This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

SweetPacks [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This add-on called SweetPacks have proved to be uninstallable. It's located in Firefox extensions and has invaded the Internet Explorer browsers as well.

I ran an OTL scan and this is what it gave me:

OTL logfile created on: 6/25/2013 9:13:53 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.69% Memory free
3.84 Gb Paging File | 3.12 Gb Available in Paging File | 81.32% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 80.37 Gb Free Space | 71.90% Space Free | Partition Type: NTFS

Computer Name: ALYSSA | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG SafeGuard toolbar\vprot.exe (AVG Secure Search)
PRC - C:\WINDOWS\system32\jmdp\stij.exe ()
PRC - C:\WINDOWS\system32\dmwu.exe ()
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe ()
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Fast Free Converter\FastFreeConverterUpdt.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Core Temp\Core Temp.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\UltraVNC\winvnc.exe (UltraVNC)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\jmdp\stij.exe ()
MOD - C:\WINDOWS\system32\dmwu.exe ()
MOD - C:\WINDOWS\system32\jmdp\lmrn.dll ()
MOD - C:\WINDOWS\system32\ImHttpComm.dll ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\SiteSafety.dll ()
MOD - C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe ()
MOD - C:\WINDOWS\system32\jmdp\sqlite3.dll ()
MOD - C:\Program Files\Fast Free Converter\FastFreeConverterUpdt.exe ()
MOD - C:\Program Files\Core Temp\Core Temp.exe ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()


========== Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (IBUpdaterService) – C:\WINDOWS\system32\dmwu.exe ()
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (vToolbarUpdater15.2.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (Updater By SweetPacks) – C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe ()
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (FastFreeConverterUpdt) – C:\Program Files\Fast Free Converter\FastFreeConverterUpdt.exe ()
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (uvnc_service) – C:\Program Files\UltraVNC\winvnc.exe (UltraVNC)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (WLANKEEPER) – C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (UIUSys) – system32\DRIVERS\UIUSYS.SYS File not found
DRV - (MpKsl5993cc0a) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A0AA98A-5E78-4C5E-9F97-75DF5DC87DE8}\MpKsl5993cc0a.sys File not found
DRV - (MpKsl447fde85) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A0AA98A-5E78-4C5E-9F97-75DF5DC87DE8}\MpKsl447fde85.sys File not found
DRV - (MpKsl1c81ed1d) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A0AA98A-5E78-4C5E-9F97-75DF5DC87DE8}\MpKsl1c81ed1d.sys File not found
DRV - (MpKsl1540c545) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A0AA98A-5E78-4C5E-9F97-75DF5DC87DE8}\MpKsl1540c545.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (cerc6) – File not found
DRV - (ALSysIO) – C:\DOCUME~1\User\LOCALS~1\Temp\ALSysIO.sys File not found
DRV - (avgtp) – C:\WINDOWS\system32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (mv2) – C:\WINDOWS\system32\drivers\mv2.sys (UVNC BVBA)
DRV - (NETw5x32) – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st…D-00188BA54669}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q={…D-00188BA54669}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mysearch.avg.com/?cid={4282688A-C77…mp;d=2013-05-28 17:17:28&v=15.2.0.8&pid=safeguard&sg=1&sap=hp
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{37143136-06C9-410F-A696-0823BA095FD0}: "URL" = http://websearch.ask.com/redirect?client=i…F5-ADF44AD75555
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={428268…mp;d=2013-05-28 17:17:28&v=15.2.0.8&pid=safeguard&sg=1&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3078318
IE - HKCU\..\SearchScopes\{CA1E227D-A2EF-45F9-BCDA-8C562085C148}: "URL" = http://us.yhs4.search.yahoo.com/yhs/search…p={SearchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com?src=6&q={s…10043&st=23
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.6.2
FF - prefs.js..extensions.enabledItems: avg@toolbar:15.2.0.8
FF - prefs.js..extensions.enabledItems: [removed]:4.1
FF - prefs.js..keyword.URL: "http://mysearch.avg.com/search?pid=safeguard&sg=1&cid=%7B7a74ac79-6290-496a-8ba5-c2a7f9a3fb3e%7D&mid=08c303c4ca1b47d0b520d151cd41af9a-29f77100f2f2bc80aba872a66b47f25383f0c3ef&ds=AVG&v=15.2.0.8&lang=en&pr=fr&d=2013-05-28%2017%3A17%3A28&sap=ku&q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\User\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Documents and Settings\User\Application Data\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\User\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\User\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2013/06/05 20:07:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\15.2.0.8 [2013/05/28 17:17:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Fast Free Converter\FastFreeConverter\[removed] [2013/06/25 20:48:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}: C:\Program Files\Updater By SweetPacks\Firefox [2013/06/25 20:48:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/25 20:33:22 | 000,000,000 | —D | M]

[2013/06/25 21:01:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/06/25 21:01:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\sahlqulh.default\extensions
[2013/06/25 20:34:55 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\sahlqulh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/05/16 20:46:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/06/25 20:33:29 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/04/28 07:40:17 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2013/06/04 14:44:09 | 000,002,118 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2013/02/18 09:32:54 | 000,003,723 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\safeguard-secure-search.xml

O1 HOSTS File: ([2011/04/29 07:37:23 | 000,615,911 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 16259 more lines…
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Updater By SweetPacks) - {7D4F1959-3F72-49d5-8E59-F02F8AA6815D} - C:\Program Files\Updater By SweetPacks\Extension32.dll ()
O2 - BHO: (Fast Free Converter 4.1) - {8232785C-5C98-4A6E-B7B4-911FFBED7582} - C:\Program Files\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll (Fast Free Converter)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe (AVG Secure Search)
O4 - HKCU..\Run: [Core Temp] C:\Program Files\Core Temp\Core Temp.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://d1ylr6sba64qi3.cloudfront.net/globa…el_4.1.66.0.cab (SysInfo Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB1B32B6-134D-480B-B004-C21DAF339401}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\User\desktop\Ghostclaw.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\desktop\Ghostclaw.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 13:31:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{b45d142f-a4b6-11df-91c5-c8fef602be14}\Shell\AutoRun\command - "" = E:\GuardianEdgeRemovableStorageAccess.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/06/25 21:01:50 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/06/25 21:00:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ARFC
[2013/06/25 20:59:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WNLT
[2013/06/25 20:27:59 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\AVG Secure Search
[2013/06/25 20:26:43 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/06/16 10:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\WMTools Downloaded Files
[2013/06/16 10:18:39 | 000,000,000 | —D | C] – C:\Program Files\Updater By SweetPacks
[2013/06/16 10:16:46 | 000,632,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr80.dll
[2013/06/16 10:16:46 | 000,554,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcp80.dll
[2013/06/16 10:16:46 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcm80.dll
[2013/06/16 10:16:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\jmdp
[2013/06/16 10:16:45 | 000,773,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr100.dll
[2013/06/16 10:16:45 | 000,421,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcp100.dll
[2013/06/16 10:12:50 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\DealPly
[2013/06/16 10:12:25 | 000,000,000 | —D | C] – C:\Documents and Settings\User\AppData
[2013/06/16 10:12:15 | 000,000,000 | —D | C] – C:\Program Files\File Type Helper
[2013/06/16 10:12:02 | 000,000,000 | —D | C] – C:\Program Files\Fast Free Converter
[5 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/25 21:22:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/06/25 21:19:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-1390067357-1417001333-1003UA.job
[2013/06/25 21:03:01 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/06/25 21:03:01 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/25 21:02:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/06/25 20:33:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/06/25 20:33:38 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/06/25 20:12:45 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/25 19:58:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/25 11:31:02 | 124,414,562 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2013/06/23 18:19:01 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-1390067357-1417001333-1003Core.job
[2013/06/23 10:12:01 | 000,000,410 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2013/06/22 11:42:36 | 000,002,515 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Office Word 2007.lnk
[2013/06/20 18:25:31 | 000,721,372 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/06/20 18:25:31 | 000,198,418 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/06/18 20:31:30 | 001,509,376 | —- | M] () – C:\Documents and Settings\User\Desktop\gggb tt mv.MSWMM
[2013/06/18 17:00:25 | 000,035,328 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/06/16 10:12:33 | 000,000,002 | —- | M] () – C:\END
[2013/06/12 11:23:07 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/06/12 11:23:04 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/06/12 10:59:41 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/06/05 16:50:57 | 000,570,510 | —- | M] () – C:\Documents and Settings\User\Desktop\unfinished.bmp
[2013/06/05 14:27:34 | 000,570,510 | —- | M] () – C:\Documents and Settings\User\Desktop\Lightgaze.bmp
[2013/06/05 13:47:50 | 000,570,510 | —- | M] () – C:\Documents and Settings\User\Desktop\Speedfoot.bmp
[2013/06/04 14:42:59 | 000,753,462 | —- | M] () – C:\Documents and Settings\User\Desktop\Ghostclaw.bmp
[2013/06/02 11:26:46 | 000,753,462 | —- | M] () – C:\Documents and Settings\User\Desktop\Shy thunder.bmp
[2013/05/31 15:43:45 | 000,753,462 | —- | M] () – C:\Documents and Settings\User\Desktop\Shystreak.bmp
[2013/05/28 17:18:08 | 000,003,723 | —- | M] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
[2013/05/27 02:58:04 | 001,167,152 | —- | M] () – C:\WINDOWS\System32\dmwu.exe
[2013/05/27 02:55:06 | 000,027,136 | —- | M] () – C:\WINDOWS\System32\ImHttpComm.dll
[5 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/25 20:33:38 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/06/25 20:05:26 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/06/25 20:05:26 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/06/16 15:03:42 | 001,509,376 | —- | C] () – C:\Documents and Settings\User\Desktop\gggb tt mv.MSWMM
[2013/06/16 10:16:45 | 001,167,152 | —- | C] () – C:\WINDOWS\System32\dmwu.exe
[2013/06/16 10:16:44 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\ImHttpComm.dll
[2013/06/16 10:12:51 | 000,000,410 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2013/06/05 16:50:57 | 000,570,510 | —- | C] () – C:\Documents and Settings\User\Desktop\unfinished.bmp
[2013/06/05 14:27:33 | 000,570,510 | —- | C] () – C:\Documents and Settings\User\Desktop\Lightgaze.bmp
[2013/06/05 13:47:50 | 000,570,510 | —- | C] () – C:\Documents and Settings\User\Desktop\Speedfoot.bmp
[2013/06/04 14:06:06 | 000,753,462 | —- | C] () – C:\Documents and Settings\User\Desktop\Ghostclaw.bmp
[2013/06/02 11:26:46 | 000,753,462 | —- | C] () – C:\Documents and Settings\User\Desktop\Shy thunder.bmp
[2013/05/31 15:43:44 | 000,753,462 | —- | C] () – C:\Documents and Settings\User\Desktop\Shystreak.bmp
[2013/05/21 19:17:17 | 000,003,723 | —- | C] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
[2013/01/18 19:35:23 | 000,027,520 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\dt.dat
[2012/11/27 10:05:39 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2012/11/27 10:05:39 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2012/10/08 11:59:27 | 000,035,328 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/19 17:11:48 | 000,000,227 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2012/02/19 17:11:45 | 000,045,568 | —- | C] () – C:\WINDOWS\UniFish3.exe
[2012/02/16 20:09:33 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/14 13:49:15 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2012/01/14 10:20:56 | 000,000,043 | —- | C] () – C:\WINDOWS\spookydisplay.ini
[2011/03/25 15:45:37 | 000,001,311 | —- | C] () – C:\Documents and Settings\User\_viminfo

========== ZeroAccess Check ==========

[2012/05/19 15:23:30 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/06/24 06:10:44 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 06:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 06:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/08/09 04:48:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2013/01/22 20:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign
[2013/06/16 10:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
[2013/01/22 21:02:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2012/07/22 08:36:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/02/11 10:32:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2012/07/22 08:23:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/28 08:02:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2013/05/14 19:14:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/07/28 08:34:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2010/08/16 18:07:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Rpcnet
[2011/06/19 09:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/10 14:31:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/12/26 12:10:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2013/01/22 21:01:54 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\AVG SafeGuard toolbar
[2012/07/22 08:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\AVG2012
[2013/06/16 10:12:50 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DealPly
[2011/04/28 08:02:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\f-secure
[2011/07/03 18:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GlarySoft
[2012/11/28 18:50:14 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OverDrive
[2012/07/28 08:41:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\PC Cleaners
[2012/07/28 08:41:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\PCPro
[2011/01/01 13:22:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SanDisk
[2012/09/30 08:44:34 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\start
[2011/08/02 13:31:05 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Unity

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/14 06:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 06:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2013/06/24 21:17:30 | 000,086,446 | —- | M] () MD5=8371C10D94B62EDC03B81087271F7FBB – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2008/04/14 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/04/14 06:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/14 06:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/06/25 21:06:06 | 000,115,640 | —- | M] () MD5=464B01294D4551765E9CCCE6602ACDA6 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2008/04/14 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2008/04/14 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2011/01/30 09:45:12 | 000,033,726 | —- | M] () MD5=98813D442AB6F9865FF408E9459D2D78 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010/11/10 12:49:34 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/02/06 05:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 06:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2010/08/10 13:31:57 | 000,001,602 | —- | M] () MD5=13797D6E512E857C70E62AFBDF44F66C – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2008/04/14 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.VIM >
[2010/10/27 09:44:14 | 000,000,459 | —- | M] () MD5=193ED9B27B25456FBE50E6111B8E6770 – C:\Program Files\Vim\vim73\ftplugin\services.vim
[2010/10/27 09:42:50 | 000,001,865 | —- | M] () MD5=A17575F0BA54E8FB1148DDFC2361D776 – C:\Program Files\Vim\vim73\syntax\services.vim

< MD5 for: WINLOGON.EXE >
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 06:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 06:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2010/08/10 13:31:50 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/03 17:50:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/10 13:31:50 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2013/06/16 10:12:33 | 000,000,002 | —- | M] () – C:\END
[2010/08/10 13:31:50 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/10 13:31:50 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 06:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/06/25 21:02:48 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/08/10 13:31:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2013/05/28 17:18:08 | 000,003,723 | —- | M] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 9C7D-C25B
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
05/16/2013 07:04 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
05/16/2013 07:03 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
2 Dir(s) 86,273,978,368 bytes free

< %systemroot%\System32\config\*.sav >
[2010/08/10 06:21:15 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/10 06:21:15 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/10 06:21:15 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/10 13:31:57 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/10 13:37:39 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/10 13:37:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-06-12 17:09:32

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
Hello SweetTrouble and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
===================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
When you've done that, please run OTL again and include the Extras.txt log that was produced when you ran OTL the first time.

Logs to include with next post:

AdwCleaner log
aswMBR log
checkup.txt
New OTL log
Extras.txt


Thanks

Satchfan
Hi It has been a couple of days since I replied to your request for help with your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI