This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows XP "system progressive protection" already fixed by

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Reset IE and Firefox, (don't have chrome) haven't seen any redirects.
I see the OTL.txt that popped up, but the extras didn't. When I checked in the folder it still has the log from the 21st in the same file folder as the new log from today.

ComboFix 13-01-28.02 - User 01/28/2013 14:19:43.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.668 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi"
.
.
((((((((((((((((((((((((( Files Created from 2012-12-28 to 2013-01-28 )))))))))))))))))))))))))))))))
.
.
2013-01-27 19:21 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E9EABE9A-32FF-4736-A752-27846C720B72}\mpengine.dll
2013-01-27 18:10 . 2013-01-27 18:10 ——– d—–w- c:\program files\ERUNT
2013-01-27 18:03 . 2013-01-27 18:03 ——– d—–w- C:\i386
2013-01-26 18:39 . 2013-01-26 18:39 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-26 18:39 . 2013-01-26 18:39 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-21 01:44 . 2013-01-21 01:44 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\PCHealth
2013-01-21 01:08 . 2013-01-21 01:08 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-13 04:17 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-01-13 04:15 . 2013-01-21 03:20 ——– d—–w- c:\documents and settings\Administrator
2013-01-11 18:50 . 2013-01-11 18:50 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Scansoft
2013-01-11 05:03 . 2013-01-21 01:18 ——– d—–w- c:\documents and settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
2013-01-11 05:01 . 2013-01-11 05:01 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Sun
2013-01-11 02:22 . 2013-01-11 02:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2013-01-10 02:22 . 2013-01-10 02:22 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2013-01-10 02:16 . 2013-01-10 02:16 ——– d—–w- c:\program files\Common Files\Adobe
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 00:19 . 2013-01-10 00:19 ——– d—–w- c:\program files\IrfanView
2013-01-10 00:02 . 2013-01-10 00:02 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ahead
2013-01-09 22:45 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2013-01-09 22:45 . 2008-04-14 13:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2013-01-09 20:40 . 2013-01-09 20:39 779704 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 859072 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 93640 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 20:39 . 2013-01-09 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2013-01-09 20:35 . 2013-01-22 02:27 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-01-09 18:37 . 2013-01-09 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2013-01-09 18:35 . 2008-04-14 08:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2013-01-09 18:35 . 2008-04-14 08:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\User\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\ScanSoft
2013-01-09 18:33 . 2013-01-09 18:33 ——– d—–w- c:\program files\Common Files\CANON
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2013-01-09 18:30 . 2007-04-02 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 215040 —-a-w- c:\windows\system32\CNMLM8U.DLL
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-09 18:30 . 2007-03-23 16:29 98304 —-a-w- c:\windows\system32\CNC470I.DLL
2013-01-09 18:30 . 2007-03-19 10:21 200704 —-a-w- c:\windows\system32\CNC470L.DLL
2013-01-09 18:30 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNC470O.DLL
2013-01-09 18:30 . 2007-03-23 16:30 1400832 —-a-w- c:\windows\system32\CNC470C.DLL
2013-01-09 18:30 . 2013-01-09 18:37 ——– d—–w- c:\program files\Canon
2013-01-09 01:35 . 2012-11-01 12:17 521728 -c—-w- c:\windows\system32\dllcache\jsdbgui.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-01-09 01:30 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-09 00:59 . 2008-04-14 08:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2013-01-09 00:04 . 2013-01-09 00:04 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 20:39 . 2008-12-27 20:36 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-12-16 12:23 . 2008-04-14 12:39 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2008-04-14 08:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01 . 2008-04-14 12:42 1371648 —-a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02 . 2008-04-14 12:41 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 12:42 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 12:42 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 12:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 07:07 385024 —-a-w- c:\windows\system32\html.iec
2013-01-21 02:52 . 2013-01-21 02:50 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-27 c:\windows\Tasks\defrag.job
- c:\windows\system32\cmd.exe [2008-04-14 12:42]
.
2013-01-28 c:\windows\Tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w4nexsx6.default-1359407675069\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-28 14:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4056)
c:\windows\system32\WININET.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2013-01-28 14:25:20
ComboFix-quarantined-files.txt 2013-01-28 22:25
ComboFix2.txt 2013-01-27 18:23
ComboFix3.txt 2013-01-25 03:51
ComboFix4.txt 2013-01-23 23:30
.
Pre-Run: 65,050,263,552 bytes free
Post-Run: 65,067,622,400 bytes free
.
- - End Of File - - CB2B0347B3E8F07ABCA67917912AFF49

OTL logfile created on: 1/28/2013 2:40:50 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 550.23 Mb Available Physical Memory | 57.35% Memory free
2.26 Gb Paging File | 1.97 Gb Available in Paging File | 86.98% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 60.62 Gb Free Space | 79.43% Space Free | Partition Type: NTFS

Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mbr) – C:\ComboFix\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys File not found
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 7A B4 2F 9C FD CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/20 18:52:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/20 18:50:50 | 000,000,000 | —D | M]

[2013/01/08 16:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/01/20 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/20 18:52:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/04 19:45:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/04 19:45:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/01/27 10:22:32 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230409023906 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05DCF09B-B7E7-470F-884D-25C0A0CAA390}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/27 12:02:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/28 14:39:11 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/28 14:25:22 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/01/28 13:14:41 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Old Firefox Data
[2013/01/27 10:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/01/27 10:10:09 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/01/27 10:03:19 | 000,000,000 | —D | C] – C:\i386
[2013/01/26 10:39:33 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/26 10:39:33 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/24 15:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Krystal
[2013/01/23 14:47:18 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/20 19:12:12 | 005,028,084 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/20 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\CC Support Logs
[2013/01/20 18:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/20 17:44:07 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2013/01/20 17:33:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/01/20 17:32:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/20 17:32:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/20 17:32:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/20 17:32:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/20 17:25:39 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/20 17:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/01/20 17:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/01/12 20:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:17:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/01/12 20:17:52 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/01/12 20:17:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/12 20:15:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2013/01/11 10:50:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Scansoft
[2013/01/10 21:03:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/10 21:01:35 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2013/01/10 18:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2013/01/09 18:22:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2013/01/09 18:12:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2013/01/09 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2013/01/09 18:00:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/09 16:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\newebay
[2013/01/09 16:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\IrfanView
[2013/01/09 16:19:16 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2013/01/09 16:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Ahead
[2013/01/09 15:21:54 | 000,000,000 | R–D | C] – C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2013/01/09 14:45:03 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2013/01/09 14:45:02 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2013/01/09 12:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2013/01/09 12:40:13 | 000,779,704 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:40:12 | 000,859,072 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:40:12 | 000,260,528 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:40:06 | 000,174,000 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:40:06 | 000,173,992 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:40:06 | 000,093,640 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/01/09 12:32:01 | 020,293,080 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series User Registration
[2013/01/09 10:35:23 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/01/09 10:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2013/01/09 10:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\ScanSoft
[2013/01/09 10:34:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2013/01/09 10:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/01/09 10:34:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2013/01/09 10:34:17 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2013/01/09 10:33:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/01/09 10:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2013/01/09 10:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series Manual
[2013/01/09 10:30:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:30:45 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8U.DLL
[2013/01/09 10:30:42 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2013/01/09 10:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series
[2013/01/09 10:30:39 | 000,200,704 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470L.DLL
[2013/01/09 10:30:39 | 000,188,416 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC470O.DLL
[2013/01/09 10:30:39 | 000,098,304 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470I.DLL
[2013/01/09 10:30:38 | 001,400,832 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470C.DLL
[2013/01/09 10:30:29 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/09 10:30:02 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/08 17:35:18 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/01/08 16:59:52 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/01/08 16:59:29 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/01/08 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Mozilla
[2013/01/08 16:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Mozilla
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/28 14:17:50 | 005,028,084 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/28 13:17:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/28 13:17:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/28 13:12:39 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
[2013/01/27 11:06:01 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2013/01/27 10:22:32 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/27 10:12:50 | 000,000,128 | —- | M] () – C:\Documents and Settings\User\Desktop\fix.reg
[2013/01/27 10:10:14 | 000,000,611 | —- | M] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2013/01/27 10:10:14 | 000,000,592 | —- | M] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2013/01/27 10:03:17 | 000,005,120 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/26 18:00:00 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2013/01/26 10:39:33 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/26 10:39:33 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/23 14:48:28 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/01/09 18:17:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | M] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:39:55 | 000,093,640 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:51 | 000,260,528 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:39:50 | 000,174,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:39:50 | 000,173,992 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:39:50 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/09 12:39:49 | 000,859,072 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:39:49 | 000,779,704 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:35:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:36:55 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 18:23:34 | 000,178,648 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/08 18:08:24 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/07 08:02:00 | 000,365,568 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2013/01/05 21:34:35 | 006,009,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/27 10:12:50 | 000,000,128 | —- | C] () – C:\Documents and Settings\User\Desktop\fix.reg
[2013/01/27 10:10:14 | 000,000,611 | —- | C] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2013/01/27 10:10:14 | 000,000,592 | —- | C] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2013/01/24 18:27:06 | 000,365,568 | —- | C] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 17:33:37 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/01/20 17:33:34 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/01/20 17:32:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/20 17:32:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/20 17:32:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/20 17:32:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/20 17:32:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/09 18:17:33 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/09 18:17:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | C] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:35:39 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/01/09 10:36:55 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/18 18:42:08 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/12/13 20:37:49 | 000,005,120 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/04 10:39:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\User\Application Data\wklnhst.dat

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/10/15 17:00:10 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 04:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/20 17:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/09 10:30:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/04 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org
[2013/01/09 10:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ScanSoft

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2013/01/27 10:24:01 | 000,080,380 | —- | M] () MD5=991AC060CF34A96D8A01DA84AFA825B0 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2004/08/04 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 21:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\iexplore.exe
[2013/01/20 17:23:08 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) MD5=EBC984F0CE40E0DAF0454D806EC2A7EC – C:\Documents and Settings\User\My Documents\Krystal\Tools\iexplore.exe

< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/03/09 10:41:40 | 000,012,532 | —- | M] () MD5=C911CCDCFD72B36DCA1B99005E32E8C3 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/01/28 14:18:09 | 000,018,278 | —- | M] () MD5=5C8F427E11D21C2D6B394B361F056C23 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf

< MD5 for: IEXPLORE.EXE-12915967.PF >
[2013/01/28 14:18:08 | 000,020,818 | —- | M] () MD5=DD4967A5F334C850A217DDFD387DBFBA – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf

< MD5 for: IEXPLORE.EXE-12BBAE74.PF >
[2013/01/28 14:18:13 | 000,010,934 | —- | M] () MD5=0E1B1FF6DE6C718FC105984E9D5C7915 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/28 14:10:24 | 000,106,246 | —- | M] () MD5=124AC62710C150D484B4EEBB592DE905 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 04:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 11:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.CNF >
[2003/02/13 19:43:03 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb\_vti_pvt\services.cnf
[2003/07/15 14:54:19 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb2\_vti_pvt\services.cnf
[2003/07/15 15:10:48 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb3\_vti_pvt\services.cnf
[2003/07/15 15:27:05 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb4\_vti_pvt\services.cnf
[2003/07/15 15:32:39 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb5\_vti_pvt\services.cnf
[2003/11/05 11:58:40 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb6\_vti_pvt\services.cnf
[2003/11/05 12:00:32 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb7\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb8\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,074 | —- | M] () MD5=C781AE0262BEB173EFFB27E59A6E6F17 – C:\Documents and Settings\User\My Documents\My Webs\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2008/12/27 12:03:05 | 000,001,602 | —- | M] () MD5=74AD18AA5CB38E317767841416B45580 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/04 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.RDB >
[2008/09/30 17:46:24 | 005,406,720 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2008/09/30 17:55:38 | 000,262,144 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb

< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/27 11:56:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/01/28 14:25:20 | 000,010,851 | —- | M] () – C:\ComboFix.txt
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 21:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 23:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/28 13:16:57 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2013/01/20 17:23:44 | 000,072,056 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_17.23.20_log.txt
[2013/01/20 19:28:07 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
[2013/01/20 19:30:22 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.30.02_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/12/27 12:02:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/01 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8U.DLL
[2007/04/01 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8U.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/12/27 03:51:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/12/27 03:51:12 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/12/27 03:51:12 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:03:05 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/31 10:02:48 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/31 10:02:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2013/01/23 14:48:28 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/28 14:17:50 | 005,028,084 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/07 08:02:00 | 000,365,568 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2010/03/05 14:15:23 | 001,688,360 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\User\Desktop\SkypeSetup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-22 02:01:10

< End of report >

OTL Extras logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS

Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"S3" = VIA/S3G Display Driver
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTOverlay" = S3 S3Overlay

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/9/2010 2:35:03 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:35:27 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:36:48 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:38:13 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:38:42 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/9/2010 2:39:51 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:39:57 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:40:45 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:41:10 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 3/9/2010 2:41:40 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

[ System Events ]
Error - 1/20/2013 10:31:27 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 10:39:24 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/20/2013 11:19:35 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/20/2013 11:19:51 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:20:52 PM | Computer Name = JOANIESYS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter

Error - 1/20/2013 11:27:22 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:29:36 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:29:53 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:30:39 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/20/2013 11:49:04 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


< End of report >
Hi StellaLynn,

I see the OTL.txt that popped up, but the extras didn't.

That's normal, OTL won't produce another Extras.txt unless we specifically request it on subsequent runs.

= = = = = = = = = = = = = = = = = = = =

Locate Malwarebytes' Anti-Malware (it should be on your desktop).
  • Double - click the MBAM icon to launch the program.
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
In your next post please provide the following:
  • MBAM log
  • ESET log.txt
  • How is the computer running, any other issues?
Computer's running great, no redirects or disconnects from the net. Thanks! I couldn't find the mbam log, but nothing was fouind on either and as there were no fixes enabled, I ran them again to produce both scan logs in the right order. But the Microsoft Security Essentials that I turn on inbetween instructions from you says it qharantined Win32/Medfos.B Trojan today before I ran the scans. I should have cleared this up earlier, it just never dawned on me to ask, should I be leaving this not-so-great antivirus off for the remainder of the fix? I leave it off for the scans, but after I post and am waiting for your next reply I've been turning it back on. Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.29.08 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 User :: JOANIESYS [administrator] 1/29/2013 12:23:00 PM mbam-log-2013-01-29 (12-23-00).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 214636 Time elapsed: 4 minute(s), 42 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=8 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6889 # api_version=3.0.2 # EOSSerial=dca6da79c3f6684d8176a869f1b7b4f8 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-01-29 07:59:07 # local_time=2013-01-29 11:59:07 (-0800, Pacific Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=5892 16777213 100 95 514618 56245217 0 0 # scanned=38864 # found=0 # cleaned=0 # scan_time=2022 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6889 # api_version=3.0.2 # EOSSerial=dca6da79c3f6684d8176a869f1b7b4f8 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-01-29 09:02:20 # local_time=2013-01-29 01:02:20 (-0800, Pacific Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=5892 16777213 100 95 514811 56249010 0 0 # scanned=38937 # found=0 # cleaned=0 # scan_time=1232
Hi StellaLynn,

I should have cleared this up earlier, it just never dawned on me to ask, should I be leaving this not-so-great antivirus off for the remainder of the fix? I leave it off for the scans, but after I post and am waiting for your next reply I've been turning it back on.

Yes, you should only disable your security software during the scans if requested to do so then re-enable them after. :thumbup:

= = = = = = = = = = = = = = = = = = = =

Your log appears to be clean. We have a few items to take care of before we get to the All Clean Speech.

The following will implement important cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bold text into the Run box and click OK:

ComboFix /Uninstall
(Note the space between the ..X and the /U, it needs to be there.)

[external image: Posted Image]

Next

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
Next

You can now delete any tools we used or logs we generated remaining on your desktop

Next

How to Re - Enable Hidden Files & Folders in XP
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Remove the check mark in the check box labeled "Display the contents of system folders".
  • Under the Hidden files and folders section De-select the radio button labeled "Show hidden files and folders".
  • Add a check mark to the check box labeled "Hide file extensions for known file types".
  • Add a check mark to the check box labeled "Hide protected operating system files".
  • Press the Apply button and then the OK button and shutdown My Computer.
Now your computer is reconfigured to it's original settings.

Next

Clear Java Cache
  • Start button, select Control Panel.
  • In the Control Panel, open the Java Control Panel.
  • Click on Settings button under Temporary Internet Files.
  • Click Delete Files button at the Temporary Files Settings window.
  • Click on OK button at confirmation dialog.
  • Exit the Control Panel.
= = = = = = = = = = = = = = = = = = = =

With the above items taken care of let's move on to the All Clean part of the process.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Free Anti-Virus
  • Avast Free Antivirus
  • Avira Free Antivirus 2013
  • PC Tools AntiVirus Free
  • Ad-Aware Free Antivirus +
Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Hi StellaLynn, You're very welcome, glad I was able to help. :D In your opening statement you said you had another computer you needed to try and clean, is that still the case?
Yes, a windows 7 with a virust that never gave me a good name to search for. Should I post the OTL here (or whatever HIjackthis/DDS log you prefer)?
Hi StellaLynn,

Sorry for the delay …

Download OTL to your desktop.

Right click and select "Run as Administrator".
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Next

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
In your next post please provide the following:
  • OTL.txt
  • Extras.txt
  • aswMBR log
  • attach MBR.zip
  • Describe what issues you are having with this computer in as much detail as you can.
No need to apologize, thank you so much for your continuing help!

Dad is older, and usually can't shut down the computer by himself, so the explanation's a little fuzzy, but there was some sort of dating ad that popped up right when he was trying to click on something else. Then he got a "are you sure you want to leave" message, that he tried to use their "yes/no" buttons to leave with, and something downloaded.
He called me to say the internet was out, 15 minutes later I came over and we were getting a stream of popups, there were weird fake-sounding warnings on all of our .exe files saying they were corrupted, and asking if we still wanted to run them anyway (I never tried), I disconnected from the internet when something started showing it was downloading and tried to alt+f4 out of the internet-based popup windows with no luck.
When I tried to shut down, it gave me an error message and started trying to download something. It couldn't because the DSL cord was out, but I freaked out and gave it a hard boot like a dork. In safe mode with networking, I ran rkill, Kapersky, mbam, and then exe-fix.bat. Exe-fix was the first program that caught something, now the computer seems ok, but I've been leaving it offline and using it offline (for picture cropping and word processors and stuff) only.

When you posted quick as you were I decided to leave the both of them alone.


OTL logfile created on: 1/31/2013 3:42:04 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.87 Gb Total Physical Memory | 2.50 Gb Available Physical Memory | 64.41% Memory free
7.75 Gb Paging File | 6.30 Gb Available in Paging File | 81.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.05 Gb Total Space | 85.26 Gb Free Space | 57.20% Space Free | Partition Type: NTFS
Drive F: | 3.63 Gb Total Space | 0.94 Gb Free Space | 26.02% Space Free | Partition Type: FAT32

Computer Name: JOAN-PC | User Name: Joan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - F:\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe ()
PRC - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.207\mcuicnt.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\National Consumer Panel\NCP Internet Transporter\HSTrans.exe (NCP)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\National Consumer Panel\NCP Internet Transporter\c4dll.dll ()
MOD - C:\Program Files (x86)\National Consumer Panel\NCP Internet Transporter\ssleay32.dll ()
MOD - C:\Program Files (x86)\National Consumer Panel\NCP Internet Transporter\libeay32.dll ()
MOD - C:\Program Files (x86)\National Consumer Panel\NCP Internet Transporter\zlib.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (ADIHdAudAddService) – C:\Windows\SysNative\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV:64bit: - (FTDIBUS) – C:\Windows\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (FTSER2K) – C:\Windows\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 08 DC F7 9F 31 F1 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nielsen/FirefoxTracker: C:\Program Files (x86)\NetRatingsNetSight\NetSight\meter1\FirefoxAddOns\npfirefoxtracker.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\NetRatingsNetSight\NetSight\meter1\FirefoxAddOns\[removed]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/19 21:44:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/19 21:44:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/19 21:44:09 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/19 21:44:10 | 000,000,000 | —D | M]

[2012/07/22 07:33:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Joan\AppData\Roaming\Mozilla\Extensions
[2012/07/22 07:33:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Joan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/10/22 18:24:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\l4nphek4.default-1349998109351\extensions
[2013/01/19 21:43:45 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/01/19 21:44:09 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/01/19 21:44:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2013/01/19 21:44:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\updated\extensions
[2013/01/19 21:44:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\updated\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/01/19 21:44:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\updated\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2012/12/05 14:28:05 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/08 19:48:32 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/10/24 19:40:25 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\Application\22.0.1229.92\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\Application\24.0.1312.52\pdf.dll
CHR - plugin: Injovo Extension Plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.530_0\npbrowserext.dll
CHR - plugin: Perion plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll
CHR - plugin: Perion plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\plugins/PerionChromeInfoBar-32.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\npSkypeChromePlugin.dll
CHR - plugin: Wajam (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.11.21.5_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.11.21.5_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: Java™ Platform SE 6 U34 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.340.4 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Joan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NVRaidService] C:\Windows\SysNative\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MegaPanel] C:\Program Files (x86)\National Consumer Panel\NCP Internet Transporter\HSTrans.exe (NCP)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [Philips Device Listener] C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe ()
O4 - Startup: C:\Users\Joan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.11.2)
O16 - DPF: {CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_34)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.11.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F6C1D52-6234-4AAB-BBCA-9E5E045F79FC}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/13 11:44:43 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/03/30 18:32:00 | 000,000,590 | —- | M] () - F:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{700bf611-d11f-11e1-9e89-001a92e3b337}\Shell - "" = AutoRun
O33 - MountPoints2\{700bf611-d11f-11e1-9e89-001a92e3b337}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{85e80add-d31f-11e1-9861-001a92e3b337}\Shell - "" = AutoRun
O33 - MountPoints2\{85e80add-d31f-11e1-9861-001a92e3b337}\Shell\AutoRun\command - "" = F:\setup.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/21 09:56:42 | 000,000,000 | —D | C] – C:\Users\Joan\Desktop\Malwarebytes' Anti-Malware
[2013/01/20 20:22:46 | 000,000,000 | —D | C] – C:\Users\Public\Desktop\CC Support Logs
[2013/01/18 17:11:41 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/01/18 17:11:41 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/01/18 17:11:41 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/17 18:03:46 | 000,962,612 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42d.dll
[2013/01/17 18:03:46 | 000,434,252 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSVCRTD.DLL
[2013/01/17 18:03:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
[2013/01/17 18:03:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASUS
[2013/01/13 14:15:19 | 000,000,000 | —D | C] – C:\Users\Joan\Documents\croppedbirds
[2013/01/13 14:13:04 | 000,000,000 | —D | C] – C:\Users\Joan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2013/01/13 14:13:00 | 000,000,000 | —D | C] – C:\Users\Joan\AppData\Roaming\IrfanView
[2013/01/13 14:12:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2013/01/12 20:40:23 | 000,000,000 | —D | C] – C:\Users\Joan\AppData\Roaming\Malwarebytes
[2013/01/12 20:40:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:40:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/12 20:40:08 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/12 20:40:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/12 20:39:50 | 000,000,000 | —D | C] – C:\Users\Joan\AppData\Local\Programs
[2013/01/12 14:02:25 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2013/01/12 13:58:44 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2013/01/12 13:58:13 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2013/01/12 13:18:22 | 000,196,096 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerfr.dll
[2013/01/12 13:18:22 | 000,196,096 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerel.dll
[2013/01/12 13:18:22 | 000,196,096 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerde.dll
[2013/01/12 13:18:22 | 000,195,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerptb.dll
[2013/01/12 13:18:22 | 000,195,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServernl.dll
[2013/01/12 13:18:22 | 000,195,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerit.dll
[2013/01/12 13:18:22 | 000,195,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServeres.dll
[2013/01/12 13:18:22 | 000,195,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServersl.dll
[2013/01/12 13:18:22 | 000,195,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServersk.dll
[2013/01/12 13:18:22 | 000,195,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerpt.dll
[2013/01/12 13:18:22 | 000,195,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServercs.dll
[2013/01/12 13:18:22 | 000,194,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServertr.dll
[2013/01/12 13:18:22 | 000,194,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerru.dll
[2013/01/12 13:18:22 | 000,194,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerpl.dll
[2013/01/12 13:18:22 | 000,194,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerhu.dll
[2013/01/12 13:18:22 | 000,194,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerda.dll
[2013/01/12 13:18:22 | 000,194,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerth.dll
[2013/01/12 13:18:22 | 000,194,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServersv.dll
[2013/01/12 13:18:22 | 000,194,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerno.dll
[2013/01/12 13:18:22 | 000,194,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerfi.dll
[2013/01/12 13:18:22 | 000,193,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerhe.dll
[2013/01/12 13:18:22 | 000,193,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerenu.dll
[2013/01/12 13:18:22 | 000,193,024 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerar.dll
[2013/01/12 13:18:22 | 000,190,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerja.dll
[2013/01/12 13:18:22 | 000,189,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerko.dll
[2013/01/12 13:18:22 | 000,188,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerzht.dll
[2013/01/12 13:18:22 | 000,188,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServerzhc.dll
[2013/01/12 13:18:22 | 000,181,760 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServereng.dll
[2013/01/12 13:18:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2013/01/12 13:18:21 | 002,148,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcplUI.exe
[2013/01/12 13:18:21 | 001,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFC71.dll
[2013/01/12 13:18:21 | 001,003,008 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcplUIR.dll
[2013/01/12 13:18:21 | 000,978,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCP71.dll
[2013/01/12 13:18:21 | 000,712,704 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidServer.dll
[2013/01/12 13:18:21 | 000,520,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCR71.dll
[2013/01/12 13:18:21 | 000,381,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvExpBar.dll
[2013/01/12 13:18:21 | 000,285,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvraidservice.exe
[2013/01/12 13:18:21 | 000,276,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsataconnection.exe
[2013/01/12 13:18:21 | 000,167,936 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardde.dll
[2013/01/12 13:18:21 | 000,166,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardpt.dll
[2013/01/12 13:18:21 | 000,165,888 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardel.dll
[2013/01/12 13:18:21 | 000,164,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardit.dll
[2013/01/12 13:18:21 | 000,164,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardfr.dll
[2013/01/12 13:18:21 | 000,164,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardes.dll
[2013/01/12 13:18:21 | 000,162,816 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardsl.dll
[2013/01/12 13:18:21 | 000,162,816 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardptb.dll
[2013/01/12 13:18:21 | 000,162,816 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardnl.dll
[2013/01/12 13:18:21 | 000,161,792 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardru.dll
[2013/01/12 13:18:21 | 000,161,280 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardhu.dll
[2013/01/12 13:18:21 | 000,161,280 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardcs.dll
[2013/01/12 13:18:21 | 000,160,768 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardtr.dll
[2013/01/12 13:18:21 | 000,160,768 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardno.dll
[2013/01/12 13:18:21 | 000,160,256 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardth.dll
[2013/01/12 13:18:21 | 000,160,256 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardsk.dll
[2013/01/12 13:18:21 | 000,160,256 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardpl.dll
[2013/01/12 13:18:21 | 000,159,744 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardsv.dll
[2013/01/12 13:18:21 | 000,159,232 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardfi.dll
[2013/01/12 13:18:21 | 000,159,232 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardda.dll
[2013/01/12 13:18:21 | 000,157,696 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardenu.dll
[2013/01/12 13:18:21 | 000,157,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardeng.dll
[2013/01/12 13:18:21 | 000,156,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardhe.dll
[2013/01/12 13:18:21 | 000,153,600 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardar.dll
[2013/01/12 13:18:21 | 000,144,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardko.dll
[2013/01/12 13:18:21 | 000,144,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardja.dll
[2013/01/12 13:18:21 | 000,140,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardzht.dll
[2013/01/12 13:18:21 | 000,139,776 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizardzhc.dll
[2013/01/12 13:18:21 | 000,062,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.cpl
[2013/01/12 13:18:21 | 000,058,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvfr.dll
[2013/01/12 13:18:21 | 000,058,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSves.dll
[2013/01/12 13:18:21 | 000,057,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvptb.dll
[2013/01/12 13:18:21 | 000,057,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvpt.dll
[2013/01/12 13:18:21 | 000,057,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvit.dll
[2013/01/12 13:18:21 | 000,057,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvel.dll
[2013/01/12 13:18:21 | 000,057,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvde.dll
[2013/01/12 13:18:21 | 000,057,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvsl.dll
[2013/01/12 13:18:21 | 000,057,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvnl.dll
[2013/01/12 13:18:21 | 000,057,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvhu.dll
[2013/01/12 13:18:21 | 000,057,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvcs.dll
[2013/01/12 13:18:21 | 000,056,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvsk.dll
[2013/01/12 13:18:21 | 000,056,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvru.dll
[2013/01/12 13:18:21 | 000,056,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvpl.dll
[2013/01/12 13:18:21 | 000,056,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvfi.dll
[2013/01/12 13:18:21 | 000,056,320 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvtr.dll
[2013/01/12 13:18:21 | 000,056,320 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvth.dll
[2013/01/12 13:18:21 | 000,056,320 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvsv.dll
[2013/01/12 13:18:21 | 000,056,320 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvno.dll
[2013/01/12 13:18:21 | 000,056,320 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvda.dll
[2013/01/12 13:18:21 | 000,055,808 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvhe.dll
[2013/01/12 13:18:21 | 000,055,808 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvenu.dll
[2013/01/12 13:18:21 | 000,055,296 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvar.dll
[2013/01/12 13:18:21 | 000,053,760 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvja.dll
[2013/01/12 13:18:21 | 000,053,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvko.dll
[2013/01/12 13:18:21 | 000,051,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvzht.dll
[2013/01/12 13:18:21 | 000,051,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSvzhc.dll
[2013/01/12 13:18:21 | 000,041,984 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidSveng.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionzht.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionzhc.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectiontr.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionth.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionsv.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionsl.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionsk.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionru.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionptb.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionpt.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionpl.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionno.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionnl.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionko.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionja.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionit.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionhu.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionhe.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionfr.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionfi.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectiones.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionenu.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectioneng.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionel.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionde.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionda.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectioncs.dll
[2013/01/12 13:18:21 | 000,036,864 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvSataConnectionar.dll
[2013/01/12 13:18:20 | 000,671,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvRaidWizard.dll
[2013/01/12 13:16:19 | 000,660,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NVUNINST.EXE
[2013/01/12 12:50:30 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/01/12 12:50:30 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/01/12 12:50:02 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/01/12 12:49:58 | 000,801,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/01/12 12:49:39 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/01/12 12:49:39 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/01/12 12:49:39 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/01/12 12:49:39 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/01/12 12:49:39 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/01/12 12:49:38 | 002,745,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/01/12 12:49:38 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/01/12 12:49:38 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/01/12 12:49:38 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/01/12 12:49:38 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/01/12 12:49:38 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/01/12 12:49:38 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/01/12 12:49:38 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/01/12 12:49:38 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/01/12 12:49:38 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/01/12 12:49:38 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/01/12 12:49:38 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/01/12 12:49:38 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/01/12 12:49:38 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/01/12 12:49:38 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/01/12 12:49:38 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/01/12 12:49:38 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/01/12 12:49:37 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/01/12 12:49:37 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/01/12 12:49:34 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/01/12 12:49:34 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/01/12 12:49:34 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/01/12 12:49:34 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/01/12 12:49:34 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/01/12 12:49:34 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/01/12 12:49:34 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/01/12 12:49:34 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/01/12 12:49:02 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/01/12 12:49:00 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/01/12 12:48:59 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/01/12 12:48:59 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/01/12 12:48:59 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/01/12 12:48:59 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/01/12 12:48:59 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/01/12 12:48:59 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/01/12 12:48:58 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/01/12 12:48:58 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/01/12 12:48:58 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/12 12:48:58 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/12 12:48:58 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/12 12:48:58 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/01/12 12:48:58 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/01/12 12:48:58 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/12 12:48:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/12 12:48:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/01/12 12:48:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/01/12 12:48:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/01/12 12:48:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/12 12:48:57 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/01/12 12:48:57 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/12 12:48:57 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/12 12:48:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/01/12 12:48:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/12 12:48:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/01/12 12:48:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/01/12 12:48:56 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/01/12 12:48:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/12 12:48:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/12 12:48:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/12 12:48:54 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/01/12 12:48:54 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/01/12 12:48:54 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/01/12 12:48:53 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/01/12 12:48:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/01/12 12:48:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/01/12 12:48:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/01/12 12:48:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/01/12 12:48:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/01/12 12:40:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy

========== Files - Modified Within 30 Days ==========

[2013/01/31 15:28:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/31 14:52:10 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3887505406-875384447-541563275-1000UA.job
[2013/01/30 16:52:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3887505406-875384447-541563275-1000Core.job
[2013/01/25 11:12:46 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/25 11:12:46 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/25 11:12:46 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/22 21:53:35 | 000,018,816 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/22 21:53:35 | 000,018,816 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/22 21:45:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/22 21:45:49 | 3120,058,368 | -HS- | M] () – C:\hiberfil.sys
[2013/01/17 17:53:43 | 429,985,082 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/12 19:44:15 | 000,435,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/12 17:54:53 | 000,002,358 | —- | M] () – C:\Users\Joan\Desktop\Google Chrome.lnk
[2013/01/12 13:29:11 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/01/12 13:29:11 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/01/12 12:40:37 | 000,001,282 | —- | M] () – C:\Users\Joan\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/01/12 12:40:36 | 000,001,258 | —- | M] () – C:\Users\Joan\Desktop\Spybot - Search & Destroy.lnk
[2013/01/12 03:30:18 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/12 03:26:16 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/01/12 03:24:49 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/01/08 14:06:57 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2013/01/07 20:36:58 | 000,000,017 | —- | M] () – C:\Users\Joan\AppData\Local\resmon.resmoncfg
[2013/01/06 14:57:23 | 000,002,794 | —- | M] () – C:\Users\Joan\AppData\Local\recently-used.xbel
[2013/01/03 20:05:52 | 001,930,240 | —- | M] () – C:\Users\Joan\Documents\labels.pub

========== Files Created - No Company Name ==========

[2013/01/17 18:03:28 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\AsIO.dll
[2013/01/17 18:03:28 | 000,013,368 | —- | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2013/01/17 18:03:23 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2013/01/17 18:03:23 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2013/01/12 20:30:12 | 429,985,082 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/12 13:18:20 | 000,006,874 | —- | C] () – C:\Windows\SysNative\nvraidapp.nvu
[2013/01/12 12:40:37 | 000,001,282 | —- | C] () – C:\Users\Joan\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/01/12 12:40:36 | 000,001,258 | —- | C] () – C:\Users\Joan\Desktop\Spybot - Search & Destroy.lnk
[2013/01/07 20:36:58 | 000,000,017 | —- | C] () – C:\Users\Joan\AppData\Local\resmon.resmoncfg
[2013/01/06 14:57:23 | 000,002,794 | —- | C] () – C:\Users\Joan\AppData\Local\recently-used.xbel
[2012/08/21 19:03:16 | 000,000,000 | —- | C] () – C:\ProgramData\Licenses
[2012/08/21 18:45:01 | 000,000,268 | RH– | C] () – C:\ProgramData\Installer Plugin
[2012/08/21 18:45:01 | 000,000,268 | RH– | C] () – C:\Users\Joan\AppData\Roaming\Image Units
[2012/08/21 18:45:01 | 000,000,020 | -H– | C] () – C:\ProgramData\PKP_DLdu.DAT
[2012/08/21 18:36:05 | 000,000,000 | -H– | C] () – C:\ProgramData\PKP_DLdw.DAT
[2012/08/21 12:03:29 | 000,000,000 | -H– | C] () – C:\ProgramData\PKP_DLes.DAT
[2012/08/21 12:02:23 | 000,000,000 | -H– | C] () – C:\ProgramData\PKP_DLev.DAT
[2012/08/21 12:02:23 | 000,000,000 | -H– | C] () – C:\ProgramData\PKP_DLet.DAT
[2012/08/21 12:02:23 | 000,000,000 | —- | C] () – C:\Users\Joan\AppData\Roaming\Internet Services
[2012/08/21 12:01:46 | 000,000,000 | —- | C] () – C:\Users\Joan\AppData\Roaming\Light Machine
[2012/08/21 12:01:45 | 000,000,000 | -H– | C] () – C:\ProgramData\PKP_DLeo.DAT
[2012/07/18 13:39:13 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/07/18 12:12:52 | 000,730,638 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/01/18 05:44:00 | 010,920,984 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2012/01/18 05:44:00 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2012/01/18 05:44:00 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:30:56 | 014,165,504 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:46:56 | 012,868,608 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/13 17:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/12/09 18:14:54 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\Amazon
[2013/01/13 14:13:00 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\IrfanView
[2012/10/15 15:09:11 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\kompozer.net
[2012/08/21 19:32:42 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\Nikon
[2012/07/18 15:25:50 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\OpenOffice.org
[2012/07/22 07:45:21 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\Philips
[2012/07/22 07:33:06 | 000,000,000 | —D | M] – C:\Users\Joan\AppData\Roaming\Philips-Songbird

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2007/08/05 13:00:24 | 000,010,920 | —- | M] () – C:\aolconnfix.exe

< MD5 for: EXPLORER.EXE >
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\explorer.exe
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 21:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\Windows.old\Windows\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\Windows.old\Windows\ServicePackFiles\i386\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\Windows.old\Windows\system32\dllcache\explorer.exe
[2009/07/13 17:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 21:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 22:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 04:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 22:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\Windows.old\Windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\Windows.old\Windows\$NtServicePackUninstall$\explorer.exe
[2009/10/30 22:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 21:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 05:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 22:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 21:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 17:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 22:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 22:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\Windows.old\Windows\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 16:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\Windows.old\Windows\$NtUninstallKB956572$\services.exe
[2008/04/13 16:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\Windows.old\Windows\ServicePackFiles\i386\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\Windows.old\Windows\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\Windows.old\Windows\system32\services.exe
[2006/03/15 04:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\Windows.old\Windows\$NtServicePackUninstall$\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Users\Joan\Desktop\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\Windows.old\Windows\ServicePackFiles\i386\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\Windows.old\Windows\system32\dllcache\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\Windows.old\Windows\system32\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2006/03/15 04:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\Windows.old\Windows\$NtServicePackUninstall$\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2006/03/15 04:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\Windows.old\Windows\$NtServicePackUninstall$\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\SysWOW64\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\SysNative\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\Windows.old\Windows\ServicePackFiles\i386\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\Windows.old\Windows\system32\dllcache\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\Windows.old\Windows\system32\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2006/03/15 04:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\Windows.old\Windows\$NtServicePackUninstall$\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 17:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Users\Joan\Desktop\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/27 23:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\SysNative\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\Windows.old\Windows\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\Windows.old\Windows\system32\dllcache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\Windows.old\Windows\system32\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Base Services ==========
SRV:64bit: - [2009/07/13 17:40:01 | 000,072,192 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\aelupsvc.dll – (AeLookupSvc)
SRV:64bit: - [2009/07/13 17:40:01 | 000,070,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\appinfo.dll – (Appinfo)
SRV:64bit: - [2009/07/13 17:38:55 | 000,079,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\alg.exe – (ALG)
SRV:64bit: - [2009/07/13 17:41:53 | 000,848,384 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\qmgr.dll – (BITS)
SRV:64bit: - [2009/07/13 17:40:10 | 000,703,488 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\BFE.DLL – (BFE)
SRV:64bit: - [2011/11/16 23:05:16 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\lsass.exe – (KeyIso)
SRV:64bit: - [2009/07/13 17:40:50 | 000,402,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\es.dll – (EventSystem)
SRV - [2009/07/13 17:15:19 | 000,271,360 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\es.dll – (EventSystem)
SRV:64bit: - [2012/07/04 14:01:38 | 000,136,704 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\browser.dll – (Browser)
SRV:64bit: - [2012/06/01 21:25:12 | 000,182,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\cryptsvc.dll – (CryptSvc)
SRV - [2012/06/01 20:45:21 | 000,139,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\cryptsvc.dll – (CryptSvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,509,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\rpcss.dll – (DcomLaunch)
SRV:64bit: - [2009/07/13 17:40:28 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV - [2009/07/13 17:15:11 | 000,253,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2011/03/02 22:17:10 | 000,182,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dnsrslvr.dll – (Dnscache)
SRV:64bit: - [2009/07/13 17:40:35 | 000,111,104 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\eapsvc.dll – (EapHost)
SRV:64bit: - [2009/07/13 17:41:00 | 000,038,912 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\hidserv.dll – (hidserv)
SRV - [2009/07/13 17:15:24 | 000,049,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\hidserv.dll – (hidserv)
SRV:64bit: - [2009/07/13 17:41:10 | 000,359,424 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\SysNative\ipnathlp.dll – (SharedAccess)
SRV:64bit: - [2009/07/13 17:41:10 | 000,500,224 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\IPSECSVC.DLL – (PolicyAgent)
SRV:64bit: - [2012/09/12 20:21:48 | 000,022,072 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2012/09/12 20:21:48 | 000,368,896 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2009/07/13 17:41:54 | 000,524,288 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\swprv.dll – (swprv)
SRV:64bit: - [2009/07/13 17:41:26 | 000,067,584 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\mmcss.dll – (MMCSS)
SRV:64bit: - [2009/07/13 17:41:52 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netman.dll – (Netman)
SRV:64bit: - [2009/07/13 17:41:52 | 000,459,776 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofm.dll – (netprofm)
SRV - [2009/07/13 17:16:03 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\netprofm.dll – (netprofm)
SRV:64bit: - [2009/07/13 17:41:52 | 000,302,080 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\nlasvc.dll – (NlaSvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,025,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\nsisvc.dll – (nsi)
SRV:64bit: - [2011/05/24 03:21:59 | 000,404,992 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpnpmgr.dll – (PlugPlay)
SRV:64bit: - [2012/02/10 22:29:02 | 000,559,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\spoolsv.exe – (Spooler)
SRV:64bit: - [2011/11/16 23:05:16 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\lsass.exe – (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009/07/13 17:41:53 | 000,099,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\rasauto.dll – (RasAuto)
SRV:64bit: - [2009/07/13 17:41:53 | 000,343,552 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\rasmans.dll – (RasMan)
SRV:64bit: - [2009/07/13 17:41:53 | 000,509,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\rpcss.dll – (RpcSs)
SRV:64bit: - [2009/07/13 17:41:53 | 000,030,720 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\seclogon.dll – (seclogon)
SRV:64bit: - [2011/11/16 23:05:16 | 000,031,232 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsass.exe – (SamSs)
SRV:64bit: - [2010/12/20 22:16:27 | 000,097,280 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wscsvc.dll – (wscsvc)
SRV:64bit: - [2010/08/26 22:14:02 | 000,236,032 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\srvsvc.dll – (LanmanServer)
SRV:64bit: - [2009/07/13 17:41:54 | 000,369,664 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\shsvcs.dll – (ShellHWDetection)
SRV - [2009/07/13 17:16:14 | 000,328,192 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\shsvcs.dll – (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010/11/01 21:16:53 | 001,114,624 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\schedsvc.dll – (Schedule)
SRV:64bit: - [2009/07/13 17:41:55 | 000,316,416 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\tapisrv.dll – (TapiSrv)
SRV - [2009/07/13 17:16:15 | 000,241,664 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\tapisrv.dll – (TapiSrv)
SRV:64bit: - [2009/07/13 17:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2012/05/01 21:32:43 | 000,208,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\profsvc.dll – (ProfSvc)
SRV:64bit: - [2009/07/13 17:39:50 | 001,598,976 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\VSSVC.exe – (VSS)
SRV:64bit: - [2009/07/13 17:40:04 | 000,676,864 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\audiosrv.dll – (AudioSrv)
SRV:64bit: - [2009/07/13 17:40:04 | 000,676,864 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\audiosrv.dll – (AudioEndpointBuilder)
SRV:64bit: - [2009/07/13 17:41:53 | 000,170,496 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sdrsvc.dll – (SDRSVC)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 17:41:56 | 001,646,080 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wevtsvc.dll – (eventlog)
SRV:64bit: - [2009/07/13 17:41:27 | 000,824,832 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\MPSSVC.dll – (MpsSvc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,578,560 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wiaservc.dll – (stisvc)
SRV:64bit: - [2009/07/13 17:39:21 | 000,127,488 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\msiexec.exe – (msiserver)
SRV - [2009/07/13 17:14:25 | 000,073,216 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWow64\msiexec.exe – (msiserver)
SRV:64bit: - [2009/07/13 17:41:56 | 000,242,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wbem\WMIsvc.dll – (Winmgmt)
SRV:64bit: - [2012/06/02 14:19:43 | 002,428,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wuaueng.dll – (wuauserv)
SRV:64bit: - [2009/07/13 17:40:32 | 000,252,416 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\dot3svc.dll – (dot3svc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,886,784 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wlansvc.dll – (Wlansvc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,118,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wkssvc.dll – (LanmanWorkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: NVIDIA RAID5 149.06G
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Removable Media
Interface type: USB
Media Type: Removable Media
Model: Audiovox OPAL USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 149.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 4.00GB
Starting Offset: 12288
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

< End of report >

OTL Extras logfile created on: 1/31/2013 3:42:04 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.87 Gb Total Physical Memory | 2.50 Gb Available Physical Memory | 64.41% Memory free
7.75 Gb Paging File | 6.30 Gb Available in Paging File | 81.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.05 Gb Total Space | 85.26 Gb Free Space | 57.20% Space Free | Partition Type: NTFS
Drive F: | 3.63 Gb Total Space | 0.94 Gb Free Space | 26.02% Space Free | Partition Type: FAT32

Computer Name: JOAN-PC | User Name: Joan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09675D70-793A-41C1-9084-8F4874B11F8A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0AAA7780-941F-4E7C-96E6-0B7B26A7D742}" = lport=10243 | protocol=6 | dir=in | app=system |
"{0DF53F56-853C-4433-884F-9676F74E92A6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{11455009-53FD-4E1B-AA94-5582506EBACA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{118DC29B-8B31-4F5A-B94D-96F18D4F899C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1E3C9203-B322-41CF-BDBE-5632437C84AA}" = lport=137 | protocol=17 | dir=in | app=system |
"{261DB700-0457-4232-A214-3A39FC0B808B}" = lport=139 | protocol=6 | dir=in | app=system |
"{2CAD86DD-61B6-4B9A-86AC-F926954B6B3E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2CEA1217-00CA-4726-BC5B-149608693486}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{2EE60AF1-721C-4DA0-A2AE-7725D706D84E}" = rport=139 | protocol=6 | dir=out | app=system |
"{37821B46-9C81-4DFC-982E-C6DCCD890234}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3FB6B7E1-6594-429C-94CF-825808C430BB}" = rport=137 | protocol=17 | dir=out | app=system |
"{52CCB695-24B7-44D4-989E-1216761C52B7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{699BEB55-D6C4-4D4A-8CCB-29DED5EECE28}" = lport=445 | protocol=6 | dir=in | app=system |
"{6AC2FE9D-581B-4368-B61B-EB85D4B4CD25}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6D7AB3FB-088C-4792-964D-4EF390D02A22}" = rport=138 | protocol=17 | dir=out | app=system |
"{6E08B09A-6C00-4C14-BFBE-9EF0B1F005D3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7C484680-9F7A-4ABB-832C-D7DA1BE11B43}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A044B06C-46F3-4615-A6D7-488725E3E1F5}" = lport=138 | protocol=17 | dir=in | app=system |
"{BADB6A97-A171-4294-AFF1-160A1D2D66C1}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E28AD6C4-20C5-4C77-AFF8-C68A1056E3A0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F3017F94-A542-4413-B818-913DB18890FA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{FF4ECB33-7630-43D8-AC43-8400CA597FDC}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C5D2081-1285-420A-BC18-750EDF98D0A9}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{10A7D447-A709-4D59-AE0B-2F25B26E6B77}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{1AC83041-FDA9-4763-9066-D3CD2C02C6AF}" = protocol=6 | dir=out | app=system |
"{21870766-76D5-4B80-B013-96854AFCCD0E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2F396F35-A828-439E-AD42-3CDB986EBB95}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{395AA754-F0F0-4EBA-85CD-FF8D6F905829}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3FCE0850-4508-4BC0-A5BD-27CBE4EECB89}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4B599167-61B7-49FF-AFCE-258FEA99F550}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4F820ADD-12CF-40E7-8CA2-A7C9EB30C731}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5DFD524D-CC41-4C27-89A8-DCB0773A66EC}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{626216AB-1AC3-4CC3-A7B5-1C76279FA679}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{65E2D02B-3AB1-49DD-A1EF-D26EA84D38DF}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{672851A5-7000-4D2E-987E-AB23D0718033}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{6DA56239-F6D7-4DD2-B083-64247A670901}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6FAC531D-333B-4C7E-B459-854BE2564658}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{72240788-9CA5-4208-A545-4C8A7444F879}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{759086DA-6E39-407A-B6F5-BEDC775B84A5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8DEE71CD-4AFB-4A82-8DEA-99AEBBB5EEEF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{94A14BB3-8584-4E18-A2BA-B6ED74D14156}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{97F36C37-E4A5-4A71-A6A3-083451EE1E9C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{996579DA-F62B-4F09-B3C4-3825392E9F2A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C473A555-73C0-4F04-BEBC-F5E761F8E6D2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CA341D3A-89A4-4AD4-A516-8B0B5199D0FE}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CB802261-A056-49A9-B634-907817DFC3C8}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{D45A55D9-6993-4F84-9615-9F8F744523F8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DC9109F1-6B92-46D3-A868-6E452167B219}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{11953C65-BB4E-4CA4-B0F0-2600A4B20040}" = Picture Control Utility x64
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{C78D3032-9DFD-41D0-9DE9-58EAE750CBA4}" = Microsoft Security Client
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"3134FEF0E1D959EC0CC2E458C94B7057B2AC0CC9" = Windows Driver Package - FTDI CDM Driver Package (10/22/2009 2.06.00)
"88EB56038379B8B7DCFB4D2448A60F52E064B265" = Windows Driver Package - FTDI CDM Driver Package (10/22/2009 2.06.00)
"CCleaner" = CCleaner
"GIMP-2_is1" = GIMP 2.8.2
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02627EE5-EACA-4742-A9CC-E687631773E4}" = Nero ShowTime
"{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}" = Cool & Quiet
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{20d568c7-24cf-488e-8d36-24d72eadb2b4}" = Nero 9 Essentials
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216034FF}" = Java™ 6 Update 34
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 11
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5D9BE3C1-8BA4-4E7E-82FD-9F74FA6815D1}" = Nero Vision Help
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7CEB5AC4-B6F8-414C-845D-4295C125D17B}" = NCP Internet Transporter
"{7D0A13FA-56BC-4755-8BAF-45A69BA6A5C8}" = Nero Multimedia Suite 10 Essentials
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{8927E07C-97F7-4A54-88FB-D976F50DD46E}" = Turbo Lister 2
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{92BF38A8-5616-4209-87A3-D910B45A1D98}" = Internet Transporter - NCP Link
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CE96F5A5-584D-4F8F-AA3E-9BAED413DB72}" = Nero CoverDesigner Help
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{F6BDD7C5-89ED-4569-9318-469AA9732572}" = Nero BurnRights Help
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"7-zip" = 7-zip v9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.17
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Philips Songbird" = Philips Songbird
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"404b9336c7552828" = Flixster
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/15/2013 4:31:24 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/16/2013 4:33:00 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/17/2013 4:32:51 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/18/2013 4:32:49 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/19/2013 4:31:58 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/20/2013 11:21:20 PM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/24/2013 4:32:30 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/27/2013 5:00:08 AM | Computer Name = Joan-PC | Source = Application Error | ID = 1000
Description = Faulting application name: sdiagnhost.exe, version: 6.1.7600.16385,
time stamp: 0x4a5bc3d4 Faulting module name: mscorwks.dll, version: 2.0.50727.4984,
time stamp: 0x503ef599 Exception code: 0xc0000096 Fault offset: 0x000000000012ba3b
Faulting
process id: 0xf18 Faulting application start time: 0x01cdfc6cb11a6910 Faulting application
path: C:\Windows\System32\sdiagnhost.exe Faulting module path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
Report
Id: f2485a50-685f-11e2-884a-001a92e3b337

Error - 1/27/2013 5:00:08 AM | Computer Name = Joan-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program Scripted Diagnostics Native Host because of this error. Program:
Scripted Diagnostics Native Host File: The error value is listed in the Additional
Data section. User Action 1. Open the file again. This situation might be a temporary
problem that corrects itself when the program runs again. 2. If the file still cannot
be accessed and - It is on the network, your network administrator should verify
that there is not a problem with the network and that the server can be contacted.
-
It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the
disk is fully inserted into the computer. 3. Check and repair the file system by
running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click
OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem
persists, restore the file from a backup copy. 5. Determine whether other files
on the same disk can be opened. If not, the disk might be damaged. If it is a hard
disk, contact your administrator or computer hardware vendor for further assistance.

Additional
Data Error value: 00000000 Disk type: 0

Error - 1/28/2013 4:31:36 AM | Computer Name = Joan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 1/30/2013 1:56:07 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 1/30/2013 1:56:09 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9103.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 1/30/2013 1:56:09 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 1/30/2013 1:56:09 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 1/31/2013 1:56:07 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9103.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 1/31/2013 1:56:07 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 1/31/2013 1:56:07 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 1/31/2013 1:56:09 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9103.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 1/31/2013 1:56:09 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 1/31/2013 1:56:09 AM | Computer Name = Joan-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.143.376.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.9103.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved


< End of report >

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-31 17:02:37
—————————–
17:02:37.672 OS Version: Windows x64 6.1.7600
17:02:37.672 Number of processors: 2 586 0x4302
17:02:37.672 ComputerName: JOAN-PC UserName: Joan
17:02:43.819 Initialize success
17:04:56.805 AVAST engine defs: 13013101
17:05:41.437 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005b
17:05:41.437 Disk 0 Vendor: NVIDIA__ Size: 152638MB BusType: 8
17:05:41.499 Disk 0 MBR read successfully
17:05:41.515 Disk 0 MBR scan
17:05:41.780 Disk 0 Windows 7 default MBR code
17:05:41.842 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152625 MB offset 63
17:05:42.201 Disk 0 scanning C:\Windows\system32\drivers
17:06:07.676 Service scanning
17:07:19.810 Modules scanning
17:07:19.810 Disk 0 trace - called modules:
17:07:19.842 ntoskrnl.exe CLASSPNP.SYS disk.sys nvrd64.sys ACPI.sys storport.sys
17:07:19.842 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c0a220]
17:07:19.857 3 CLASSPNP.SYS[fffff88000daa43f] -> nt!IofCallDriver -> \Device\0000005b[0xfffffa80048c73d0]
17:07:19.857 5 nvrd64.sys[fffff8800104059c] -> nt!IofCallDriver -> [0xfffffa8004814040]
17:07:19.857 7 ACPI.sys[fffff88000f56781] -> nt!IofCallDriver -> \Device\00000059[0xfffffa8004812060]
17:07:19.873 9 nvrd64.sys[fffff8800104059c] -> nt!IofCallDriver -> [0xfffffa80048c0e40]
17:07:19.873 11 ACPI.sys[fffff88000f56781] -> nt!IofCallDriver -> \Device\0000005a[0xfffffa800481a420]
17:07:20.746 AVAST engine scan C:\Windows
17:07:28.765 AVAST engine scan C:\Windows\system32
17:14:34.729 AVAST engine scan C:\Windows\system32\drivers
17:14:56.725 AVAST engine scan C:\Users\Joan
17:28:18.104 AVAST engine scan C:\ProgramData
17:31:42.055 Scan finished successfully
17:34:57.820 Disk 0 MBR has been saved successfully to "C:\Users\Joan\Desktop\MBR.dat"
17:34:57.883 The log file has been saved successfully to "C:\Users\Joan\Desktop\aswMBR.txt"

Attachments:

Hi StellaLynn,

If you download the tools to a zip drive, please transfer them to the infected computer prior to running the scan. :thumbup:

= = = = = = = = = = = = = = = = = = = =

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Java™ 6 Update 34
Next

There is a vulnerablilty with regards to Java and web browsers. Therefore, we recommend to disable java in web browsers.
More information can be found here: http://www.techsupportforum.com/forums/f50…ers-683721.html

Disable Java in Web Browsers
  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter Java Control Panel.
  • Click on the Java icon to open the Java Control Panel.
[external image: Posted Image]

Disable Java through the Java Control Panel

  • In the Java Control Panel, click on the Security tab.
  • Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser.
  • Click Apply. When the Windows User Account Control (UAC) dialog appears, allow permissions to make the changes.
  • Click OK in the Java Plug-in confirmation window.
  • Restart the browser for changes to take effect.
[external image: Posted Image]

Next

Run OTL.exe
Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
    CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.11.21.5_0\plugins/ConduitChromeApiPlugin.dll
    CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.11.21.5_0\plugins/np-cwmp.dll
    
    :Files
    C:\Windows\SysNative\drivers\lvuvc.hs
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Next

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
You stated you ran rKill, Kaspersky & MBAM prior when the issues first arrived. Can you please locate the logs and post them in your next reply. (if they are still available)


In your next post please provide the following:
  • OTL.txt
  • AdwCleaner log
  • Previous scan logs
  • How is the computer running, any noticeable issues?
Sorry, it's been a heck of a day…
I could only find the rKill log, I can find the mbam folder, and every "easy" place I should have tried to save it, but I can't. Nor can I even find the Kapersky program file. Sorry. It's possible I'm just frazzled, and I'll have a 3am epiphony and I can post them with my next logs. But I can tell you, out of all the programs I ran, exe-fix (and rkill of course) were the only ones that said they did anything. Both mbam and kapersky scanned and found 0 problems.

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found.
File C:\Program Files\IB Updater\Firefox not found.
File C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.11.21.5_0\plugins/ConduitChromeApiPlugin.dll not found.
File C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.11.21.5_0\plugins/np-cwmp.dll not found.
========== FILES ==========
C:\Windows\SysNative\drivers\lvuvc.hs moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Joan
->Temp folder emptied: 86253537 bytes
->Temporary Internet Files folder emptied: 180889945 bytes
->Java cache emptied: 520546 bytes
->FireFox cache emptied: 428576824 bytes
->Google Chrome cache emptied: 819568 bytes
->Flash cache emptied: 5840 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 22473452 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46413668 bytes
RecycleBin emptied: 1021765195 bytes

Total Files Cleaned = 1,705.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 02012013_183504

Files\Folders moved on Reboot…
C:\Users\Joan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

# AdwCleaner v2.109 - Logfile created 02/01/2013 at 18:44:18
# Updated 26/01/2013 by Xplode
# Operating system : Windows 7 Home Premium (64 bits)
# User : Joan - JOAN-PC
# Boot Mode : Normal
# Running from : C:\Users\Joan\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\user.js
Folder Deleted : C:\Program Files (x86)\Perion
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\Users\Joan\AppData\Local\Wajam
Folder Deleted : C:\Users\Joan\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Joan\AppData\LocalLow\incredibar.com

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD79F359-E577-46DB-AA74-D6E6B8B45BA8}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\Software\IB Updater
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FD79F359-E577-46DB-AA74-D6E6B8B45BA8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3B181CF2-878B-4758-8FBD-59D8AC5AB12D}
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v17.0.1 (en-US)

File : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\l4nphek4.default-1349998109351\prefs.js

[OK] File is clean.

-\\ Google Chrome v24.0.1312.52

File : C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2476 octets] - [01/02/2013 18:44:18]

########## EOF - C:\AdwCleaner[S1].txt - [2536 octets] ##########

Rkill 2.4.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 01/20/2013 08:23:32 PM in x64 mode.
Windows Version: Windows 7 Home Premium

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

* HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!


Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* COM+ Event System (EventSystem) is not Running.
Startup Type set to: Automatic

* Security Center (wscsvc) is not Running.
Startup Type set to: Automatic (Delayed Start)

* Windows Update (wuauserv) is not Running.
Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 01/20/2013 08:23:40 PM
Execution time: 0 hours(s), 0 minute(s), and 8 seconds(s)
Hi StellaLynn,
  • Are you still having issues with pop-ups?
  • If so, which browsers does this occur in?
  • If not, please "test drive" the computer to verify.
Next

Please download Farbar Service Scanner and save it to your desktop.
  • Right click and select "Run as Administrator"
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Next

Locate Malwarebytes' Anti-Malware (it should be on your desktop).

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
In your next post please provide the following:
  • Answer about the pop-ups.
  • FSS.txt
  • MBAM log
  • ESET log.txt
  • How is the computer running, any remaining issues?
No popups (or anything else symptom-wise) since I ran exe-fix. I couldn't find any log.txt for the ESET scan, there is an eset.txt on C: (the three last lines I posted below): Farbar Service Scanner Version: 30-01-2013 Ran by [removed] (administrator) on 02-02-2013 at 18:32:43 Running from "C:\Users\Joan\Desktop" Windows 7 Home Premium (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. There is no connection to network. Attempt to access Google IP returned error. Attempt to access Google.com returned error: Other errors Attempt to access Yahoo IP returned error. Attempt to access Yahoo.com returned error: Other errors Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.03.01 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Joan :: JOAN-PC [administrator] 2/2/2013 7:19:14 PM mbam-log-2013-02-02 (19-19-14).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 212609 Time elapsed: 3 minute(s), 47 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Documents and Settings\Joan Hite\Desktop\avz4\Quarantine\2009-05-22\avz00003.dta a variant of Win32/Tinxy.AD trojan cleaned by deleting - quarantined C:\Documents and Settings\Joan Hite\Desktop\avz4\Quarantine\2009-05-22\avz00005.dta Win32/Koobface.FX worm cleaned by deleting - quarantined C:\Documents and Settings\Joan Hite\Desktop\avz4\Quarantine\2009-05-22\avz00006.dta a variant of Win32/Wigon.KT trojan cleaned by deleting - quarantined
Hi StellaLynn,

If there are no other outstanding issues, please continue with the following steps.

= = = = = = = = = = = = = = = = = = = =

Your log appears to be clean. We have a few items to take care of before we get to the All Clean Speech.

Clean up with OTL:
  • Right-click OTL.exe select "Run as Administrator" to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
Next

You can now delete any tools and logs remaining on your desktop

Next

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Adobe Reader 10.0
Next

Adobe Reader: Go to http://get.adobe.com/reader/otherversions/
  • Use the drop down menu's to select your operating system
  • Select your language > Select The current version of Adobe Reader for your language
  • Remove the check mark from the box "Free! McAfee Security Scan Plus"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

Next

Locate the Java Control Panel in Windows 7
  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter "Java Control Panel".
  • Click on the Java icon [external image: Posted Image] to open the Java Control Panel.
Delete Temporary Files through the Java Control Panel
[external image: Posted Image]
  • In the Java Control Panel, under the General tab, click Settings under the Temporary Internet Files section.
    The Temporary Files Settings dialog box appears.
[external image: Posted Image]
  • Click Delete Files on the Temporary Files Settings dialog.
    The Delete Temporary Files dialog box appears.
[external image: Posted Image]
  • Click OK on the Delete Temporary Files dialog.
    Note: This deletes all the Downloaded Applications and Applets from the cache.
  • Click OK on the Temporary Files Settings dialog.
    Note: If you want to delete a specific application and applet from the cache, click on View Application and View Applet options respectively.
Next

Create a new Restore Point in Windows 7
  • Open System by clicking the Start button, right-clicking Computer, and then clicking Properties.
  • In the left pane, click System protection. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • Click the System Protection tab, and then click Create.
  • In the System Protection dialog box, type a description, and then click Create.
Next

Clear All Restore Points (except the most recent)
Click Start > All Programs > System Tools > Disk Cleanup
  • Select Files from all users on this computer
  • Click on Continue
  • Select the appropriate drive letter (usually C: )
  • When the Disk Cleanup Window opens, select the More Options tab
  • Under System Restore and Shadow Copies click on the Clean Up button
  • All but the latest restore point will be removed
Note: In some editions of Windows Vista, the disc might include file shadow copies and older Windows Complete PC Backup images as part of restore points. This information will also be deleted.

With the above items taken care of let's move on to the All Clean part of the process.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI