Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Trojan Virus - AcroIEHelp.dll and a few others

  • 09-06-2009 2:49pm
    #1
    Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭


    Hi,
    I have a hijack this log of my Dell Laptop. Recently it's been getting slow with Internet explorer and crashing alot. AVG doesn't pick up Anything but Malware Bytes does. It cleans the laptop and then it either finds more files after I reboot or it shows as being clean.

    Whenever the laptop connects to the internet the trojans appear again.

    If anyone can have a look at the below hijack this file and advise what I need to do to get rid of this once and for all I'd be delighted.

    The main trojan that appears is in a file on C:\WINDOWS\System32\AcroIEhelp.dll while sometimes picking up on other possible trojans.
    I've read that this file relates to Adobe Acrobat and how it is supposed to be for opening PDF files through IE, yet takes up a lot of RAM.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:25:44, on 09/06/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    c:\windows\system32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    c:\windows\ehome\ehtray.exe
    c:\windows\system32\hkcmd.exe
    c:\windows\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    c:\windows\stsystra.exe
    c:\program files\synaptics\syntp\syntpenh.exe
    c:\windows\system32\wltray.exe
    c:\program files\creative\sbaudigy\surround mixer\ctsysvol.exe
    c:\windows\system32\rundll32.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    c:\program files\common files\installshield\updateservice\issch.exe
    c:\program files\dell\mediadirect\pcmservice.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\UAService7.exe
    c:\program files\windows defender\msascui.exe
    c:\program files\dell support center\bin\sprtcmd.exe
    c:\program files\java\jre6\bin\jusched.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    c:\progra~1\avg\avg8\avgtray.exe
    c:\docume~1\aaron\locals~1\temp\clclean.0001
    c:\program files\itunes\ituneshelper.exe
    c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
    c:\windows\system32\ctfmon.exe
    c:\program files\dna\btdna.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    c:\program files\widcomm\bluetooth software\bttray.exe
    c:\program files\digital line detect\dlg.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\Mobile Partner\Mobile Partner.exe
    c:\program files\windows live\messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    c:\program files\itunes\itunes.exe
    C:\WINDOWS\system32\lodupgd.jpg
    c:\program files\malwarebytes' anti-malware\mbam.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    c:\program files\trend micro\hijackthis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=8pPZOBNAeZLayr8Ub4zj4ZmanqU
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: (no name) - {B42BF63C-5354-4C5C-A789-66EFEEC5E1B0} - (no file)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.line6.net
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189787015656
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5C622FDF-5466-4ED8-9DC0-3D56E73E7816}: NameServer = 193.120.14.100 193.120.14.101
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 13324 bytes


Comments

  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hi

    Download Rooter.exe to your desktop
    • Then doubleclick it to start the tool
    • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here


  • Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


    Microsoft Windows XP Professional (5.1.2600) Service Pack 3

    C:\ [Fixed] - NTFS - (Total:88498 Mo/Free:2366 Mo)
    D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
    E:\ [CD-Rom] (Total:22 Mo/Free:0 Mo)
    F:\ [Removable] (Total:0 Mo/Free:0 Mo)
    G:\ [Removable] (Total:951 Mo/Free:28 Mo)

    09/06/2009|20:10

    \\ Processes..

    --Locked-- [System Process]
    System
    \SystemRoot\System32\smss.exe
    \??\C:\WINDOWS\system32\csrss.exe
    \??\C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    c:\windows\system32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\UAService7.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    C:\WINDOWS\System32\alg.exe
    c:\windows\ehome\ehtray.exe
    c:\windows\system32\hkcmd.exe
    c:\windows\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    c:\windows\stsystra.exe
    c:\program files\synaptics\syntp\syntpenh.exe
    c:\windows\system32\wltray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    c:\program files\creative\sbaudigy\surround mixer\ctsysvol.exe
    c:\windows\system32\rundll32.exe
    c:\program files\common files\installshield\updateservice\issch.exe
    c:\program files\dell\mediadirect\pcmservice.exe
    c:\program files\windows defender\msascui.exe
    c:\program files\dell support center\bin\sprtcmd.exe
    c:\program files\java\jre6\bin\jusched.exe
    c:\progra~1\avg\avg8\avgtray.exe
    c:\program files\itunes\ituneshelper.exe
    c:\docume~1\aaron\locals~1\temp\clclean.0001
    c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
    c:\windows\system32\ctfmon.exe
    c:\program files\dna\btdna.exe
    c:\program files\widcomm\bluetooth software\bttray.exe
    c:\program files\digital line detect\dlg.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mobile Partner\Mobile Partner.exe
    c:\program files\windows live\messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\cmd.exe
    c:\rooter$\rk.exe

    \\ Search..

    \\ ROOTKIT !!


    \\ Cracks & Keygens..

    C:\DOCUME~1\Aaron\Local Settings\Temp\Temporary Internet Files\Content.IE5\RGKWC4OO\lifeishotincracktown_200905131514[1].jpg
    C:\DOCUME~1\Aaron\My Documents\Ableton\Library\Presets\Audio Effects\Vinyl Distortion\Crack.adv
    C:\DOCUME~1\Aaron\My Documents\Downloads\Sony Sound Forge 9.0e Build 441\Keygen.exe


    1 - "C:\Rooter$\Rooter_1.txt" - 09/06/2009|20:12

    \\ Scan completed at 20:12


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hi
    • Download OTL to your desktop.
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Under Custom Scan paste this in

      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      %systemroot%\System32\antiwpa.dll
      %systemroot%\SYSTEM32\wpa.dll
      %systemroot%\setup\scripts\biestart.exe
      %systemroot%\system32\drivers\royal.sys
      %SYSTEMDRIVE%\*.
      %SYSTEMDRIVE%\*.*
      %PROGRAMFILES%\*.

    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
      • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
      • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


  • Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


    OTL Extras logfile created on: 09/06/2009 23:47:13 - Run 1
    OTL by OldTimer - Version 2.1.1.0 Folder = c:\documents and settings\aaron\desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy

    1.99 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.86% Memory free
    3.84 Gb Paging File | 3.28 Gb Available in Paging File | 85.41% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 86.42 Gb Total Space | 2.24 Gb Free Space | 2.59% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    Drive E: | 23.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: AC_D7T6943J
    Current User Name: Aaron
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Output = Minimal
    File Age = 30 Days
    Company Name Whitelist: On

    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
    "EnableFirewall" = 1

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
    C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program (CyberLink Corp.)
    C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
    %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
    C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer (Microsoft Corporation)
    C:\Program Files\DNA\btdna.exe:*:Enabled:DNA (BitTorrent, Inc.)
    C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent (BitTorrent, Inc.)
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
    C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
    C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary (Sun Microsystems, Inc.)
    C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
    C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)
    C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe:*:Enabled:Flickr Uploadr (Mozilla Foundation)
    C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
    C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player ()
    C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
    "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
    "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
    "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
    "{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
    "{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
    "{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
    "{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 11
    "{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
    "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
    "{2C4A5877-21D1-4A15-9D20-24BA54A24093}" = Playlist tool
    "{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
    "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
    "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
    "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
    "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
    "{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
    "{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = O2 Broadband USB Modem
    "{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
    "{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
    "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
    "{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
    "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
    "{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
    "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
    "{582D2A53-F426-4C5E-A2E6-43C1AB36B907}" = Safari
    "{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
    "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
    "{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
    "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
    "{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6DA9102E-199F-43A0-A36B-6EF48081A658}" = MobileMe Control Panel
    "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
    "{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
    "{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
    "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
    "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
    "{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
    "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
    "{8D2AE3F6-79DF-423C-91CB-389F6FB5837B}" = Andrea VoiceCenter
    "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
    "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
    "{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
    "{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
    "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
    "{90FF23FE-0E1B-40DF-A22E-B4C0372E5936}" = Iomega Product Registration
    "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
    "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
    "{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
    "{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
    "{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
    "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
    "{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
    "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
    "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
    "{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
    "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
    "{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
    "{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
    "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
    "{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
    "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
    "{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
    "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
    "{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
    "{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
    "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
    "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
    "{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
    "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
    "{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
    "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
    "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
    "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
    "{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
    "{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}" = Adobe Stock Photos 1.0
    "{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
    "12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
    "AC3Filter" = AC3Filter (remove only)
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
    "Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
    "Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
    "Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
    "Any Video Converter_is1" = Any Video Converter 2.7.1
    "AVG8Uninstall" = AVG 8.5
    "AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
    "AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
    "B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
    "Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
    "CAL" = Canon Camera Access Library
    "CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
    "CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
    "CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
    "CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
    "Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
    "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
    "Creative Audio Pack" = Creative Audio Pack
    "CSCLIB" = Canon Camera Support Core Library
    "DPP" = Canon Utilities Digital Photo Professional 2.2
    "DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.1.1.0
    "dvdSanta 4.00 - Create Your Own DVD Movies!_is1" = dvdSanta 4.00
    "EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
    "EOS Utility" = Canon Utilities EOS Utility
    "Flickr Uploadr" = Flickr Uploadr 3.1.4
    "FLV Player" = FLV Player 2.0, build 23
    "Google Desktop" = Google Desktop
    "HijackThis" = HijackThis 2.0.2
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{E914A24F-2412-4374-B420-86D21D6D444A}" = LEGO Star Wars
    "Line 6 Uninstaller" = Line 6 Uninstaller
    "Live 7.0.10" = Live 7.0.10
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Mobile Partner" = Mobile Partner
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "Neat Image_is1" = Neat Image v5 Demo (with plug-in)
    "Nero - Burning Rom!UninstallKey" = Nero OEM
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "O2 Broadband" = O2 Broadband
    "Photomatix Pro_is1" = Photomatix Pro version 2.5
    "PhotoStitch" = Canon Utilities PhotoStitch
    "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
    "RealPlayer 6.0" = RealPlayer
    "RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
    "SAMB_ADVMB_FILTER_DRV" = Sound Blaster ADVANCED MB Drivers
    "SearchAssist" = SearchAssist
    "Security Task Manager" = Security Task Manager 1.7h
    "Sound Blaster Audigy ADVANCED MB Product Registration" = Sound Blaster Audigy ADVANCED MB Product Registration
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "VLC media player" = VLC media player 0.9.9
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinRAR archiver" = WinRAR archiver
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "Xvid_is1" = Xvid 1.1.3 final uninstall
    "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "BitTorrent" = BitTorrent
    "BitTorrent DNA" = DNA

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 28/05/2009 18:46:50 | Computer Name = AC_D7T6943J | Source = Application Hang | ID = 1002
    Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 28/05/2009 18:47:53 | Computer Name = AC_D7T6943J | Source = Application Hang | ID = 1002
    Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 01/06/2009 12:17:05 | Computer Name = AC_D7T6943J | Source = MPSampleSubmission | ID = 5000
    Description =

    Error - 07/06/2009 13:49:18 | Computer Name = AC_D7T6943J | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module wiashext.dll, version 5.1.2600.5512, fault address 0x0000d3ff.

    Error - 07/06/2009 13:49:30 | Computer Name = AC_D7T6943J | Source = Application Error | ID = 1000
    Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
    dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

    Error - 07/06/2009 16:49:03 | Computer Name = AC_D7T6943J | Source = MPSampleSubmission | ID = 5000
    Description =

    Error - 08/06/2009 19:14:42 | Computer Name = AC_D7T6943J | Source = Application Error | ID = 1000
    Description = Faulting application softwareupdate.exe, version 2.1.1.116, faulting
    module unknown, version 0.0.0.0, fault address 0x64575653.

    Error - 09/06/2009 15:54:13 | Computer Name = AC_D7T6943J | Source = Application Error | ID = 1000
    Description = Faulting application softwareupdate.exe, version 2.1.1.116, faulting
    module , version 0.0.0.0, fault address 0x00000000.

    Error - 09/06/2009 18:15:31 | Computer Name = AC_D7T6943J | Source = Application Hang | ID = 1002
    Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 09/06/2009 18:15:36 | Computer Name = AC_D7T6943J | Source = Application Hang | ID = 1001
    Description = Fault bucket 1180947459.

    [ System Events ]
    Error - 01/06/2009 14:56:29 | Computer Name = AC_D7T6943J | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the Schedule service.

    Error - 04/06/2009 16:40:40 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452689
    Description = Time Provider NtpClient: An error occurred during DNS lookup of the
    manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
    again in 15 minutes. The error was: A socket operation was attempted to an unreachable
    host. (0x80072751)

    Error - 04/06/2009 16:40:40 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452701
    Description = The time provider NtpClient is configured to acquire time from one
    or more time sources, however none of the sources are currently accessible. No attempt
    to contact a source will be made for 14 minutes. NtpClient has no source of accurate
    time.

    Error - 04/06/2009 16:40:40 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452701
    Description = The time provider NtpClient is configured to acquire time from one
    or more time sources, however none of the sources are currently accessible. No attempt
    to contact a source will be made for 14 minutes. NtpClient has no source of accurate
    time.

    Error - 04/06/2009 16:51:38 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452689
    Description = Time Provider NtpClient: An error occurred during DNS lookup of the
    manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
    again in 15 minutes. The error was: A socket operation was attempted to an unreachable
    host. (0x80072751)

    Error - 04/06/2009 16:51:38 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452701
    Description = The time provider NtpClient is configured to acquire time from one
    or more time sources, however none of the sources are currently accessible. No attempt
    to contact a source will be made for 14 minutes. NtpClient has no source of accurate
    time.

    Error - 05/06/2009 18:19:05 | Computer Name = AC_D7T6943J | Source = Windows Update Agent | ID = 16
    Description = Unable to Connect: Windows is unable to connect to the automatic updates
    service and therefore cannot download and install updates according to the set
    schedule. Windows will continue to try to establish a connection.

    Error - 07/06/2009 15:10:16 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452689
    Description = Time Provider NtpClient: An error occurred during DNS lookup of the
    manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
    again in 15 minutes. The error was: A socket operation was attempted to an unreachable
    host. (0x80072751)

    Error - 07/06/2009 15:10:16 | Computer Name = AC_D7T6943J | Source = W32Time | ID = 39452701
    Description = The time provider NtpClient is configured to acquire time from one
    or more time sources, however none of the sources are currently accessible. No attempt
    to contact a source will be made for 14 minutes. NtpClient has no source of accurate
    time.

    Error - 07/06/2009 20:10:50 | Computer Name = AC_D7T6943J | Source = Windows Update Agent | ID = 16
    Description = Unable to Connect: Windows is unable to connect to the automatic updates
    service and therefore cannot download and install updates according to the set
    schedule. Windows will continue to try to establish a connection.


    < End of report >


  • Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


    OTL logfile created on: 09/06/2009 23:47:13 - Run 1
    OTL by OldTimer - Version 2.1.1.0 Folder = c:\documents and settings\aaron\desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy

    1.99 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.86% Memory free
    3.84 Gb Paging File | 3.28 Gb Available in Paging File | 85.41% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 86.42 Gb Total Space | 2.24 Gb Free Space | 2.59% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    Drive E: | 23.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: AC_D7T6943J
    Current User Name: Aaron
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Output = Minimal
    File Age = 30 Days
    Company Name Whitelist: On

    ========== Processes (SafeList) ==========

    PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\System32\WLTRYSVC.EXE ()
    PRC - c:\windows\system32\bcmwltry.exe (Dell Inc.)
    PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
    PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
    PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
    PRC - C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
    PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
    PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
    PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
    PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
    PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
    PRC - C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
    PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
    PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
    PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
    PRC - c:\windows\ehome\ehtray.exe (Microsoft Corporation)
    PRC - c:\windows\system32\hkcmd.exe (Intel Corporation)
    PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
    PRC - c:\windows\system32\igfxpers.exe (Intel Corporation)
    PRC - c:\windows\stsystra.exe (SigmaTel, Inc.)
    PRC - c:\program files\synaptics\syntp\syntpenh.exe (Synaptics, Inc.)
    PRC - c:\windows\system32\wltray.exe (Dell Inc.)
    PRC - c:\program files\creative\sbaudigy\surround mixer\ctsysvol.exe (Creative Technology Ltd)
    PRC - c:\program files\common files\installshield\updateservice\issch.exe (Macrovision Corporation)
    PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation)
    PRC - c:\program files\dell\mediadirect\pcmservice.exe (CyberLink Corp.)
    PRC - c:\program files\windows defender\msascui.exe (Microsoft Corporation)
    PRC - c:\program files\dell support center\bin\sprtcmd.exe (SupportSoft, Inc.)
    PRC - c:\program files\java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
    PRC - c:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
    PRC - c:\program files\itunes\ituneshelper.exe (Apple Inc.)
    PRC - c:\Documents and Settings\Aaron\Local Settings\Temp\clclean.0001 (Macrovision Europe Ltd.)
    PRC - c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe (Google Inc.)
    PRC - c:\program files\dna\btdna.exe (BitTorrent, Inc.)
    PRC - c:\program files\widcomm\bluetooth software\bttray.exe (Broadcom Corporation.)
    PRC - c:\program files\digital line detect\dlg.exe (BVRP Software)
    PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
    PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
    PRC - C:\Program Files\Mobile Partner\Mobile Partner.exe ()
    PRC - c:\program files\windows live\messenger\msnmsgr.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
    PRC - c:\documents and settings\aaron\desktop\otl.exe (OldTimer Tools)

    ========== Win32 Services (SafeList) ==========

    SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
    SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
    SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
    SRV - (btwdins [Auto | Running]) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
    SRV - (CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
    SRV - (Creative Labs Licensing Service [Auto | Running]) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
    SRV - (Creative Service for CDROM Access [Auto | Running]) -- C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
    SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe ()
    SRV - (ehRecvr [Auto | Running]) -- C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
    SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
    SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
    SRV - (GoogleDesktopManager [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
    SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
    SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
    SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
    SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
    SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
    SRV - (McrdSvc [Auto | Running]) -- C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
    SRV - (MHN [On_Demand | Stopped]) -- C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
    SRV - (RoxMediaDB9 [On_Demand | Running]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
    SRV - (RoxWatch9 [Auto | Running]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
    SRV - (sprtsvc_dellsupportcenter [Auto | Running]) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
    SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
    SRV - (UserAccess7 [Auto | Running]) -- C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
    SRV - (usnjsvc [On_Demand | Running]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
    SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
    SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
    SRV - (wltrysvc [Auto | Running]) -- C:\WINDOWS\System32\WLTRYSVC.EXE ()
    SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

    ========== Driver Services (SafeList) ==========

    DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
    DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
    DRV - (APPDRV [System | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
    DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
    DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
    DRV - (ASPI [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ASPI32.sys (Adaptec)
    DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
    DRV - (BCM43XX [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
    DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
    DRV - (btaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
    DRV - (BTDriver [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btport.sys (Broadcom Corporation.)
    DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
    DRV - (BTSERIAL [Auto | Running]) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
    DRV - (BTWDNDIS [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
    DRV - (btwhid [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwhid.sys (Broadcom Corporation.)
    DRV - (btwmodem [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btwmodem.sys (Broadcom Corporation.)
    DRV - (BTWUSB [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
    DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
    DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
    DRV - (CTUSFSYN [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
    DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
    DRV - (DLABMFSM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABMFSM.SYS (Roxio)
    DRV - (DLABOIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Roxio)
    DRV - (DLACDBHM [System | Running]) -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Roxio)
    DRV - (DLADResM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLADResM.SYS (Roxio)
    DRV - (DLAIFS_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Roxio)
    DRV - (DLAOPIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Roxio)
    DRV - (DLAPoolM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Roxio)
    DRV - (DLARTL_M [System | Running]) -- C:\WINDOWS\System32\Drivers\DLARTL_M.SYS (Roxio)
    DRV - (DLAUDFAM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Roxio)
    DRV - (DLAUDF_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Roxio)
    DRV - (DRVMCDB [Boot | Running]) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
    DRV - (DRVNDDM [Auto | Running]) -- C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Roxio)
    DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
    DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
    DRV - (E100B [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
    DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
    DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (HSFHWAZL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
    DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
    DRV - (hwdatacard [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
    DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
    DRV - (L6UX2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\L6UX2.sys (Line 6)
    DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
    DRV - (monfilt [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
    DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
    DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
    DRV - (omci [System | Running]) -- C:\WINDOWS\system32\DRIVERS\omci.sys (Dell Inc)
    DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
    DRV - (pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
    DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
    DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
    DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
    DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
    DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
    DRV - (rimmptsk [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
    DRV - (rimsptsk [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
    DRV - (rismxdp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
    DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
    DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
    DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
    DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
    DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
    DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
    DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
    DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
    DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
    DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
    DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
    DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
    O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
    O2 - BHO: (no name) - {B42BF63C-5354-4C5C-A789-66EFEEC5E1B0} - Reg Error: Key error. File not found
    O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
    O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
    O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r (Creative Technology Ltd)
    O4 - HKLM..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter (SupportSoft, Inc.)
    O4 - HKLM..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" ( )
    O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
    O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
    O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
    O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (Macrovision Corporation)
    O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
    O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
    O4 - HKLM..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon File not found
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" (CyberLink Corp.)
    O4 - HKLM..\Run: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime (Apple Inc.)
    O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
    O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
    O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
    O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
    O4 - HKCU..\Run: [BitTorrent DNA] "c:\program files\dna\btdna.exe" (BitTorrent, Inc.)
    O4 - HKCU..\Run: [SetDefaultMIDI] MIDIDef.exe (Creative Technology Ltd)
    O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript (Malwarebytes Corporation)
    O4 - Startup: C:\Documents and Settings\Aaron\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
    O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
    O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: line6.net ([]* in Trusted sites)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
    O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189787015656 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
    O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
    O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2005/08/16 04:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.) - E:\AutoRun.exe -- [ CDFS ]
    O32 - AutoRun File - [2008/06/07 21:58:08 | 00,000,052 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
    O33 - MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\Shell - "" = AutoRun
    O33 - MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\setup.exe -- [2008/04/14 01:12:34 | 00,023,040 | ---- | M] (Microsoft Corporation)
    O33 - MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\Shell - "" = AutoRun
    O33 - MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
    O33 - MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\Shell - "" = AutoRun
    O33 - MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\Shell - "" = AutoRun
    O33 - MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\Shell - "" = AutoRun
    O33 - MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\Shell\AutoRun\command - "" = E:\WIN\setup.exe -- File not found
    O33 - MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\Shell - "" = AutoRun
    O33 - MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\Shell - "" = AutoRun
    O33 - MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{821d763c-d116-11dd-b8fa-001c26efcb70}\Shell\AutoRun\command - "" = E:\wd_windows_tools\setup.exe -- File not found
    O33 - MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
    O33 - MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
    O33 - MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
    O33 - MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
    O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O34 - HKLM BootExecute: (autocheck) - File not found
    O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (*) - * [2009/06/09 23:41:55 | 00,000,000 | ---D | M]
    NetSvcs: 6to4 -
    NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll (Microsoft Corporation)
    NetSvcs: AudioSrv - C:\WINDOWS\System32\audiosrv.dll (Microsoft Corporation)
    NetSvcs: Browser - C:\WINDOWS\System32\browser.dll (Microsoft Corporation)
    NetSvcs: CryptSvc - C:\WINDOWS\System32\cryptsvc.dll (Microsoft Corporation)
    NetSvcs: DMServer - C:\WINDOWS\System32\dmserver.dll (Microsoft Corp.)
    NetSvcs: DHCP - C:\WINDOWS\System32\dhcpcsvc.dll (Microsoft Corporation)
    NetSvcs: ERSvc - C:\WINDOWS\System32\ersvc.dll (Microsoft Corporation)
    NetSvcs: EventSystem - C:\WINDOWS\system32\es.dll (Microsoft Corporation)
    NetSvcs: FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
    NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll (Microsoft Corporation)
    NetSvcs: Ias -
    NetSvcs: Iprip -
    NetSvcs: Irmon -
    NetSvcs: LanmanServer - C:\WINDOWS\System32\srvsvc.dll (Microsoft Corporation)
    NetSvcs: LanmanWorkstation - C:\WINDOWS\System32\wkssvc.dll (Microsoft Corporation)
    NetSvcs: Messenger - C:\WINDOWS\System32\msgsvc.dll (Microsoft Corporation)
    NetSvcs: Netman - C:\WINDOWS\System32\netman.dll (Microsoft Corporation)
    NetSvcs: Nla - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
    NetSvcs: Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)
    NetSvcs: NWCWorkstation -
    NetSvcs: Nwsapagent -
    NetSvcs: Rasauto - C:\WINDOWS\System32\rasauto.dll (Microsoft Corporation)
    NetSvcs: Rasman - C:\WINDOWS\System32\rasmans.dll (Microsoft Corporation)
    NetSvcs: Remoteaccess - C:\WINDOWS\System32\mprdim.dll (Microsoft Corporation)
    NetSvcs: Schedule - C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)
    NetSvcs: Seclogon - C:\WINDOWS\System32\seclogon.dll (Microsoft Corporation)
    NetSvcs: SENS - C:\WINDOWS\system32\sens.dll (Microsoft Corporation)
    NetSvcs: Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll (Microsoft Corporation)
    NetSvcs: SRService - C:\WINDOWS\system32\srsvc.dll (Microsoft Corporation)
    NetSvcs: Tapisrv - C:\WINDOWS\System32\tapisrv.dll (Microsoft Corporation)
    NetSvcs: Themes - C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
    NetSvcs: TrkWks - C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)
    NetSvcs: W32Time - C:\WINDOWS\system32\w32time.dll (Microsoft Corporation)
    NetSvcs: WZCSVC - C:\WINDOWS\System32\wzcsvc.dll (Microsoft Corporation)
    NetSvcs: Wmi - C:\WINDOWS\System32\advapi32.dll (Microsoft Corporation)
    NetSvcs: WmdmPmSp -
    NetSvcs: winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll (Microsoft Corporation)
    NetSvcs: wscsvc - C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)
    NetSvcs: xmlprov - C:\WINDOWS\System32\xmlprov.dll (Microsoft Corporation)
    NetSvcs: MHN - C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
    NetSvcs: BITS - C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)
    NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
    NetSvcs: ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
    NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
    NetSvcs: WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll (Microsoft Corporation)
    NetSvcs: napagent - C:\WINDOWS\System32\qagentrt.dll (Microsoft Corporation)
    NetSvcs: hkmsvc - C:\WINDOWS\System32\kmsvc.dll (Microsoft Corporation)
    MsConfig - StartUpReg: Dell QuickSet - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Dell Inc)
    MsConfig - StartUpReg: DellSupportCenter - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (SupportSoft, Inc.)
    MsConfig - StartUpReg: Google Desktop Search - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Google)
    MsConfig - StartUpReg: iTunesHelper - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Apple Inc.)
    MsConfig - StartUpReg: QuickTime Task - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Apple Inc.)
    MsConfig - StartUpReg: RoxioDragToDisc - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Roxio)
    MsConfig - StartUpReg: RoxWatchTray - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Sonic Solutions)
    MsConfig - StartUpReg: swg - hkey=HKCU - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - File not found
    MsConfig - StartUpReg: VoiceCenter - hkey=HKLM - key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run - (Andrea Electronics Corporation)
    MsConfig - State: "system.ini" - 0
    MsConfig - State: "win.ini" - 0
    MsConfig - State: "bootini" - 0
    MsConfig - State: "services" - 0
    MsConfig - State: "startup" - 2


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


    SafeBootMin: AppMgmt - (Microsoft Corporation)
    SafeBootMin: Base - Driver Group
    SafeBootMin: Boot Bus Extender - Driver Group
    SafeBootMin: Boot file system - Driver Group
    SafeBootMin: CryptSvc - (Microsoft Corporation)
    SafeBootMin: DcomLaunch - (Microsoft Corporation)
    SafeBootMin: dmadmin - (Microsoft Corp., Veritas Software)
    SafeBootMin: dmboot.sys - (Microsoft Corp., Veritas Software)
    SafeBootMin: dmio.sys - (Microsoft Corp., Veritas Software)
    SafeBootMin: dmload.sys - (Microsoft Corp., Veritas Software.)
    SafeBootMin: dmserver - (Microsoft Corp.)
    SafeBootMin: EventLog - (Microsoft Corporation)
    SafeBootMin: File system - Driver Group
    SafeBootMin: Filter - Driver Group
    SafeBootMin: HelpSvc - (Microsoft Corporation)
    SafeBootMin: Netlogon - (Microsoft Corporation)
    SafeBootMin: PCI Configuration - Driver Group
    SafeBootMin: PlugPlay - (Microsoft Corporation)
    SafeBootMin: PNP Filter - Driver Group
    SafeBootMin: Primary disk - Driver Group
    SafeBootMin: RpcSs - (Microsoft Corporation)
    SafeBootMin: SCSI Class - Driver Group
    SafeBootMin: sermouse.sys - Driver
    SafeBootMin: sr.sys - (Microsoft Corporation)
    SafeBootMin: SRService - (Microsoft Corporation)
    SafeBootMin: System Bus Extender - Driver Group
    SafeBootMin: vds - Service
    SafeBootMin: vga.sys - Driver
    SafeBootMin: vgasave.sys - (Microsoft Corporation)
    SafeBootMin: WinDefend - (Microsoft Corporation)
    SafeBootMin: WinMgmt - (Microsoft Corporation)
    SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootNet: AFD - (Microsoft Corporation)
    SafeBootNet: AppMgmt - (Microsoft Corporation)
    SafeBootNet: Base - Driver Group
    SafeBootNet: Boot Bus Extender - Driver Group
    SafeBootNet: Boot file system - Driver Group
    SafeBootNet: Browser - (Microsoft Corporation)
    SafeBootNet: CryptSvc - (Microsoft Corporation)
    SafeBootNet: DcomLaunch - (Microsoft Corporation)
    SafeBootNet: Dhcp - (Microsoft Corporation)
    SafeBootNet: dmadmin - (Microsoft Corp., Veritas Software)
    SafeBootNet: dmboot.sys - (Microsoft Corp., Veritas Software)
    SafeBootNet: dmio.sys - (Microsoft Corp., Veritas Software)
    SafeBootNet: dmload.sys - (Microsoft Corp., Veritas Software.)
    SafeBootNet: dmserver - (Microsoft Corp.)
    SafeBootNet: DnsCache - (Microsoft Corporation)
    SafeBootNet: EventLog - (Microsoft Corporation)
    SafeBootNet: File system - Driver Group
    SafeBootNet: Filter - Driver Group
    SafeBootNet: HelpSvc - (Microsoft Corporation)
    SafeBootNet: ip6fw.sys - (Microsoft Corporation)
    SafeBootNet: ipnat.sys - (Microsoft Corporation)
    SafeBootNet: LanmanServer - (Microsoft Corporation)
    SafeBootNet: LanmanWorkstation - (Microsoft Corporation)
    SafeBootNet: LmHosts - (Microsoft Corporation)
    SafeBootNet: Messenger - (Microsoft Corporation)
    SafeBootNet: NDIS - (Microsoft Corporation)
    SafeBootNet: NDIS Wrapper - Driver Group
    SafeBootNet: Ndisuio - (Microsoft Corporation)
    SafeBootNet: NetBIOS - (Microsoft Corporation)
    SafeBootNet: NetBIOSGroup - Driver Group
    SafeBootNet: NetBT - (Microsoft Corporation)
    SafeBootNet: NetDDEGroup - Driver Group
    SafeBootNet: Netlogon - (Microsoft Corporation)
    SafeBootNet: NetMan - (Microsoft Corporation)
    SafeBootNet: Network - Driver Group
    SafeBootNet: NetworkProvider - Driver Group
    SafeBootNet: NtLmSsp - (Microsoft Corporation)
    SafeBootNet: PCI Configuration - Driver Group
    SafeBootNet: PlugPlay - (Microsoft Corporation)
    SafeBootNet: PNP Filter - Driver Group
    SafeBootNet: PNP_TDI - Driver Group
    SafeBootNet: Primary disk - Driver Group
    SafeBootNet: rdpcdd.sys - (Microsoft Corporation)
    SafeBootNet: rdpdd.sys - (Microsoft Corporation)
    SafeBootNet: rdpwd.sys - (Microsoft Corporation)
    SafeBootNet: rdsessmgr - (Microsoft Corporation)
    SafeBootNet: RpcSs - (Microsoft Corporation)
    SafeBootNet: SCSI Class - Driver Group
    SafeBootNet: sermouse.sys - Driver
    SafeBootNet: SharedAccess - (Microsoft Corporation)
    SafeBootNet: sr.sys - (Microsoft Corporation)
    SafeBootNet: SRService - (Microsoft Corporation)
    SafeBootNet: Streams Drivers - Driver Group
    SafeBootNet: System Bus Extender - Driver Group
    SafeBootNet: Tcpip - (Microsoft Corporation)
    SafeBootNet: TDI - Driver Group
    SafeBootNet: tdpipe.sys - (Microsoft Corporation)
    SafeBootNet: tdtcp.sys - (Microsoft Corporation)
    SafeBootNet: termservice - (Microsoft Corporation)
    SafeBootNet: vga.sys - Driver
    SafeBootNet: vgasave.sys - (Microsoft Corporation)
    SafeBootNet: WinDefend - (Microsoft Corporation)
    SafeBootNet: WinMgmt - (Microsoft Corporation)
    SafeBootNet: WZCSVC - (Microsoft Corporation)
    SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
    SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
    SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
    SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
    SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
    ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
    ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
    ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
    ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
    ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
    ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
    ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
    ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
    ActiveX: {407408d4-94ed-4d86-ab69-a7f649d112ee} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf
    ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
    ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
    ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
    ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
    ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
    ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
    ActiveX: {467B03A5-ACFB-D7A7-3AB8-BD486B68719B} - Microsoft Windows Media Player 6.4
    ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
    ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
    ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
    ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
    ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
    ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
    ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
    ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
    ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
    ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
    ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
    ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
    ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
    ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
    ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)
    ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
    ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
    ActiveX: {BDE0FA43-6952-4BA8-8C58-09AF690F88E1} - Microsoft .NET Framework 1.0 Hotfix (KB930494)
    ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
    ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
    ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
    ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
    ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
    ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
    ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
    ActiveX: {EA29D410-CE41-4953-A862-2DE706A1DAD7} - Microsoft .NET Framework 1.0 Service Pack 3
    ActiveX: {FDC11A6F-17D1-48f9-9EA3-9051954BAA24} - .NET Framework
    ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
    ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
    ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
    ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
    ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
    ActiveX: KB910393 - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall
    Drivers32: aux - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: midi - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: midi1 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: midi2 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: midi3 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: midimapper - C:\WINDOWS\system32\midimap.dll (Microsoft Corporation)
    Drivers32: mixer - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: mixer1 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: mixer2 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: mixer3 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: msacm.ac3filter - C:\WINDOWS\system32\ac3filter.acm ()
    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.imaadpcm - C:\WINDOWS\system32\imaadp32.acm (Microsoft Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.msadpcm - C:\WINDOWS\system32\msadp32.acm (Microsoft Corporation)
    Drivers32: msacm.msaudio1 - C:\WINDOWS\system32\msaud32.acm (Microsoft Corporation)
    Drivers32: msacm.msg711 - C:\WINDOWS\system32\msg711.acm (Microsoft Corporation)
    Drivers32: msacm.msg723 - C:\WINDOWS\system32\msg723.acm (Microsoft Corporation)
    Drivers32: msacm.msgsm610 - C:\WINDOWS\system32\msgsm32.acm (Microsoft Corporation)
    Drivers32: msacm.siren - C:\WINDOWS\system32\sirenacm.dll (Microsoft Corporation)
    Drivers32: msacm.sl_anet - C:\WINDOWS\system32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\system32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: vidc.cvid - C:\WINDOWS\system32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.I420 - C:\WINDOWS\system32\msh263.drv (Microsoft Corporation)
    Drivers32: vidc.iv31 - C:\WINDOWS\system32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\system32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\system32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\system32\ir50_32.dll (Intel Corporation)
    Drivers32: vidc.iyuv - C:\WINDOWS\system32\iyuv_32.dll (Microsoft Corporation)
    Drivers32: vidc.M261 - C:\WINDOWS\system32\msh261.drv (Microsoft Corporation)
    Drivers32: vidc.M263 - C:\WINDOWS\system32\msh263.drv (Microsoft Corporation)
    Drivers32: vidc.mrle - C:\WINDOWS\system32\msrle32.dll (Microsoft Corporation)
    Drivers32: vidc.msvc - C:\WINDOWS\system32\msvidc32.dll (Microsoft Corporation)
    Drivers32: vidc.uyvy - C:\WINDOWS\system32\msyuv.dll (Microsoft Corporation)
    Drivers32: vidc.XVID - C:\WINDOWS\system32\xvidvfw.dll ()
    Drivers32: vidc.yuy2 - C:\WINDOWS\system32\msyuv.dll (Microsoft Corporation)
    Drivers32: vidc.yvu9 - C:\WINDOWS\system32\tsbyuv.dll (Microsoft Corporation)
    Drivers32: vidc.yvyu - C:\WINDOWS\system32\msyuv.dll (Microsoft Corporation)
    Drivers32: wave - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: wave1 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: wave2 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: wave3 - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)
    Drivers32: wavemapper - C:\WINDOWS\system32\msacm32.drv (Microsoft Corporation)

    ========== Files/Folders - Created Within 30 Days ==========

    [11 C:\WINDOWS\System32\*.tmp files]
    [2009/06/09 23:41:50 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Aaron\Desktop\OTL.exe
    [2009/06/09 23:25:20 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\ixokyxcy.sys
    [2009/06/09 20:10:36 | 00,000,000 | ---D | C] -- C:\Rooter$
    [2009/06/09 20:00:36 | 00,000,009 | ---- | C] () -- C:\WINDOWS\System32\urhtps.dat
    [2009/06/09 15:46:33 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Aaron\Desktop\Rooter.exe
    [2009/06/09 00:27:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Aaron\Application Data\Help
    [2009/06/09 00:25:30 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2009/06/04 21:35:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
    [2009/06/04 21:35:08 | 00,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
    [2009/05/28 22:56:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Aaron\Application Data\vlc
    [2009/05/28 22:54:41 | 00,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    [2009/05/28 21:03:59 | 21,374,56640 | -HS- | C] () -- C:\hiberfil.sys
    [2009/05/27 00:13:51 | 00,000,000 | ---D | C] -- C:\!KillBox
    [2009/05/26 20:02:29 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\Post01Mutex
    [2009/05/25 20:19:43 | 00,043,208 | ---- | C] () -- C:\WINDOWS\System32\shifld2.old
    [2009/05/20 00:08:09 | 00,000,000 | ---D | C] -- C:\Program Files\Macromedia
    [2009/05/18 23:41:36 | 00,039,296 | ---- | C] () -- C:\Documents and Settings\Aaron\Desktop\susanhunter01.jpg
    [2009/05/18 23:36:05 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2009/05/14 21:38:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xmldm
    [2009/05/14 21:38:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\cock
    [2009/05/14 20:26:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\UAs
    [2009/05/14 00:04:50 | 00,993,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysk.ini
    [2009/05/14 00:04:50 | 00,989,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osysk.dat
    [2009/05/14 00:04:50 | 00,919,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysw.ini
    [2009/05/14 00:04:50 | 00,914,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osysw.dat
    [2009/05/14 00:04:50 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysp.ini
    [2009/05/14 00:04:50 | 00,020,247 | ---- | C] () -- C:\WINDOWS\System32\wincode.dat
    [2009/05/14 00:04:50 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osysp.dat
    [2009/05/14 00:04:50 | 00,006,394 | ---- | C] () -- C:\WINDOWS\System32\krncode.dat
    [2009/05/14 00:04:50 | 00,001,575 | ---- | C] () -- C:\WINDOWS\System32\pwrcode.dat
    [2009/05/14 00:04:45 | 00,043,728 | ---- | C] () -- C:\WINDOWS\System32\ldshyf1.old
    [2009/05/11 17:40:22 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2008/03/11 23:45:22 | 00,782,336 | ---- | C] () -- C:\WINDOWS\System32\IlmImf.dll
    [2008/03/11 23:45:22 | 00,446,464 | ---- | C] () -- C:\WINDOWS\System32\Photomatix_jpg.dll
    [2008/03/11 23:45:22 | 00,353,280 | ---- | C] () -- C:\WINDOWS\System32\pmtf2.dll
    [2008/03/11 23:45:22 | 00,266,240 | ---- | C] () -- C:\WINDOWS\System32\Photomatix25Lib.dll
    [2008/03/11 23:45:22 | 00,249,856 | ---- | C] () -- C:\WINDOWS\System32\Photomatix25Lib2.dll
    [2008/03/11 23:45:22 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\pmtf1.dll
    [2008/03/11 23:45:22 | 00,204,288 | ---- | C] () -- C:\WINDOWS\System32\pmtf3.dll
    [2008/03/11 23:45:22 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\Photomatix25Lib3.dll
    [2008/03/11 23:45:22 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\pmexr.dll
    [2008/03/11 23:45:22 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmbm.dll
    [2007/12/05 00:47:02 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2007/11/25 13:54:12 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
    [2007/11/25 12:48:43 | 00,000,024 | ---- | C] () -- C:\WINDOWS\System32\sysogg.dll
    [2007/11/14 19:06:42 | 00,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
    [2007/09/29 22:43:36 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
    [2007/09/29 22:43:36 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
    [2007/09/29 22:43:36 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
    [2007/09/29 10:14:03 | 00,000,403 | ---- | C] () -- C:\WINDOWS\boxworld.ini
    [2007/09/20 18:40:53 | 00,000,026 | ---- | C] () -- C:\WINDOWS\dvdSanta.INI
    [2007/09/13 17:59:35 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/09/13 17:39:36 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2007/09/13 17:39:36 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2007/09/11 16:39:19 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2007/09/11 16:30:43 | 00,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
    [2007/09/11 16:30:43 | 00,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2007/09/11 16:25:00 | 00,010,820 | ---- | C] () -- C:\WINDOWS\System32\CTSBMB.INI
    [2007/09/11 16:24:37 | 00,000,040 | ---- | C] () -- C:\WINDOWS\System32\mes2046.dll
    [2007/09/11 16:24:19 | 00,022,629 | ---- | C] () -- C:\WINDOWS\System32\CiFilter.ini
    [2007/09/11 16:23:19 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
    [2007/09/11 16:23:17 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
    [2007/09/11 15:56:39 | 01,355,042 | ---- | C] () -- C:\WINDOWS\System32\CTMBHA.DLL
    [2007/09/11 15:55:57 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
    [2007/09/11 15:54:47 | 00,001,204 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2006/11/07 04:25:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2006/09/16 23:36:50 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
    [2006/09/16 23:36:50 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
    [2006/05/24 18:16:22 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
    [2005/08/16 04:37:24 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
    [2005/08/16 04:18:43 | 00,000,603 | ---- | C] () -- C:\WINDOWS\win.ini
    [2005/08/16 04:18:41 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
    [2005/08/05 14:01:54 | 00,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2005/02/17 12:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
    [2005/02/17 12:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
    [2001/11/14 13:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

    ========== Files - Modified Within 30 Days ==========

    [11 C:\WINDOWS\System32\*.tmp files]
    [1 C:\WINDOWS\*.tmp files]
    [2009/06/09 23:42:05 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Aaron\Desktop\OTL.exe
    [2009/06/09 23:25:20 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\drivers\ixokyxcy.sys
    [2009/06/09 23:13:50 | 00,000,577 | ---- | M] () -- C:\Documents and Settings\Aaron\My Documents\My Sharing Folders.lnk
    [2009/06/09 21:01:32 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2009/06/09 20:58:12 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Aaron\Local Settings\desktop.ini
    [2009/06/09 20:58:12 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2009/06/09 20:58:09 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2009/06/09 20:58:08 | 21,374,56640 | -HS- | M] () -- C:\hiberfil.sys
    [2009/06/09 20:49:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2009/06/09 20:00:36 | 00,000,009 | ---- | M] () -- C:\WINDOWS\System32\urhtps.dat
    [2009/06/09 15:46:46 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Aaron\Desktop\Rooter.exe
    [2009/06/08 23:57:03 | 00,021,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\powrprof.dll
    [2009/06/08 23:57:03 | 00,021,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysp.ini
    [2009/06/08 23:57:03 | 00,020,247 | ---- | M] () -- C:\WINDOWS\System32\wincode.dat
    [2009/06/08 23:57:03 | 00,006,394 | ---- | M] () -- C:\WINDOWS\System32\krncode.dat
    [2009/06/08 23:57:03 | 00,001,575 | ---- | M] () -- C:\WINDOWS\System32\pwrcode.dat
    [2009/06/08 23:57:02 | 00,993,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysk.ini
    [2009/06/08 23:57:02 | 00,993,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\kernel32.dll
    [2009/06/08 23:57:02 | 00,993,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kernel32.dll
    [2009/06/08 23:57:00 | 00,919,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet.dll
    [2009/06/08 23:57:00 | 00,919,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysw.ini
    [2009/06/08 23:57:00 | 00,919,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
    [2009/06/08 23:56:52 | 00,043,208 | ---- | M] () -- C:\WINDOWS\System32\shifld2.old
    [2009/06/08 23:55:51 | 36,931,938 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
    [2009/06/08 23:55:51 | 00,066,205 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
    [2009/06/08 23:48:53 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2009/06/07 18:37:15 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2009/05/28 22:54:41 | 00,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    [2009/05/26 20:02:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\Post01Mutex
    [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2009/05/25 20:23:08 | 00,382,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2009/05/25 20:23:07 | 00,053,838 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2009/05/25 20:23:04 | 00,441,626 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2009/05/24 22:32:18 | 00,043,728 | ---- | M] () -- C:\WINDOWS\System32\ldshyf1.old
    [2009/05/18 23:41:17 | 00,039,296 | ---- | M] () -- C:\Documents and Settings\Aaron\Desktop\susanhunter01.jpg

    ========== LOP Check ==========

    [2009/06/09 00:27:26 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Aaron\Application Data
    [2009/04/06 19:29:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Ableton
    [2008/09/22 23:53:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Adobe
    [2007/09/23 20:42:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\AdobeUM
    [2009/04/02 20:24:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Any Video Converter
    [2008/12/17 01:42:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Apple Computer
    [2009/02/27 17:16:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\AVS4YOU
    [2009/05/27 00:41:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\BitTorrent
    [2007/10/25 21:10:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Canon
    [2007/09/29 10:19:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\CyberLink
    [2009/06/09 23:42:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\DNA
    [2009/02/03 00:06:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\dvdcss
    [2009/03/08 19:03:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Flickr
    [2007/09/13 17:27:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Google
    [2007/09/14 17:39:48 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Aaron\Application Data\GTek
    [2009/06/09 00:27:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Help
    [2005/08/16 04:50:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Identities
    [2007/09/11 16:22:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\InstallShield
    [2008/05/01 21:02:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Leadertech
    [2007/09/14 17:18:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Macromedia
    [2008/11/04 20:16:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Malwarebytes
    [2008/05/01 20:59:54 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Aaron\Application Data\Microsoft
    [2009/03/08 19:03:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Mozilla
    [2007/09/24 22:58:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Opera
    [2009/04/06 19:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Propellerhead Software
    [2008/04/09 22:27:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Real
    [2007/10/13 21:15:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Roxio
    [2009/05/02 10:32:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Sierra Wireless
    [2007/12/29 20:30:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Sun
    [2007/12/18 20:53:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\U3
    [2009/06/04 23:43:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\vlc
    [2009/02/22 17:29:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Vso
    [2008/02/11 23:18:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\WinRAR
    [2009/04/23 21:03:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\ZoomBrowser EX
    [2009/06/04 21:35:18 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
    [2009/03/24 19:59:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
    [2009/04/09 23:52:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [2009/04/06 19:29:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ableton
    [2008/08/10 20:10:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
    [2007/09/13 17:48:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe Systems
    [2007/09/13 17:41:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
    [2007/09/13 17:42:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
    [2009/03/18 20:40:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg8
    [2009/02/27 17:16:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
    [2007/09/11 16:24:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Creative Labs
    [2007/09/11 16:36:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
    [2008/03/01 15:19:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
    [2008/08/05 21:15:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
    [2009/01/21 01:45:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
    [2007/09/14 17:39:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gtek
    [2007/09/11 16:27:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield
    [2009/04/06 19:59:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Line 6
    [2008/11/04 20:16:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2007/12/08 18:47:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
    [2009/05/11 17:39:52 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
    [2009/04/06 19:45:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
    [2007/09/11 16:30:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Roxio
    [2009/06/04 21:39:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
    [2007/09/11 16:27:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonic
    [2009/04/06 19:41:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonoma Wire Works
    [2008/10/08 00:19:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    [2007/12/04 22:19:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
    [2007/09/14 17:35:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    [2008/04/02 22:50:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
    [2009/02/24 21:07:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
    [2009/06/09 20:49:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    [2004/08/10 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
    [2009/06/09 21:01:32 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
    [2009/06/09 20:58:12 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

    ========== Purity Check ==========


    ========== Custom Scans ==========


    < %systemroot%\System32\antiwpa.dll >

    < %systemroot%\SYSTEM32\wpa.dll >

    < %systemroot%\setup\scripts\biestart.exe >

    < %systemroot%\system32\drivers\royal.sys >

    < %SYSTEMDRIVE%\*. >
    [2009/06/09 23:41:55 | 00,000,000 | ---D | M] -- C:
    [2009/05/28 23:59:30 | 00,000,000 | ---D | M] -- C:\!KillBox
    [2009/05/29 14:08:44 | 00,000,000 | -H-D | M] -- C:\$AVG8.VAULT$
    [2008/03/22 20:04:43 | 00,000,000 | ---D | M] -- C:\086a95cdd49f4a0477
    [2008/03/22 20:03:36 | 00,000,000 | ---D | M] -- C:\cdb0f108ef8656b02ea480073847
    [2007/09/14 18:48:48 | 00,000,000 | ---D | M] -- C:\dell
    [2007/09/13 17:25:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings
    [2006/11/23 06:47:34 | 00,000,000 | ---D | M] -- C:\drivers
    [2007/09/14 17:20:10 | 00,000,000 | ---D | M] -- C:\i386
    [2009/06/09 20:59:03 | 00,000,000 | ---D | M] -- C:\MDT
    [2009/06/09 23:25:20 | 00,000,000 | R--D | M] -- C:\Program Files
    [2007/09/13 18:07:37 | 00,000,000 | -HSD | M] -- C:\RECYCLER
    [2009/06/09 20:12:53 | 00,000,000 | ---D | M] -- C:\Rooter$
    [2007/09/13 17:25:27 | 00,000,000 | -HSD | M] -- C:\System Volume Information
    [2008/03/11 23:17:49 | 00,000,000 | ---D | M] -- C:\TempDVD
    [2009/06/09 20:58:44 | 00,000,000 | ---D | M] -- C:\WINDOWS

    < %SYSTEMDRIVE%\*.* >
    [2005/08/16 04:43:04 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2008/10/29 01:30:47 | 00,000,209 | RHS- | M] () -- C:\boot.ini
    [2005/08/16 04:43:04 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2007/09/11 15:59:34 | 00,006,867 | RH-- | M] () -- C:\dell.sdr
    [2008/03/11 23:20:04 | 00,002,998 | ---- | M] () -- C:\dvdlog.txt
    [2008/03/11 23:20:05 | 00,000,572 | ---- | M] () -- C:\graph.txt
    [2009/06/09 20:58:08 | 21,374,56640 | -HS- | M] () -- C:\hiberfil.sys
    [2007/09/13 17:35:39 | 00,004,128 | ---- | M] () -- C:\INFCACHE.1
    [2005/08/16 04:43:04 | 00,000,000 | -H-- | M] () -- C:\IO.SYS
    [2005/08/16 04:43:04 | 00,000,000 | -H-- | M] () -- C:\MSDOS.SYS
    [2007/11/02 20:59:50 | 00,003,830 | ---- | M] () -- C:\NBA Jam (Beta) [b1+C].inp
    [2008/09/04 01:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
    [2004/08/10 05:00:00 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2008/08/27 17:34:35 | 00,250,048 | RHS- | M] () -- C:\ntldr
    [2009/06/09 20:58:07 | 21,453,86496 | -HS- | M] () -- C:\pagefile.sys
    [2009/06/09 20:12:53 | 00,004,556 | ---- | M] () -- C:\Rooter.txt
    [2007/12/07 22:07:43 | 00,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
    [2008/07/07 20:46:19 | 00,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
    [2007/12/07 22:07:42 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
    [2008/07/07 20:46:19 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm

    < %PROGRAMFILES%\*. >
    [2009/06/09 23:25:20 | 00,000,000 | R--D | M] -- C:\Program Files
    [2009/05/02 10:41:06 | 00,000,000 | ---D | M] -- C:\Program Files\7-Zip
    [2009/04/06 19:25:54 | 00,000,000 | ---D | M] -- C:\Program Files\Ableton
    [2007/11/28 00:49:44 | 00,000,000 | ---D | M] -- C:\Program Files\AC3Filter
    [2009/05/20 00:08:09 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
    [2007/11/21 22:58:54 | 00,000,000 | ---D | M] -- C:\Program Files\Ahead
    [2009/03/08 14:46:30 | 00,000,000 | ---D | M] -- C:\Program Files\Any Video Converter
    [2008/08/10 16:23:53 | 00,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
    [2009/03/18 20:40:54 | 00,000,000 | ---D | M] -- C:\Program Files\AVG
    [2009/03/08 13:08:46 | 00,000,000 | ---D | M] -- C:\Program Files\AVS4YOU
    [2007/09/11 16:34:28 | 00,000,000 | ---D | M] -- C:\Program Files\BAE
    [2008/07/18 17:53:29 | 00,000,000 | ---D | M] -- C:\Program Files\BitTorrent
    [2009/05/02 10:55:10 | 00,000,000 | ---D | M] -- C:\Program Files\Bonjour
    [2007/09/11 16:22:50 | 00,000,000 | ---D | M] -- C:\Program Files\Broadcom
    [2007/10/15 22:38:46 | 00,000,000 | ---D | M] -- C:\Program Files\Canon
    [2009/05/11 17:40:22 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files
    [2005/08/16 04:38:36 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
    [2007/09/11 16:20:22 | 00,000,000 | ---D | M] -- C:\Program Files\CONEXANT
    [2007/09/11 16:25:51 | 00,000,000 | ---D | M] -- C:\Program Files\Creative
    [2007/09/11 16:25:23 | 00,000,000 | -H-D | M] -- C:\Program Files\Creative Installation Information
    [2008/01/10 00:53:03 | 00,000,000 | ---D | M] -- C:\Program Files\CyberLink
    [2007/09/11 16:35:56 | 00,000,000 | ---D | M] -- C:\Program Files\Dell
    [2007/12/04 22:19:10 | 00,000,000 | ---D | M] -- C:\Program Files\Dell Support Center
    [2007/09/11 16:34:08 | 00,000,000 | ---D | M] -- C:\Program Files\DellSupport
    [2007/09/11 16:23:11 | 00,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
    [2008/12/23 20:34:51 | 00,000,000 | ---D | M] -- C:\Program Files\DivX
    [2009/06/09 20:58:54 | 00,000,000 | ---D | M] -- C:\Program Files\DNA
    [2007/12/05 00:37:08 | 00,000,000 | ---D | M] -- C:\Program Files\DVD Genie
    [2009/02/13 22:04:33 | 00,000,000 | ---D | M] -- C:\Program Files\DVDFab 5
    [2009/02/13 19:02:58 | 00,000,000 | ---D | M] -- C:\Program Files\DVDFab Platinum 3
    [2008/03/11 23:20:04 | 00,000,000 | ---D | M] -- C:\Program Files\dvdSanta
    [2005/08/16 20:51:50 | 00,000,000 | ---D | M] -- C:\Program Files\EnglishOtto
    [2009/05/28 22:50:26 | 00,000,000 | ---D | M] -- C:\Program Files\Flickr Uploadr
    [2008/02/12 21:07:48 | 00,000,000 | ---D | M] -- C:\Program Files\FLV Player
    [2007/09/29 22:44:28 | 00,000,000 | ---D | M] -- C:\Program Files\Fox
    [2005/08/16 20:54:44 | 00,000,000 | ---D | M] -- C:\Program Files\GemMaster
    [2009/01/21 02:15:24 | 00,000,000 | ---D | M] -- C:\Program Files\Google
    [2007/12/22 13:22:26 | 00,000,000 | ---D | M] -- C:\Program Files\Grisoft
    [2009/03/22 12:25:45 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
    [2009/05/04 16:53:08 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
    [2008/05/01 21:02:27 | 00,000,000 | ---D | M] -- C:\Program Files\Iomega
    [2009/04/09 23:52:04 | 00,000,000 | ---D | M] -- C:\Program Files\iPod
    [2009/04/09 23:52:30 | 00,000,000 | ---D | M] -- C:\Program Files\iTunes
    [2008/12/13 19:03:46 | 00,000,000 | ---D | M] -- C:\Program Files\Java
    [2009/04/06 19:59:37 | 00,000,000 | ---D | M] -- C:\Program Files\Line6
    [2007/11/25 13:43:51 | 00,000,000 | ---D | M] -- C:\Program Files\LucasArts
    [2009/05/20 00:08:10 | 00,000,000 | ---D | M] -- C:\Program Files\Macromedia
    [2009/05/26 19:56:00 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2008/08/27 17:45:25 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger
    [2009/05/18 23:36:05 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft
    [2007/09/13 17:58:54 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
    [2005/08/16 04:43:46 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
    [2007/09/13 17:58:16 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
    [2008/09/09 20:48:35 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
    [2009/04/30 00:10:40 | 00,000,000 | ---D | M] -- C:\Program Files\Mobile Partner
    [2007/09/11 16:23:05 | 00,000,000 | ---D | M] -- C:\Program Files\Modem Helper
    [2008/08/27 17:39:51 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
    [2005/08/16 04:37:22 | 00,000,000 | ---D | M] -- C:\Program Files\MSN
    [2005/08/16 04:37:30 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
    [2007/10/02 20:38:47 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
    [2007/09/24 22:47:09 | 00,000,000 | ---D | M] -- C:\Program Files\Neat Image
    [2008/08/27 17:37:04 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting
    [2007/09/11 16:22:58 | 00,000,000 | ---D | M] -- C:\Program Files\NetWaiting
    [2007/11/03 18:09:41 | 00,000,000 | ---D | M] -- C:\Program Files\O2
    [2005/08/16 04:38:24 | 00,000,000 | ---D | M] -- C:\Program Files\Online Services
    [2008/08/27 17:36:59 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express
    [2008/03/19 18:48:36 | 00,000,000 | ---D | M] -- C:\Program Files\Photomatix
    [2009/03/24 19:56:51 | 00,000,000 | ---D | M] -- C:\Program Files\QuickTime
    [2008/04/09 22:24:23 | 00,000,000 | ---D | M] -- C:\Program Files\Real
    [2005/08/16 20:58:50 | 00,000,000 | ---D | M] -- C:\Program Files\RGB
    [2007/09/11 16:30:42 | 00,000,000 | ---D | M] -- C:\Program Files\Roxio
    [2008/12/17 01:42:34 | 00,000,000 | ---D | M] -- C:\Program Files\Safari
    [2009/06/09 00:27:26 | 00,000,000 | ---D | M] -- C:\Program Files\Security Task Manager
    [2009/05/02 10:32:06 | 00,000,000 | ---D | M] -- C:\Program Files\Sierra Wireless Inc
    [2007/09/11 16:20:16 | 00,000,000 | ---D | M] -- C:\Program Files\Sigmatel
    [2009/05/02 10:36:42 | 00,000,000 | ---D | M] -- C:\Program Files\Sonoma Wire Works
    [2008/10/08 21:25:35 | 00,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
    [2008/09/09 20:39:31 | 00,000,000 | ---D | M] -- C:\Program Files\Sun
    [2007/09/11 16:22:20 | 00,000,000 | ---D | M] -- C:\Program Files\Synaptics
    [2009/06/09 00:25:30 | 00,000,000 | ---D | M] -- C:\Program Files\Trend Micro
    [2005/08/16 04:50:18 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
    [2007/09/13 17:40:03 | 00,000,000 | ---D | M] -- C:\Program Files\VideoLAN
    [2007/09/11 16:23:34 | 00,000,000 | ---D | M] -- C:\Program Files\WIDCOMM
    [2007/09/14 17:45:15 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Defender
    [2008/03/03 00:45:14 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Live
    [2008/03/22 20:05:23 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
    [2008/03/22 20:05:21 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
    [2008/08/27 17:37:00 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
    [2005/08/16 04:37:56 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Plus
    [2005/08/16 04:40:46 | 00,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
    [2008/02/11 23:17:55 | 00,000,000 | ---D | M] -- C:\Program Files\WinRAR
    [2005/08/16 04:43:46 | 00,000,000 | ---D | M] -- C:\Program Files\xerox
    [2007/09/14 16:16:47 | 00,000,000 | ---D | M] -- C:\Program Files\XviD

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\My Documents\Downloads:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\susanhunter01.jpg:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\recording_audio[2].mov:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\MP3s:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\IMG_5070.jpg:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\IMG_4949.jpg:Roxio EMC Stream
    < End of report >


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hi

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following
      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      C:\DOCUME~1\Aaron\My Documents\Downloads\Sony Sound Forge 9.0e Build 441\Keygen.exe
      
      PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
      O2 - BHO: (no name) - {B42BF63C-5354-4C5C-A789-66EFEEC5E1B0} - Reg Error: Key error. File not found
      O4 - HKLM..\Run: [] File not found
      O33 - MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\Shell - "" = AutoRun
      O33 - MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
      O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\setup.exe -- [2008/04/14 01:12:34 | 00,023,040 | ---- | M] (Microsoft Corporation)
      O33 - MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\Shell - "" = AutoRun
      O33 - MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
      O33 - MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\Shell - "" = AutoRun
      O33 - MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\Shell - "" = AutoRun
      O33 - MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\Shell - "" = AutoRun
      O33 - MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\Shell\AutoRun\command - "" = E:\WIN\setup.exe -- File not found
      O33 - MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\Shell - "" = AutoRun
      O33 - MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\Shell - "" = AutoRun
      O33 - MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{821d763c-d116-11dd-b8fa-001c26efcb70}\Shell\AutoRun\command - "" = E:\wd_windows_tools\setup.exe -- File not found
      O33 - MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
      O33 - MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
      O33 - MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
      O33 - MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
      O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
      [2009/06/09 23:25:20 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\ixokyxcy.sys
      [2009/06/09 20:00:36 | 00,000,009 | ---- | C] () -- C:\WINDOWS\System32\urhtps.dat
      [2009/06/04 21:35:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
      [2009/06/04 21:35:08 | 00,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
      [2009/05/25 20:19:43 | 00,043,208 | ---- | C] () -- C:\WINDOWS\System32\shifld2.old
      [2009/05/14 21:38:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xmldm
      [2009/05/14 21:38:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\cock
      [2009/05/14 20:26:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\UAs
      [2009/05/14 00:04:50 | 00,993,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysk.ini
      [2009/05/14 00:04:50 | 00,989,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osysk.dat
      [2009/05/14 00:04:50 | 00,919,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysw.ini
      [2009/05/14 00:04:50 | 00,914,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osysw.dat
      [2009/05/14 00:04:50 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nsysp.ini
      [2009/05/14 00:04:50 | 00,020,247 | ---- | C] () -- C:\WINDOWS\System32\wincode.dat
      [2009/05/14 00:04:50 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osysp.dat
      [2009/05/14 00:04:50 | 00,006,394 | ---- | C] () -- C:\WINDOWS\System32\krncode.dat
      [2009/05/14 00:04:50 | 00,001,575 | ---- | C] () -- C:\WINDOWS\System32\pwrcode.dat
      [2009/05/14 00:04:45 | 00,043,728 | ---- | C] () -- C:\WINDOWS\System32\ldshyf1.old
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot when it is done
    • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time, and don't run the Custom Scan )


  • Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


    ========== OTL ==========
    Process explorer.exe killed successfully!
    No active process named MsMpEng.exe was found!
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B42BF63C-5354-4C5C-A789-66EFEEC5E1B0}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B42BF63C-5354-4C5C-A789-66EFEEC5E1B0}\ not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25a5d78f-1662-11de-adec-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25a5d78f-1662-11de-adec-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{25a5d78f-1662-11de-adec-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25a5d78f-1662-11de-adec-001c26efcb70}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
    C:\WINDOWS\system32\setup.exe moved successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d69f22a-ada2-11dc-bc22-001c26efcb70}\ not found.
    File E:\LaunchU3.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c167c82-8a2f-11dc-bbd2-001c26efcb70}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74aba132-3368-11de-ae04-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74aba132-3368-11de-ae04-001c26efcb70}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74aba132-3368-11de-ae04-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74aba132-3368-11de-ae04-001c26efcb70}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74aba13a-3368-11de-ae04-ff0900a4e70e}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74aba13a-3368-11de-ae04-ff0900a4e70e}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74aba13a-3368-11de-ae04-ff0900a4e70e}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74aba13a-3368-11de-ae04-ff0900a4e70e}\ not found.
    File E:\WIN\setup.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77a7ad79-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77a7ad79-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77a7ad79-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77a7ad79-781e-11dd-b88d-001c2393785c}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77a7ad7d-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77a7ad7d-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77a7ad7d-781e-11dd-b88d-001c2393785c}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77a7ad7d-781e-11dd-b88d-001c2393785c}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{821d763c-d116-11dd-b8fa-001c26efcb70}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{821d763c-d116-11dd-b8fa-001c26efcb70}\ not found.
    File E:\wd_windows_tools\setup.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8871316d-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8871316d-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8871316d-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8871316d-36fe-11de-ae05-001c264a068b}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8871316e-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8871316e-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8871316e-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8871316e-36fe-11de-ae05-001c264a068b}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88713170-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88713170-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88713170-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88713170-36fe-11de-ae05-001c264a068b}\ not found.
    File E:\AutoRun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88713171-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88713171-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88713171-36fe-11de-ae05-001c264a068b}\ not found.
    File E:\AutoRun.exe not found.
    File C:\WINDOWS\System32\drivers\ixokyxcy.sys not found.
    File C:\WINDOWS\System32\urhtps.dat not found.
    Folder C:\Documents and Settings\All Users\Application Data\SecTaskMan not found.
    Folder C:\Program Files\Security Task Manager not found.
    File C:\WINDOWS\System32\shifld2.old not found.
    Folder C:\WINDOWS\System32\xmldm not found.
    Folder C:\WINDOWS\System32\cock not found.
    Folder C:\WINDOWS\System32\UAs not found.
    File C:\WINDOWS\System32\nsysk.ini not found.
    File C:\WINDOWS\System32\osysk.dat not found.
    File C:\WINDOWS\System32\nsysw.ini not found.
    File C:\WINDOWS\System32\osysw.dat not found.
    File C:\WINDOWS\System32\nsysp.ini not found.
    File C:\WINDOWS\System32\wincode.dat not found.
    File C:\WINDOWS\System32\osysp.dat not found.
    File C:\WINDOWS\System32\krncode.dat not found.
    File C:\WINDOWS\System32\pwrcode.dat not found.
    File C:\WINDOWS\System32\ldshyf1.old not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========
    File delete failed. C:\Documents and Settings\Aaron\Local Settings\Temp\clclean.0001.dir.0000\~df394b.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Aaron\Local Settings\Temp\clclean.0001.dir.0000\~efe2.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Network Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Network Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\JETC0A0.tmp scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_25c.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTL by OldTimer - Version 2.1.1.0 log created on 06102009_205937

    Files moved on Reboot...
    File C:\Documents and Settings\Aaron\Local Settings\Temp\clclean.0001.dir.0000\~df394b.tmp not found!
    File C:\Documents and Settings\Aaron\Local Settings\Temp\clclean.0001.dir.0000\~efe2.tmp not found!
    C:\WINDOWS\temp\JETC0A0.tmp moved successfully.
    File C:\WINDOWS\temp\Perflib_Perfdata_25c.dat not found!

    Registry entries deleted on Reboot...


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    post a new OTL log as well


  • Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


    I should add that Internet Explorer is now shutting down all the time since I ran the scan from you're last post. Not sure if this is supposed to happen.



    OTL logfile created on: 10/06/2009 23:17:12 - Run 2
    OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Aaron\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy

    1.99 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 62.20% Memory free
    3.84 Gb Paging File | 3.16 Gb Available in Paging File | 82.44% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 86.42 Gb Total Space | 2.77 Gb Free Space | 3.21% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    Drive E: | 23.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: AC_D7T6943J
    Current User Name: Aaron
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Output = Minimal
    File Age = 30 Days
    Company Name Whitelist: On

    ========== Processes (SafeList) ==========

    PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\System32\WLTRYSVC.EXE ()
    PRC - C:\WINDOWS\System32\bcmwltry.exe (Dell Inc.)
    PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
    PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
    PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
    PRC - C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
    PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
    PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
    PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
    PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
    PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
    PRC - C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
    PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
    PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
    PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
    PRC - C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
    PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
    PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
    PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
    PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
    PRC - C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
    PRC - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
    PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation)
    PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
    PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
    PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
    PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
    PRC - C:\Documents and Settings\Aaron\Local Settings\Temp\clclean.0001 (Macrovision Europe Ltd.)
    PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
    PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    PRC - C:\program files\dna\btdna.exe (BitTorrent, Inc.)
    PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
    PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
    PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
    PRC - C:\Program Files\Mobile Partner\Mobile Partner.exe ()
    PRC - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
    PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    PRC - C:\Documents and Settings\Aaron\Desktop\OTL.exe (OldTimer Tools)

    ========== Win32 Services (SafeList) ==========

    SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
    SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
    SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
    SRV - (btwdins [Auto | Running]) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
    SRV - (CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
    SRV - (Creative Labs Licensing Service [Auto | Running]) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
    SRV - (Creative Service for CDROM Access [Auto | Running]) -- C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
    SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe ()
    SRV - (ehRecvr [Auto | Running]) -- C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
    SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
    SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
    SRV - (GoogleDesktopManager [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
    SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
    SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
    SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
    SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
    SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
    SRV - (McrdSvc [Auto | Running]) -- C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
    SRV - (MHN [On_Demand | Stopped]) -- C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
    SRV - (RoxMediaDB9 [On_Demand | Running]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
    SRV - (RoxWatch9 [Auto | Running]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
    SRV - (sprtsvc_dellsupportcenter [Auto | Running]) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
    SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
    SRV - (UserAccess7 [Auto | Running]) -- C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
    SRV - (usnjsvc [On_Demand | Running]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
    SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
    SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
    SRV - (wltrysvc [Auto | Running]) -- C:\WINDOWS\System32\WLTRYSVC.EXE ()
    SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

    ========== Driver Services (SafeList) ==========

    DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
    DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
    DRV - (APPDRV [System | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
    DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
    DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
    DRV - (ASPI [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ASPI32.sys (Adaptec)
    DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
    DRV - (BCM43XX [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
    DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
    DRV - (btaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
    DRV - (BTDriver [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btport.sys (Broadcom Corporation.)
    DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
    DRV - (BTSERIAL [Auto | Running]) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
    DRV - (BTWDNDIS [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
    DRV - (btwhid [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwhid.sys (Broadcom Corporation.)
    DRV - (btwmodem [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btwmodem.sys (Broadcom Corporation.)
    DRV - (BTWUSB [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
    DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
    DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
    DRV - (CTUSFSYN [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
    DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
    DRV - (DLABMFSM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABMFSM.SYS (Roxio)
    DRV - (DLABOIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Roxio)
    DRV - (DLACDBHM [System | Running]) -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Roxio)
    DRV - (DLADResM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLADResM.SYS (Roxio)
    DRV - (DLAIFS_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Roxio)
    DRV - (DLAOPIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Roxio)
    DRV - (DLAPoolM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Roxio)
    DRV - (DLARTL_M [System | Running]) -- C:\WINDOWS\System32\Drivers\DLARTL_M.SYS (Roxio)
    DRV - (DLAUDFAM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Roxio)
    DRV - (DLAUDF_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Roxio)
    DRV - (DRVMCDB [Boot | Running]) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
    DRV - (DRVNDDM [Auto | Running]) -- C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Roxio)
    DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
    DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
    DRV - (E100B [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
    DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
    DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (HSFHWAZL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
    DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
    DRV - (hwdatacard [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
    DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
    DRV - (L6UX2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\L6UX2.sys (Line 6)
    DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
    DRV - (monfilt [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
    DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
    DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
    DRV - (omci [System | Running]) -- C:\WINDOWS\system32\DRIVERS\omci.sys (Dell Inc)
    DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
    DRV - (pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
    DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
    DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
    DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
    DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
    DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
    DRV - (rimmptsk [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
    DRV - (rimsptsk [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
    DRV - (rismxdp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
    DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
    DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
    DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
    DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
    DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
    DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
    DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
    DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
    DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
    DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
    DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
    DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070911
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
    O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
    O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
    O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
    O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r (Creative Technology Ltd)
    O4 - HKLM..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter (SupportSoft, Inc.)
    O4 - HKLM..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" ( )
    O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
    O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
    O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
    O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (Macrovision Corporation)
    O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
    O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
    O4 - HKLM..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon File not found
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" (CyberLink Corp.)
    O4 - HKLM..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime (Apple Inc.)
    O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
    O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
    O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
    O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
    O4 - HKCU..\Run: [BitTorrent DNA] "C:\program files\dna\btdna.exe" (BitTorrent, Inc.)
    O4 - HKCU..\Run: [SetDefaultMIDI] MIDIDef.exe (Creative Technology Ltd)
    O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - Startup: C:\Documents and Settings\Aaron\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
    O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
    O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: line6.net ([]* in Trusted sites)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
    O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189787015656 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
    O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
    O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2005/08/16 04:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.) - E:\AutoRun.exe -- [ CDFS ]
    O32 - AutoRun File - [2008/06/07 21:58:08 | 00,000,052 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
    O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell - "" = AutoRun
    O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{88713171-36fe-11de-ae05-001c264a068b}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/25 23:58:10 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
    O34 - HKLM BootExecute: (autocheck) - File not found
    O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (*) - * [2009/06/10 23:16:58 | 00,000,000 | ---D | M]

    ========== Files/Folders - Created Within 30 Days ==========

    [1 C:\WINDOWS\*.tmp files]
    [2009/06/10 21:10:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
    [2009/06/10 20:57:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Aaron\Desktop\Unused Desktop Shortcuts
    [2009/06/10 20:52:13 | 00,000,000 | ---D | C] -- C:\_OTL
    [2009/06/09 23:41:50 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Aaron\Desktop\OTL.exe
    [2009/06/09 20:10:36 | 00,000,000 | ---D | C] -- C:\Rooter$
    [2009/06/09 00:27:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Aaron\Application Data\Help
    [2009/06/09 00:25:30 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2009/05/28 22:56:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Aaron\Application Data\vlc
    [2009/05/28 22:54:41 | 00,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    [2009/05/28 21:03:59 | 21,374,56640 | -HS- | C] () -- C:\hiberfil.sys
    [2009/05/27 00:13:51 | 00,000,000 | ---D | C] -- C:\!KillBox
    [2009/05/26 20:02:29 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\Post01Mutex
    [2009/05/20 00:08:09 | 00,000,000 | ---D | C] -- C:\Program Files\Macromedia
    [2009/05/18 23:41:36 | 00,039,296 | ---- | C] () -- C:\Documents and Settings\Aaron\Desktop\susanhunter01.jpg
    [2009/05/18 23:36:05 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2008/03/11 23:45:22 | 00,782,336 | ---- | C] () -- C:\WINDOWS\System32\IlmImf.dll
    [2008/03/11 23:45:22 | 00,446,464 | ---- | C] () -- C:\WINDOWS\System32\Photomatix_jpg.dll
    [2008/03/11 23:45:22 | 00,353,280 | ---- | C] () -- C:\WINDOWS\System32\pmtf2.dll
    [2008/03/11 23:45:22 | 00,266,240 | ---- | C] () -- C:\WINDOWS\System32\Photomatix25Lib.dll
    [2008/03/11 23:45:22 | 00,249,856 | ---- | C] () -- C:\WINDOWS\System32\Photomatix25Lib2.dll
    [2008/03/11 23:45:22 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\pmtf1.dll
    [2008/03/11 23:45:22 | 00,204,288 | ---- | C] () -- C:\WINDOWS\System32\pmtf3.dll
    [2008/03/11 23:45:22 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\Photomatix25Lib3.dll
    [2008/03/11 23:45:22 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\pmexr.dll
    [2008/03/11 23:45:22 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmbm.dll
    [2007/12/05 00:47:02 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2007/11/25 13:54:12 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
    [2007/11/25 12:48:43 | 00,000,024 | ---- | C] () -- C:\WINDOWS\System32\sysogg.dll
    [2007/11/14 19:06:42 | 00,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
    [2007/09/29 22:43:36 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
    [2007/09/29 22:43:36 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
    [2007/09/29 22:43:36 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
    [2007/09/29 10:14:03 | 00,000,403 | ---- | C] () -- C:\WINDOWS\boxworld.ini
    [2007/09/20 18:40:53 | 00,000,026 | ---- | C] () -- C:\WINDOWS\dvdSanta.INI
    [2007/09/13 17:59:35 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/09/13 17:39:36 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2007/09/13 17:39:36 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2007/09/11 16:39:19 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2007/09/11 16:30:43 | 00,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
    [2007/09/11 16:30:43 | 00,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2007/09/11 16:25:00 | 00,010,820 | ---- | C] () -- C:\WINDOWS\System32\CTSBMB.INI
    [2007/09/11 16:24:37 | 00,000,040 | ---- | C] () -- C:\WINDOWS\System32\mes2046.dll
    [2007/09/11 16:24:19 | 00,022,629 | ---- | C] () -- C:\WINDOWS\System32\CiFilter.ini
    [2007/09/11 16:23:19 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
    [2007/09/11 16:23:17 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
    [2007/09/11 15:56:39 | 01,355,042 | ---- | C] () -- C:\WINDOWS\System32\CTMBHA.DLL
    [2007/09/11 15:55:57 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
    [2007/09/11 15:54:47 | 00,001,204 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2006/11/07 04:25:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2006/09/16 23:36:50 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
    [2006/09/16 23:36:50 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
    [2006/05/24 18:16:22 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
    [2005/08/16 04:37:24 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
    [2005/08/16 04:18:43 | 00,000,603 | ---- | C] () -- C:\WINDOWS\win.ini
    [2005/08/16 04:18:41 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
    [2005/08/05 14:01:54 | 00,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2005/02/17 12:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
    [2005/02/17 12:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
    [2001/11/14 13:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

    ========== Files - Modified Within 30 Days ==========

    [11 C:\WINDOWS\System32\*.tmp files]
    [1 C:\WINDOWS\*.tmp files]
    [2009/06/10 23:14:53 | 00,000,577 | ---- | M] () -- C:\Documents and Settings\Aaron\My Documents\My Sharing Folders.lnk
    [2009/06/10 21:07:19 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2009/06/10 21:04:07 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Aaron\Local Settings\desktop.ini
    [2009/06/10 21:04:07 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2009/06/10 21:04:04 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2009/06/10 21:04:03 | 21,374,56640 | -HS- | M] () -- C:\hiberfil.sys
    [2009/06/09 23:42:05 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Aaron\Desktop\OTL.exe
    [2009/06/09 20:49:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2009/06/08 23:57:03 | 00,021,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\powrprof.dll
    [2009/06/08 23:57:02 | 00,993,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\kernel32.dll
    [2009/06/08 23:57:02 | 00,993,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kernel32.dll
    [2009/06/08 23:57:00 | 00,919,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet.dll
    [2009/06/08 23:57:00 | 00,919,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
    [2009/06/08 23:55:51 | 36,931,938 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
    [2009/06/08 23:55:51 | 00,066,205 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
    [2009/06/08 23:48:53 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2009/06/07 18:37:15 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2009/05/28 22:54:41 | 00,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    [2009/05/26 20:02:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\Post01Mutex
    [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2009/05/25 20:23:08 | 00,382,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2009/05/25 20:23:07 | 00,053,838 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2009/05/25 20:23:04 | 00,441,626 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2009/05/18 23:41:17 | 00,039,296 | ---- | M] () -- C:\Documents and Settings\Aaron\Desktop\susanhunter01.jpg

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\My Documents\Downloads:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\Unused Desktop Shortcuts:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\susanhunter01.jpg:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\recording_audio[2].mov:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\MP3s:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\IMG_5070.jpg:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Aaron\Desktop\IMG_4949.jpg:Roxio EMC Stream
    < End of report >


  • Advertisement
  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hi

    Download TFC to your desktop
    • Open the file and close any other windows.
    • It will close all programs itself when run, make sure to let it run uninterrupted.
    • Click the Start button to begin the process. The program should not take long to finish its job
    • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean




    Please download Malwarebytes' Anti-Malware from Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






    Go to Kaspersky website and perform an online antivirus scan.
    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
        Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
        Mail databases
      [*]Click on My Computer under Scan.
      [*]Once the scan is complete, it will display the results. Click on View Scan Report.
      [*]You will see a list of infected items there. Click on Save Report As....
      [*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.


    5. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      Cheers for the feedback every time.
      Just an FYI - I have Malware Bytes and it picks up the trojans and new scan on reboot shows laptop is fine until the internet is connected and it can pick them up again.

      Since one of the scans last night Internet Explorer keeps shutting down "for my computer's safety" so I might have a problem running that online scan but I'll give it a go after work.


    6. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      Malwarebytes' Anti-Malware 1.37
      Database version: 2182
      Windows 5.1.2600 Service Pack 3

      11/06/2009 18:30:44
      mbam-log-2009-06-11 (18-30-44).txt

      Scan type: Quick Scan
      Objects scanned: 89329
      Time elapsed: 4 minute(s), 42 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)


    7. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      tell me how its running after the kaspersky step


    8. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      that site showed 1 possible threat -

      not-a-virus:AdWare.Win32.Gator.3202

      Detection added Sep 23 2005 07:28 GMT
      Update released Oct 28 2008 00:27 GMT
      Behavior not-a-virus:AdWare

      Here's a new mbam log file - 2 trojans found

      Malwarebytes' Anti-Malware 1.37
      Database version: 2279
      Windows 5.1.2600 Service Pack 3

      14/06/2009 23:33:09
      mbam-log-2009-06-14 (23-33-07).txt

      Scan type: Quick Scan
      Objects scanned: 97782
      Time elapsed: 5 minute(s), 57 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 2

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      c:\WINDOWS\system32\wbem\grpconv.exe (Trojan.Agent) -> No action taken.
      c:\documents and settings\Aaron\Application Data\wiaserva.log (Malware.Trace) -> No action taken.


    9. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      best run this, thats a new infection

      Download ComboFix from one of these locations:

      Link 1
      Link 2


      * IMPORTANT !!! Save ComboFix.exe to your Desktop

      • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you don't know how to disable them then just continue on.

      • Double click on ComboFix.exe & follow the prompts.

      • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

      • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

      **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

      RcAuto1.gif


      Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

      whatnext.png


      Click on Yes, to continue scanning for malware.

      When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.


    10. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      ComboFix 09-06-14.02 - Aaron 15/06/2009 19:52.1 - NTFSx86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1547 [GMT 1:00]
      Running from: c:\documents and settings\Aaron\Desktop\ComboFix.exe
      * Created a new restore point
      .
      /wow section - STAGE 8
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.

      /wow section - STAGE 9
      The process cannot access the file because it is being used by another process.

      /wow section - STAGE 10
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.
      The process cannot access the file because it is being used by another process.


      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Aaron\Application Data\inst.exe
      c:\windows\kb913800.exe

      c:\windows\system32\powrprof.dll . . . is infected!!

      c:\windows\system32\grpconv.exe was missing
      Restored copy from - c:\windows\ServicePackFiles\i386\grpconv.exe

      .
      ((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
      .

      2009-06-15 18:55 . 2008-04-14 00:12 39424 ----a-w- c:\windows\system32\grpconv.exe
      2009-06-15 18:55 . 2008-04-14 00:12 39424 ----a-w- c:\windows\system32\dllcache\grpconv.exe
      2009-06-15 18:12 . 2009-06-15 18:12
      d-sh--w- c:\documents and settings\LocalService\IETldCache
      2009-06-14 17:51 . 2009-06-14 17:51 0 ----a-w- c:\windows\nsreg.dat
      2009-06-14 17:51 . 2009-06-14 17:51
      d
      w- c:\documents and settings\Aaron\Local Settings\Application Data\Mozilla
      2009-06-14 17:47 . 2009-04-30 21:22 12800
      w- c:\windows\system32\dllcache\xpshims.dll
      2009-06-14 17:47 . 2009-04-30 21:22 246272
      w- c:\windows\system32\dllcache\ieproxy.dll
      2009-06-10 19:52 . 2009-06-10 19:52
      d
      w- C:\_OTL
      2009-06-09 19:10 . 2009-06-09 19:12
      d
      w- C:\Rooter$
      2009-06-08 23:27 . 2009-06-08 23:27
      d
      w- c:\documents and settings\Aaron\Local Settings\Application Data\Help
      2009-06-08 23:25 . 2009-06-08 23:25
      d
      w- c:\program files\Trend Micro
      2009-05-28 21:56 . 2009-06-04 22:43
      d
      w- c:\documents and settings\Aaron\Application Data\vlc
      2009-05-26 23:13 . 2009-05-28 22:59
      d
      w- C:\!KillBox
      2009-05-26 22:18 . 2003-11-04 14:11 159744 ----a-w- c:\windows\system32\lfpng13n.dll
      2009-05-26 22:18 . 2003-11-04 14:10 69632 ----a-w- c:\windows\system32\lfgif13n.dll
      2009-05-26 22:18 . 2004-05-14 15:53 462848 ----a-w- c:\windows\system32\ltkrn13n.dll
      2009-05-26 22:18 . 2004-05-14 15:53 450560 ----a-w- c:\windows\system32\ltimg13n.dll
      2009-05-26 22:18 . 2004-05-14 15:53 299008 ----a-w- c:\windows\system32\ltdis13n.dll
      2009-05-26 22:18 . 2004-05-14 15:53 163840 ----a-w- c:\windows\system32\ltfil13n.dll
      2009-05-26 22:18 . 2004-05-14 15:53 57344 ----a-w- c:\windows\system32\lfbmp13n.dll
      2009-05-26 22:18 . 2004-05-14 15:53 401408 ----a-w- c:\windows\system32\lfcmp13n.dll
      2009-05-26 22:18 . 2004-01-12 01:09 206336 ----a-w- c:\windows\system32\ltefx13n.dll
      2009-05-19 23:08 . 2009-05-19 23:08
      d
      w- c:\program files\Macromedia
      2009-05-18 22:36 . 2009-05-18 22:36
      d
      w- c:\program files\Microsoft
      2009-05-17 11:13 . 2009-05-17 11:13
      d-sh--w- c:\documents and settings\Aaron\IECompatCache

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-06-15 18:58 . 2008-06-14 13:07
      d
      w- c:\program files\DNA
      2009-06-15 18:58 . 2008-06-14 13:07
      d
      w- c:\documents and settings\Aaron\Application Data\DNA
      2009-06-15 18:43 . 2009-03-18 19:40
      d
      w- c:\documents and settings\All Users\Application Data\avg8
      2009-06-14 22:41 . 2007-09-11 15:35
      d
      w- c:\program files\Microsoft Works
      2009-06-08 22:57 . 2005-08-16 03:18 21504 ----a-w- c:\windows\system32\powrprof.dll
      2009-05-28 21:50 . 2007-09-15 12:51
      d
      w- c:\program files\Flickr Uploadr
      2009-05-26 23:41 . 2008-06-14 13:07
      d
      w- c:\documents and settings\Aaron\Application Data\BitTorrent
      2009-05-13 05:15 . 2005-08-16 03:18 915456 ----a-w- c:\windows\system32\wininet.dll
      2009-05-11 16:40 . 2009-05-11 16:40
      d
      w- c:\program files\Common Files\Windows Live
      2009-05-07 15:32 . 2005-08-16 03:18 345600 ----a-w- c:\windows\system32\localspl.dll
      2009-05-02 09:55 . 2008-08-05 20:11
      d
      w- c:\program files\Bonjour
      2009-05-02 09:41 . 2007-10-17 18:47
      d
      w- c:\program files\7-Zip
      2009-05-02 09:36 . 2009-04-06 18:40
      d
      w- c:\program files\Sonoma Wire Works
      2009-05-02 09:32 . 2009-05-02 09:32
      d
      w- c:\program files\Sierra Wireless Inc
      2009-05-02 09:32 . 2009-05-02 09:32
      d
      w- c:\documents and settings\Aaron\Application Data\Sierra Wireless
      2009-04-29 23:10 . 2009-04-29 23:07
      d
      w- c:\program files\Mobile Partner
      2009-04-23 20:03 . 2007-11-13 20:51
      d
      w- c:\documents and settings\Aaron\Application Data\ZoomBrowser EX
      2009-04-17 12:26 . 2005-08-16 03:18 1847168 ----a-w- c:\windows\system32\win32k.sys
      2009-04-15 14:51 . 2005-08-16 03:18 585216 ----a-w- c:\windows\system32\rpcrt4.dll
      2009-04-09 22:38 . 2009-04-09 22:38 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
      2009-03-19 15:32 . 2009-03-19 15:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
      2009-03-19 15:32 . 2008-01-29 11:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
      .

      Sigcheck

      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\$NtServicePackUninstall$\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\$NtUninstallKB935839$\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\$NtUninstallKB959426$\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\ServicePackFiles\i386\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\system32\kernel32.dll
      [-] 2009-06-08 22:57 993792 C1FC04A603EE3F80AA51A090C42E5E2C c:\windows\system32\dllcache\kernel32.dll

      [-] 2009-06-08 22:57 21504 70299B463F8C940CBA318171148005F6 c:\windows\$NtServicePackUninstall$\powrprof.dll
      [-] 2009-06-08 22:57 21504 70299B463F8C940CBA318171148005F6 c:\windows\ServicePackFiles\i386\powrprof.dll
      [-] 2009-06-08 22:57 21504 70299B463F8C940CBA318171148005F6 c:\windows\system32\powrprof.dll
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-27 68856]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
      "BitTorrent DNA"="c:\program files\dna\btdna.exe" [2008-12-16 342848]
      "SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2004-12-22 24576]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
      "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
      "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
      "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
      "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-10-31 1392640]
      "CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
      "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
      "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
      "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
      "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
      "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
      "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
      "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
      "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
      "QuickTime Task"="c:\program files\quicktime\qttask.exe" [2009-01-05 413696]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
      "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
      "MBMon"="CTMBHA.DLL" - c:\windows\system32\CTMBHA.DLL [2006-06-28 1355042]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
      "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

      c:\documents and settings\Aaron\Start Menu\Programs\Startup\
      Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
      Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
      Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-9-11 24576]
      Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
      @=&quot;Service"

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\DNA\\btdna.exe"=
      "c:\\Program Files\\BitTorrent\\bittorrent.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
      "c:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=

      R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
      S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [20/09/2007 23:21 16512]
      S3 L6UX2;Service - Line 6 UX2;c:\windows\system32\drivers\L6UX2.sys [06/04/2009 20:10 530560]
      S3 PCD5SRVC{FBEA8B78-1B22F121-05040000};PCD5SRVC{FBEA8B78-1B22F121-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~2\HWDiag\bin\PCD5SRVC.pkms [05/12/2007 16:47 20640]
      S3 zlportio;zlportio;\??\c:\documents and settings\Aaron\Desktop\Aaron\Ultrastar\zlportio.sys --> c:\documents and settings\Aaron\Desktop\Aaron\Ultrastar\zlportio.sys [?]

      [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
      "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
      .
      Contents of the 'Scheduled Tasks' folder

      2009-06-09 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]

      2009-06-15 c:\windows\Tasks\MP Scheduled Scan.job
      - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
      .
      - - - - ORPHANS REMOVED - - - -

      Notify-avgrsstarter - avgrsstx.dll


      .
      Supplementary Scan
      .
      uStart Page = hxxp://www.myspace.com/
      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
      uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=8pPZOBNAeZLayr8Ub4zj4ZmanqU
      IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
      IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      Trusted Zone: line6.net
      FF - ProfilePath -
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-06-15 19:58
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCD5SRVC{FBEA8B78-1B22F121-05040000}]
      "ImagePath"="\??\c:\progra~1\DELLSU~2\HWDiag\bin\PCD5SRVC.pkms"
      .
      DLLs Loaded Under Running Processes

      - - - - - - - > 'winlogon.exe'(960)
      c:\windows\System32\BCMLogon.dll

      - - - - - - - > 'explorer.exe'(3508)
      c:\windows\system32\WININET.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\webcheck.dll
      c:\windows\system32\WPDShServiceObj.dll
      c:\windows\system32\btncopy.dll
      c:\program files\Roxio\Drag-to-Disc\Shellex.dll
      c:\windows\system32\DLAAPI_W.DLL
      c:\windows\system32\CDRTC.DLL
      c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
      c:\windows\system32\PortableDeviceTypes.dll
      c:\windows\system32\PortableDeviceApi.dll
      .
      Other Running Processes
      .
      c:\windows\system32\WLTRYSVC.EXE
      c:\windows\system32\BCMWLTRY.EXE
      c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
      c:\windows\system32\CTSVCCDA.EXE
      c:\windows\ehome\ehrecvr.exe
      c:\windows\ehome\ehSched.exe
      c:\program files\Java\jre6\bin\jqs.exe
      c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      c:\program files\Dell Support Center\bin\sprtsvc.exe
      c:\windows\system32\UAService7.exe
      c:\windows\ehome\mcrdsvc.exe
      c:\program files\Canon\CAL\CALMAIN.exe
      c:\windows\system32\dllhost.exe
      c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      c:\windows\system32\wscntfy.exe
      c:\windows\system32\CF26215.exe
      c:\windows\ehome\ehmsas.exe
      c:\windows\system32\igfxsrvc.exe
      c:\windows\system32\rundll32.exe
      c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
      c:\docume~1\Aaron\LOCALS~1\temp\clclean.0001
      c:\program files\iPod\bin\iPodService.exe
      .
      **************************************************************************
      .
      Completion time: 2009-06-15 20:02 - machine was rebooted
      ComboFix-quarantined-files.txt 2009-06-15 19:02

      Pre-Run: 3,918,356,480 bytes free
      Post-Run: 3,956,543,488 bytes free

      WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

      248 --- E O F --- 2009-06-15 18:14


    11. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      hi
      • Make sure to use Internet Explorer for this
      • Please go to VirSCAN.org FREE on-line scan service
      • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
        • c:\windows\system32\powrprof.dll
      • Click on the Upload button
      • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
      • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
      • Paste the contents of the Clipboard in your next reply.


      Repeat it for these files

      c:\windows\ServicePackFiles\i386\powrprof.dll
      c:\windows\$NtServicePackUninstall$\powrprof.dll
      c:\windows\system32\kernel32.dll


    12. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      I just got the first file scanned - the internet connection has been too slow to complete the other files. Will update when I can.

      VirSCAN.org Scanned Report :
      Scanned time : 2009/06/15 23:44:06 (IST)
      Scanner results: All Scanners reported not find malware!
      File Name : powrprof.dll
      File Size : 21504 byte
      File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
      MD5 : 70299b463f8c940cba318171148005f6
      SHA1 : 004d67f594697d9a141e3159e4defcb5cf32e3fe
      Online report : http://virscan.org/report/9240ace25b1db45d133e243a3d346bb4.html

      Scanner Engine Ver Sig Ver Sig Date Time Scan result
      a-squared 4.5.0.1 20090614213204 2009-06-14 2.22 -
      AhnLab V3 2009.06.16.00 2009.06.16 2009-06-16 0.71 -
      AntiVir 8.2.0.187 7.1.4.95 2009-06-15 0.15 -
      Antiy 2.0.18 20090615.2540363 2009-06-15 0.12 -
      Arcavir 2009 200906150719 2009-06-15 0.04 -
      Authentium 5.1.1 200906151603 2009-06-15 1.16 -
      AVAST! 4.7.4 090615-0 2009-06-15 0.01 -
      AVG 8.5.286 270.12.71/2178 2009-06-16 3.32 -
      BitDefender 7.81008.3348858 7.26001 2009-06-16 3.01 -
      CA (VET) 9.0.0.143 31.6.6556 2009-06-15 4.77 -
      ClamAV 0.95.1 9466 2009-06-15 0.01 -
      Comodo 3.9 1337 2009-06-15 0.72 -
      CP Secure 1.1.0.715 2009.06.16 2009-06-16 10.27 -
      Dr.Web 4.44.0.9170 2009.06.15 2009-06-15 4.67 -
      F-Prot 4.4.4.56 20090615 2009-06-15 1.11 -
      F-Secure 5.51.6100 2009.06.15.10 2009-06-15 0.06 -
      Fortinet 2.81-3.117 10.500 2009-06-15 0.20 -
      GData 19.5852/19.365 20090616 2009-06-16 4.38 -
      ViRobot 20090615 2009.06.15 2009-06-15 0.41 -
      Ikarus T3.1.01.59 2009.06.15.72871 2009-06-15 3.21 -
      JiangMin 11.0.706 2009.06.15 2009-06-15 2.05 -
      Kaspersky 5.5.10 2009.06.15 2009-06-15 0.05 -
      KingSoft 2009.2.5.15 2009.6.15.22 2009-06-15 0.51 -
      McAfee 5.3.00 5647 2009-06-15 3.06 -
      Microsoft 1.4701 2009.06.15 2009-06-15 4.28 -
      mks_vir 2.01 2009.06.15 2009-06-15 3.18 -
      Norman 6.01.09 6.01.00 2009-06-15 4.01 -
      Panda 9.05.01 2009.06.15 2009-06-15 1.53 -
      Trend Micro 8.700-1004 6.194.15 2009-06-15 0.03 -
      Quick Heal 10.00 2009.06.15 2009-06-15 1.17 -
      Rising 20.0 21.34.04.00 2009-06-15 0.76 -
      Sophos 2.87.1 4.42 2009-06-16 2.44 -
      Sunbelt 5190 5190 2009-06-15 0.89 -
      Symantec 1.3.0.24 20090615.003 2009-06-15 0.05 -
      nProtect 20090614.01 4249058 2009-06-14 5.53 -
      The Hacker 6.3.4.3 v00345 2009-06-15 0.66 -
      VBA32 3.12.10.7 20090614.1156 2009-06-14 1.98 -
      VirusBuster 4.5.11.10 10.107.14/1629766 2009-06-15 1.96 -


    13. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      File information
      File Name : powrprof.dll
      File Size : 21504 byte
      File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
      MD5 : 70299b463f8c940cba318171148005f6
      SHA1 : 004d67f594697d9a141e3159e4defcb5cf32e3fe

      Scanner results
      Scanner results : All Scanners reported not find malware!
      Time : 2009/06/16 23:32:08 (IST)
      Scanner ↓ Engine Ver Sig Ver Sig Date Scan result Time
      a-squared 4.5.0.1 20090616223118 2009-06-16
      -
      40.144
      AhnLab V3 2009.06.17.00 2009.06.17 2009-06-17
      -
      0.714
      AntiVir 8.2.0.187 7.1.4.100 2009-06-16
      -
      0.269
      Antiy 2.0.18 20090616.2549523 2009-06-16
      -
      0.121
      Arcavir 2009 200906161748 2009-06-16
      -
      0.009
      Authentium 5.1.1 200906161813 2009-06-16
      -
      1.128
      AVAST! 4.7.4 090616-0 2009-06-16
      -
      0.004
      AVG 8.5.286 270.12.74/2181 2009-06-17
      -
      3.382
      BitDefender 7.81008.3349141 7.26020 2009-06-17
      -
      3.001
      CA (VET) 9.0.0.143 31.6.6560 2009-06-16
      -
      5.651
      ClamAV 0.95.1 9470 2009-06-16
      -
      0.011
      Comodo 3.9 1341 2009-06-16
      -
      0.722
      CP Secure 1.1.0.715 2009.06.16 2009-06-16
      -
      10.051
      Dr.Web 4.44.0.9170 2009.06.16 2009-06-16
      -
      4.669
      F-Prot 4.4.4.56 20090616 2009-06-16
      -
      1.107
      F-Secure 5.51.6100 2009.06.16.14 2009-06-16
      -
      4.861
      Fortinet 2.81-3.117 10.502 2009-06-16
      -
      0.197
      GData 19.5860/19.366 20090616 2009-06-16
      -
      4.274
      Ikarus T3.1.01.59 2009.06.16.72877 2009-06-16
      -
      3.217
      JiangMin 11.0.706 2009.06.16 2009-06-16
      -
      2.075
      Kaspersky 5.5.10 2009.06.16 2009-06-16
      -
      0.052
      KingSoft 2009.2.5.15 2009.6.16.18 2009-06-16
      -
      0.504
      McAfee 5.3.00 5648 2009-06-16
      -
      3.059
      Microsoft 1.4701 2009.06.17 2009-06-17
      -
      4.357
      mks_vir 2.01 2009.06.15 2009-06-15
      -
      3.181
      Norman 6.01.09 6.01.00 2009-06-16
      -
      4.006
      nProtect 20090616.03 4261430 2009-06-16
      -
      5.387
      Panda 9.05.01 2009.06.16 2009-06-16
      -
      1.664
      Quick Heal 10.00 2009.06.16 2009-06-16
      -
      1.168
      Rising 20.0 21.34.13.00 2009-06-16
      -
      0.757
      Sophos 2.87.1 4.42 2009-06-17
      -
      2.481
      Sunbelt 5192 5192 2009-06-16
      -
      0.890
      Symantec 1.3.0.24 20090616.004 2009-06-16
      -
      0.047
      The Hacker 6.3.4.3 v00345 2009-06-15
      -
      0.687
      Trend Micro 8.700-1004 6.200.03 2009-06-16
      -
      0.033
      VBA32 3.12.10.7 20090615.1405 2009-06-15
      -
      1.968
      ViRobot 20090616 2009.06.16 2009-06-16
      -
      0.413
      VirusBuster 4.5.11.10 10.107.15/1636796 2009-06-16
      -
      1.967


    14. Advertisement
    15. Registered Users, Registered Users 2 Posts: 7,032 ✭✭✭homerun_homer


      the Copy to Clipboard function wouldn't work last night - hence the above badly pasted detail.

      The other 2 files wouldn't scan for me last night.


    16. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      hows the pc running


    Advertisement