This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Is My PC infected? [Closed] [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been acting very strange lately, I'm not sure if it is a virus, spyware, malware, or if someone is hacking into my computer. When I go to network and sharing center I started to noticed that my firewall would be turned off so I would turn it back on change settings for it to work properly and I would exit screen then go back to to the network and sharing center and it would be off again. I then noticed that at times my computer runs very slow and then at other times it runs fine. I've scanned for viruses and everything comes back fine but I think something or someone is connecting to my computer. I just notice different settings changed, like network discovery will be on when I know it was off, or different things showing about remote access that normally are not activated or haven't been there before. I was on internet earlier and had no sign of internet connection lost then network connection screen popped up saying connect to samsung galaxy and then try connecting to router, or something along those lines. I was looking at the event viewer after network popup and it had logs about firewall not being able to tell user it blocked 2 connections, a user logged off. It says malware was detected when i've never had a scan come back with issues.Also was saying special prililvages were made for user, be was attempted using explicit credentials just Sorry I'm not a little more rate, but I do know things are different and not right. At first I was set on that boyfrind was hacking into my computer but he swearOTL Extras logfile created on: 7/18/2013 9:13:59 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rose\Desktop


Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.10% Memory free
3.43 Gb Paging File | 2.38 Gb Available in Paging File | 69.50% Paging File free
Paging file location(s): c:\pagefile.sys 1530 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 83.67 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 7.45 Gb Free Space | 50.86% Space Free | Partition Type: NTFS

Computer Name: LULU | User Name: Rose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Value error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – Reg Error: Key error.
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3876892959-2368528674-3984381725-1000]
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{98CDF18C-2176-4380-BD0E-0B2EA867428C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{30B48E87-F382-4643-8E06-E968B471682B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{348AB39A-6B1F-471D-BA3F-32E07B82D633}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{82741CEB-B33D-4180-BEEC-483A61187EC6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{D80A6FBE-E723-4B03-8850-BCA96B8DBF70}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"TCP Query User{CE4F62E2-203A-4184-A8A4-33E82A7E7863}C:\program files\microsoft office\office14\groove.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"UDP Query User{422E0F52-E9AC-4B39-BBE2-D927BB7C6434}C:\program files\microsoft office\office14\groove.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series" = Canon MG3100 series MP Drivers
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A6D9B5E-9BAB-4141-85BA-2C6552FA7913}" = Dell Backup and Recovery Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E6C7A4F4-D098-4412-BA79-6806C2675395}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D8CD8BBE-81F6-49CB-84D2-A1E616875792}" = AVG 2012
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Internet Security
"Baidu PC Faster 3.6.0.33146" = Baidu PC Faster
"Canon MG3100 series On-screen Manual" = Canon MG3100 series On-screen Manual
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist Corporate
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MP Navigator EX 5.0" = Canon MP Navigator EX 5.0
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/16/2013 11:04:26 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/16/2013 11:08:56 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/16/2013 11:30:43 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/16/2013 7:29:02 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/17/2013 5:38:57 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/17/2013 2:43:45 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/17/2013 7:36:41 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

Error - 7/17/2013 9:51:45 PM | Computer Name = LULU | Source = Windows Search Service | ID = 3024
Description =

Error - 7/17/2013 10:18:46 PM | Computer Name = LULU | Source = Windows Search Service | ID = 3013
Description =

Error - 7/18/2013 12:28:12 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 7/17/2013 7:36:42 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =

Error - 7/17/2013 8:05:43 PM | Computer Name = LULU | Source = DCOM | ID = 10005
Description =

Error - 7/17/2013 8:05:44 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7009
Description =

Error - 7/17/2013 8:05:44 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =

Error - 7/17/2013 9:47:55 PM | Computer Name = LULU | Source = Microsoft-Windows-Diagnostics-Networking | ID = 5300
Description =

Error - 7/18/2013 12:26:22 AM | Computer Name = LULU | Source = volmgr | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 7/18/2013 12:26:30 AM | Computer Name = LULU | Source = volmgr | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 7/18/2013 12:26:40 AM | Computer Name = LULU | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =

Error - 7/18/2013 12:28:13 AM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =

Error - 7/18/2013 12:28:13 AM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =


< End of report >


s it is not him.


OTL logfile created on: 7/18/2013 9:13:59 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rose\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.10% Memory free
3.43 Gb Paging File | 2.38 Gb Available in Paging File | 69.50% Paging File free
Paging file location(s): c:\pagefile.sys 1530 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 83.67 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 7.45 Gb Free Space | 50.86% Space Free | Partition Type: NTFS

Computer Name: LULU | User Name: Rose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rose\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()


========== Services (SafeList) ==========

SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe File not found
SRV - (vToolbarUpdater15.3.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (PCFasterSvc_{PCFaster_3.6.0.33146}) – C:\Program Files\Baidu Security\PC Faster\3.6.0.33146\PCFasterSvc.exe (Baidu Inc.)
SRV - (BAVSvc) – C:\Program Files\Baidu Security\Cloud Security\BAVSvc.exe (Baidu, Inc.)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV - (ezSharedSvc) – C:\Windows\System32\ezSharedSvcHost.exe (EasyBits Software AS)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (wanatw) – File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (NwlnkFwd) – File not found
DRV - (NwlnkFlt) – File not found
DRV - (IpInIp) – File not found
DRV - (easytether) – system32\DRIVERS\easytthr.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswNdis2) – C:\Windows\System32\drivers\aswNdis2.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswKbd) – C:\Windows\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (aswFW) – C:\Windows\System32\drivers\aswFW.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (aswNdis) – C:\Windows\System32\drivers\aswNdis.sys (ALWIL Software)
DRV - (FlyUsb) – C:\Windows\System32\drivers\FlyUsb.sys (LeapFrog)
DRV - (ssadmdm) – C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) – C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) – C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (androidusb) – C:\Windows\System32\drivers\ssadadb.sys (Google Inc)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (PID_PEPI) – C:\Windows\System32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (toshidpt) – C:\Windows\System32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (DLADResM) – C:\Windows\System32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{5a15c091-f3c2-4c8f-8964-e3434a2a4a95}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes,DefaultScope = {4C1EF763-FF77-4D7C-8E5D-189249B83B78}
IE - HKCU\..\SearchScopes\{4C1EF763-FF77-4D7C-8E5D-189249B83B78}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}: C:\Program Files\Updater By Smilebox\Firefox


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: blank:new
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Disabled) = internal-remoting-viewer
CHR - plugin: Native Client (Disabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Disabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: AVG SiteSafety plugin (Disabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Disabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Disabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Glitter Text Maker = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\bcgebmidacnhidoinadkojhhcpjomhck\3.777_0\
CHR - Extension: Gismeteo = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\bfegaehidkkcfaikpaijcdahnpikhobf\2.3.3_0\
CHR - Extension: YouTube = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Ebates Cash Back = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\chhjbpecpncaggjpdakmflnfcopglcmi\3.0.1.16_0\
CHR - Extension: Google Search = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Pump Knuckles Theme = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\dgcllodjkonpmdledaaoihjfckkjmhig\1_0\
CHR - Extension: Mahjongg = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\eegpopcingfghbompjfejakfeaolmbop\1.0.0.2_0\
CHR - Extension: Hospital Hustle = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ehakeingkmjibabcmjdncekhodablbon\0.1_0\
CHR - Extension: Pandora = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: PicMonkey = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fgdgokchhicmaiacmgegjnppjkgogdhm\1.5_0\
CHR - Extension: A Girl in the City = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fklbnfemodbmkehogchaclhggkjmldda\0.1_0\
CHR - Extension: My Scrap Nook = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\gnaghjfblmncnfgjddgelpkbhfdflicf\4.96.1.48221_0\
CHR - Extension: Dropbox = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.6_0\
CHR - Extension: GCH Calendar = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\lhammhngpacbengeachfclhcjbjfkfmf\0.0.4_0\
CHR - Extension: Webfetti = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\lmpchpgemlpnbapjajinolkefniihpod\4.96.1.48191_0\
CHR - Extension: Love and Death - Bitten = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\mihacdejifldbkobglccfmnfhinealma\0.2_0\
CHR - Extension: Incredible StartPage - Productive Start Page for Chrome! = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ncdfeghkpohnalmpblddmnppfooljekh\1.6.2_0\
CHR - Extension: Blood Ties = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\paldnkgokaahkjfgadfkhbpghcgonbhl\0.2_0\
CHR - Extension: deviantART\u2122 = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\pbppfiakkcakldnnhcfncfmclhkhhdcp\2.0.3_0\
CHR - Extension: Gmail = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Dr Wise - Medical Mysteries = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\podjepkbfogcclejdjapofifhfjebeik\0.1_0\

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 189
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 189
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD67D9B2-CA97-45C7-82AF-F82320ED645F}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E343DDE5-E345-4655-97A9-44B48425462F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E35E3665-1BD0-4F66-8D61-782107C97B01}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\viprotocol - No CLSID value found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\615\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Rose\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rose\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{818b3ab6-fc1a-11de-b43a-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{818b3ab6-fc1a-11de-b43a-00038a000015}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{8977c4d5-2a75-11df-85c1-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{8977c4d5-2a75-11df-85c1-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{9629c68d-d696-11e1-afb2-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{9629c68d-d696-11e1-afb2-00038a000015}\Shell\AutoRun\command - "" = F:\PcOptions.exe
O33 - MountPoints2\{a6e2d327-0076-11df-b1ed-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{a6e2d327-0076-11df-b1ed-00038a000015}\Shell\AutoRun\command - "" = F:\iStudio.exe
O33 - MountPoints2\{b36b8768-f360-11de-b5db-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{b36b8768-f360-11de-b5db-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{d91af080-0d53-11df-85c3-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{d91af080-0d53-11df-85c3-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/18 08:49:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Rose\Desktop\OTL.exe
[2013/07/14 05:07:02 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{A133B38B-07CA-450B-8A62-9E3C541EDB24}
[2013/07/14 04:44:00 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{78095194-C4CB-4E11-A49A-BBBABEC0FBE6}
[2013/07/14 04:09:51 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\AquaSoft
[2013/07/14 04:08:16 | 000,000,000 | —D | C] – C:\Program Files\AquaSoft
[2013/07/13 12:15:38 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{48DAF17A-1F57-4F0D-AE17-5D3E964E4228}
[2013/07/13 03:41:38 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Magentic
[2013/07/13 00:00:21 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Stardock_Corporation
[2013/07/12 23:59:09 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\PackageAware
[2013/07/12 19:29:18 | 000,000,000 | —D | C] – C:\ProgramData\Baidu Security
[2013/07/12 19:29:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster
[2013/07/12 19:29:17 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Templates\Start Menu\Programs\Baidu PC Faster
[2013/07/12 19:28:25 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Baidu
[2013/07/12 19:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Baidu
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Baidu Security
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Baidu Security
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Program Files\Baidu Security
[2013/07/12 01:38:56 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/12 01:38:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/12 01:38:52 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/12 01:38:52 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/12 01:38:52 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/12 01:38:48 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/12 01:38:48 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/12 01:38:43 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/12 00:42:33 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/07/12 00:41:56 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/12 00:41:55 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/12 00:41:55 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/12 00:41:54 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/12 00:41:53 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/12 00:41:52 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/12 00:41:52 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/12 00:41:52 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/12 00:41:47 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/07/12 00:41:43 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/07/09 19:15:44 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\WinRAR
[2013/07/09 18:57:39 | 000,000,000 | —D | C] – C:\Users\Rose\Documents\Graboid
[2013/07/09 18:53:17 | 000,000,000 | —D | C] – C:\ProgramData\Graboid Inc
[2013/07/09 18:53:07 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Geckofx
[2013/07/09 18:53:03 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Mozilla
[2013/07/09 18:47:29 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2013/07/09 18:47:13 | 000,000,000 | —D | C] – C:\Program Files\Graboid
[2013/06/30 02:53:59 | 000,204,784 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswNdis2.sys
[2013/06/30 02:53:58 | 000,104,752 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFW.sys
[2013/06/30 02:53:56 | 000,021,576 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswKbd.sys
[2013/06/30 02:52:48 | 000,012,112 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswNdis.sys
[2013/06/30 02:47:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2013/06/30 01:30:07 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/06/30 01:30:06 | 000,369,584 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/30 01:30:02 | 000,049,760 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/06/30 01:30:01 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/06/30 01:30:00 | 000,770,344 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/30 01:29:52 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/06/30 01:29:50 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/06/30 01:28:16 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/06/30 01:27:13 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/06/30 01:25:29 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/06/29 18:36:34 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Avg2013
[2013/06/29 18:22:49 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Windows Live Writer
[2013/06/29 12:03:54 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/06/29 07:35:11 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{EB461E1B-B31A-41B8-AF8F-DE14C2EBBB71}
[2013/06/29 01:24:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/06/29 01:21:46 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2013/06/29 01:21:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2013/06/29 01:20:38 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2013/06/29 01:20:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2013/06/29 01:18:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2013/06/29 01:17:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2013/06/29 01:17:33 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2013/06/29 01:16:15 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Microsoft Help
[2013/06/29 01:15:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/06/29 01:14:35 | 000,000,000 | RH-D | C] – C:\MSOCache
[2013/06/22 23:36:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/22 14:19:36 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\DownLite
[2013/06/21 17:33:11 | 000,000,000 | —D | C] – C:\Users\Rose\Desktop\–SCHOOL–
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/18 08:50:01 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/18 08:49:57 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Rose\Desktop\OTL.exe
[2013/07/18 07:29:30 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/18 07:29:30 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/18 06:58:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/18 03:37:41 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/17 21:13:34 | 000,000,000 | —- | M] () – C:\END
[2013/07/17 18:48:57 | 000,000,040 | —- | M] () – C:\user_defpage_list
[2013/07/13 03:15:24 | 000,002,064 | —- | M] () – C:\Users\Rose\Desktop\Baidu PC Faster.lnk
[2013/07/13 03:15:24 | 000,001,921 | —- | M] () – C:\Users\Rose\Desktop\Google Chrome.lnk
[2013/07/13 03:15:24 | 000,001,841 | —- | M] () – C:\Users\Rose\Desktop\avast! Internet Security.lnk
[2013/07/13 03:15:24 | 000,001,749 | —- | M] () – C:\Users\Rose\Desktop\Internet Explorer.lnk
[2013/07/13 03:15:24 | 000,000,448 | —- | M] () – C:\Users\Rose\Desktop\Downloads - Shortcut.lnk
[2013/07/12 02:23:50 | 000,383,440 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/07/12 02:09:29 | 000,640,658 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/12 02:09:29 | 000,118,878 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/12 00:27:43 | 000,003,584 | —- | M] () – C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/09 01:44:55 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/07/09 00:14:07 | 000,006,702 | —- | M] () – C:\Users\Rose\AppData\Roaming\wklnhst.dat
[2013/07/08 19:02:06 | 000,713,217 | —- | M] () – C:\Users\Rose\Desktop\Creek Nation School Clothes Assistance Application.pdf
[2013/06/30 02:03:58 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/06/30 02:03:58 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/06/30 01:30:15 | 000,770,344 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/30 01:30:15 | 000,369,584 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/30 01:30:15 | 000,175,176 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/30 00:12:46 | 000,000,512 | —- | M] () – C:\Windows\System32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD
[2013/06/28 16:27:59 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/23 14:27:36 | 000,001,957 | —- | M] () – C:\Users\Rose\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/19 00:44:23 | 000,000,680 | —- | M] () – C:\Users\Rose\AppData\Local\d3d9caps.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/13 03:15:24 | 000,002,064 | —- | C] () – C:\Users\Rose\Desktop\Baidu PC Faster.lnk
[2013/07/13 03:15:24 | 000,001,921 | —- | C] () – C:\Users\Rose\Desktop\Google Chrome.lnk
[2013/07/13 03:15:24 | 000,001,841 | —- | C] () – C:\Users\Rose\Desktop\avast! Internet Security.lnk
[2013/07/13 03:15:24 | 000,001,749 | —- | C] () – C:\Users\Rose\Desktop\Internet Explorer.lnk
[2013/07/13 03:15:24 | 000,000,448 | —- | C] () – C:\Users\Rose\Desktop\Downloads - Shortcut.lnk
[2013/07/12 19:29:32 | 000,000,040 | —- | C] () – C:\user_defpage_list
[2013/07/12 00:27:42 | 000,003,584 | —- | C] () – C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/08 19:02:05 | 000,713,217 | —- | C] () – C:\Users\Rose\Desktop\Creek Nation School Clothes Assistance Application.pdf
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/30 01:29:59 | 000,175,176 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/30 01:29:57 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/06/30 00:12:46 | 000,000,512 | —- | C] () – C:\Windows\System32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD
[2013/06/28 19:44:14 | 000,006,702 | —- | C] () – C:\Users\Rose\AppData\Roaming\wklnhst.dat
[2013/06/22 23:36:07 | 000,001,957 | —- | C] () – C:\Users\Rose\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/22 23:35:20 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/22 23:35:18 |
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.



Scan with Malwarebytes Anti-Rootkit

Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-[date and time]***.txt . Please attach that to your next reply.
Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
ComboFix 13-07-20.01 - Rose 07/20/2013 7:03.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2038.1094 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\users\Rose\GoToAssistDownloadHelper.exe
c:\windows\system32\roboot.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-06-20 to 2013-07-20 )))))))))))))))))))))))))))))))
.
.
2013-07-20 07:01 . 2013-07-20 07:01 60872 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{41B443A2-8D75-4DA9-B226-2CCBD8788246}\offreg.dll
2013-07-19 23:40 . 2013-07-19 23:56 ——– d—–w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-07-19 23:39 . 2013-07-19 23:39 ——– d—–w- c:\programdata\Malwarebytes
2013-07-14 09:09 . 2013-07-14 09:09 ——– d—–w- c:\users\Rose\AppData\Roaming\AquaSoft
2013-07-14 09:08 . 2013-07-14 09:08 ——– d—–w- c:\program files\AquaSoft
2013-07-13 08:41 . 2013-07-13 08:41 ——– d—–w- c:\users\Rose\AppData\Local\Magentic
2013-07-13 05:00 . 2013-07-13 05:00 ——– d—–w- c:\users\Rose\AppData\Local\Stardock_Corporation
2013-07-13 04:59 . 2013-07-13 04:59 ——– d—–w- c:\users\Rose\AppData\Local\PackageAware
2013-07-13 00:29 . 2013-07-13 00:29 ——– d—–w- c:\programdata\Baidu Security
2013-07-13 00:28 . 2013-07-13 00:28 ——– d—–w- c:\users\Rose\AppData\Roaming\Baidu
2013-07-13 00:28 . 2013-07-13 00:28 ——– d—–w- c:\programdata\Baidu
2013-07-13 00:21 . 2013-07-13 00:28 ——– d—–w- c:\program files\Baidu Security
2013-07-13 00:21 . 2013-07-13 00:28 ——– d—–w- c:\users\Rose\AppData\Roaming\Baidu Security
2013-07-12 07:50 . 2013-06-12 04:18 7068072 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{41B443A2-8D75-4DA9-B226-2CCBD8788246}\mpengine.dll
2013-07-12 05:42 . 2013-06-04 01:50 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-07-12 05:41 . 2013-04-17 10:10 1069056 —-a-w- c:\windows\system32\DWrite.dll
2013-07-12 05:41 . 2013-04-17 10:10 798208 —-a-w- c:\windows\system32\FntCache.dll
2013-07-12 05:41 . 2013-04-17 11:28 189952 —-a-w- c:\windows\system32\d3d10core.dll
2013-07-12 05:41 . 2013-04-17 10:33 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2013-07-12 05:41 . 2013-04-17 11:28 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-07-12 05:41 . 2013-04-17 11:28 1029120 —-a-w- c:\windows\system32\d3d10.dll
2013-07-12 05:41 . 2013-04-17 11:28 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2013-07-12 05:41 . 2013-04-17 10:34 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2013-07-12 05:41 . 2013-04-17 10:14 683008 —-a-w- c:\windows\system32\d2d1.dll
2013-07-12 05:41 . 2013-06-01 04:06 505344 —-a-w- c:\windows\system32\qedit.dll
2013-07-12 05:41 . 2013-05-08 04:04 1548288 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-12 05:41 . 2013-04-09 03:51 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-09 23:53 . 2013-07-09 23:53 ——– d—–w- c:\programdata\Graboid Inc
2013-07-09 23:53 . 2013-07-09 23:53 ——– d—–w- c:\users\Rose\AppData\Local\Geckofx
2013-07-09 23:47 . 2013-07-09 23:47 ——– d—–w- c:\program files\VideoLAN
2013-07-09 23:47 . 2013-07-12 05:31 ——– d—–w- c:\program files\Graboid
2013-06-30 07:53 . 2013-05-09 08:59 21576 —-a-w- c:\windows\system32\drivers\aswKbd.sys
2013-06-30 06:30 . 2013-05-09 08:59 29816 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-06-30 06:30 . 2013-06-30 06:30 369584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-06-30 06:30 . 2013-05-09 08:59 49760 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2013-06-30 06:30 . 2013-05-09 08:59 56080 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-06-30 06:30 . 2013-06-30 06:30 770344 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-30 06:29 . 2013-06-30 06:30 175176 —-a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-30 06:29 . 2013-05-09 08:59 49376 —-a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-06-30 06:29 . 2013-05-09 08:59 66336 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-06-30 06:29 . 2013-05-09 08:58 229648 —-a-w- c:\windows\system32\aswBoot.exe
2013-06-30 06:28 . 2013-05-09 08:58 41664 —-a-w- c:\windows\avastSS.scr
2013-06-30 06:27 . 2013-06-30 06:27 ——– d—–w- c:\program files\AVAST Software
2013-06-30 06:25 . 2013-06-30 06:27 ——– d—–w- c:\programdata\AVAST Software
2013-06-30 05:12 . 2013-06-30 05:12 512 —-a-w- c:\windows\system32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD.tmp
2013-06-29 23:36 . 2013-06-29 23:36 ——– d—–w- c:\users\Rose\AppData\Local\Avg2013
2013-06-29 23:22 . 2013-06-29 23:22 ——– d—–w- c:\users\Rose\AppData\Roaming\Windows Live Writer
2013-06-29 14:00 . 2013-06-29 14:00 ——– d—–w- c:\users\Default\AppData\Local\Microsoft Help
2013-06-29 06:21 . 2013-06-29 06:21 ——– d—–w- c:\program files\Microsoft Synchronization Services
2013-06-29 06:20 . 2013-06-29 06:20 ——– d—–w- c:\windows\PCHEALTH
2013-06-29 06:20 . 2013-06-29 06:20 ——– d—–w- c:\program files\Microsoft Sync Framework
2013-06-29 06:18 . 2013-06-29 06:18 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2013-06-29 06:17 . 2013-06-29 06:17 ——– d—–w- c:\program files\Microsoft Analysis Services
2013-06-29 06:17 . 2013-06-29 06:23 ——– d—–w- c:\windows\SHELLNEW
2013-06-29 06:16 . 2013-07-18 01:49 ——– d—–w- c:\users\Rose\AppData\Local\Microsoft Help
2013-06-29 06:15 . 2013-07-12 07:05 ——– d—–w- c:\programdata\Microsoft Help
2013-06-29 06:14 . 2013-06-29 06:14 ——– d—–r- C:\MSOCache
2013-06-22 19:19 . 2013-06-22 19:19 ——– d—–w- c:\users\Rose\AppData\Roaming\DownLite
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-30 07:03 . 2012-09-30 05:03 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-30 07:03 . 2012-09-30 05:03 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-28 21:27 . 2013-06-16 02:22 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-06-12 16:19 . 2013-03-13 16:14 17018248 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-06-10 21:14 . 2011-03-28 23:36 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-08 04:37 . 2013-06-11 19:24 905576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-02 22:03 . 2013-06-11 19:24 3603832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 22:03 . 2013-06-11 19:24 3551096 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-02 07:06 . 2009-10-03 03:00 238872 ——w- c:\windows\system32\MpSigStub.exe
2013-05-02 04:04 . 2013-06-11 19:24 443904 —-a-w- c:\windows\system32\win32spl.dll
2013-05-02 04:03 . 2013-06-11 19:24 37376 —-a-w- c:\windows\system32\printcom.dll
2013-04-24 04:00 . 2013-06-11 19:24 985600 —-a-w- c:\windows\system32\crypt32.dll
2013-04-24 04:00 . 2013-06-11 19:24 98304 —-a-w- c:\windows\system32\cryptnet.dll
2013-04-24 04:00 . 2013-06-11 19:24 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2013-04-24 04:00 . 2013-06-11 19:24 41984 —-a-w- c:\windows\system32\certenc.dll
2013-04-24 01:46 . 2013-06-11 19:24 812544 —-a-w- c:\windows\system32\certutil.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-12-02 07:38 13672 —-a-w- c:\program files\Citrix\GoToAssist\615\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Rose^AppData^Roaming^Microsoft^Windows^Templates^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\users\Rose\AppData\Roaming\Microsoft\Windows\Templates\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SelectRebates
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeetItUpFree
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\225517B3BEC763B24377202884D2E14DF81F1D35._service_run]
2013-07-12 18:49 846288 —-a-w- c:\program files\Google\Chrome\Application\chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2008-07-10 00:21 163840 —-a-w- c:\program files\DellTPad\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-07-10 00:25 170520 —-a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-07-10 00:26 150040 —-a-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2006-09-11 09:40 218032 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-07-10 00:26 141848 —-a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3876892959-2368528674-3984381725-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
BullGuard_Backup REG_MULTI_SZ BsBackup
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-07-13 01:45 1173456 —-a-w- c:\program files\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-23 04:35]
.
2013-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-23 04:35]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
SafeBoot-BsScanner
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-AVG_UI - c:\program files\AVG\AVG2013\avgui.exe
MSConfigStartUp-Google Quick Search Box - c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-LogitechQuickCamRibbon - c:\program files\Logitech\Logitech WebCam Software\LWS.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSConfigStartUp-vProt - c:\program files\AVG Secure Search\vprot.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-07-20 07:20
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3876892959-2368528674-3984381725-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3876892959-2368528674-3984381725-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-07-20 07:23:41
ComboFix-quarantined-files.txt 2013-07-20 12:23
.
Pre-Run: 88,847,736,832 bytes free
Post-Run: 89,240,854,528 bytes free
.
- - End Of File - - 37F3C4CEF3B9B1F85CC9806843D3F6EC
CDB4DE4BBD714F152979DA2DCBEF57EB
Quick Scan with Malwarebytes Antimalware

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If the program is already installed:
  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.



Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.07.23.02 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Rose :: LULU [administrator] 7/22/2013 9:39:21 PM mbam-log-2013-07-22 (21-39-21).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 205703 Time elapsed: 10 minute(s), 21 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESSET: C:\AI_RecycleBin\{6E5DF2C3-3B08-4027-BA06-88BD863B6C62}\3\Strongvault\StrongVaultApp.exe a variant of MSIL/Adware.StrongVault.A application C:\Program Files\PDFCreator\message.exe a variant of Win32/InstallCore.A application D:\BaiduDownloads\Super_Mario_Bros.X_1.3.exe Win32/OpenCandy application

D:\BaiduDownloads\Super_Mario_Bros.X_1.3.exe Win32/OpenCandy application


Delete this file.

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
# AdwCleaner v2.306 - Logfile created 07/26/2013 at 18:03:38
# Updated 19/07/2013 by Xplode
# Operating system : Windows Vista ™ Home Basic Service Pack 2 (32 bits)
# User : Rose - LULU
# Boot Mode : Normal
# Running from : C:\Users\Rose\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\END
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Browser Manager
Folder Deleted : C:\ProgramData\DriverCure
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\Users\Rose\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Rose\AppData\Local\PackageAware
Folder Deleted : C:\Users\Rose\AppData\Roaming\DriverCure

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\BrowserMngr
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\d488dfbd69ea48
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\InstallCore






Results of screen317's Security Check version 0.99.71
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Adobe Flash Player 11.7.700.224
Google Chrome 28.0.1500.71
Google Chrome 28.0.1500.72
````````Process Check: objlist.exe by Laurent````````
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
In one of the last threads i was asked to run some scans and post the logs and I did but I havent heard anything and not sure if my computer is clean or what?
Your system is clean now!


Uninstall our tools using delfix

Please follow these steps in order:

  • In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  • In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  • In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process
  • If there is still something left please delete it manualy.



How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:
    • Secunia Online Software Inspector - Checks if your software has updates available.
    • Filehippo Update Checkere - This tool also scans your computer for outdated software.
    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins in your Firefox browser.
  • Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.
  • Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.
I tired uninstalling combofix by renaming it, but when I run the program it just rescans and has a log come up. It never says program was uninstalled and still exists in my files. Am I able to uninstall program the way you would normally uninstall a program? Also, I am wondering if you could tell me what was wrong with my computer. Thank You for your time and your help. Kacy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI