site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
5880
Share Topic
Posting?
Post a:
Post a:
Links: ·SCU FAQ ·Pre-Clean ·Site IMs ·VundoFix ·Zlob/Smitfraud ·SCU Helpers
page: 1 · 2 · 3
AuthorAll Replies

Carcassonne

join:2012-11-26
11000

[Malware] Starburn software problem -Virus/malware?

Hello,
About a month ago on start up I was getting a message something like,”youtube downloader Free_helper.exe has encountered a problem. Since I was not aware of having uploaded anything to do with youtube I am afraid I just ignored it.
Shortly after this (a few days) whilst still getting the youtube message when I launched my browser Mozilla Firefox 17. ,instead of getting my Google homepage I was getting search.starburnsoftware.com. No matter how may times I reset my options back to Google it did not work. Eventually I did a search for files or folders containing the word “starburn” I found about 3 files, which I deleted. This worked like a charm! Instead I got apype.com. I then repeated the search this time for “apype” it came up with nothing. After this however apype.com had gone & starburn was back. When I tried to reset my preferences it showed apype .com but when I launched my browser I got starburn. This continues to be the case even after doing you recommended clean up.
At one point my husband suggested trying Explorer. This was also showing starburn however after about 10 resets it is now sticking with Google. I am now using Explorer but I have not uninstalled Firefox
I tried Bitdefender Quick Scan, which froze at the end but found nothing, and Malwarebytes and latterly Avast but to no avail. I also used Microsoft Fix It.
I then contacted my son who is in England and works in IT & he directed me to you. I have now completed your Mandatory Steps Before Requesting Assistance and here are my results: Incidentally
I got to this point on your web page about half an hour ago & it all my text disappeared.
My results:

1.Contents of the MBAM log

Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.26.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
annas :: DELL [administrator]

Protection: Disabled

26/11/2012 14:27:05
mbam-log-2012-11-26 (14-27-05).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|Z:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 434356
Time elapsed: 2 hour(s), 50 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DECEAAA2-370A-49BB-9362-68C3A58DDC62} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKCU\Software\PlayVolcanoSA (Adware.HotBar.PV) -> Quarantined and deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayVolcanoSA (Adware.HotBar.PV) -> Quarantined and deleted successfully.

Registry Values Detected: 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Run|PlayVolcanoSA (Adware.HotBar.PV) -> Data: "C:\Documents and Settings\annas\Local Settings\Application Data\PlayVolcanoSA\bin\1.0.10.0\PlayVolcanoSA.exe" -> Quarantined and deleted successfully.

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 3
C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA (Adware.HotBar.PV) -> Quarantined and deleted successfully.
C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA\bin (Adware.HotBar.PV) -> Quarantined and deleted successfully.
C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA\bin\1.0.10.0 (Adware.HotBar.PV) -> Quarantined and deleted successfully.

Files Detected: 3
E:\program files\Corel® Painter™ Essentials 4+Keygen-HeartBug\keygen\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP2168\A0265087.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA\bin\1.0.10.0\PlayVolcanoSAHook.dll (Adware.HotBar.PV) -> Quarantined and deleted successfully.

(end)
2. contents of OTL.txt - Attached

3. Contents of Extras.txt

OTL Extras logfile created on: 26/11/2012 17:42:58 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 71.78% Memory free
7.81 Gb Paging File | 7.43 Gb Available in Paging File | 95.11% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 24.81 Gb Free Space | 35.54% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.96% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]

[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[color=#E56717]========== System Restore Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI)
"9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI)
"9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI)
"9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI)
"9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI)
"9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI)
"9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI)
"9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI)
"9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI)
"9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI)
"9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI)
"9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI)
"8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI)
"10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI)
"9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI)
"3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp
"3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"18694:TCP" = 18694:TCP:*:Enabled:BitComet 18694 TCP
"18694:UDP" = 18694:UDP:*:Enabled:BitComet 18694 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"27629:TCP" = 27629:TCP:*:Enabled:BitComet 27629 TCP
"27629:UDP" = 27629:UDP:*:Enabled:BitComet 27629 UDP
"8081:TCP" = 8081:TCP:*:Enabled:VLC
"8080:TCP" = 8080:TCP:*:Enabled:Homeplayer
"9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI)
"9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI)
"9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI)
"9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI)
"9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI)
"9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI)
"9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI)
"9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI)
"9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI)
"9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI)
"9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI)
"9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI)
"8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI)
"10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI)
"9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI)
"3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp
"3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
"C:\Documents and Settings\annas\Desktop\utorrent.exe" = C:\Documents and Settings\annas\Desktop\utorrent.exe:*:Enabled:µTorrent
"C:\Program Files\Grisoft\AVG Free\avginet.exe" = C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Documents and Settings\annas\My Documents\Freeplayer\vlc\vlc.exe" = C:\Documents and Settings\annas\My Documents\Freeplayer\vlc\vlc.exe:*:Enabled:VLC media player
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" = C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe:*:Enabled:SpeedUpMyPC 3
"F:\Bit comet setup\BitComet\BitComet.exe" = F:\Bit comet setup\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client
"F:\Downloads\Free Download Manager\fdm.exe" = F:\Downloads\Free Download Manager\fdm.exe:*:Enabled:fdm
"C:\WINDOWS\system32\freecell.exe" = C:\WINDOWS\system32\freecell.exe:*:Enabled:FreeCell -- (Microsoft Corporation)
"F:\Downloads\Free Download Manager\FUM\fum.exe" = F:\Downloads\Free Download Manager\FUM\fum.exe:*:Enabled:Free Upload Manager
"F:\Downloads\Free Download Manager\fdmwi.exe" = F:\Downloads\Free Download Manager\fdmwi.exe:*:Enabled:FDM remote control server
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Disabled:AOL
"C:\Program Files\Wyzo\wyzo.exe" = C:\Program Files\Wyzo\wyzo.exe:*:Disabled:Wyzo
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)
"C:\Program Files\EasyBox\EasyBox.exe" = C:\Program Files\EasyBox\EasyBox.exe:*:Enabled:Lancer EasyBox
"C:\Program Files\EasyBox\unins000.exe" = C:\Program Files\EasyBox\unins000.exe:*:Enabled:Désinstaller EasyBox v3.5-RC1
"C:\Program Files\HomePlayer1.5.4\HomePlayer.exe" = C:\Program Files\HomePlayer1.5.4\HomePlayer.exe:*:Enabled:HomePlayer
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"C:\Program Files\UseNeXT\UseNeXT.exe" = C:\Program Files\UseNeXT\UseNeXT.exe:*:Enabled:UseNeXT -- ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd)
"C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe" = C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe:*:Enabled:Firefox
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird -- (Mozilla Corporation)
"C:\Program Files\Squeezebox\server\squeezeboxcp.exe" = C:\Program Files\Squeezebox\server\squeezeboxcp.exe:*:Enabled:Squeezebox Control Panel -- (Logitech Inc.)
"F:\iTunes Installer\iTunes.exe" = F:\iTunes Installer\iTunes.exe:*:Disabled:iTunes
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe" = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe:*:Enabled:Audible Download Manager -- (Audible, Inc.)
"C:\Program Files\Audible\Bin\Manager.exe" = C:\Program Files\Audible\Bin\Manager.exe:*:Enabled:AudibleManager -- (Audible Inc.)
"C:\Program Files\Creative\DiskManager\ctpdemgr.exe" = C:\Program Files\Creative\DiskManager\ctpdemgr.exe:*:Enabled:Creative Removable Disk Manager
"C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\LGMLauncher.exe" = C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\LGMLauncher.exe:*:Enabled:LGMobile update -- (LG Electronics)
"C:\Program Files\NCH Swift Sound\SoundTap\soundtap.exe" = C:\Program Files\NCH Swift Sound\SoundTap\soundtap.exe:*:Enabled:SoundTap -- (NCH Software)
"C:\Program Files\Uniblue\DiskRescue\UBDiskRescue.exe" = C:\Program Files\Uniblue\DiskRescue\UBDiskRescue.exe:*:Enabled:DiskRescue 2009 -- (Uniblue)
"C:\Program Files\AC3Filter\ac3config.exe" = C:\Program Files\AC3Filter\ac3config.exe:*:Enabled:AC3Filter Config -- ()
"C:\Program Files\Fluendo\Moovida\Moovida.exe" = C:\Program Files\Fluendo\Moovida\Moovida.exe:*:Enabled:Moovida
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer
"C:\BTGUARD\uTorrent.exe" = C:\BTGUARD\uTorrent.exe:*:Enabled:µTorrent
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Steam\steamapps\common\stronghold kingdoms\StrongholdKingdoms.exe" = C:\Program Files\Steam\steamapps\common\stronghold kingdoms\StrongholdKingdoms.exe:*:Enabled:Stronghold Kingdoms -- (Firefly Studios)
"C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
"C:\Program Files\Expat Shield\bin\openvpntray.exe" = C:\Program Files\Expat Shield\bin\openvpntray.exe:*:Enabled:Expat Shield Launch
"C:\WINDOWS\system32\msiexec.exe" = C:\WINDOWS\system32\msiexec.exe:*:Enabled:UpdateManagerSetup -- (Microsoft Corporation)
"C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe" = C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe:*:Enabled:SweetPacksUpdateManager
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\HomePlayer\HomePlayer.exe" = C:\Program Files\HomePlayer\HomePlayer.exe:*:Enabled:HomePlayer -- ()
"C:\Program Files\HomePlayer\VLC\vlc.exe" = C:\Program Files\HomePlayer\VLC\vlc.exe:*:Enabled:VLC HomePlayer -- ()
"C:\BTGUARD\settings.exe" = C:\BTGUARD\settings.exe:*:Enabled:BTGuard Settings
"C:\BTGUARD\myentunnel.exe" = C:\BTGUARD\myentunnel.exe:*:Enabled:BTGuard Encryption
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0C35EAE4-A535-46B7-B4BF-68952BD94E68}" = Uniblue DiskRescue 2009
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{106DADAD-B062-4de5-8D1F-3FD2AD195E49}" = PC Utility Kit
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{162D2FB8-60A3-4871-B6A1-5C744CD34FF5}" = 725plc32
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 23
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{487C2D48-A9E3-4F34-92BD-B6A847025C16}" = Free eXPert PDF Reader
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel(R) PROSet for Wired Connections
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
"{8B6490BA-FAEA-486C-BAB5-561251D5F2B1}" = Hercules Blog Webcam
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C450606-ED24-4958-92BA-B8940C99D441}" = PixiePack Codec Pack
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A638EC76-65C3-4F82-BA68-D105DDA393E7}" = FileOpen Plug-in for Adobe Acrobat® and Acrobat Reader®
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks
"{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009
"{C94924F7-C20B-4E83-B63F-FAF006908B25}" = calibre
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CC8E0363-B20C-4792-8A1C-8DF5E01B68A6}" = GoGear VIBE Device Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07205E7-F6D3-4333-AFCC-782A07685B72}" = OverDrive Media Console
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D615D099-5C0F-41E0-B69E-B7D1CDC51B61}" = Philips Media Converter
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC
"{E55B3271-7CA8-4D0C-AE06-69A24856E997}_is1" = Uniblue RegistryBooster
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FE48654B-F9AA-40ED-BEF3-48F3FE2FA847}" = Philips Media Converter
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AudibleManager" = AudibleManager
"avast" = avast! Free Antivirus
"AVIConverter" = AVIConverter 5.1.6
"B81055EA372C9E3EA5000B4BD9585D992D51F1DE" = Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/11/2009 2.0.0010.00002)
"BurnAware Free_is1" = BurnAware Free 2.1.6
"Codec_is1" = Codec 8.3n
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"Dell Color Printer 725" = Dell Color Printer 725
"Digital Video Repair" = Digital Video Repair 1.0
"DjVu" = LizardTech DjVu Control (autoinstall)
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"FpTest" = FpTest 3.2
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"GSpot" = GSpot Codec Information Appliance
"HomePlayer" = HomePlayer 1.5.9e
"ie8" = Windows Internet Explorer 8
"Logitech Media Server_is1" = Logitech Media Server 7.7.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 17.0 (x86 en-GB)" = Mozilla Firefox 17.0 (x86 en-GB)
"Mozilla Thunderbird 16.0.2 (x86 en-GB)" = Mozilla Thunderbird 16.0.2 (x86 en-GB)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Peer2Peer-EN Toolbar" = Peer2Peer-EN Toolbar
"Philips Songbird" = Philips Songbird
"PROSet" = Intel(R) PRO Network Connections Drivers
"PuTTY_is1" = PuTTY version 0.60
"RealAlt_is1" = Real Alternative 1.48
"RealPlayer 15.0" = RealPlayer
"Slice" = Slice Audio File Splitter
"SoundTap" = SoundTap Streaming Audio Recorder
"SpeedUpMyPC_is1" = Uniblue SpeedUpMyPC 3
"Spotify" = Spotify
"Steam App 47410" = Stronghold Kingdoms
"Switch" = Switch
"ToolBox" = NCH Toolbox Uninstall
"UFRaw_is1" = UFRaw 0.17
"Uniblue DiskRescue 2009" = Uniblue DiskRescue 2009
"Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009
"UseNeXT_is1" = UseNeXT
"uTorrent" = µTorrent
"uTorrentControl_v2 Toolbar" = uTorrentControl_v2 Toolbar
"VLC media player" = VideoLAN VLC media player 0.8.6e
"WavePad" = WavePad Sound Editor
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"XviD4PSP5" = XviD4PSP 5

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Dropbox" = Dropbox
"Sansa Updater" = Sansa Updater

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 24/11/2012 12:26:27 | Computer Name = DELL | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 4.1.522.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 25/11/2012 18:15:57 | Computer Name = DELL | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 25/11/2012 18:15:57 | Computer Name = DELL | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018

Error - 25/11/2012 18:16:18 | Computer Name = DELL | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 25/11/2012 18:16:18 | Computer Name = DELL | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018

Error - 25/11/2012 18:18:00 | Computer Name = DELL | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 25/11/2012 18:18:00 | Computer Name = DELL | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018

Error - 25/11/2012 18:22:57 | Computer Name = DELL | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 25/11/2012 18:22:57 | Computer Name = DELL | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018

Error - 26/11/2012 11:22:58 | Computer Name = DELL | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 4.1.522.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 26/11/2012 09:04:34 | Computer Name = DELL | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume D:.

Error - 26/11/2012 09:06:37 | Computer Name = DELL | Source = Service Control Manager | ID = 7022
Description = The Logitech Media Server service hung on starting.

Error - 26/11/2012 09:06:37 | Computer Name = DELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
szkg

Error - 26/11/2012 12:24:40 | Computer Name = DELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service dlcf_device
with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Error - 26/11/2012 12:24:40 | Computer Name = DELL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the dlcf_device service to
connect.

Error - 26/11/2012 12:24:40 | Computer Name = DELL | Source = Service Control Manager | ID = 7000
Description = The dlcf_device service failed to start due to the following error:
%%1053

Error - 26/11/2012 12:24:50 | Computer Name = DELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service dlcf_device
with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Error - 26/11/2012 12:26:23 | Computer Name = DELL | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume D:.

Error - 26/11/2012 12:26:23 | Computer Name = DELL | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume D:.

Error - 26/11/2012 12:27:25 | Computer Name = DELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
IntelIde szkg

4. Contents of checkup.txt

Results of screen317's Security Check version 0.99.56
Windows XP Service Pack 3 x86
Internet Explorer 8
[u]``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled!
Microsoft Security Essentials
avast! Antivirus
McAfee VirusScan
Antivirus up to date! (On Access scanning disabled!)
[u]`````````Anti-malware/Other Utilities Check:`````````[/u]
Malwarebytes Anti-Malware version 1.65.1.1000
JavaFX 2.1.1
Java(TM) 6 Update 23
Java 7 Update 9
Adobe Flash Player 11.4.402.287
Mozilla Firefox (17.0)
Mozilla Thunderbird 16.0.2 [color=red]Thunderbird out of Date![/color]
[u]````````Process Check: objlist.exe by Laurent````````[/u]
Microsoft Security Essentials MSMpEng.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
[u]`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C:: 15% [color=red]Defragment your hard drive soon! (Do NOT defrag if SSD!)[/color]
[u]````````````````````End of Log``````````````````````[/u]

5. Contents of the Online AntiVirus Scan log

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=c49982a5574c1948a833d550b7e9db46
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-11-26 09:19:20
# local_time=2012-11-26 10:19:20 (+0100, Romance Standard Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5891 16776533 42 93 19740 7589840 0 0
# compatibility_mode=8192 67108863 100 0 4320 4320 0 0
# scanned=150894
# found=14
# cleaned=14
# scan_time=14295
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SweetIM23.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SweetIM78.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YontooPagerage2.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\Application Data\Uniblue\RegistryBooster\_temp\ub.exe a variant of Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\Desktop\Installs\se2_0_1_1516.exe a variant of Win32/UbSpyEraser application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\Desktop\Installs\spyeraser2.exe a variant of Win32/UbSpyEraser application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\My Documents\Downloads\PETER_ROBINSON_-_THE_HANGING_VALLEY_[MYANONAMOUSE.NET]-ebook.exe Win32/Adware.1ClickDownload.G application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\My Documents\Downloads\registrybooster(1).exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\My Documents\Downloads\registrybooster.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\My Documents\Downloads\The_Diggers_Rest_Hotel_-_by_Geoffrey_McGeachin_(an_unabridge.exe Win32/Adware.1ClickDownload.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\annas\My Documents\Downloads\_Retail).exe Win32/Adware.1ClickDownload application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\i386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent.LCKGTSG application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files\Uniblue\RegistryBooster\Launcher.exe a variant of Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

Over to you & many thanks!


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

Download and run TDSS Killer, posting the log in this thread. Please post the log, even if nothing is detected.

You'll find the link(s) and instruction(s) here:
»Security Cleanup FAQ »Rootkit Detection Applications
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


Carcassonne

join:2012-11-26
11000

reply to Carcassonne
OK will do that right now. Sorry for delay - it was amost 1.00 am here when i posted last night & i was pooped!


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
Okay - here it is:
10:17:22.0984 2188 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
10:17:23.0281 2188 ============================================================
10:17:23.0281 2188 Current date / time: 2012/11/27 10:17:23.0281
10:17:23.0281 2188 SystemInfo:
10:17:23.0281 2188
10:17:23.0281 2188 OS Version: 5.1.2600 ServicePack: 3.0
10:17:23.0281 2188 Product type: Workstation
10:17:23.0281 2188 ComputerName: DELL
10:17:23.0281 2188 UserName: annas
10:17:23.0281 2188 Windows directory: C:\WINDOWS
10:17:23.0281 2188 System windows directory: C:\WINDOWS
10:17:23.0281 2188 Processor architecture: Intel x86
10:17:23.0281 2188 Number of processors: 2
10:17:23.0281 2188 Page size: 0x1000
10:17:23.0281 2188 Boot type: Normal boot
10:17:23.0281 2188 ============================================================
10:17:27.0406 2188 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:17:27.0453 2188 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:17:27.0453 2188 ============================================================
10:17:27.0453 2188 \Device\Harddisk0\DR0:
10:17:27.0453 2188 MBR partitions:
10:17:27.0453 2188 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x8BA231A
10:17:27.0453 2188 \Device\Harddisk1\DR1:
10:17:27.0453 2188 MBR partitions:
10:17:27.0453 2188 ============================================================
10:17:27.0515 2188 C: \Device\Harddisk0\DR0\Partition1
10:17:27.0515 2188 ============================================================
10:17:27.0515 2188 Initialize success
10:17:27.0515 2188 ============================================================
10:17:35.0843 3928 ============================================================
10:17:35.0843 3928 Scan started
10:17:35.0843 3928 Mode: Manual;
10:17:35.0843 3928 ============================================================
10:17:36.0328 3928 ================ Scan system memory ========================
10:17:36.0328 3928 System memory - ok
10:17:36.0328 3928 ================ Scan services =============================
10:17:36.0484 3928 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
10:17:36.0484 3928 Aavmker4 - ok
10:17:36.0484 3928 Abiosdsk - ok
10:17:36.0546 3928 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
10:17:36.0546 3928 abp480n5 - ok
10:17:36.0609 3928 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:17:36.0625 3928 ACPI - ok
10:17:36.0640 3928 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
10:17:36.0640 3928 ACPIEC - ok
10:17:36.0750 3928 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
10:17:36.0750 3928 AdobeFlashPlayerUpdateSvc - ok
10:17:36.0765 3928 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys
10:17:36.0781 3928 adpu160m - ok
10:17:36.0796 3928 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
10:17:36.0796 3928 aec - ok
10:17:36.0843 3928 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
10:17:36.0843 3928 AFD - ok
10:17:36.0890 3928 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
10:17:36.0890 3928 agp440 - ok
10:17:36.0906 3928 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
10:17:36.0906 3928 agpCPQ - ok
10:17:36.0937 3928 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys
10:17:36.0953 3928 Aha154x - ok
10:17:37.0000 3928 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys
10:17:37.0015 3928 aic78u2 - ok
10:17:37.0031 3928 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys
10:17:37.0031 3928 aic78xx - ok
10:17:37.0093 3928 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
10:17:37.0093 3928 Alerter - ok
10:17:37.0109 3928 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
10:17:37.0109 3928 ALG - ok
10:17:37.0125 3928 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys
10:17:37.0125 3928 AliIde - ok
10:17:37.0140 3928 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys
10:17:37.0140 3928 alim1541 - ok
10:17:37.0140 3928 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys
10:17:37.0156 3928 amdagp - ok
10:17:37.0171 3928 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys
10:17:37.0171 3928 amsint - ok
10:17:37.0250 3928 [ 019A9B80A0C207278CF70808FF527683 ] APL531 C:\WINDOWS\system32\Drivers\BLvid.sys
10:17:37.0281 3928 APL531 - ok
10:17:37.0328 3928 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
10:17:37.0328 3928 AppMgmt - ok
10:17:37.0375 3928 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys
10:17:37.0390 3928 asc - ok
10:17:37.0390 3928 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys
10:17:37.0390 3928 asc3350p - ok
10:17:37.0406 3928 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys
10:17:37.0406 3928 asc3550 - ok
10:17:37.0578 3928 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
10:17:37.0609 3928 aspnet_state - ok
10:17:37.0640 3928 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
10:17:37.0640 3928 aswFsBlk - ok
10:17:37.0703 3928 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
10:17:37.0703 3928 aswMon2 - ok
10:17:37.0718 3928 [ 7C9F0A2AB17D52261A9252A2EB320884 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys
10:17:37.0718 3928 AswRdr - ok
10:17:37.0765 3928 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
10:17:37.0781 3928 aswSnx - ok
10:17:37.0812 3928 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
10:17:37.0812 3928 aswSP - ok
10:17:37.0828 3928 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
10:17:37.0828 3928 aswTdi - ok
10:17:37.0890 3928 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:17:37.0890 3928 AsyncMac - ok
10:17:37.0906 3928 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
10:17:37.0906 3928 atapi - ok
10:17:37.0921 3928 Atdisk - ok
10:17:37.0953 3928 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:17:37.0953 3928 Atmarpc - ok
10:17:38.0000 3928 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
10:17:38.0000 3928 AudioSrv - ok
10:17:38.0062 3928 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
10:17:38.0062 3928 audstub - ok
10:17:38.0203 3928 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
10:17:38.0203 3928 avast! Antivirus - ok
10:17:38.0250 3928 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
10:17:38.0250 3928 Beep - ok
10:17:38.0312 3928 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
10:17:38.0328 3928 BITS - ok
10:17:38.0390 3928 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
10:17:38.0390 3928 Bonjour Service - ok
10:17:38.0437 3928 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
10:17:38.0437 3928 Browser - ok
10:17:38.0515 3928 [ CA794C7F1BF59B1F4638FBCEEF55337A ] camfilt C:\WINDOWS\system32\Drivers\camfilt.sys
10:17:38.0562 3928 camfilt - ok
10:17:38.0593 3928 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
10:17:38.0593 3928 cbidf - ok
10:17:38.0593 3928 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
10:17:38.0609 3928 cbidf2k - ok
10:17:38.0656 3928 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:17:38.0656 3928 CCDECODE - ok
10:17:38.0671 3928 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
10:17:38.0703 3928 cd20xrnt - ok
10:17:38.0734 3928 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
10:17:38.0734 3928 Cdaudio - ok
10:17:38.0796 3928 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
10:17:38.0796 3928 Cdfs - ok
10:17:38.0828 3928 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:17:38.0828 3928 Cdrom - ok
10:17:38.0828 3928 Changer - ok
10:17:38.0890 3928 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
10:17:38.0890 3928 CiSvc - ok
10:17:38.0953 3928 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
10:17:38.0953 3928 ClipSrv - ok
10:17:39.0000 3928 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:17:39.0125 3928 clr_optimization_v2.0.50727_32 - ok
10:17:39.0203 3928 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys
10:17:39.0218 3928 CmdIde - ok
10:17:39.0234 3928 COMSysApp - ok
10:17:39.0281 3928 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys
10:17:39.0281 3928 Cpqarray - ok
10:17:39.0296 3928 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
10:17:39.0296 3928 CryptSvc - ok
10:17:39.0312 3928 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
10:17:39.0328 3928 dac2w2k - ok
10:17:39.0328 3928 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys
10:17:39.0328 3928 dac960nt - ok
10:17:39.0390 3928 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
10:17:39.0406 3928 DcomLaunch - ok
10:17:39.0468 3928 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
10:17:39.0484 3928 Dhcp - ok
10:17:39.0500 3928 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
10:17:39.0500 3928 Disk - ok
10:17:39.0500 3928 dlcf_device - ok
10:17:39.0515 3928 dmadmin - ok
10:17:39.0546 3928 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
10:17:39.0562 3928 dmboot - ok
10:17:39.0578 3928 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
10:17:39.0578 3928 dmio - ok
10:17:39.0640 3928 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
10:17:39.0640 3928 dmload - ok
10:17:39.0703 3928 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
10:17:39.0703 3928 dmserver - ok
10:17:39.0718 3928 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
10:17:39.0718 3928 DMusic - ok
10:17:39.0765 3928 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
10:17:39.0765 3928 Dnscache - ok
10:17:39.0828 3928 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
10:17:39.0828 3928 Dot3svc - ok
10:17:39.0843 3928 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys
10:17:39.0859 3928 dpti2o - ok
10:17:39.0875 3928 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
10:17:39.0875 3928 drmkaud - ok
10:17:39.0937 3928 [ 24646242310499D75C6DB4B32768A3B3 ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys
10:17:39.0937 3928 drvmcdb - ok
10:17:39.0937 3928 [ 2FF629C1C443E25D0149B9DFB77E43A8 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys
10:17:39.0953 3928 drvnddm - ok
10:17:40.0031 3928 [ FE80901578E7E3DA70299A5AEB2B7FBD ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe
10:17:40.0031 3928 DSBrokerService - ok
10:17:40.0109 3928 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
10:17:40.0109 3928 DSproct - ok
10:17:40.0140 3928 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
10:17:40.0156 3928 dsunidrv - ok
10:17:40.0218 3928 [ 95974E66D3DE4951D29E28E8BC0B644C ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
10:17:40.0218 3928 E100B - ok
10:17:40.0281 3928 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
10:17:40.0296 3928 EapHost - ok
10:17:40.0359 3928 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
10:17:40.0359 3928 ERSvc - ok
10:17:40.0406 3928 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
10:17:40.0421 3928 Eventlog - ok
10:17:40.0484 3928 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
10:17:40.0484 3928 EventSystem - ok
10:17:40.0546 3928 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
10:17:40.0546 3928 Fastfat - ok
10:17:40.0593 3928 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
10:17:40.0609 3928 FastUserSwitchingCompatibility - ok
10:17:40.0625 3928 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe
10:17:40.0640 3928 Fax - ok
10:17:40.0671 3928 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
10:17:40.0734 3928 Fdc - ok
10:17:40.0750 3928 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
10:17:40.0750 3928 Fips - ok
10:17:40.0765 3928 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:17:40.0765 3928 Flpydisk - ok
10:17:40.0812 3928 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
10:17:40.0828 3928 FltMgr - ok
10:17:40.0937 3928 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
10:17:40.0953 3928 FontCache3.0.0.0 - ok
10:17:40.0953 3928 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:17:40.0953 3928 Fs_Rec - ok
10:17:41.0015 3928 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:17:41.0031 3928 Ftdisk - ok
10:17:41.0078 3928 [ 4AC51459805264AFFD5F6FDFB9D9235F ] GEARAspiWDM C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
10:17:41.0078 3928 GEARAspiWDM - ok
10:17:41.0187 3928 [ F0187E45268E86AAAA932CBD9087BEA8 ] GoogleDesktopManager-110309-193829 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
10:17:41.0187 3928 GoogleDesktopManager-110309-193829 - ok
10:17:41.0296 3928 [ D3316F6E3C011435F36E3D6E49B3196C ] GoToAssist C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
10:17:41.0296 3928 GoToAssist - ok
10:17:41.0359 3928 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:17:41.0359 3928 Gpc - ok
10:17:41.0375 3928 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
10:17:41.0390 3928 HDAudBus - ok
10:17:41.0453 3928 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
10:17:41.0453 3928 helpsvc - ok
10:17:41.0453 3928 HidServ - ok
10:17:41.0500 3928 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:17:41.0515 3928 HidUsb - ok
10:17:41.0562 3928 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
10:17:41.0562 3928 hkmsvc - ok
10:17:41.0609 3928 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys
10:17:41.0609 3928 hpn - ok
10:17:41.0671 3928 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
10:17:41.0687 3928 HTTP - ok
10:17:41.0703 3928 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
10:17:41.0718 3928 HTTPFilter - ok
10:17:41.0765 3928 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys
10:17:41.0781 3928 i2omgmt - ok
10:17:41.0796 3928 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys
10:17:41.0812 3928 i2omp - ok
10:17:41.0828 3928 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:17:41.0828 3928 i8042prt - ok
10:17:41.0937 3928 [ 5A8E05F1D5C36ABD58CFFA111EB325EA ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
10:17:41.0953 3928 ialm - ok
10:17:42.0062 3928 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
10:17:42.0078 3928 idsvc - ok
10:17:42.0109 3928 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
10:17:42.0125 3928 Imapi - ok
10:17:42.0187 3928 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
10:17:42.0203 3928 ImapiService - ok
10:17:42.0250 3928 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys
10:17:42.0250 3928 ini910u - ok
10:17:42.0312 3928 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
10:17:42.0312 3928 IntelIde - ok
10:17:42.0375 3928 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:17:42.0375 3928 intelppm - ok
10:17:42.0406 3928 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
10:17:42.0406 3928 Ip6Fw - ok
10:17:42.0453 3928 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:17:42.0453 3928 IpFilterDriver - ok
10:17:42.0484 3928 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:17:42.0484 3928 IpInIp - ok
10:17:42.0515 3928 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:17:42.0515 3928 IpNat - ok
10:17:42.0546 3928 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:17:42.0546 3928 IPSec - ok
10:17:42.0578 3928 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
10:17:42.0578 3928 IRENUM - ok
10:17:42.0609 3928 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:17:42.0609 3928 isapnp - ok
10:17:42.0812 3928 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
10:17:42.0812 3928 JavaQuickStarterService - ok
10:17:42.0843 3928 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:17:42.0843 3928 Kbdclass - ok
10:17:42.0859 3928 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:17:42.0859 3928 kbdhid - ok
10:17:42.0921 3928 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
10:17:42.0921 3928 kmixer - ok
10:17:42.0953 3928 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
10:17:42.0953 3928 KSecDD - ok
10:17:42.0968 3928 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
10:17:43.0000 3928 lanmanserver - ok
10:17:43.0062 3928 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
10:17:43.0078 3928 lanmanworkstation - ok
10:17:43.0078 3928 lbrtfdc - ok
10:17:43.0140 3928 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
10:17:43.0156 3928 LmHosts - ok
10:17:43.0265 3928 [ DDF15A42E27E8EFE27B18FD403151A86 ] MatSvc C:\Program Files\Microsoft Fix it Center\Matsvc.exe
10:17:43.0281 3928 MatSvc - ok
10:17:43.0328 3928 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
10:17:43.0328 3928 MBAMProtector - ok
10:17:43.0437 3928 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
10:17:43.0453 3928 MBAMScheduler - ok
10:17:43.0531 3928 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
10:17:43.0546 3928 MBAMService - ok
10:17:43.0546 3928 mcdbus - ok
10:17:43.0671 3928 [ DF0A511F38F16016BF658FCA0090CB87 ] McrdSvc C:\WINDOWS\ehome\mcrdsvc.exe
10:17:43.0671 3928 McrdSvc - ok
10:17:43.0718 3928 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
10:17:43.0734 3928 Messenger - ok
10:17:43.0781 3928 [ B7521F69C0A9B29D356157229376FB21 ] MHN C:\WINDOWS\System32\mhn.dll
10:17:43.0781 3928 MHN - ok
10:17:43.0812 3928 [ 7F2F1D2815A6449D346FCCCBC569FBD6 ] MHNDRV C:\WINDOWS\system32\DRIVERS\mhndrv.sys
10:17:43.0812 3928 MHNDRV - ok
10:17:43.0828 3928 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
10:17:43.0828 3928 mnmdd - ok
10:17:43.0875 3928 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
10:17:43.0890 3928 mnmsrvc - ok
10:17:43.0937 3928 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
10:17:43.0937 3928 Modem - ok
10:17:43.0984 3928 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:17:43.0984 3928 Mouclass - ok
10:17:44.0046 3928 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:17:44.0046 3928 mouhid - ok
10:17:44.0062 3928 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
10:17:44.0062 3928 MountMgr - ok
10:17:44.0109 3928 [ 313265CF4F5F02ED927774DA1DB3FE00 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
10:17:44.0125 3928 MozillaMaintenance - ok
10:17:44.0171 3928 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys
10:17:44.0187 3928 MpFilter - ok
10:17:44.0234 3928 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys
10:17:44.0234 3928 mraid35x - ok
10:17:44.0250 3928 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:17:44.0265 3928 MRxDAV - ok
10:17:44.0328 3928 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:17:44.0328 3928 MRxSmb - ok
10:17:44.0390 3928 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
10:17:44.0406 3928 MSDTC - ok
10:17:44.0406 3928 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
10:17:44.0421 3928 Msfs - ok
10:17:44.0421 3928 MSIServer - ok
10:17:44.0437 3928 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:17:44.0437 3928 MSKSSRV - ok
10:17:44.0546 3928 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
10:17:44.0546 3928 MsMpSvc - ok
10:17:44.0609 3928 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:17:44.0609 3928 MSPCLOCK - ok
10:17:44.0625 3928 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
10:17:44.0625 3928 MSPQM - ok
10:17:44.0687 3928 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:17:44.0687 3928 mssmbios - ok
10:17:44.0734 3928 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
10:17:44.0734 3928 MSTEE - ok
10:17:44.0781 3928 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
10:17:44.0781 3928 Mup - ok
10:17:44.0828 3928 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:17:44.0828 3928 NABTSFEC - ok
10:17:44.0875 3928 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
10:17:44.0890 3928 napagent - ok
10:17:44.0921 3928 [ 0DF9CC7B5CC173F545723F23E68FAC93 ] NCHSSVAD C:\WINDOWS\system32\drivers\nchssvad.sys
10:17:44.0953 3928 NCHSSVAD - ok
10:17:44.0984 3928 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
10:17:44.0984 3928 NDIS - ok
10:17:45.0015 3928 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:17:45.0015 3928 NdisIP - ok
10:17:45.0046 3928 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:17:45.0046 3928 NdisTapi - ok
10:17:45.0109 3928 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:17:45.0109 3928 Ndisuio - ok
10:17:45.0140 3928 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:17:45.0140 3928 NdisWan - ok
10:17:45.0203 3928 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
10:17:45.0218 3928 NDProxy - ok
10:17:45.0218 3928 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
10:17:45.0218 3928 NetBIOS - ok
10:17:45.0234 3928 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
10:17:45.0250 3928 NetBT - ok
10:17:45.0312 3928 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
10:17:45.0312 3928 NetDDE - ok
10:17:45.0328 3928 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
10:17:45.0328 3928 NetDDEdsdm - ok
10:17:45.0390 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
10:17:45.0390 3928 Netlogon - ok
10:17:45.0421 3928 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
10:17:45.0437 3928 Netman - ok
10:17:45.0593 3928 [ 9DA26B773BD04B867A8E9F427CD048FC ] NetSvc C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
10:17:45.0734 3928 NetSvc - ok
10:17:45.0781 3928 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:17:45.0781 3928 NetTcpPortSharing - ok
10:17:45.0828 3928 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
10:17:45.0843 3928 Nla - ok
10:17:45.0921 3928 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
10:17:46.0000 3928 Npfs - ok
10:17:46.0093 3928 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
10:17:46.0234 3928 Ntfs - ok
10:17:46.0328 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
10:17:46.0343 3928 NtLmSsp - ok
10:17:46.0421 3928 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
10:17:46.0437 3928 NtmsSvc - ok
10:17:46.0453 3928 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
10:17:46.0453 3928 Null - ok
10:17:46.0546 3928 [ 2B298519EDBFCF451D43E0F1E8F1006D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:17:46.0578 3928 nv - ok
10:17:46.0593 3928 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:17:46.0593 3928 NwlnkFlt - ok
10:17:46.0656 3928 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:17:46.0656 3928 NwlnkFwd - ok
10:17:46.0703 3928 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
10:17:46.0703 3928 Parport - ok
10:17:46.0734 3928 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
10:17:46.0734 3928 PartMgr - ok
10:17:46.0796 3928 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
10:17:46.0812 3928 ParVdm - ok
10:17:46.0828 3928 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
10:17:46.0828 3928 PCI - ok
10:17:46.0828 3928 PCIDump - ok
10:17:46.0843 3928 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
10:17:46.0843 3928 PCIIde - ok
10:17:46.0875 3928 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
10:17:46.0875 3928 Pcmcia - ok
10:17:46.0875 3928 PDCOMP - ok
10:17:46.0890 3928 PDFRAME - ok
10:17:46.0890 3928 PDRELI - ok
10:17:46.0906 3928 PDRFRAME - ok
10:17:46.0921 3928 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys
10:17:46.0921 3928 perc2 - ok
10:17:46.0937 3928 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys
10:17:46.0937 3928 perc2hib - ok
10:17:46.0984 3928 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
10:17:47.0000 3928 PlugPlay - ok
10:17:47.0015 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
10:17:47.0015 3928 PolicyAgent - ok
10:17:47.0078 3928 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:17:47.0093 3928 PptpMiniport - ok
10:17:47.0093 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
10:17:47.0109 3928 ProtectedStorage - ok
10:17:47.0171 3928 [ F115AF58ABE5605D7D709CBFBD83F418 ] ProtexisLicensing C:\WINDOWS\system32\PSIService.exe
10:17:47.0187 3928 ProtexisLicensing - ok
10:17:47.0234 3928 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
10:17:47.0234 3928 PSched - ok
10:17:47.0250 3928 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:17:47.0265 3928 Ptilink - ok
10:17:47.0265 3928 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:17:47.0265 3928 PxHelp20 - ok
10:17:47.0328 3928 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys
10:17:47.0328 3928 ql1080 - ok
10:17:47.0343 3928 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
10:17:47.0343 3928 Ql10wnt - ok
10:17:47.0359 3928 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys
10:17:47.0359 3928 ql12160 - ok
10:17:47.0359 3928 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys
10:17:47.0375 3928 ql1240 - ok
10:17:47.0375 3928 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys
10:17:47.0390 3928 ql1280 - ok
10:17:47.0390 3928 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:17:47.0390 3928 RasAcd - ok
10:17:47.0453 3928 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
10:17:47.0468 3928 RasAuto - ok
10:17:47.0484 3928 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:17:47.0484 3928 Rasl2tp - ok
10:17:47.0546 3928 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
10:17:47.0562 3928 RasMan - ok
10:17:47.0578 3928 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:17:47.0593 3928 RasPppoe - ok
10:17:47.0609 3928 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
10:17:47.0609 3928 Raspti - ok
10:17:47.0609 3928 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:17:47.0625 3928 Rdbss - ok
10:17:47.0640 3928 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:17:47.0640 3928 RDPCDD - ok
10:17:47.0671 3928 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:17:47.0671 3928 rdpdr - ok
10:17:47.0734 3928 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
10:17:47.0734 3928 RDPWD - ok
10:17:47.0750 3928 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
10:17:47.0765 3928 RDSessMgr - ok
10:17:47.0781 3928 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
10:17:47.0781 3928 redbook - ok
10:17:47.0828 3928 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
10:17:47.0843 3928 RemoteAccess - ok
10:17:47.0875 3928 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
10:17:47.0890 3928 RemoteRegistry - ok
10:17:47.0921 3928 [ 5F83735559A1D9B610020065741F5AA5 ] RkHit C:\WINDOWS\system32\drivers\RKHit.sys
10:17:47.0921 3928 RkHit - ok
10:17:47.0968 3928 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
10:17:47.0984 3928 RpcLocator - ok
10:17:48.0000 3928 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll
10:17:48.0015 3928 RpcSs - ok
10:17:48.0078 3928 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
10:17:48.0109 3928 RSVP - ok
10:17:48.0156 3928 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
10:17:48.0156 3928 rtl8139 - ok
10:17:48.0218 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
10:17:48.0234 3928 SamSs - ok
10:17:48.0296 3928 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
10:17:48.0312 3928 SCardSvr - ok
10:17:48.0390 3928 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
10:17:48.0406 3928 Schedule - ok
10:17:48.0453 3928 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:17:48.0453 3928 Secdrv - ok
10:17:48.0484 3928 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
10:17:48.0500 3928 seclogon - ok
10:17:48.0515 3928 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
10:17:48.0531 3928 SENS - ok
10:17:48.0562 3928 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
10:17:48.0562 3928 serenum - ok
10:17:48.0593 3928 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
10:17:48.0593 3928 Serial - ok
10:17:48.0625 3928 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
10:17:48.0625 3928 Sfloppy - ok
10:17:48.0703 3928 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
10:17:48.0718 3928 SharedAccess - ok
10:17:48.0734 3928 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
10:17:48.0750 3928 ShellHWDetection - ok
10:17:48.0750 3928 Simbad - ok
10:17:48.0796 3928 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys
10:17:48.0796 3928 sisagp - ok
10:17:48.0843 3928 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
10:17:48.0843 3928 SkypeUpdate - ok
10:17:48.0875 3928 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:17:48.0890 3928 SLIP - ok
10:17:48.0937 3928 [ 2DEADE72F7CDEF9C9E8B5AB6255157CA ] SMServer C:\WINDOWS\system32\snmvtsvc.exe
10:17:49.0093 3928 SMServer - ok
10:17:49.0125 3928 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys
10:17:49.0125 3928 Sparrow - ok
10:17:49.0171 3928 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
10:17:49.0187 3928 splitter - ok
10:17:49.0234 3928 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
10:17:49.0250 3928 Spooler - ok
10:17:49.0328 3928 sprtsvc_dellsupportcenter - ok
10:17:49.0828 3928 [ 287D75A3D421D16D9FEAC81DDDCB703A ] squeezesvc C:\PROGRA~1\Squeezebox\server\SqueezeSvr.exe
10:17:58.0437 3928 squeezesvc - ok
10:17:58.0500 3928 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
10:17:58.0500 3928 sr - ok
10:17:58.0562 3928 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
10:17:58.0578 3928 srservice - ok
10:17:58.0640 3928 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
10:17:58.0640 3928 Srv - ok
10:17:58.0703 3928 [ 1CBD1B58A32DE97899F5290B05F856DB ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys
10:17:58.0703 3928 sscdbhk5 - ok
10:17:58.0718 3928 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
10:17:58.0734 3928 SSDPSRV - ok
10:17:58.0750 3928 [ 7FB07AC152D7A87E66204860002BD9A4 ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys
10:17:58.0750 3928 ssrtln - ok
10:17:58.0812 3928 Steam Client Service - ok
10:17:58.0890 3928 [ 2A2DC39623ADEF8AB3703AB9FAC4B440 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys
10:17:58.0921 3928 STHDA - ok
10:17:59.0000 3928 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
10:17:59.0015 3928 stisvc - ok
10:17:59.0046 3928 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:17:59.0046 3928 streamip - ok
10:17:59.0109 3928 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
10:17:59.0109 3928 swenum - ok
10:17:59.0187 3928 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
10:17:59.0187 3928 swmidi - ok
10:17:59.0187 3928 SwPrv - ok
10:17:59.0250 3928 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys
10:17:59.0250 3928 symc810 - ok
10:17:59.0265 3928 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys
10:17:59.0265 3928 symc8xx - ok
10:17:59.0281 3928 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys
10:17:59.0281 3928 sym_hi - ok
10:17:59.0296 3928 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys
10:17:59.0296 3928 sym_u3 - ok
10:17:59.0343 3928 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
10:17:59.0343 3928 sysaudio - ok
10:17:59.0406 3928 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
10:17:59.0421 3928 SysmonLog - ok
10:17:59.0437 3928 szkg - ok
10:17:59.0484 3928 [ 0C3B2A9C4BD2DD9A6C2E4084314DD719 ] taphss C:\WINDOWS\system32\DRIVERS\taphss.sys
10:17:59.0484 3928 taphss - ok
10:17:59.0515 3928 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
10:17:59.0531 3928 TapiSrv - ok
10:17:59.0578 3928 [ 4D46F63F7DDC2442941D63327C360B90 ] tbhsd C:\WINDOWS\system32\drivers\tbhsd.sys
10:17:59.0578 3928 tbhsd - ok
10:17:59.0578 3928 tclondrv - ok
10:17:59.0656 3928 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:17:59.0656 3928 Tcpip - ok
10:17:59.0703 3928 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
10:17:59.0718 3928 TDPIPE - ok
10:17:59.0734 3928 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
10:17:59.0734 3928 TDTCP - ok
10:17:59.0765 3928 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
10:17:59.0781 3928 TermDD - ok
10:17:59.0843 3928 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
10:17:59.0875 3928 TermService - ok
10:17:59.0968 3928 [ C89DAABDFF5BD984181F45ADF6DDB24A ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys
10:18:00.0015 3928 tfsnboio - ok
10:18:00.0031 3928 [ F093906C27FC9C59BD03D84807266107 ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys
10:18:00.0062 3928 tfsncofs - ok
10:18:00.0078 3928 [ 9294575CDAD17D1DADFCD98A2CA26E7A ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys
10:18:00.0093 3928 tfsndrct - ok
10:18:00.0109 3928 [ CDCC394CBAAC183F9BDEBF6D2F97C5C6 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys
10:18:00.0140 3928 tfsndres - ok
10:18:00.0171 3928 [ 0A6C7C989DD76BB8989FD958AC5601D0 ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys
10:18:00.0250 3928 tfsnifs - ok
10:18:00.0281 3928 [ 92A17C0D73500F9B9C3028DA9E4CDBA6 ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys
10:18:00.0296 3928 tfsnopio - ok
10:18:00.0312 3928 [ 15AB1A2BB2B35EB1DCDA39405114AFC6 ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys
10:18:00.0343 3928 tfsnpool - ok
10:18:00.0359 3928 [ 370D2779668BF3B8D14F34356C41AB9C ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys
10:18:00.0421 3928 tfsnudf - ok
10:18:00.0437 3928 [ 4564799868C4BCDF28C8EFC6D4C48C4B ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys
10:18:00.0500 3928 tfsnudfa - ok
10:18:00.0515 3928 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
10:18:00.0531 3928 Themes - ok
10:18:00.0593 3928 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
10:18:00.0609 3928 TlntSvr - ok
10:18:00.0625 3928 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys
10:18:00.0640 3928 TosIde - ok
10:18:00.0703 3928 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
10:18:00.0718 3928 TrkWks - ok
10:18:00.0781 3928 [ 78A3E03AB4792E3514FCFDB893EF7D39 ] TucbAudio C:\WINDOWS\system32\drivers\TucbAudio.sys
10:18:00.0812 3928 TucbAudio - ok
10:18:00.0859 3928 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
10:18:00.0859 3928 Udfs - ok
10:18:00.0890 3928 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys
10:18:00.0890 3928 ultra - ok
10:18:00.0968 3928 [ 586DD78A81BA2DB209C94DA23F3B1691 ] Uniblue DiskRescue C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
10:18:00.0968 3928 Uniblue DiskRescue - ok
10:18:01.0031 3928 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
10:18:01.0046 3928 Update - ok
10:18:01.0109 3928 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
10:18:01.0125 3928 upnphost - ok
10:18:01.0171 3928 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
10:18:01.0171 3928 UPS - ok
10:18:01.0234 3928 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
10:18:01.0250 3928 usbaudio - ok
10:18:01.0312 3928 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:18:01.0312 3928 usbccgp - ok
10:18:01.0328 3928 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:18:01.0343 3928 usbehci - ok
10:18:01.0390 3928 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:18:01.0390 3928 usbhub - ok
10:18:01.0421 3928 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:18:01.0421 3928 usbprint - ok
10:18:01.0468 3928 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:18:01.0468 3928 usbscan - ok
10:18:01.0500 3928 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:18:01.0515 3928 USBSTOR - ok
10:18:01.0515 3928 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:18:01.0531 3928 usbuhci - ok
10:18:01.0656 3928 [ C5B70A6AA947667CE0E5FC84A05EC8B6 ] usnjsvc C:\Program Files\MSN Messenger\usnsvc.exe
10:18:01.0656 3928 usnjsvc - ok
10:18:01.0671 3928 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
10:18:01.0671 3928 VgaSave - ok
10:18:01.0718 3928 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys
10:18:01.0718 3928 viaagp - ok
10:18:01.0734 3928 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
10:18:01.0734 3928 ViaIde - ok
10:18:01.0796 3928 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
10:18:01.0796 3928 VolSnap - ok
10:18:01.0859 3928 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
10:18:01.0875 3928 VSS - ok
10:18:01.0906 3928 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll
10:18:01.0921 3928 w32time - ok
10:18:01.0953 3928 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:18:01.0953 3928 Wanarp - ok
10:18:01.0953 3928 wanatw - ok
10:18:02.0031 3928 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
10:18:02.0046 3928 Wdf01000 - ok
10:18:02.0046 3928 WDICA - ok
10:18:02.0078 3928 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
10:18:02.0078 3928 wdmaud - ok
10:18:02.0109 3928 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
10:18:02.0125 3928 WebClient - ok
10:18:02.0250 3928 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
10:18:02.0250 3928 winmgmt - ok
10:18:02.0312 3928 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
10:18:02.0312 3928 WmdmPmSN - ok
10:18:02.0359 3928 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
10:18:02.0359 3928 Wmi - ok
10:18:02.0390 3928 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
10:18:02.0390 3928 WmiApSrv - ok
10:18:02.0515 3928 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
10:18:02.0531 3928 WMPNetworkSvc - ok
10:18:02.0546 3928 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
10:18:02.0562 3928 WpdUsb - ok
10:18:02.0609 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(1) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys
10:18:02.0656 3928 WsAudio_DeviceS(1) - ok
10:18:02.0687 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(2) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys
10:18:02.0718 3928 WsAudio_DeviceS(2) - ok
10:18:02.0765 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(3) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys
10:18:02.0796 3928 WsAudio_DeviceS(3) - ok
10:18:02.0843 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(4) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys
10:18:02.0875 3928 WsAudio_DeviceS(4) - ok
10:18:02.0921 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(5) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys
10:18:02.0953 3928 WsAudio_DeviceS(5) - ok
10:18:03.0000 3928 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
10:18:03.0015 3928 wscsvc - ok
10:18:03.0062 3928 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:18:03.0062 3928 WSTCODEC - ok
10:18:03.0109 3928 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
10:18:03.0125 3928 wuauserv - ok
10:18:03.0187 3928 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:18:03.0187 3928 WudfPf - ok
10:18:03.0250 3928 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:18:03.0250 3928 WudfRd - ok
10:18:03.0265 3928 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
10:18:03.0281 3928 WudfSvc - ok
10:18:03.0343 3928 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
10:18:03.0359 3928 WZCSVC - ok
10:18:03.0406 3928 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
10:18:03.0421 3928 xmlprov - ok
10:18:03.0437 3928 ================ Scan global ===============================
10:18:03.0484 3928 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
10:18:03.0531 3928 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
10:18:03.0562 3928 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
10:18:03.0578 3928 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
10:18:03.0593 3928 [Global] - ok
10:18:03.0593 3928 ================ Scan MBR ==================================
10:18:03.0625 3928 [ 91722E6BC3A2B40FF00222DCA4A3DB3E ] \Device\Harddisk0\DR0
10:18:03.0828 3928 \Device\Harddisk0\DR0 - ok
10:18:03.0828 3928 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
10:18:03.0828 3928 \Device\Harddisk1\DR1 - ok
10:18:03.0828 3928 ================ Scan VBR ==================================
10:18:03.0843 3928 [ E277A2030501530D9C30930555EF2B92 ] \Device\Harddisk0\DR0\Partition1
10:18:03.0843 3928 \Device\Harddisk0\DR0\Partition1 - ok
10:18:03.0843 3928 ============================================================
10:18:03.0843 3928 Scan finished
10:18:03.0843 3928 ============================================================
10:18:03.0859 2952 Detected object count: 0
10:18:03.0859 2952 Actual detected object count: 0
10:20:48.0578 3496 Deinitialize success


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
Hi,
Just a couple of things which may or not be important.
When i switched on this morning the following message came up:
Windows no disk Exception processing message
00000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c
Malware then proceeded to pop up telling me that it had successfully blocked access to a potentially malicious website (outgoing) I got some of the codes ie 218.10.63.240 - is it worth noting these down if I can?
Also today when I close down internet explorer it shuts down Thunderbird too. I am trying not to use my machine unless absolutely neccesary but am checking in regularly to see if you are around and have more instructions.
Cheers,
Anna



LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne

OTL Log

OTL logfile created on: 26/11/2012 17:42:58 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 71.78% Memory free
7.81 Gb Paging File | 7.43 Gb Available in Paging File | 95.11% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 24.81 Gb Free Space | 35.54% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.96% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/07/08 13:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe
PRC - [2009/12/23 17:16:26 | 001,701,224 | ---- | M] (Philips) -- C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/26 17:29:17 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\93e7e3d6030f426844228042348210cf\Service.dll
MOD - [2012/11/26 17:29:14 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/11/26 17:29:13 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/11/26 17:29:11 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/11/26 17:29:09 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/11/26 17:29:07 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/11/26 17:29:02 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/11/26 17:29:01 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/11/26 17:28:59 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/11/26 17:28:56 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/11/26 17:28:53 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/11/26 17:28:51 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/11/26 17:28:49 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/11/26 17:28:48 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/11/26 17:28:48 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/11/26 17:28:46 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/11/26 17:28:44 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/11/26 17:28:41 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/11/26 08:48:55 | 002,033,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112600\algo.dll
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2012/07/08 13:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll
MOD - [2012/07/08 13:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll
MOD - [2012/07/08 13:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\en\en.dll
MOD - [2009/12/23 17:16:26 | 000,135,168 | ---- | M] () -- C:\Program Files\Philips\GoGear VIBE Device Manager\Scsi_nt.dll
MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Stopped] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw)
DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv)
DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio)
DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit)
DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531)
DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »home.sweetim.com/?crg=3.1010000.···606FC20}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = »www.google.com/ie
IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = »www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »www.google.co.uk/
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···m=IE8SRC
IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = »apype.com/results.php?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = »search.conduit.com/ResultsExt.as···T3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: 14xRm%40skywebsearch.com:3.0.0.0
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] ()

[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions
[2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/09/27 17:40:26 | 000,046,060 | ---- | M] () (No name found) -- C:\DOCUME~1\ANNAS\A YOUTUBE DOWNLOADER FREE.XPI
[2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml

O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips)
O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} »eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} »cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} »update.microsoft.com/windowsupda···43462484 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O34 - HKLM BootExecute: (autocheck autochk /k:E *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter
[2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit
[2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data
[2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth
[2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer
[2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2
[2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes
[2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2)
[2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 17:36:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/26 17:30:18 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/26 17:28:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/26 17:27:47 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/26 17:26:30 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/26 17:26:29 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/26 17:26:26 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/11/26 17:26:25 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/26 17:26:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/26 15:14:03 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/11/25 22:36:38 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg
[2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp
[2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp
[2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos
[2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg
[2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi
[2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll
[2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll
[2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel
[2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc
[2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND
[2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe
[2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini
[2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== LOP Check ==========[/color]

[2012/11/25 18:26:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/10/12 19:19:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 09:05:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/02/16 18:22:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/07/03 15:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileOpen
[2012/01/31 10:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2011/11/03 18:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/07/14 13:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2012/11/26 10:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/25 22:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2010/02/27 20:55:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution
[2008/01/29 15:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SongbirdVLC
[2012/01/31 19:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Squeezebox
[2007/04/10 09:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/11/22 10:25:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2012/11/24 20:10:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/10/26 17:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/03/04 14:33:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2008/10/09 13:32:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2009/02/16 18:17:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
[2012/07/26 10:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46}
[2010/02/27 21:30:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/11 13:50:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{8A09CD83-59E1-4DB1-AAFC-E25174FC6706}
[2010/05/26 18:29:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
[2012/07/09 09:07:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{F0489EF2-D393-4114-85BA-A94D71D89543}
[2007/12/06 13:49:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\.wyzo
[2010/10/21 09:21:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Amazon
[2009/02/24 20:03:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\ArchosLink
[2008/03/07 11:47:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Azureus
[2008/10/09 13:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\BitTorrent
[2012/04/26 12:11:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\calibre
[2008/10/09 13:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\DNA
[2012/11/25 22:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/26 17:30:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Dropbox
[2012/11/21 15:51:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\EurekaLog
[2010/02/17 16:19:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\eXPert PDF Editor
[2009/07/03 15:45:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\FileOpen
[2012/06/30 15:45:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Firefly Studios
[2012/09/30 17:42:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Free Download Manager
[2010/02/27 18:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\GetRightToGo
[2010/12/28 17:41:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\gtk-2.0
[2007/01/17 12:41:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Leadertech
[2008/08/30 20:15:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\LGSync
[2011/03/01 15:11:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\moovida-1
[2006/10/11 20:58:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\MSNInstaller
[2009/05/18 17:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\NCH Swift Sound
[2012/08/18 14:49:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Oracle
[2009/03/06 10:53:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\OverDrive
[2012/11/26 10:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/25 22:36:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2011/03/13 17:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\PCDr
[2012/09/07 18:48:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Philips
[2012/09/07 18:31:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Philips-Songbird
[2009/06/05 17:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\PIFreePC
[2008/01/29 15:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Qtrax1
[2012/11/25 22:14:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/08/10 13:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\SanDisk
[2012/11/15 15:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Spotify
[2010/08/26 19:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Thunderbird
[2011/04/28 13:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Uniblue
[2012/11/24 18:39:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\UseNeXT
[2012/11/26 17:30:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\uTorrent
[2007/12/07 22:27:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Wyzo

[color=#E56717]========== Purity Check ==========[/color]

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\?ý??????????
[2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\?ý??????????

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
Thanks for the TDSS log. It was negative.

However, there are several adware programs installed, as well as a torrent client that I assume you did not install (came with something else, most likely).

First:
Use Add/Remove Programs to uninstall the following. Note, that if there is no Add/Remove Programs entry, just go on to the next item.

Yontoo 1.10.02
µTorrent
uTorrentControl_v2 Toolbar
A You Tube Downloader

Second:
In Firefox, remove SkyWebSearch from the list of search entries, and any addon (extension) for it.

Third:
Run OTL again, and post the new log in this thread. Note that there will not be a new Extras log.
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


Carcassonne

join:2012-11-26
11000

Sorry - I am not sure how to remove Skysearch from the list of search entries?



LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26

reply to Carcassonne
Click in the Search Box and press 'Alt+UpArrow'. Then select 'Manage Search Engines'

Alternatively, left click on the arrow to the right of the currently selected search engine. Then select 'Manage Search Engines' as before.


Carcassonne

join:2012-11-26
11000

I have done both those things and I am not given that option. I just get a list of 12 previously search items


Carcassonne

join:2012-11-26
11000

sorry should have said I have never noticed Skysearch coming up


Carcassonne

join:2012-11-26
11000

1 edit

reply to LoPhatPhuud

Ok - I uninstalled Utorrent
No utorrentControl v2 toolbar
No A youtube Downloader
When I tried to remove Yontoo I got the message:
C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat
Error2 while loading archive: The system cannot find the specified file

While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it – I do not seem to be able to remove it.

Machine now going very slow & capricious!
Applications opening & closing unexpectedly

Attatched is the OTL report

OTL logfile created on: 27/11/2012 19:00:53 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free
7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32
Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll
MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll
MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll
MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw)
DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv)
DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio)
DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit)
DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531)
DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »home.sweetim.com/?crg=3.1010000.···606FC20}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = »www.google.com/ie
IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = »www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »www.google.co.uk/
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···m=IE8SRC
IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = »apype.com/results.php?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = »search.conduit.com/ResultsExt.as···T3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] ()

[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions
[2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml

O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found
O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd)
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips)
O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} »eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} »cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} »update.microsoft.com/windowsupda···43462484 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} »download.eset.com/special/eos/On···nner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O34 - HKLM BootExecute: (autocheck autochk /k:E *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012
[2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter
[2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit
[2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data
[2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth
[2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer
[2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2
[2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2
[2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes
[2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2)
[2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat
[2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg
[2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp
[2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat
[2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp
[2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos
[2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg
[2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi
[2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll
[2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll
[2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel
[2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc
[2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND
[2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe
[2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini
[2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑￿￿۫粑퀣睏
[2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑￿￿۫粑퀣睏

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

Carcassonne

join:2012-11-26
11000

reply to Carcassonne

Ok - I uninstalled Utorrent
No utorrentControl v2 toolbar
No A youtube Downloader
When I tried to remove Yontoo I got the message:
C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat
Error2 while loading archive: The system cannot find the specified file
While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it – I do not seem to be able to remove it.
OTL Scan results:
OTL logfile created on: 27/11/2012 19:00:53 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free
7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32
Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll
MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll
MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll
MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw)
DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv)
DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio)
DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit)
DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531)
DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »home.sweetim.com/?crg=3.1010000.···606FC20}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = »www.google.com/ie
IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = »www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »www.google.co.uk/
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···m=IE8SRC
IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = »apype.com/results.php?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = »search.conduit.com/ResultsExt.as···T3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] ()

[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions
[2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml

O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found
O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd)
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips)
O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} »eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} »cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} »update.microsoft.com/windowsupda···43462484 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} »download.eset.com/special/eos/On···nner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O34 - HKLM BootExecute: (autocheck autochk /k:E *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012
[2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter
[2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit
[2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data
[2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth
[2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer
[2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2
[2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2
[2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes
[2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2)
[2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat
[2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg
[2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp
[2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat
[2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp
[2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos
[2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg
[2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi
[2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll
[2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll
[2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel
[2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc
[2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND
[2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe
[2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini
[2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏
[2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

Carcassonne

join:2012-11-26
11000

reply to Carcassonne

Ok - I uninstalled Utorrent
No utorrentControl v2 toolbar
No A youtube Downloader
When I tried to remove Yontoo I got the message:
C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat
Error2 while loading archive: The system cannot find the specified file
While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it – I do not seem to be able to remove it.
Here are the OTL scan results:
OTL logfile created on: 27/11/2012 19:00:53 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free
7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32
Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll
MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll
MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll
MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw)
DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv)
DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio)
DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit)
DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531)
DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »home.sweetim.com/?crg=3.1010000.···606FC20}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = »www.google.com/ie
IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = »www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »www.google.co.uk/
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···m=IE8SRC
IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = »apype.com/results.php?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = »search.conduit.com/ResultsExt.as···T3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] ()

[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions
[2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml

O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found
O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd)
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips)
O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} »eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} »cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} »update.microsoft.com/windowsupda···43462484 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} »download.eset.com/special/eos/On···nner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O34 - HKLM BootExecute: (autocheck autochk /k:E *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012
[2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter
[2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit
[2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data
[2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth
[2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer
[2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2
[2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2
[2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes
[2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2)
[2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat
[2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg
[2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp
[2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat
[2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp
[2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos
[2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg
[2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi
[2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll
[2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll
[2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel
[2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc
[2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND
[2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe
[2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini
[2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏
[2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
Based on the additional symptoms you mention (capricious starts) you may be best served by reformatting and starting over.

I'm not to the point where that is the only option I will recommend, but we are going in that direction.

Let me know if you want to continue, or if you would prefer to just start over nowl.
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


Carcassonne

join:2012-11-26
11000

I like a challenge and I am finding it quite interesting so I am happy to carry on if you are!
THANKS FOR YOUR PATIENCE


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
Just to let you know I have to go out now for about an hour and a half but then will be in all evening. cheers


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
I await further instructions!



LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, copy and paste the contents of the following box:


:OTL
IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found
IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = »apype.com/results.php?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = »search.conduit.com/ResultsExt.as···T3220468
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found
O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)

:Services

:Reg

:Files

:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Once you see a message box "Fix complete! Click OK to open the fix log."
[*]Click the OK button
[*]The log will open in Notepad (your default text editor).
{*]Save the log. Post a copy of that log in your next reply.


Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.

If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum

Carcassonne

join:2012-11-26
11000

Ok - thanks!


Tuesday, 09-Apr 00:34:36 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics