,000,000 | —D | C] – C:\Program Files\QuickTime

========== Files - Modified Within 30 Days ==========

[2012/11/17 07:14:14 | 000,001,356 | —- | M] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/11/17 07:00:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/15 19:20:31 | 000,314,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/11/14 23:32:39 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000UA.job
[2012/11/14 20:09:37 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/14 20:09:37 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/14 17:55:56 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/11/14 17:51:49 | 212,013,147 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/11/14 10:14:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 10:13:29 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Users\Owner\Desktop\mbam-setup-1.65.1.1000.exe
[2012/11/12 16:10:59 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/11/12 16:10:59 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/11/11 08:35:03 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/11/11 08:13:12 | 005,000,376 | R— | M] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/11/08 19:30:11 | 000,000,512 | —- | M] () – C:\Users\Owner\Desktop\MBR.dat
[2012/11/08 19:19:12 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/11/08 18:39:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/11/08 16:36:45 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2012/11/08 15:17:03 | 000,000,563 | —- | M] () – C:\Users\Owner\Desktop\Resume Ad-Aware Free Antivirus+ Installation.lnk
[2012/11/07 15:37:05 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2012/11/06 22:20:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/06 22:18:04 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000UA.job
[2012/11/06 17:14:44 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000Core.job
[2012/11/06 17:02:25 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000Core.job
[2012/11/03 17:11:17 | 000,002,627 | —- | M] () – C:\Users\Owner\Desktop\Microsoft Office Word 2007.lnk
[2012/10/29 20:26:51 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2012/10/29 17:47:51 | 004,730,912 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.dat
[2012/10/29 17:47:51 | 001,097,760 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.dat
[2012/10/29 17:47:51 | 000,039,088 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.idx
[2012/10/29 17:47:51 | 000,004,832 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.idx
[2012/10/23 08:28:20 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk

========== Files Created - No Company Name ==========

[2012/11/14 10:14:40 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/09 17:30:42 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/11/09 17:30:42 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/11/09 17:30:42 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/11/09 17:30:42 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/11/09 17:30:42 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/11/08 19:30:11 | 000,000,512 | —- | C] () – C:\Users\Owner\Desktop\MBR.dat
[2012/11/08 15:17:03 | 000,000,563 | —- | C] () – C:\Users\Owner\Desktop\Resume Ad-Aware Free Antivirus+ Installation.lnk
[2012/11/07 15:35:29 | 212,013,147 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/10/29 20:26:51 | 000,001,726 | —- | C] () – C:\Users\Public\Desktop\ooVoo.lnk
[2012/10/23 08:28:20 | 000,001,726 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/10/08 20:27:22 | 000,005,632 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/22 22:47:32 | 000,000,044 | —- | C] () – C:\Users\Owner\jagex_cl_runescape_LIVE.dat
[2012/09/22 22:47:32 | 000,000,024 | —- | C] () – C:\Users\Owner\random.dat
[2012/08/22 10:24:33 | 000,000,436 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2012/07/22 00:08:39 | 027,884,433 | —- | C] () – C:\Users\Owner\Pokemon_Diamond.zip
[2012/06/01 23:03:46 | 000,001,356 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/05/23 09:37:08 | 009,605,844 | —- | C] () – C:\Users\Owner\01 - Goldfinger - 99 Red Balloons.mp3
[2009/08/19 11:49:26 | 000,024,227 | —- | C] () – C:\Users\Owner\AppData\Roaming\UserTile.png
[2009/05/16 09:36:11 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini

========== ZeroAccess Check ==========

[2006/11/02 06:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 11:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 00:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 00:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/05/24 13:07:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.minecraft
[2012/05/24 12:57:39 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.techniclauncher
[2012/07/21 23:36:23 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\4Sync
[2012/11/08 15:13:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Ad-Aware Antivirus
[2012/09/28 09:48:58 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Babylon
[2012/04/22 22:16:15 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Eurotalk
[2012/10/29 20:34:46 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ooVoo Details
[2012/08/22 10:24:37 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Template

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 641 bytes -> C:\Users\Owner\Desktop\Worth Reading.eml:OECustomProperty

< End of report >
Hello jdcats007

Thank you for the log.


  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      SRV - File not found [Auto | Stopped] – C:\ProgramData\UpdaterService\wsupdsvc.exe /SERVICE – (UpdaterService)
      IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
      IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…00000242c6ea9d7
      IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = Playbryte-fa-v/search/redirect/?type=default&user_id=cae7fe76-9c4e-476a-acd6-6fdd4686b491&query={searchTerms}
      O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
      O3 - HKLM\..\Toolbar: (PasswordBox Toolbar) - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files\PasswordBox\Application\pbbtn.dll File not found
      O3 - HKCU\..\Toolbar\WebBrowser: (PasswordBox Toolbar) - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files\PasswordBox\Application\pbbtn.dll File not found
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
      [2012/09/28 09:48:58 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Babylon
      
      :Files
      C:\ProgramData\UpdaterService
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

    Once you have ran the above script, let see if we can get a different online scan to run:

  • BitDefender


    • Lets try an online scan with BitDefender QuickScan.
    • Please be patient as scanning can take some time.
    • We recommend that you disable any real time protection that you have before starting the scan.
    • Click here here to access the BitDefender QuickScan page

    • For Firefox users:
    • Click on the Free Scan Now button.
    • You will be prompted to install a plug-in. Please Allow the installation.
    • If the process stalls you may need to refresh the page.
    • A Software Installation window will appear.
    • Click on Install Now and the plugin will be installed as an Add-on.
    • Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.

    • For Internet Explorer users:
    • Click on the Free Scan Now button.
    • You will be prompted to install an ActiveX control. Please allow the control to install.
    • The page will refresh. Click on the Free Scan Now button again and proceed accordingly.

    If you are unable to run the bitdefender scan just let me know.


    Please post the OTL fix log and the Bitdefender log (if the scan completes) in your next reply, along with another OTL scan log.
Question? If the hard drive has crashed, how hard will it be to replace? Is something anyone can do? OTL log: All processes killed ========== OTL ========== Service UpdaterService stopped successfully! Service UpdaterService deleted successfully! File C:\ProgramData\UpdaterService\wsupdsvc.exe /SERVICE not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1\\http deleted successfully. C:\Users\Owner\AppData\Roaming\Babylon folder moved successfully. ========== FILES ========== File\Folder C:\ProgramData\UpdaterService not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Owner ->Temp folder emptied: 883451 bytes ->Temporary Internet Files folder emptied: 50703532 bytes ->Java cache emptied: 1780160 bytes ->FireFox cache emptied: 2014741 bytes ->Google Chrome cache emptied: 6099312 bytes ->Flash cache emptied: 1960635 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 26112 bytes Total Files Cleaned = 61.00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Owner ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 11182012_112354 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot… Bitfinder log: QuickScan 32-bit v0.9.9.119 ————————— Scan date: Sun Nov 18 11:37:34 2012 Machine ID: 5DD85BA3 No infection found. ——————- Processes ——— Firefox 1780 C:\Program Files\Mozilla Firefox\firefox.exe Firefox 572 C:\Program Files\Mozilla Firefox\plugin-container.exe Microsoft® Windows® Operating System 1288 C:\Windows\explorer.exe Microsoft® Windows® Operating System 384 C:\Windows\System32\csrss.exe Microsoft® Windows® Operating System 420 C:\Windows\System32\csrss.exe Microsoft® Windows® Operating System 516 C:\Windows\System32\lsass.exe Microsoft® Windows® Operating System 504 C:\Windows\System32\services.exe Microsoft® Windows® Operating System 324 C:\Windows\System32\smss.exe Microsoft® Windows® Operating System 1992 C:\Windows\System32\wbem\unsecapp.exe Microsoft® Windows® Operating System 2036 C:\Windows\System32\wbem\WmiPrvSE.exe Microsoft® Windows® Operating System 428 C:\Windows\System32\wininit.exe Microsoft® Windows® Operating System 456 C:\Windows\System32\winlogon.exe (verified) Microsoft® Windows® Operating System 524 C:\Windows\System32\lsm.exe (verified) Microsoft® Windows® Operating System 680 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 736 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 772 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 860 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 888 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 924 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 976 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1132 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1376 C:\Windows\System32\svchost.exe (verified) Microsoft® Windows® Operating System 1396 C:\Windows\System32\svchost.exe Network activity —————- Process firefox.exe (1780) connected on port 80 (HTTP) –> 74.125.225.57 Process firefox.exe (1780) connected on port 80 (HTTP) –> [removed] Process firefox.exe (1780) connected on port 80 (HTTP) –> [removed] Process firefox.exe (1780) connected on port 80 (HTTP) –> [removed] Process firefox.exe (1780) connected on port 80 (HTTP) –> [removed] Process firefox.exe (1780) connected on port 80 (HTTP) –> [removed] Process firefox.exe (1780) connected on port 80 (HTTP) –> [removed] Process wininit.exe (428) listens on ports: 49152 (RPC) Process services.exe (504) listens on ports: 49156 (RPC) Process lsass.exe (516) listens on ports: 49154 (RPC) Process svchost.exe (736) listens on ports: 135 (RPC) Process svchost.exe (860) listens on ports: 49153 (RPC) Process svchost.exe (1396) listens on ports: 49155 (RPC) Autoruns and critical files ————————— 4Sync C:\Program Files\4Sync\4Sync.exe Adobe® Flash® Player Installer/Uninstal C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe Adobe® Flash® Player Update Service C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Apple Push C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe CEEment C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe Facebook Update C:\Users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe Google Update C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe HP Quick Launch Buttons C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe HP QuickPlay C:\Program Files\HP\QuickPlay\QPService.exe HP Wireless Assistant C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe IncrediMail C:\Program Files\IncrediMail\bin\IncMail.exe Intel® Common User Interface C:\Windows\system32\hkcmd.exe Intel® Common User Interface C:\Windows\system32\igfxdev.dll Intel® Common User Interface C:\Windows\system32\igfxpers.exe Intel® Common User Interface C:\Windows\system32\igfxtray.exe iTunes C:\Program Files\iTunes\iTunesHelper.exe Java™ Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe Kaspersky Anti-Virus c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll Kaspersky Anti-Virus C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe Kaspersky Anti-Virus c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll Kaspersky Anti-Virus c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll Kaspersky Anti-Virus c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll Kaspersky Anti-Virus C:\Windows\system32\klogon.dll LightScribe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe Malwarebytes Anti-Malware C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe Microsoft LifeCam C:\Program Files\Microsoft LifeCam\LifeExp.exe Microsoft Office OneNote C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE Microsoft® Windows® Operating System C:\Program Files\Windows Sidebar\Sidebar.exe Microsoft® Windows® Operating System C:\Windows\system32\BROWSEUI.dll Microsoft® Windows® Operating System C:\Windows\system32\Ribbons.scr ooVoo C:\Program Files\ooVoo\oovoo.exe OTL C:\Users\Owner\Desktop\OTL.exe QuickTime C:\Program Files\QuickTime\QTTask.exe Skype C:\Program Files\Skype\Phone\Skype.exe Synaptics Pointing Device Driver C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Updater C:\Program Files\Ask.com\Updater\Updater.exe Windows® Internet Explorer c:\windows\system32\webcheck.dll (verified) Microsoft® Windows® Operating System C:\Windows\ehome\ehTray.exe (verified) Microsoft® Windows® Operating System c:\windows\system32\userinit.exe Browser plugins ————— Bitdefender QuickScan C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll Bonjour C:\Program Files\Bonjour\mdnsNSP.dll Facebook Video Calling Plugin C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll Google Update C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll Java Deployment Toolkit 7.0.70.11 C:\Windows\system32\npDeployJava1.dll Java™ Platform SE 7 U7 c:\program files\java\jre7\bin\jp2ssv.dll Java™ Platform SE 7 U7 C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll Java™ Platform SE 7 U7 c:\program files\java\jre7\bin\ssv.dll Kaspersky Anti-Virus c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll npitunes.dll C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll NPSWF32_11_4_402_287.dll C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll QuickTime Plug-in 7.7.2 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll registryAccess C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanijiojpcccpkjdjjmjghddcgcbfj\7.17.0.0_0\background\registryAccess.dll Shockwave for Director C:\Windows\system32\Adobe\Director\np32dsw.dll Silverlight Plug-In c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll Toolbar c:\program files\ask.com\genericasktoolbar.dll Vizzed Retro Game Room Plugin C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll Windows Presentation Foundation c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll Windows® Internet Explorer C:\Windows\system32\ieframe.dll (verified) AcroIEHelperShim Library c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\mswsock.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll (verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll Scan —- MD5: f9c162f980d3cb5e8c2a69cb4e69f55f C:\Program Files\4Sync\4Sync.exe MD5: 91dbd8da178be91e2f99c326cf660ffe C:\Program Files\4Sync\ShellExt.dll MD5: b580d2d00faeeabe6c1ebc0bd736d265 c:\program files\ask.com\genericasktoolbar.dll MD5: efc9daec6c427da6b56d6d0b745c1cc4 C:\Program Files\Ask.com\Updater\Updater.exe MD5: 40947436a70e0034e41123df5a0a7702 C:\Program Files\Bonjour\mdnsNSP.dll MD5: db5bea73edaf19ac68b2c0fad0f92b1a C:\Program Files\Bonjour\mDNSResponder.exe MD5: 82cc8f77e9ec61c6b4d48dd4d5ca78e7 C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe MD5: a5299d04ed225d64cf07a568a3e1bf8c C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe MD5: 12916e0642e92561c98b18a2a2d01b14 C:\Program Files\Common Files\Java\Java Update\jusched.exe MD5: 4a9295c9be22739d030ab072e9a0b169 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe MD5: abf90fc5a127f481219b873c1b8dfc1c C:\Program Files\Common Files\LightScribe\LSSrvc.exe MD5: 785f487a64950f3cb8e9f16253ba3b7b C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE MD5: 805ae1f90c64758d19aaa001cf8cba12 C:\Program Files\CyberLink\Shared files\RichVideo.exe MD5: a19b0bb5a7eb6df2dd4a0711d36955ee c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe MD5: 7795f8cebc284a426b53f541e538695f C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe MD5: f7cf218e5caa6fc0bb55791ad31e2b3f C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe MD5: 8cb896c573fd15ae8b13180da53e93d2 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe MD5: e7e91ebf735d68c4ba1b8367d3121e0c C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe MD5: 1665c7121a026df10c903db9bc5e9d43 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe MD5: 617dc2877015270914ca3c03873560d5 C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe MD5: 5e5208a733bbcc4571f384754a9a6746 C:\Program Files\HP\QuickPlay\QPService.exe MD5: 6a8f8cb5346c028cb6476994fb7ba4d5 C:\Program Files\IncrediMail\bin\IncMail.exe MD5: 5e4ff36923c37c80b537dce6caa755f9 C:\Program Files\Internet Explorer\ieproxy.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll MD5: bc0ea61246f8d940fbc5f652d337d6bd C:\Program Files\iPod\bin\iPodService.exe MD5: 4affdcaadcb1dbbffaf06c7f82e7f6fc C:\Program Files\iTunes\iTunesHelper.exe MD5: c1680c34de8a405c8829ab93236576fd C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll MD5: 87e063f1e676c99b6c1c047794deb115 c:\program files\java\jre7\bin\jp2ssv.dll MD5: 632f5b29e8c27631e7ac76e330fe2980 C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll MD5: a8ea3f37f4f31e620383f40526e723fe c:\program files\java\jre7\bin\ssv.dll MD5: 76ad93c7f420b724a9adf673dbd84e91 c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll MD5: 26de7793a6437ceb66c049d76ff1b555 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe MD5: f09ee70d53cd3c336375d363191bba76 c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll MD5: 22b145980a4fb79204217b7f3c14c798 c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll MD5: d84e0ff88869047147c3c795f4ef35a7 c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll MD5: 4dba4917081d7b6f3ce73fa1f3966ca7 c:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll MD5: 12e33dd823d74680de6f33bfa359efb3 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe MD5: 19be5bf2ff9283894bc0f22322fdf56b C:\Program Files\Microsoft LifeCam\LifeExp.exe MD5: d98350792a7ce82e7459a7c36481beda C:\Program Files\Microsoft LifeCam\MSCamS32.exe MD5: 9013599b12923a45c029c34e8d2211ac c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll MD5: 4069a06436494c4de12f65477bb92ebe C:\Program Files\Mozilla Firefox\components\browsercomps.dll MD5: e60e9d5f229cb8da347d48add6e8dc47 C:\Program Files\Mozilla Firefox\firefox.exe MD5: 340a842b7c5d21e08bfcbb7f9b58139d C:\Program Files\Mozilla Firefox\freebl3.dll MD5: b9a5a116229ff8e1d5994f6793eb6a6e C:\Program Files\Mozilla Firefox\gkmedias.dll MD5: 7ef5d4b34137d053b9f4f843ae796802 C:\Program Files\Mozilla Firefox\mozalloc.dll MD5: be852d6ad0a67ee9dd28c6f95e5896e1 C:\Program Files\Mozilla Firefox\mozglue.dll MD5: cc726292a4fdec2857688ca3c32a510d C:\Program Files\Mozilla Firefox\mozjs.dll MD5: f9cf7ed9f44176962d182b80ae0c66d4 C:\Program Files\Mozilla Firefox\mozsqlite3.dll MD5: 03e9314004f504a14a61c3d364b62f66 C:\Program Files\Mozilla Firefox\MSVCP100.dll MD5: 67ec459e42d3081dd8fd34356f7cafc1 C:\Program Files\Mozilla Firefox\MSVCR100.dll MD5: cebc736458c1f79c23b1bbc5493db4c2 C:\Program Files\Mozilla Firefox\nspr4.dll MD5: e1fbacb92fe471c684546dd9336afef6 C:\Program Files\Mozilla Firefox\nss3.dll MD5: f3b8464a02e793fd46bcf6f8f6da878d C:\Program Files\Mozilla Firefox\nssckbi.dll MD5: a062f4f9f2e2a89f7c0ed75be5ab8d3f C:\Program Files\Mozilla Firefox\nssdbm3.dll MD5: d8474b89fd26b18eed414a42ae5175ac C:\Program Files\Mozilla Firefox\nssutil3.dll MD5: a38276867df9ecfac4bae167ba34772d C:\Program Files\Mozilla Firefox\plc4.dll MD5: 74e3fd55c2bcfedcecc80121e93ffec5 C:\Program Files\Mozilla Firefox\plds4.dll MD5: b204707e5f48e90427da6874e72345f9 C:\Program Files\Mozilla Firefox\plugin-container.exe MD5: 94fb1d160021fe9f54c84ff587273868 C:\Program Files\Mozilla Firefox\smime3.dll MD5: 7f1d7cfabb351d8f46a0b94d5787fcf3 C:\Program Files\Mozilla Firefox\softokn3.dll MD5: 5914766c39b2d62ce67e2509f78216ab C:\Program Files\Mozilla Firefox\ssl3.dll MD5: 7f89683200960ffae7c6f7f99360949c C:\Program Files\Mozilla Firefox\xpcom.dll MD5: 819fa5f084b3174cf702320ce58aa7e6 C:\Program Files\Mozilla Firefox\xul.dll MD5: 8be15f71de6ff33fc56dcde7b2b9efe8 C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe MD5: db82ea00432d9e4e4ba416c2907d55e7 C:\Program Files\ooVoo\oovoo.exe MD5: 2f436caa73e16a8211c2cbaa838ffe62 C:\Program Files\PasswordBox\pbbtnService.exe MD5: 916a2c4eb028604783fd5ea169236c1d C:\Program Files\QuickTime\QTTask.exe MD5: cbec06e32d0ac9c3d0a9199edc1fb959 C:\Program Files\Skype\Phone\Skype.exe MD5: f07af60b152221472fbdb2fecec4896d C:\Program Files\Skype\Updater\Updater.exe MD5: 0d362785bef9bdf5a6e1f4628d06716d C:\Program Files\SMINST\BLService.exe MD5: ae567d261d281b51be55e53a786e8574 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe MD5: 4c47a5d633793e4d2ee247373593a4fe C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll MD5: 7d1f2afe12bafc4c18c5a0e3c6866e38 c:\program files\windows defender\mprtplug.dll MD5: aefd5e1d91b86ab41d9705600303f34e C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C053699A-2D19-4E4A-88C8-BFEE7A2CF622}\mpengine.dll MD5: 2a3fb4c98f139038e23330d2439db8a4 C:\Users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe MD5: 0b31b0f8fa99cfd009c8fbea9e20c9de C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll MD5: cf118ba396261f8890cea8615d8cfadb C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanijiojpcccpkjdjjmjghddcgcbfj\7.17.0.0_0\background\registryAccess.dll MD5: 586fdc4e02623ee228ec35b9604ae5f2 C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll MD5: 506708142bc63daba64f2d3ad1dcd5bf C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe MD5: c9e3864fb9cbfa93d9010bcfe18a5697 C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll MD5: 4adcfee16ee9978f06157634669d36fb C:\Users\Owner\Desktop\OTL.exe MD5: ab87eeffd18f2baafc274e7075ea6c67 c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll MD5: e2318e8514abf50e3ecedab9465a90a1 C:\Windows\system32\Adobe\Director\np32dsw.dll MD5: e9b9c1b98c8d6d48407e1c1203eac659 C:\Windows\System32\adsldpc.dll MD5: f31eebc1a1c81fd04005489cc3dcdfe7 C:\Windows\system32\basesrv.dll MD5: 74f26fc01b180d4a99a168ed69c30a53 C:\Windows\system32\cmd.exe MD5: 7f15b4953378c8b5161d65c26d5fed4d C:\Windows\system32\cngaudit.dll MD5: 93e317d7ad783d8eaee2e3500bfe889d C:\Windows\System32\credui.dll MD5: b0f9073be86c6d4edd4eba674251e699 C:\Windows\system32\CRYPT32.dll MD5: 09469b8edd2755143fda06867aad7e73 c:\windows\system32\CRYPTNET.dll MD5: f1e8c34892336d33eddcdfe44e474f64 c:\windows\system32\cryptsvc.dll MD5: 187076dd5d8d4d5d23079d0741195ead C:\Windows\system32\CSRSRV.dll MD5: abca209eba02cb59233614db83b4f50d C:\Windows\System32\csrss.exe MD5: 85e861d0b88db2b54acb0839654c09f7 C:\Windows\system32\DNSAPI.dll MD5: 57d762f6f5974af0da2be88a3349baaa C:\Windows\System32\dnsrslvr.dll MD5: 3911b972b55fea0478476b2e777b29fa C:\Windows\system32\drivers\afd.sys MD5: 02d34ac487df3da4e3f01874e61eb619 C:\Windows\system32\DRIVERS\athr.sys MD5: 35f376253f687bde63976ccb3f2108ca C:\Windows\system32\DRIVERS\bowser.sys MD5: 1adf6f4852e7d7e2e8ac481bdb970586 C:\Windows\system32\drivers\CHDRT32.sys MD5: 622c41a07ca7e6dd91770f50d532cb6c C:\Windows\System32\Drivers\dfsc.sys MD5: c68ac676b0ef30cfbb1080adce49eb1f C:\Windows\System32\drivers\dxgkrnl.sys MD5: 185ada973b5020655cee342059a86cbb C:\Windows\system32\DRIVERS\GEARAspiWDM.sys MD5: 35956140e686d53bf676cf0c778880fc C:\Windows\system32\DRIVERS\HpqKbFiltr.sys MD5: 0acd399f5db3df1b58903cf4949ab5a8 C:\Windows\system32\DRIVERS\HSX_CNXT.sys MD5: cc267848cb3508e72762be65734e764d C:\Windows\system32\DRIVERS\HSX_DPV.sys MD5: a2882945cc4b6e3e4e9e825590438888 C:\Windows\system32\DRIVERS\HSXHWAZL.sys MD5: 8266ae06df974e5ba047b3e9e9e70b3f C:\Windows\system32\DRIVERS\igdkmd32.sys MD5: c7e7e43cbd34d3b0a0156b51b917dfcc C:\Windows\system32\drivers\IntcHdmi.sys MD5: cd6a8fa9395460ffe7fd8881a6c67254 C:\Windows\system32\DRIVERS\kl1.sys MD5: f9089982ed97340984e3dd60edd75490 C:\Windows\system32\drivers\klbg.sys MD5: 73eb94ad1c85b4a3c5a8b4d879f668b9 C:\Windows\system32\DRIVERS\klfltdev.sys MD5: 016ccb39030fed3138eb41af8d2b24b6 C:\Windows\system32\DRIVERS\klif.sys MD5: 29458f09e485e3c37ef3d440bab9ca9b C:\Windows\system32\DRIVERS\klim6.sys MD5: 4a1445efa932a3baf5bdb02d7131ee20 C:\Windows\System32\Drivers\ksecdd.sys MD5: 0db7527db188c7d967a37bb51bbf3963 C:\Windows\system32\drivers\mbamswissarmy.sys MD5: 1e94971c4b446ab2290deb71d01cf0c2 C:\Windows\system32\DRIVERS\mrxsmb.sys MD5: 4fccb34d793b116423209c0f8b7a3b03 C:\Windows\system32\DRIVERS\mrxsmb10.sys MD5: c3cb1b40ad4a0124d617a1199b0b9d7c C:\Windows\system32\DRIVERS\mrxsmb20.sys MD5: 35d5458d9a1b26b2005abffbf4c1c5e7 C:\Windows\system32\DRIVERS\NETw3v32.sys MD5: 5119ffc2a6b51089cdb0efdc75808c97 C:\Windows\System32\Drivers\nx6000.sys MD5: b9c2b89f08670e159f7181891e449cd9 C:\Windows\System32\drivers\partmgr.sys MD5: 125c504a34d0a2e152517e342e7e432c C:\Windows\system32\DRIVERS\Rtlh86.sys MD5: 126ea89bcc413ee45e3004fb0764888f C:\Windows\system32\DRIVERS\sdbus.sys MD5: 41987f9fc0e61adf54f581e15029ad91 C:\Windows\System32\DRIVERS\srv.sys MD5: ff33aff99564b1aa534f58868cbe41ef C:\Windows\System32\DRIVERS\srv2.sys MD5: 7605c0e1d01a08f3ecd743f38b834a44 C:\Windows\System32\DRIVERS\srvnet.sys MD5: 00b19f27858f56181edb58b71a7c67a0 C:\Windows\system32\DRIVERS\SynTP.sys MD5: 27d470dabc77bc60d0a3b0e4deb6cb91 C:\Windows\System32\drivers\tcpip.sys MD5: 73b41f4ead65f355962168d766af0f2e C:\Windows\System32\Drivers\usbaapl.sys MD5: cd5f291a1161f15896d1a4d63daff5df C:\Windows\system32\DRIVERS\xaudio.exe MD5: dab33cfa9dd24251aaa389ff36b64d4b C:\Windows\system32\DRIVERS\xaudio.sys MD5: 7d1f3b131d503ef43ee594b5a2b9b427 C:\Windows\system32\DRIVERS\yk60x86.sys MD5: cabd1b34bd05c986b4dbc18bc0e947ee C:\Windows\system32\dwrite.dll MD5: abaeaee763e287bdd39094c4165e1f3f C:\Windows\system32\fdproxy.dll MD5: 8ce364388c8eca59b14b539179276d44 C:\Windows\system32\FntCache.dll MD5: 3cd5bbda19a1ab4eba359e0a14fdf0f0 C:\Windows\system32\hkcmd.exe MD5: 0ba3f31e2b4d8d99df8dd19e81155374 C:\Windows\system32\ieframe.dll MD5: eb8a00e8e9931a7ec04f920b09d880d8 C:\Windows\system32\iertutil.dll MD5: fdc6bd427e353d205c1afb6065fa8175 C:\Windows\system32\igfxdev.dll MD5: 3142195521fee436088ee8a5748de1b1 C:\Windows\system32\igfxpers.exe MD5: 493164122dc72e1bf6d12f575604fbda C:\Windows\system32\igfxsrvc.dll MD5: 1029b84ecbe4b95acb8491a3fe63d70f C:\Windows\system32\igfxtray.exe MD5: eb49faa5ebbc06356fb12476438781b9 C:\Windows\system32\imagehlp.dll MD5: 574b473facaa0e91702b86578440b525 C:\Windows\system32\KERNEL32.dll MD5: 74c2f29cc612b2b34231bebd824d2fb2 C:\Windows\system32\keyiso.dll MD5: 1fe46082a766cebe72ff30d0de7ddcd1 C:\Windows\system32\klogon.dll MD5: 19ffad68a02af1bf0bc336ee26cd6767 c:\windows\system32\l2gpstore.dll MD5: 35d40113e4a5b961b6ce5c5857702518 c:\windows\system32\lmhsvc.dll MD5: 178fac2b7c66e9a4400ce7ac37623e3f C:\Windows\system32\LSASRV.dll MD5: a3e186b4b935905b829219502557314e C:\Windows\System32\lsass.exe MD5: 44c00a385ca9dbc1d5cf3781f8c26aea C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe MD5: 8709c95e4ec55378d5bf27f02b0ed5a5 C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe MD5: e7bc792810ec02dd1f7ed25d830e9324 C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll MD5: 56e315acfb08a177b4d01e42b9044db5 C:\Windows\System32\MPRAPI.dll MD5: abe9eea1eabea0711610a637a7b1c25d C:\Windows\system32\msprivs.dll MD5: ff41e1ac301f51e16f61ad7c0f45467c C:\Windows\System32\msshsq.dll MD5: 73fd66b14d3c4252f7a524b8836a4359 C:\Windows\System32\mstask.dll MD5: 17af64d727545f2804f6e6d998327e3f C:\Windows\system32\msvcrt.dll MD5: 6abd253226770eae1292b4c945ed4b4b C:\Windows\System32\msxml3.dll MD5: 024528e25bbe8768536861ea09be1672 C:\Windows\System32\msxml6.dll MD5: 2fa16465f64db54b1f7f511395eb4fd7 C:\Windows\system32\NCObjAPI.DLL MD5: 188cc19108b0ebd6332d6628d4ede469 C:\Windows\system32\ncrypt.dll MD5: f4d9ed6bd74ad7cc0bec83c43a1cb76b c:\windows\system32\ncsi.dll MD5: 98b656eaf128cd06f625b09c84d959e1 C:\Windows\system32\NETAPI32.dll MD5: 6bc5fcef351e4cb5a269c1e84b5a06da C:\Windows\system32\netcfgx.dll MD5: 95daecf0fb120a7b5da679cc54e37dde C:\Windows\system32\netlogon.dll MD5: ab87c54ca19675880b0cae65b8af140c C:\Windows\system32\npDeployJava1.dll MD5: 8bb86f0c7eea2bded6fe095d0b4ca9bd c:\windows\system32\nsisvc.dll MD5: dda770bbd7c2ed024d6f50e279d90e5b C:\Windows\system32\ntdll.dll MD5: 9586e7cb2255a8b097a7e4538202585e C:\Windows\system32\ole32.dll MD5: dc15ab7168c0309d8f04fd95b6240422 C:\Windows\system32\OLEACC.dll MD5: b218342214d9bba0f54ea12ba2e9278c C:\Windows\system32\OLEAUT32.dll MD5: 2dd6af8e97f59c9d39329bbc2a81f13f C:\Windows\System32\RASDLG.dll MD5: 5a32d90a3d3d63e9011869a07a720ab3 C:\Windows\system32\Ribbons.scr MD5: 50e3e76b0901bb4fc029bb88bfa5ce79 C:\Windows\system32\schannel.dll MD5: 1a58069db21d05eb2ab58ee5753ebe8d C:\Windows\system32\schedsvc.dll MD5: d602fedbd9155fc2ded6863fb60c950f C:\Windows\system32\Secur32.dll MD5: 167ac31450c0c53a01fa1491e94d7678 C:\Windows\system32\SHDOCVW.dll MD5: aaf101900a23d75ae1ae00840fa6f3b8 C:\Windows\system32\SHELL32.dll MD5: 9176285122b7b849fec2aa1b72a8f7a8 C:\Windows\system32\SHLWAPI.dll MD5: c7230fbee14437716701c15be02c27b8 C:\Windows\system32\SHSVCS.dll MD5: 8554097e5136c3bf9f69fe578a1b35f4 C:\Windows\System32\spoolsv.exe MD5: 1bf5eebfd518dd7298434d8c862f825d C:\Windows\system32\srvsvc.dll MD5: b5950df243837d8217f4e597919b224a C:\Windows\system32\stobject.dll MD5: 71f5a7104fdf16c0ac5283a6ce666553 C:\Windows\system32\SYSNTFY.dll MD5: bfa034aac103d8a6f591ac9364688339 C:\Windows\system32\t2embed.dll MD5: 52e129522c1775dbb8cc252e7a0655c7 C:\Windows\system32\taskschd.dll MD5: 8a38b5e8493a9d103083b8620ac5f3a1 C:\Windows\System32\tdh.dll MD5: f8873d15018f411588bec02c1725bada C:\Windows\system32\tspkg.dll MD5: e45051c374f845edf3db02a35ba13193 C:\Windows\system32\umb.dll MD5: 9fac0f6d5f3d922db294e30cd3f62369 C:\Windows\system32\urlmon.dll MD5: 80fff14f1757b9af8be9d314fc1ae88b C:\Windows\system32\USP10.dll MD5: dc3ae9f1554dcd97f90983ddbdacd83d C:\Windows\system32\vsstrace.dll MD5: e3f535656b5abf249702eb64f3cf9af0 C:\Windows\system32\wbem\wbemcons.dll MD5: 2c3b09e586bda2cc49a292be7badc589 C:\Windows\system32\wbem\wmiutils.dll MD5: 5193de33f3284c447e0d31dafbf92570 c:\windows\system32\webcheck.dll MD5: 0745d6ead386710110817fbec03f5161 C:\Windows\system32\wfapigp.dll MD5: dbd02e3e6f061ebbbf9b99a9d7cba30b C:\Windows\System32\WINHTTP.dll MD5: 5553611e2f9ea6f613079177f1233068 C:\Windows\system32\WININET.dll MD5: 101ba3ea053480bb5d957ef37c06b5ed C:\Windows\System32\wininit.exe MD5: 14ff750efe13b0c21e5a06507c3a97b1 C:\Windows\system32\WINMM.dll MD5: 5ec8fb83f31aa2d6f421f02c3f4f4475 C:\Windows\system32\WINSPOOL.DRV MD5: d2293b069e4b63dc17b2f08d45e71124 C:\Windows\system32\winsrv.dll MD5: b2e569ef26dac9d6994a2aff4f601b7a C:\Windows\system32\WINTRUST.dll MD5: 87cdffcbd09c1ca03a068343d5d93250 C:\Windows\system32\WMI.dll MD5: f0321da5203f1e71917f3b7a13dc4912 C:\Windows\system32\WMsgAPI.dll MD5: fc3ec24fce372c89423e015a2ac1a31e C:\Windows\system32\wuaueng.dll MD5: 399bb52ad0668472717498e97cf28341 c:\windows\system32\WUDFPlatform.dll MD5: 1908cc7673f72601affdca022689cedf C:\Windows\system32\XmlLite.dll MD5: be3c082837866c4c291adaf163c10ea6 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll MD5: 76eaef4ddebbc7c38853f586c0e91dce C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052 ca1013d0\gdiplus.dll No file uploaded. Scan finished - communication took 5 sec Total traffic - 0.01 MB sent, 1.32 KB recvd Scanned 677 files and modules - 58 seconds ==============================================================================
Hello jdcats007

Question? If the hard drive has crashed, how hard will it be to replace? Is something anyone can do?

If a hard drive crashes it is usually recoverable. What I think you are asking is - what happens if you have a hard drive failure.

A hard drive failure is very different from a crash. When a hard drive fails you will (most likely) be unable to access the files stored on the drive, which is why I advised you to ensure you have a backup of your files after we determined the meaning of the blue screen error message you were receiving. If you have a PC tower (rather than a laptop), replacing a defective drive ought to be easy enough, and I can put you in touch with experts who will be able to guide you through the process.

The online scan looks good.

I would like to continue by checking for core system file corruption but before we do, please re-scan your machine with OTL as you did in post number 33 and post the log for me to review :)
Due to inactivity, this topic has been closed. If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic.
OTL log:

OTL logfile created on: 11/23/2012 8:51:15 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 81.49% Memory free
6.06 Gb Paging File | 5.70 Gb Available in Paging File | 93.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.13 Gb Total Space | 80.56 Gb Free Space | 58.32% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.83 Gb Free Space | 16.77% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/11/08 18:39:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe /s Norton Internet Security /m C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll /prefetch:1 – (Norton Internet Security)
SRV - [2012/11/09 02:48:51 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/10/29 14:21:48 | 000,055,808 | —- | M] (PasswordBox, Inc.) [Auto | Stopped] – C:\Program Files\PasswordBox\pbbtnService.exe – (PasswordBox)
SRV - [2012/10/08 22:20:24 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/08/06 15:17:54 | 000,208,616 | —- | M] (Kaspersky Lab) [Auto | Stopped] – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe – (AVP)
SRV - [2008/10/06 10:54:52 | 000,365,952 | —- | M] () [Auto | Stopped] – C:\Program Files\SMINST\BLService.exe – (Recovery Service for Windows)
SRV - [2008/01/20 20:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS – (SRTSPX)
DRV - File not found [File_System | System | Stopped] – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS – (SRTSP)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS – (NAVEX15)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS – (NAVENG)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - [2010/01/29 00:03:58 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2009/08/06 15:17:54 | 000,224,272 | —- | M] (Kaspersky Lab) [File_System | System | Stopped] – C:\Windows\System32\drivers\klif.sys – (KLIF)
DRV - [2009/08/06 15:17:54 | 000,033,808 | —- | M] (Kaspersky Lab) [File_System | Boot | Stopped] – C:\Windows\System32\drivers\klbg.sys – (klbg)
DRV - [2008/12/20 01:01:46 | 001,093,120 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2008/07/21 17:34:36 | 000,121,872 | —- | M] (Kaspersky Lab) [Kernel | System | Stopped] – C:\Windows\System32\drivers\kl1.sys – (kl1)
DRV - [2008/07/09 17:28:26 | 000,020,496 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\System32\drivers\klim6.sys – (KLIM6)
DRV - [2008/06/29 08:52:26 | 000,112,128 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV - [2008/06/10 12:54:36 | 000,123,904 | —- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2008/06/05 10:58:42 | 000,222,208 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2008/03/13 18:02:46 | 000,026,640 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\klfltdev.sys – (KLFLTDEV)
DRV - [2008/01/20 20:23:20 | 002,225,664 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NETw3v32.sys – (NETw3v32)
DRV - [2007/10/17 17:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/18 18:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKLM\..\SearchScopes\{A23B6865-91F4-4D89-B386-7D1A3EFEF156}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPNTDF
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3198785

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 66 AA 48 54 99 C3 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKCU\..\SearchScopes\{A23B6865-91F4-4D89-B386-7D1A3EFEF156}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3198785
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/?search={se…box_im2_test_v2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.119
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@vizzed.com/VizzedRGR: C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll (Vizzed.com)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/09 02:48:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\THBExt [2009/08/06 19:58:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Owner\AppData\Local\PasswordBox\Firefox [2012/09/28 09:49:26 | 000,000,000 | —D | M]

[2012/09/28 09:54:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/11/18 11:37:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions
[2012/11/18 11:37:28 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/10/29 20:28:29 | 000,000,000 | —D | M] (ooVoo toolbar, powered by Ask.com) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\[removed]
[2012/11/09 02:48:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/09 02:48:51 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 19:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 19:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT3198785
CHR - default_search_provider: suggest_url = http://search.conduit.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahilkiibpgjnonbhdfkkgjddddmapala\2.3.15.10_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Vizzed Retro Game Room Plugin (Enabled) = C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Oovoo Toolbar = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanijiojpcccpkjdjjmjghddcgcbfj\7.17.0.0_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Kingdom Rush = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckmfhhjalnddapegkbbohfaodgbnocim\1.0.7.3_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Isoball 3 = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj\1.3.0_0\
CHR - Extension: A Crack in Time and Space = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmpbeckibaikflbnegjemaegnpbgjol\1.1_0\
CHR - Extension: Mini Ninjas = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi\1.0.0.15_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/11/11 08:35:03 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [4Sync] C:\Program Files\4Sync\4Sync.exe (New IT Solutions Ltd.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{288F8038-4777-4D83-B729-FD77311C5E15}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B91195D5-7DA2-4565-8F17-CD419245C711}: DhcpNameServer = 10.40.45.1 10.40.45.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/18 11:37:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\QuickScan
[2012/11/18 11:23:54 | 000,000,000 | —D | C] – C:\_OTL
[2012/11/15 19:39:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/11/14 14:37:09 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/11/14 10:14:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/11/14 10:14:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/14 10:14:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/11/14 10:14:38 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/11/14 10:14:38 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/14 10:11:08 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Users\Owner\Desktop\mbam-setup-1.65.1.1000.exe
[2012/11/12 18:31:30 | 000,000,000 | —D | C] – C:\FRST
[2012/11/11 08:37:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\temp
[2012/11/11 08:37:04 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/11/09 17:30:42 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/11/09 17:30:42 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/11/09 17:30:42 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/11/09 17:30:31 | 000,000,000 | —D | C] – C:\Qoobox
[2012/11/09 17:30:09 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/11/09 17:28:25 | 005,000,376 | R— | C] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/11/09 02:48:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/11/08 19:14:57 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/11/08 18:38:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/11/08 15:17:16 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\LavasoftStatistics
[2012/11/08 15:13:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Ad-Aware Antivirus
[2012/11/07 15:36:36 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/10/29 20:28:55 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\ooVoo Details
[2012/10/29 20:27:57 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2012/10/29 20:26:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2012/10/29 20:26:45 | 000,000,000 | —D | C] – C:\Program Files\ooVoo

========== Files - Modified Within 30 Days ==========

[2012/11/23 09:01:16 | 000,001,356 | —- | M] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/11/23 08:36:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/15 19:20:31 | 000,314,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/11/14 23:32:39 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000UA.job
[2012/11/14 20:09:37 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/14 20:09:37 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/14 17:55:56 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/11/14 17:51:49 | 212,013,147 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/11/14 10:14:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 10:13:29 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Users\Owner\Desktop\mbam-setup-1.65.1.1000.exe
[2012/11/12 16:10:59 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/11/12 16:10:59 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/11/11 08:35:03 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/11/11 08:13:12 | 005,000,376 | R— | M] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/11/08 19:30:11 | 000,000,512 | —- | M] () – C:\Users\Owner\Desktop\MBR.dat
[2012/11/08 19:19:12 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/11/08 18:39:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/11/08 16:36:45 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2012/11/08 15:17:03 | 000,000,563 | —- | M] () – C:\Users\Owner\Desktop\Resume Ad-Aware Free Antivirus+ Installation.lnk
[2012/11/07 15:37:05 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2012/11/06 22:20:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/06 22:18:04 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000UA.job
[2012/11/06 17:14:44 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000Core.job
[2012/11/06 17:02:25 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000Core.job
[2012/11/03 17:11:17 | 000,002,627 | —- | M] () – C:\Users\Owner\Desktop\Microsoft Office Word 2007.lnk
[2012/10/29 20:26:51 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2012/10/29 17:47:51 | 004,730,912 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.dat
[2012/10/29 17:47:51 | 001,097,760 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.dat
[2012/10/29 17:47:51 | 000,039,088 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.idx
[2012/10/29 17:47:51 | 000,004,832 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.idx

========== Files Created - No Company Name ==========

[2012/11/14 10:14:40 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/09 17:30:42 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/11/09 17:30:42 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/11/09 17:30:42 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/11/09 17:30:42 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/11/09 17:30:42 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/11/08 19:30:11 | 000,000,512 | —- | C] () – C:\Users\Owner\Desktop\MBR.dat
[2012/11/08 15:17:03 | 000,000,563 | —- | C] () – C:\Users\Owner\Desktop\Resume Ad-Aware Free Antivirus+ Installation.lnk
[2012/11/07 15:35:29 | 212,013,147 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/10/29 20:26:51 | 000,001,726 | —- | C] () – C:\Users\Public\Desktop\ooVoo.lnk
[2012/10/08 20:27:22 | 000,005,632 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/22 22:47:32 | 000,000,044 | —- | C] () – C:\Users\Owner\jagex_cl_runescape_LIVE.dat
[2012/09/22 22:47:32 | 000,000,024 | —- | C] () – C:\Users\Owner\random.dat
[2012/08/22 10:24:33 | 000,000,436 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2012/07/22 00:08:39 | 027,884,433 | —- | C] () – C:\Users\Owner\Pokemon_Diamond.zip
[2012/06/01 23:03:46 | 000,001,356 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/05/23 09:37:08 | 009,605,844 | —- | C] () – C:\Users\Owner\01 - Goldfinger - 99 Red Balloons.mp3
[2009/08/19 11:49:26 | 000,024,227 | —- | C] () – C:\Users\Owner\AppData\Roaming\UserTile.png
[2009/05/16 09:36:11 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini

========== ZeroAccess Check ==========

[2006/11/02 06:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 11:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 00:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 00:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/05/24 13:07:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.minecraft
[2012/05/24 12:57:39 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.techniclauncher
[2012/07/21 23:36:23 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\4Sync
[2012/11/08 15:13:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Ad-Aware Antivirus
[2012/04/22 22:16:15 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Eurotalk
[2012/10/29 20:34:46 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ooVoo Details
[2012/11/18 11:37:34 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\QuickScan
[2012/08/22 10:24:37 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Template

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 641 bytes -> C:\Users\Owner\Desktop\Worth Reading.eml:OECustomProperty

< End of report >
Hello jdcats007

Your OTL log looks good.

Please work your way through the following steps and then report back on how the machine is running:

===

Please download Windows Repair (all in one) from here

Install the program then run it

Go to step 2 and allow it to run Disk check

[external image: Posted Image]

Once that is done then go to step 3 and allow it to run SFC

[external image: Posted Image]

On the the Start Repairs tab => Click the Start

[external image: Posted Image]

Click on the select all check box and then click on Start

DON'T use the computer while each scan is in progress.

Restart may be needed to finish the repair procedure.

===

Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.
Note: Further documentation can be found in the ReadMe.rtf file which is located in the Malwarebytes Anti-Rootkit folder.

===

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

Please post thge logs in your next reply and let me know if there has been any change with the machine.
Hello jdcats007

The windows repair doesn't work well with safe mode

Please run the other two scans as requested and post the logs in your next reply.
It allowed me to boot up in regular mode from the last known good time… So I ran OTL in case you may need it.

here is that log and i am running the other ones now

OTL logfile created on: 11/29/2012 9:53:46 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 53.91% Memory free
6.11 Gb Paging File | 4.84 Gb Available in Paging File | 79.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.13 Gb Total Space | 79.15 Gb Free Space | 57.30% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.83 Gb Free Space | 16.77% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/11/08 18:39:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/10/29 14:21:48 | 000,055,808 | —- | M] (PasswordBox, Inc.) – C:\Program Files\PasswordBox\pbbtnService.exe
PRC - [2012/10/04 11:47:20 | 027,112,568 | —- | M] (ooVoo LLC) – C:\Program Files\ooVoo\ooVoo.exe
PRC - [2010/07/02 08:34:17 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\Bin\IncMail.exe
PRC - [2010/07/02 08:34:17 | 000,255,432 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\Bin\ImApp.exe
PRC - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2009/08/06 15:17:54 | 000,208,616 | —- | M] (Kaspersky Lab) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
PRC - [2009/04/11 00:28:11 | 001,143,296 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/04/11 00:27:20 | 000,088,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
PRC - [2008/10/06 10:54:52 | 000,365,952 | —- | M] () – C:\Program Files\SMINST\BLService.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/30 19:06:48 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/05/30 19:06:30 | 001,242,512 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/07/02 08:34:19 | 000,071,112 | —- | M] () – C:\Program Files\IncrediMail\Bin\wlessfp1.dll
MOD - [2010/07/02 08:34:18 | 000,251,336 | —- | M] () – C:\Program Files\IncrediMail\Bin\ImLookExU.dll
MOD - [2010/07/02 08:34:17 | 000,132,552 | —- | M] () – C:\Program Files\IncrediMail\Bin\ImComUtlU.dll
MOD - [2010/07/02 08:34:17 | 000,079,304 | —- | M] () – C:\Program Files\IncrediMail\Bin\ImAppRU.dll
MOD - [2008/09/23 18:21:22 | 000,066,856 | —- | M] () – C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007/08/14 14:59:54 | 006,365,184 | —- | M] () – C:\Program Files\Common Files\LightScribe\QtGui4.dll
MOD - [2007/07/12 14:55:52 | 000,131,072 | —- | M] () – C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2007/07/12 14:55:28 | 001,581,056 | —- | M] () – C:\Program Files\Common Files\LightScribe\QtCore4.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe /s Norton Internet Security /m C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll /prefetch:1 – (Norton Internet Security)
SRV - [2012/11/09 02:48:51 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/10/29 14:21:48 | 000,055,808 | —- | M] (PasswordBox, Inc.) [Auto | Running] – C:\Program Files\PasswordBox\pbbtnService.exe – (PasswordBox)
SRV - [2012/10/08 22:20:24 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/08/06 15:17:54 | 000,208,616 | —- | M] (Kaspersky Lab) [Auto | Running] – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe – (AVP)
SRV - [2008/10/06 10:54:52 | 000,365,952 | —- | M] () [Auto | Running] – C:\Program Files\SMINST\BLService.exe – (Recovery Service for Windows)
SRV - [2008/01/20 20:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS – (SRTSPX)
DRV - File not found [File_System | System | Stopped] – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS – (SRTSP)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS – (NAVEX15)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS – (NAVENG)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - [2010/01/29 00:03:58 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2009/08/06 15:17:54 | 000,224,272 | —- | M] (Kaspersky Lab) [File_System | System | Running] – C:\Windows\System32\drivers\klif.sys – (KLIF)
DRV - [2009/08/06 15:17:54 | 000,033,808 | —- | M] (Kaspersky Lab) [File_System | Boot | Running] – C:\Windows\System32\drivers\klbg.sys – (klbg)
DRV - [2008/12/20 01:01:46 | 001,093,120 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2008/07/21 17:34:36 | 000,121,872 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\System32\drivers\kl1.sys – (kl1)
DRV - [2008/07/09 17:28:26 | 000,020,496 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\System32\drivers\klim6.sys – (KLIM6)
DRV - [2008/06/29 08:52:26 | 000,112,128 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV - [2008/06/10 12:54:36 | 000,123,904 | —- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2008/06/05 10:58:42 | 000,222,208 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2008/03/13 18:02:46 | 000,026,640 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\klfltdev.sys – (KLFLTDEV)
DRV - [2008/01/20 20:23:20 | 002,225,664 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NETw3v32.sys – (NETw3v32)
DRV - [2007/10/17 17:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/18 18:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKLM\..\SearchScopes\{A23B6865-91F4-4D89-B386-7D1A3EFEF156}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPNTDF
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3198785

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 66 AA 48 54 99 C3 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKCU\..\SearchScopes\{A23B6865-91F4-4D89-B386-7D1A3EFEF156}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3198785
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/?search={se…box_im2_test_v2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.119
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@vizzed.com/VizzedRGR: C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll (Vizzed.com)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/09 02:48:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\THBExt [2009/08/06 19:58:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Owner\AppData\Local\PasswordBox\Firefox [2012/09/28 09:49:26 | 000,000,000 | —D | M]

[2012/09/28 09:54:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/11/18 11:37:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions
[2012/11/18 11:37:28 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/10/29 20:28:29 | 000,000,000 | —D | M] (ooVoo toolbar, powered by Ask.com) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\yvru7yi8.default\extensions\[removed]
[2012/11/09 02:48:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/09 02:48:51 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 19:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 19:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT3198785
CHR - default_search_provider: suggest_url = http://search.conduit.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahilkiibpgjnonbhdfkkgjddddmapala\2.3.15.10_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Vizzed Retro Game Room Plugin (Enabled) = C:\Program Files\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Oovoo Toolbar = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanijiojpcccpkjdjjmjghddcgcbfj\7.17.0.0_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Kingdom Rush = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckmfhhjalnddapegkbbohfaodgbnocim\1.0.7.3_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Isoball 3 = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj\1.3.0_0\
CHR - Extension: A Crack in Time and Space = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmpbeckibaikflbnegjemaegnpbgjol\1.1_0\
CHR - Extension: Mini Ninjas = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi\1.0.0.15_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/11/11 08:35:03 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [4Sync] C:\Program Files\4Sync\4Sync.exe (New IT Solutions Ltd.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.40.45.1 10.40.45.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{288F8038-4777-4D83-B729-FD77311C5E15}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B91195D5-7DA2-4565-8F17-CD419245C711}: DhcpNameServer = 10.40.45.1 10.40.45.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/26 10:14:19 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\subinacl.exe
[2012/11/26 10:07:47 | 000,000,000 | —D | C] – C:\RegBackup
[2012/11/25 15:26:32 | 000,000,000 | —D | C] – C:\Tweaking.com_Windows_Repair_Logs
[2012/11/25 15:26:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2012/11/25 15:26:25 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2012/11/25 15:21:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2012/11/25 15:21:18 | 000,000,000 | —D | C] – C:\rei
[2012/11/25 15:21:15 | 000,000,000 | —D | C] – C:\Program Files\Reimage
[2012/11/18 11:37:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\QuickScan
[2012/11/18 11:23:54 | 000,000,000 | —D | C] – C:\_OTL
[2012/11/15 19:39:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/11/14 14:37:09 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/11/14 10:14:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/11/14 10:14:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/14 10:14:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/11/14 10:14:38 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/11/14 10:14:38 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/14 10:11:08 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Users\Owner\Desktop\mbam-setup-1.65.1.1000.exe
[2012/11/12 18:31:30 | 000,000,000 | —D | C] – C:\FRST
[2012/11/11 08:37:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\temp
[2012/11/11 08:37:04 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/11/09 17:30:42 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/11/09 17:30:42 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/11/09 17:30:42 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/11/09 17:30:31 | 000,000,000 | —D | C] – C:\Qoobox
[2012/11/09 17:30:09 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/11/09 17:28:25 | 005,000,376 | R— | C] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/11/09 02:48:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/11/08 19:14:57 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/11/08 18:38:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/11/08 15:17:16 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\LavasoftStatistics
[2012/11/08 15:13:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Ad-Aware Antivirus
[2012/11/07 15:36:36 | 000,000,000 | —D | C] – C:\Windows\Minidump

========== Files - Modified Within 30 Days ==========

[2012/11/29 09:31:49 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000UA.job
[2012/11/29 09:31:42 | 000,002,042 | —- | M] () – C:\Users\Owner\Desktop\Google Chrome.lnk
[2012/11/29 09:31:42 | 000,002,004 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/29 09:20:16 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/29 08:58:14 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/11/29 08:58:14 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/11/29 08:54:53 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2012/11/29 07:49:45 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/29 07:49:45 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/29 07:49:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/26 19:08:26 | 000,314,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/11/26 16:05:06 | 000,001,356 | —- | M] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/11/26 10:02:53 | 219,402,363 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/11/25 15:26:26 | 000,002,068 | —- | M] () – C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/11/25 15:21:56 | 000,000,162 | —- | M] () – C:\Windows\reimage.ini
[2012/11/25 15:21:18 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2012/11/14 17:55:56 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/11/14 10:14:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 10:13:29 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Users\Owner\Desktop\mbam-setup-1.65.1.1000.exe
[2012/11/11 08:35:03 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/11/11 08:13:12 | 005,000,376 | R— | M] (Swearware) – C:\Users\Owner\Desktop\ComboFix.exe
[2012/11/08 19:30:11 | 000,000,512 | —- | M] () – C:\Users\Owner\Desktop\MBR.dat
[2012/11/08 19:19:12 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2012/11/08 18:39:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/11/08 15:17:03 | 000,000,563 | —- | M] () – C:\Users\Owner\Desktop\Resume Ad-Aware Free Antivirus+ Installation.lnk
[2012/11/07 15:37:05 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2012/11/06 22:18:04 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000UA.job
[2012/11/06 17:14:44 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000Core.job
[2012/11/06 17:02:25 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3503118179-941401948-2877446358-1000Core.job
[2012/11/03 17:11:17 | 000,002,627 | —- | M] () – C:\Users\Owner\Desktop\Microsoft Office Word 2007.lnk

========== Files Created - No Company Name ==========

[2012/11/26 10:37:14 | 000,303,616 | —- | C] ( ) – C:\SetACL.exe
[2012/11/25 15:26:26 | 000,002,068 | —- | C] () – C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/11/25 15:21:18 | 000,001,889 | —- | C] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2012/11/25 15:21:18 | 000,000,162 | —- | C] () – C:\Windows\reimage.ini
[2012/11/14 10:14:40 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/09 17:30:42 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/11/09 17:30:42 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/11/09 17:30:42 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/11/09 17:30:42 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/11/09 17:30:42 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/11/08 19:30:11 | 000,000,512 | —- | C] () – C:\Users\Owner\Desktop\MBR.dat
[2012/11/08 15:17:03 | 000,000,563 | —- | C] () – C:\Users\Owner\Desktop\Resume Ad-Aware Free Antivirus+ Installation.lnk
[2012/11/07 15:35:29 | 219,402,363 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/10/08 20:27:22 | 000,005,632 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/22 22:47:32 | 000,000,044 | —- | C] () – C:\Users\Owner\jagex_cl_runescape_LIVE.dat
[2012/09/22 22:47:32 | 000,000,024 | —- | C] () – C:\Users\Owner\random.dat
[2012/08/22 10:24:33 | 000,000,436 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2012/07/22 00:08:39 | 027,884,433 | —- | C] () – C:\Users\Owner\Pokemon_Diamond.zip
[2012/06/01 23:03:46 | 000,001,356 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/05/23 09:37:08 | 009,605,844 | —- | C] () – C:\Users\Owner\01 - Goldfinger - 99 Red Balloons.mp3
[2009/08/19 11:49:26 | 000,024,227 | —- | C] () – C:\Users\Owner\AppData\Roaming\UserTile.png
[2009/05/16 09:36:11 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini

========== ZeroAccess Check ==========

[2006/11/02 06:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 11:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 00:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 00:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/05/24 13:07:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.minecraft
[2012/05/24 12:57:39 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.techniclauncher
[2012/07/21 23:36:23 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\4Sync
[2012/11/08 15:13:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Ad-Aware Antivirus
[2012/04/22 22:16:15 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Eurotalk
[2012/10/29 20:34:46 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ooVoo Details
[2012/11/18 11:37:34 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\QuickScan
[2012/08/22 10:24:37 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Template

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 641 bytes -> C:\Users\Owner\Desktop\Worth Reading.eml:OECustomProperty

< End of report >
here is a regular malwarebytes scan… it removed 7 threats… Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.29.09 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Owner :: OWNER-PC [administrator] 11/29/2012 11:07:56 AM mbam-log-2012-11-29 (11-07-56).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 211726 Time elapsed: 7 minute(s), 1 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKCU\Software\cheerychickenSA (Adware.HotBar.CC) -> Quarantined and deleted successfully. HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PLAYBRYTE (PUP.PlayBryte) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playbryte|Publisher (PUP.PlayBryte) -> Data: Playbryte -> Quarantined and deleted successfully. Registry Data Items Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 3 C:\Users\Owner\Downloads\Setup.exe (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Users\Owner\Downloads\vGrabber_Setup (1).exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully. C:\Users\Owner\Downloads\vGrabber_Setup.exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully. (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI