
how-to block ads
|
|
Uniqs: 5880 |
Share Topic  |
 |
|
|
|
 | [Malware] Starburn software problem -Virus/malware? Hello, About a month ago on start up I was getting a message something like,youtube downloader Free_helper.exe has encountered a problem. Since I was not aware of having uploaded anything to do with youtube I am afraid I just ignored it. Shortly after this (a few days) whilst still getting the youtube message when I launched my browser Mozilla Firefox 17. ,instead of getting my Google homepage I was getting search.starburnsoftware.com. No matter how may times I reset my options back to Google it did not work. Eventually I did a search for files or folders containing the word starburn I found about 3 files, which I deleted. This worked like a charm! Instead I got apype.com. I then repeated the search this time for apype it came up with nothing. After this however apype.com had gone & starburn was back. When I tried to reset my preferences it showed apype .com but when I launched my browser I got starburn. This continues to be the case even after doing you recommended clean up. At one point my husband suggested trying Explorer. This was also showing starburn however after about 10 resets it is now sticking with Google. I am now using Explorer but I have not uninstalled Firefox I tried Bitdefender Quick Scan, which froze at the end but found nothing, and Malwarebytes and latterly Avast but to no avail. I also used Microsoft Fix It. I then contacted my son who is in England and works in IT & he directed me to you. I have now completed your Mandatory Steps Before Requesting Assistance and here are my results: Incidentally I got to this point on your web page about half an hour ago & it all my text disappeared. My results:
1.Contents of the MBAM log
Malwarebytes Anti-Malware (Trial) 1.65.1.1000 www.malwarebytes.org
Database version: v2012.11.26.04
Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 annas :: DELL [administrator]
Protection: Disabled
26/11/2012 14:27:05 mbam-log-2012-11-26 (14-27-05).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|Z:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 434356 Time elapsed: 2 hour(s), 50 minute(s), 56 second(s)
Memory Processes Detected: 0 (No malicious items detected)
Memory Modules Detected: 0 (No malicious items detected)
Registry Keys Detected: 3 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DECEAAA2-370A-49BB-9362-68C3A58DDC62} (Adware.180Solutions) -> Quarantined and deleted successfully. HKCU\Software\PlayVolcanoSA (Adware.HotBar.PV) -> Quarantined and deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayVolcanoSA (Adware.HotBar.PV) -> Quarantined and deleted successfully.
Registry Values Detected: 1 HKCU\Software\Microsoft\Windows\CurrentVersion\Run|PlayVolcanoSA (Adware.HotBar.PV) -> Data: "C:\Documents and Settings\annas\Local Settings\Application Data\PlayVolcanoSA\bin\1.0.10.0\PlayVolcanoSA.exe" -> Quarantined and deleted successfully.
Registry Data Items Detected: 1 HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 3 C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA (Adware.HotBar.PV) -> Quarantined and deleted successfully. C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA\bin (Adware.HotBar.PV) -> Quarantined and deleted successfully. C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA\bin\1.0.10.0 (Adware.HotBar.PV) -> Quarantined and deleted successfully.
Files Detected: 3 E:\program files\Corel® Painter Essentials 4+Keygen-HeartBug\keygen\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully. E:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP2168\A0265087.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully. C:\Documents and Settings\annas\Local Settings\Application Data\PLAYVOLCANOSA\bin\1.0.10.0\PlayVolcanoSAHook.dll (Adware.HotBar.PV) -> Quarantined and deleted successfully.
(end) 2. contents of OTL.txt - Attached
3. Contents of Extras.txt
OTL Extras logfile created on: 26/11/2012 17:42:58 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.99 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 71.78% Memory free 7.81 Gb Paging File | 7.43 Gb Available in Paging File | 95.11% Paging File free Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.82 Gb Total Space | 24.81 Gb Free Space | 35.54% Space Free | Partition Type: NTFS Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.96% Space Free | Partition Type: NTFS Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS
Computer Name: DELL | User Name: annas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[color=#E56717]========== Shell Spawning ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] "DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] "DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[color=#E56717]========== System Restore Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2
[color=#E56717]========== Firewall Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 "9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI) "9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI) "9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI) "9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI) "9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI) "9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI) "9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI) "9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI) "9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI) "9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI) "9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI) "9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI) "8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI) "10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI) "9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI) "3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp "3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "18694:TCP" = 18694:TCP:*:Enabled:BitComet 18694 TCP "18694:UDP" = 18694:UDP:*:Enabled:BitComet 18694 UDP "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "27629:TCP" = 27629:TCP:*:Enabled:BitComet 27629 TCP "27629:UDP" = 27629:UDP:*:Enabled:BitComet 27629 UDP "8081:TCP" = 8081:TCP:*:Enabled:VLC "8080:TCP" = 8080:TCP:*:Enabled:Homeplayer "9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI) "9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI) "9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI) "9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI) "9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI) "9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI) "9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI) "9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI) "9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI) "9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI) "9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI) "9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI) "8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI) "10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI) "9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI) "3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp "3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp
[color=#E56717]========== Authorized Applications List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL "C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL "C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) "C:\Documents and Settings\annas\Desktop\utorrent.exe" = C:\Documents and Settings\annas\Desktop\utorrent.exe:*:Enabled:µTorrent "C:\Program Files\Grisoft\AVG Free\avginet.exe" = C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation) "C:\Documents and Settings\annas\My Documents\Freeplayer\vlc\vlc.exe" = C:\Documents and Settings\annas\My Documents\Freeplayer\vlc\vlc.exe:*:Enabled:VLC media player "C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- () "C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent "C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" = C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe:*:Enabled:SpeedUpMyPC 3 "F:\Bit comet setup\BitComet\BitComet.exe" = F:\Bit comet setup\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client "F:\Downloads\Free Download Manager\fdm.exe" = F:\Downloads\Free Download Manager\fdm.exe:*:Enabled:fdm "C:\WINDOWS\system32\freecell.exe" = C:\WINDOWS\system32\freecell.exe:*:Enabled:FreeCell -- (Microsoft Corporation) "F:\Downloads\Free Download Manager\FUM\fum.exe" = F:\Downloads\Free Download Manager\FUM\fum.exe:*:Enabled:Free Upload Manager "F:\Downloads\Free Download Manager\fdmwi.exe" = F:\Downloads\Free Download Manager\fdmwi.exe:*:Enabled:FDM remote control server "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL "C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Disabled:AOL "C:\Program Files\Wyzo\wyzo.exe" = C:\Program Files\Wyzo\wyzo.exe:*:Disabled:Wyzo "C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation) "C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation) "C:\Program Files\EasyBox\EasyBox.exe" = C:\Program Files\EasyBox\EasyBox.exe:*:Enabled:Lancer EasyBox "C:\Program Files\EasyBox\unins000.exe" = C:\Program Files\EasyBox\unins000.exe:*:Enabled:Désinstaller EasyBox v3.5-RC1 "C:\Program Files\HomePlayer1.5.4\HomePlayer.exe" = C:\Program Files\HomePlayer1.5.4\HomePlayer.exe:*:Enabled:HomePlayer "C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation) "C:\Program Files\UseNeXT\UseNeXT.exe" = C:\Program Files\UseNeXT\UseNeXT.exe:*:Enabled:UseNeXT -- () "C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd) "C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe" = C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe:*:Enabled:Firefox "C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird -- (Mozilla Corporation) "C:\Program Files\Squeezebox\server\squeezeboxcp.exe" = C:\Program Files\Squeezebox\server\squeezeboxcp.exe:*:Enabled:Squeezebox Control Panel -- (Logitech Inc.) "F:\iTunes Installer\iTunes.exe" = F:\iTunes Installer\iTunes.exe:*:Disabled:iTunes "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.) "C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe" = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe:*:Enabled:Audible Download Manager -- (Audible, Inc.) "C:\Program Files\Audible\Bin\Manager.exe" = C:\Program Files\Audible\Bin\Manager.exe:*:Enabled:AudibleManager -- (Audible Inc.) "C:\Program Files\Creative\DiskManager\ctpdemgr.exe" = C:\Program Files\Creative\DiskManager\ctpdemgr.exe:*:Enabled:Creative Removable Disk Manager "C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\LGMLauncher.exe" = C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\LGMLauncher.exe:*:Enabled:LGMobile update -- (LG Electronics) "C:\Program Files\NCH Swift Sound\SoundTap\soundtap.exe" = C:\Program Files\NCH Swift Sound\SoundTap\soundtap.exe:*:Enabled:SoundTap -- (NCH Software) "C:\Program Files\Uniblue\DiskRescue\UBDiskRescue.exe" = C:\Program Files\Uniblue\DiskRescue\UBDiskRescue.exe:*:Enabled:DiskRescue 2009 -- (Uniblue) "C:\Program Files\AC3Filter\ac3config.exe" = C:\Program Files\AC3Filter\ac3config.exe:*:Enabled:AC3Filter Config -- () "C:\Program Files\Fluendo\Moovida\Moovida.exe" = C:\Program Files\Fluendo\Moovida\Moovida.exe:*:Enabled:Moovida "C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer "C:\BTGUARD\uTorrent.exe" = C:\BTGUARD\uTorrent.exe:*:Enabled:µTorrent "C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation) "C:\Program Files\Steam\steamapps\common\stronghold kingdoms\StrongholdKingdoms.exe" = C:\Program Files\Steam\steamapps\common\stronghold kingdoms\StrongholdKingdoms.exe:*:Enabled:Stronghold Kingdoms -- (Firefly Studios) "C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.) "C:\Program Files\Expat Shield\bin\openvpntray.exe" = C:\Program Files\Expat Shield\bin\openvpntray.exe:*:Enabled:Expat Shield Launch "C:\WINDOWS\system32\msiexec.exe" = C:\WINDOWS\system32\msiexec.exe:*:Enabled:UpdateManagerSetup -- (Microsoft Corporation) "C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe" = C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe:*:Enabled:SweetPacksUpdateManager "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) "C:\Program Files\HomePlayer\HomePlayer.exe" = C:\Program Files\HomePlayer\HomePlayer.exe:*:Enabled:HomePlayer -- () "C:\Program Files\HomePlayer\VLC\vlc.exe" = C:\Program Files\HomePlayer\VLC\vlc.exe:*:Enabled:VLC HomePlayer -- () "C:\BTGUARD\settings.exe" = C:\BTGUARD\settings.exe:*:Enabled:BTGuard Settings "C:\BTGUARD\myentunnel.exe" = C:\BTGUARD\myentunnel.exe:*:Enabled:BTGuard Encryption "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{0C35EAE4-A535-46B7-B4BF-68952BD94E68}" = Uniblue DiskRescue 2009 "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{106DADAD-B062-4de5-8D1F-3FD2AD195E49}" = PC Utility Kit "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up "{162D2FB8-60A3-4871-B6A1-5C744CD34FF5}" = 725plc32 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 23 "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{487C2D48-A9E3-4F34-92BD-B6A847025C16}" = Free eXPert PDF Reader "{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger "{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore "{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport "{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel(R) PROSet for Wired Connections "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver "{8B6490BA-FAEA-486C-BAB5-561251D5F2B1}" = Hercules Blog Webcam "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C450606-ED24-4958-92BA-B8940C99D441}" = PixiePack Codec Pack "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A638EC76-65C3-4F82-BA68-D105DDA393E7}" = FileOpen Plug-in for Adobe Acrobat® and Acrobat Reader® "{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP) "{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1 "{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks "{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009 "{C94924F7-C20B-4E83-B63F-FAF006908B25}" = calibre "{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim "{CC8E0363-B20C-4792-8A1C-8DF5E01B68A6}" = GoGear VIBE Device Manager "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D07205E7-F6D3-4333-AFCC-782A07685B72}" = OverDrive Media Console "{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU "{D615D099-5C0F-41E0-B69E-B7D1CDC51B61}" = Philips Media Converter "{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software) "{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC "{E55B3271-7CA8-4D0C-AE06-69A24856E997}_is1" = Uniblue RegistryBooster "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype 5.10 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{FE48654B-F9AA-40ED-BEF3-48F3FE2FA847}" = Philips Media Converter "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "AC3Filter" = AC3Filter (remove only) "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AudibleManager" = AudibleManager "avast" = avast! Free Antivirus "AVIConverter" = AVIConverter 5.1.6 "B81055EA372C9E3EA5000B4BD9585D992D51F1DE" = Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/11/2009 2.0.0010.00002) "BurnAware Free_is1" = BurnAware Free 2.1.6 "Codec_is1" = Codec 8.3n "Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18 "Dell Color Printer 725" = Dell Color Printer 725 "Digital Video Repair" = Digital Video Repair 1.0 "DjVu" = LizardTech DjVu Control (autoinstall) "EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] "FpTest" = FpTest 3.2 "Google Desktop" = Google Desktop "GoToAssist" = GoToAssist 8.0.0.514 "GSpot" = GSpot Codec Information Appliance "HomePlayer" = HomePlayer 1.5.9e "ie8" = Windows Internet Explorer 8 "Logitech Media Server_is1" = Logitech Media Server 7.7.2 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft Security Client" = Microsoft Security Essentials "Mozilla Firefox 17.0 (x86 en-GB)" = Mozilla Firefox 17.0 (x86 en-GB) "Mozilla Thunderbird 16.0.2 (x86 en-GB)" = Mozilla Thunderbird 16.0.2 (x86 en-GB) "MozillaMaintenanceService" = Mozilla Maintenance Service "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "Peer2Peer-EN Toolbar" = Peer2Peer-EN Toolbar "Philips Songbird" = Philips Songbird "PROSet" = Intel(R) PRO Network Connections Drivers "PuTTY_is1" = PuTTY version 0.60 "RealAlt_is1" = Real Alternative 1.48 "RealPlayer 15.0" = RealPlayer "Slice" = Slice Audio File Splitter "SoundTap" = SoundTap Streaming Audio Recorder "SpeedUpMyPC_is1" = Uniblue SpeedUpMyPC 3 "Spotify" = Spotify "Steam App 47410" = Stronghold Kingdoms "Switch" = Switch "ToolBox" = NCH Toolbox Uninstall "UFRaw_is1" = UFRaw 0.17 "Uniblue DiskRescue 2009" = Uniblue DiskRescue 2009 "Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009 "UseNeXT_is1" = UseNeXT "uTorrent" = µTorrent "uTorrentControl_v2 Toolbar" = uTorrentControl_v2 Toolbar "VLC media player" = VideoLAN VLC media player 0.8.6e "WavePad" = WavePad Sound Editor "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "winusb0100" = Microsoft WinUsb 1.0 "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Xvid_is1" = Xvid 1.1.3 final uninstall "XviD4PSP5" = XviD4PSP 5
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent DNA" = DNA "Dropbox" = Dropbox "Sansa Updater" = Sansa Updater
[color=#E56717]========== Last 20 Event Log Errors ==========[/color]
[ Application Events ] Error - 24/11/2012 12:26:27 | Computer Name = DELL | Source = MPSampleSubmission | ID = 5000 Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 4.1.522.0, P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 25/11/2012 18:15:57 | Computer Name = DELL | Source = MatSvc | ID = 262147 Description = The MATS service encountered a web service failure. hr=0xC004F018
Error - 25/11/2012 18:15:57 | Computer Name = DELL | Source = MatSvc | ID = 262148 Description = The MATS service encountered a failure when uploading data. hr=0xC004F018
Error - 25/11/2012 18:16:18 | Computer Name = DELL | Source = MatSvc | ID = 262147 Description = The MATS service encountered a web service failure. hr=0xC004F018
Error - 25/11/2012 18:16:18 | Computer Name = DELL | Source = MatSvc | ID = 262148 Description = The MATS service encountered a failure when uploading data. hr=0xC004F018
Error - 25/11/2012 18:18:00 | Computer Name = DELL | Source = MatSvc | ID = 262147 Description = The MATS service encountered a web service failure. hr=0xC004F018
Error - 25/11/2012 18:18:00 | Computer Name = DELL | Source = MatSvc | ID = 262148 Description = The MATS service encountered a failure when uploading data. hr=0xC004F018
Error - 25/11/2012 18:22:57 | Computer Name = DELL | Source = MatSvc | ID = 262147 Description = The MATS service encountered a web service failure. hr=0xC004F018
Error - 25/11/2012 18:22:57 | Computer Name = DELL | Source = MatSvc | ID = 262148 Description = The MATS service encountered a failure when uploading data. hr=0xC004F018
Error - 26/11/2012 11:22:58 | Computer Name = DELL | Source = MPSampleSubmission | ID = 5000 Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile, P4 4.1.522.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
[ System Events ] Error - 26/11/2012 09:04:34 | Computer Name = DELL | Source = Ntfs | ID = 262199 Description = The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume D:.
Error - 26/11/2012 09:06:37 | Computer Name = DELL | Source = Service Control Manager | ID = 7022 Description = The Logitech Media Server service hung on starting.
Error - 26/11/2012 09:06:37 | Computer Name = DELL | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: szkg
Error - 26/11/2012 12:24:40 | Computer Name = DELL | Source = DCOM | ID = 10005 Description = DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}
Error - 26/11/2012 12:24:40 | Computer Name = DELL | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the dlcf_device service to connect.
Error - 26/11/2012 12:24:40 | Computer Name = DELL | Source = Service Control Manager | ID = 7000 Description = The dlcf_device service failed to start due to the following error: %%1053
Error - 26/11/2012 12:24:50 | Computer Name = DELL | Source = DCOM | ID = 10005 Description = DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}
Error - 26/11/2012 12:26:23 | Computer Name = DELL | Source = Ntfs | ID = 262199 Description = The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume D:.
Error - 26/11/2012 12:26:23 | Computer Name = DELL | Source = Ntfs | ID = 262199 Description = The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume D:.
Error - 26/11/2012 12:27:25 | Computer Name = DELL | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: IntelIde szkg
4. Contents of checkup.txt
Results of screen317's Security Check version 0.99.56 Windows XP Service Pack 3 x86 Internet Explorer 8 [u]``````````````Antivirus/Firewall Check:``````````````[/u] Windows Firewall Enabled! Microsoft Security Essentials avast! Antivirus McAfee VirusScan Antivirus up to date! (On Access scanning disabled!) [u]`````````Anti-malware/Other Utilities Check:`````````[/u] Malwarebytes Anti-Malware version 1.65.1.1000 JavaFX 2.1.1 Java(TM) 6 Update 23 Java 7 Update 9 Adobe Flash Player 11.4.402.287 Mozilla Firefox (17.0) Mozilla Thunderbird 16.0.2 [color=red]Thunderbird out of Date![/color] [u]````````Process Check: objlist.exe by Laurent````````[/u] Microsoft Security Essentials MSMpEng.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast avastUI.exe [u]`````````````````System Health check`````````````````[/u] Total Fragmentation on Drive C:: 15% [color=red]Defragment your hard drive soon! (Do NOT defrag if SSD!)[/color] [u]````````````````````End of Log``````````````````````[/u]
5. Contents of the Online AntiVirus Scan log
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=c49982a5574c1948a833d550b7e9db46 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-11-26 09:19:20 # local_time=2012-11-26 10:19:20 (+0100, Romance Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=5891 16776533 42 93 19740 7589840 0 0 # compatibility_mode=8192 67108863 100 0 4320 4320 0 0 # scanned=150894 # found=14 # cleaned=14 # scan_time=14295 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SweetIM23.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SweetIM78.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YontooPagerage2.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\Application Data\Uniblue\RegistryBooster\_temp\ub.exe a variant of Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\Desktop\Installs\se2_0_1_1516.exe a variant of Win32/UbSpyEraser application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\Desktop\Installs\spyeraser2.exe a variant of Win32/UbSpyEraser application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\My Documents\Downloads\PETER_ROBINSON_-_THE_HANGING_VALLEY_[MYANONAMOUSE.NET]-ebook.exe Win32/Adware.1ClickDownload.G application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\My Documents\Downloads\registrybooster(1).exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\My Documents\Downloads\registrybooster.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\My Documents\Downloads\The_Diggers_Rest_Hotel_-_by_Geoffrey_McGeachin_(an_unabridge.exe Win32/Adware.1ClickDownload.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\annas\My Documents\Downloads\_Retail).exe Win32/Adware.1ClickDownload application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\i386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent.LCKGTSG application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\Uniblue\RegistryBooster\Launcher.exe a variant of Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Over to you & many thanks! | |  LoPhatPhuudPremium,VIP,MVM join:2002-01-06 Albuquerque, NM kudos:26 Reviews:
·Comcast
| Download and run TDSS Killer, posting the log in this thread. Please post the log, even if nothing is detected.
You'll find the link(s) and instruction(s) here: »Security Cleanup FAQ »Rootkit Detection Applications -- When angry count four; when very angry, swear. Microsoft MVP/Consumer Security 2005-2011 Gladiator Security Forum | |  | reply to Carcassonne OK will do that right now. Sorry for delay - it was amost 1.00 am here when i posted last night & i was pooped! | |  | reply to LoPhatPhuud Okay - here it is: 10:17:22.0984 2188 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 10:17:23.0281 2188 ============================================================ 10:17:23.0281 2188 Current date / time: 2012/11/27 10:17:23.0281 10:17:23.0281 2188 SystemInfo: 10:17:23.0281 2188 10:17:23.0281 2188 OS Version: 5.1.2600 ServicePack: 3.0 10:17:23.0281 2188 Product type: Workstation 10:17:23.0281 2188 ComputerName: DELL 10:17:23.0281 2188 UserName: annas 10:17:23.0281 2188 Windows directory: C:\WINDOWS 10:17:23.0281 2188 System windows directory: C:\WINDOWS 10:17:23.0281 2188 Processor architecture: Intel x86 10:17:23.0281 2188 Number of processors: 2 10:17:23.0281 2188 Page size: 0x1000 10:17:23.0281 2188 Boot type: Normal boot 10:17:23.0281 2188 ============================================================ 10:17:27.0406 2188 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 10:17:27.0453 2188 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 10:17:27.0453 2188 ============================================================ 10:17:27.0453 2188 \Device\Harddisk0\DR0: 10:17:27.0453 2188 MBR partitions: 10:17:27.0453 2188 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x8BA231A 10:17:27.0453 2188 \Device\Harddisk1\DR1: 10:17:27.0453 2188 MBR partitions: 10:17:27.0453 2188 ============================================================ 10:17:27.0515 2188 C: \Device\Harddisk0\DR0\Partition1 10:17:27.0515 2188 ============================================================ 10:17:27.0515 2188 Initialize success 10:17:27.0515 2188 ============================================================ 10:17:35.0843 3928 ============================================================ 10:17:35.0843 3928 Scan started 10:17:35.0843 3928 Mode: Manual; 10:17:35.0843 3928 ============================================================ 10:17:36.0328 3928 ================ Scan system memory ======================== 10:17:36.0328 3928 System memory - ok 10:17:36.0328 3928 ================ Scan services ============================= 10:17:36.0484 3928 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys 10:17:36.0484 3928 Aavmker4 - ok 10:17:36.0484 3928 Abiosdsk - ok 10:17:36.0546 3928 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 10:17:36.0546 3928 abp480n5 - ok 10:17:36.0609 3928 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 10:17:36.0625 3928 ACPI - ok 10:17:36.0640 3928 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 10:17:36.0640 3928 ACPIEC - ok 10:17:36.0750 3928 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 10:17:36.0750 3928 AdobeFlashPlayerUpdateSvc - ok 10:17:36.0765 3928 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys 10:17:36.0781 3928 adpu160m - ok 10:17:36.0796 3928 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 10:17:36.0796 3928 aec - ok 10:17:36.0843 3928 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 10:17:36.0843 3928 AFD - ok 10:17:36.0890 3928 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys 10:17:36.0890 3928 agp440 - ok 10:17:36.0906 3928 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 10:17:36.0906 3928 agpCPQ - ok 10:17:36.0937 3928 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys 10:17:36.0953 3928 Aha154x - ok 10:17:37.0000 3928 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys 10:17:37.0015 3928 aic78u2 - ok 10:17:37.0031 3928 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys 10:17:37.0031 3928 aic78xx - ok 10:17:37.0093 3928 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 10:17:37.0093 3928 Alerter - ok 10:17:37.0109 3928 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 10:17:37.0109 3928 ALG - ok 10:17:37.0125 3928 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys 10:17:37.0125 3928 AliIde - ok 10:17:37.0140 3928 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys 10:17:37.0140 3928 alim1541 - ok 10:17:37.0140 3928 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys 10:17:37.0156 3928 amdagp - ok 10:17:37.0171 3928 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys 10:17:37.0171 3928 amsint - ok 10:17:37.0250 3928 [ 019A9B80A0C207278CF70808FF527683 ] APL531 C:\WINDOWS\system32\Drivers\BLvid.sys 10:17:37.0281 3928 APL531 - ok 10:17:37.0328 3928 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 10:17:37.0328 3928 AppMgmt - ok 10:17:37.0375 3928 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys 10:17:37.0390 3928 asc - ok 10:17:37.0390 3928 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys 10:17:37.0390 3928 asc3350p - ok 10:17:37.0406 3928 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys 10:17:37.0406 3928 asc3550 - ok 10:17:37.0578 3928 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 10:17:37.0609 3928 aspnet_state - ok 10:17:37.0640 3928 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys 10:17:37.0640 3928 aswFsBlk - ok 10:17:37.0703 3928 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys 10:17:37.0703 3928 aswMon2 - ok 10:17:37.0718 3928 [ 7C9F0A2AB17D52261A9252A2EB320884 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys 10:17:37.0718 3928 AswRdr - ok 10:17:37.0765 3928 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys 10:17:37.0781 3928 aswSnx - ok 10:17:37.0812 3928 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys 10:17:37.0812 3928 aswSP - ok 10:17:37.0828 3928 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys 10:17:37.0828 3928 aswTdi - ok 10:17:37.0890 3928 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 10:17:37.0890 3928 AsyncMac - ok 10:17:37.0906 3928 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 10:17:37.0906 3928 atapi - ok 10:17:37.0921 3928 Atdisk - ok 10:17:37.0953 3928 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 10:17:37.0953 3928 Atmarpc - ok 10:17:38.0000 3928 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 10:17:38.0000 3928 AudioSrv - ok 10:17:38.0062 3928 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 10:17:38.0062 3928 audstub - ok 10:17:38.0203 3928 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 10:17:38.0203 3928 avast! Antivirus - ok 10:17:38.0250 3928 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 10:17:38.0250 3928 Beep - ok 10:17:38.0312 3928 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 10:17:38.0328 3928 BITS - ok 10:17:38.0390 3928 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 10:17:38.0390 3928 Bonjour Service - ok 10:17:38.0437 3928 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 10:17:38.0437 3928 Browser - ok 10:17:38.0515 3928 [ CA794C7F1BF59B1F4638FBCEEF55337A ] camfilt C:\WINDOWS\system32\Drivers\camfilt.sys 10:17:38.0562 3928 camfilt - ok 10:17:38.0593 3928 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 10:17:38.0593 3928 cbidf - ok 10:17:38.0593 3928 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 10:17:38.0609 3928 cbidf2k - ok 10:17:38.0656 3928 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 10:17:38.0656 3928 CCDECODE - ok 10:17:38.0671 3928 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 10:17:38.0703 3928 cd20xrnt - ok 10:17:38.0734 3928 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 10:17:38.0734 3928 Cdaudio - ok 10:17:38.0796 3928 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 10:17:38.0796 3928 Cdfs - ok 10:17:38.0828 3928 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 10:17:38.0828 3928 Cdrom - ok 10:17:38.0828 3928 Changer - ok 10:17:38.0890 3928 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 10:17:38.0890 3928 CiSvc - ok 10:17:38.0953 3928 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 10:17:38.0953 3928 ClipSrv - ok 10:17:39.0000 3928 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 10:17:39.0125 3928 clr_optimization_v2.0.50727_32 - ok 10:17:39.0203 3928 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys 10:17:39.0218 3928 CmdIde - ok 10:17:39.0234 3928 COMSysApp - ok 10:17:39.0281 3928 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys 10:17:39.0281 3928 Cpqarray - ok 10:17:39.0296 3928 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 10:17:39.0296 3928 CryptSvc - ok 10:17:39.0312 3928 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 10:17:39.0328 3928 dac2w2k - ok 10:17:39.0328 3928 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys 10:17:39.0328 3928 dac960nt - ok 10:17:39.0390 3928 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 10:17:39.0406 3928 DcomLaunch - ok 10:17:39.0468 3928 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 10:17:39.0484 3928 Dhcp - ok 10:17:39.0500 3928 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 10:17:39.0500 3928 Disk - ok 10:17:39.0500 3928 dlcf_device - ok 10:17:39.0515 3928 dmadmin - ok 10:17:39.0546 3928 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 10:17:39.0562 3928 dmboot - ok 10:17:39.0578 3928 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 10:17:39.0578 3928 dmio - ok 10:17:39.0640 3928 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 10:17:39.0640 3928 dmload - ok 10:17:39.0703 3928 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 10:17:39.0703 3928 dmserver - ok 10:17:39.0718 3928 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 10:17:39.0718 3928 DMusic - ok 10:17:39.0765 3928 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 10:17:39.0765 3928 Dnscache - ok 10:17:39.0828 3928 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 10:17:39.0828 3928 Dot3svc - ok 10:17:39.0843 3928 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys 10:17:39.0859 3928 dpti2o - ok 10:17:39.0875 3928 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 10:17:39.0875 3928 drmkaud - ok 10:17:39.0937 3928 [ 24646242310499D75C6DB4B32768A3B3 ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys 10:17:39.0937 3928 drvmcdb - ok 10:17:39.0937 3928 [ 2FF629C1C443E25D0149B9DFB77E43A8 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys 10:17:39.0953 3928 drvnddm - ok 10:17:40.0031 3928 [ FE80901578E7E3DA70299A5AEB2B7FBD ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe 10:17:40.0031 3928 DSBrokerService - ok 10:17:40.0109 3928 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 10:17:40.0109 3928 DSproct - ok 10:17:40.0140 3928 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 10:17:40.0156 3928 dsunidrv - ok 10:17:40.0218 3928 [ 95974E66D3DE4951D29E28E8BC0B644C ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys 10:17:40.0218 3928 E100B - ok 10:17:40.0281 3928 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 10:17:40.0296 3928 EapHost - ok 10:17:40.0359 3928 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 10:17:40.0359 3928 ERSvc - ok 10:17:40.0406 3928 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 10:17:40.0421 3928 Eventlog - ok 10:17:40.0484 3928 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 10:17:40.0484 3928 EventSystem - ok 10:17:40.0546 3928 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 10:17:40.0546 3928 Fastfat - ok 10:17:40.0593 3928 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 10:17:40.0609 3928 FastUserSwitchingCompatibility - ok 10:17:40.0625 3928 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe 10:17:40.0640 3928 Fax - ok 10:17:40.0671 3928 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 10:17:40.0734 3928 Fdc - ok 10:17:40.0750 3928 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 10:17:40.0750 3928 Fips - ok 10:17:40.0765 3928 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 10:17:40.0765 3928 Flpydisk - ok 10:17:40.0812 3928 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 10:17:40.0828 3928 FltMgr - ok 10:17:40.0937 3928 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 10:17:40.0953 3928 FontCache3.0.0.0 - ok 10:17:40.0953 3928 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 10:17:40.0953 3928 Fs_Rec - ok 10:17:41.0015 3928 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 10:17:41.0031 3928 Ftdisk - ok 10:17:41.0078 3928 [ 4AC51459805264AFFD5F6FDFB9D9235F ] GEARAspiWDM C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 10:17:41.0078 3928 GEARAspiWDM - ok 10:17:41.0187 3928 [ F0187E45268E86AAAA932CBD9087BEA8 ] GoogleDesktopManager-110309-193829 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 10:17:41.0187 3928 GoogleDesktopManager-110309-193829 - ok 10:17:41.0296 3928 [ D3316F6E3C011435F36E3D6E49B3196C ] GoToAssist C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe 10:17:41.0296 3928 GoToAssist - ok 10:17:41.0359 3928 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 10:17:41.0359 3928 Gpc - ok 10:17:41.0375 3928 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 10:17:41.0390 3928 HDAudBus - ok 10:17:41.0453 3928 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 10:17:41.0453 3928 helpsvc - ok 10:17:41.0453 3928 HidServ - ok 10:17:41.0500 3928 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 10:17:41.0515 3928 HidUsb - ok 10:17:41.0562 3928 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 10:17:41.0562 3928 hkmsvc - ok 10:17:41.0609 3928 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys 10:17:41.0609 3928 hpn - ok 10:17:41.0671 3928 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 10:17:41.0687 3928 HTTP - ok 10:17:41.0703 3928 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 10:17:41.0718 3928 HTTPFilter - ok 10:17:41.0765 3928 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys 10:17:41.0781 3928 i2omgmt - ok 10:17:41.0796 3928 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys 10:17:41.0812 3928 i2omp - ok 10:17:41.0828 3928 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 10:17:41.0828 3928 i8042prt - ok 10:17:41.0937 3928 [ 5A8E05F1D5C36ABD58CFFA111EB325EA ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 10:17:41.0953 3928 ialm - ok 10:17:42.0062 3928 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 10:17:42.0078 3928 idsvc - ok 10:17:42.0109 3928 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 10:17:42.0125 3928 Imapi - ok 10:17:42.0187 3928 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 10:17:42.0203 3928 ImapiService - ok 10:17:42.0250 3928 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys 10:17:42.0250 3928 ini910u - ok 10:17:42.0312 3928 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys 10:17:42.0312 3928 IntelIde - ok 10:17:42.0375 3928 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 10:17:42.0375 3928 intelppm - ok 10:17:42.0406 3928 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 10:17:42.0406 3928 Ip6Fw - ok 10:17:42.0453 3928 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 10:17:42.0453 3928 IpFilterDriver - ok 10:17:42.0484 3928 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 10:17:42.0484 3928 IpInIp - ok 10:17:42.0515 3928 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 10:17:42.0515 3928 IpNat - ok 10:17:42.0546 3928 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 10:17:42.0546 3928 IPSec - ok 10:17:42.0578 3928 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 10:17:42.0578 3928 IRENUM - ok 10:17:42.0609 3928 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 10:17:42.0609 3928 isapnp - ok 10:17:42.0812 3928 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 10:17:42.0812 3928 JavaQuickStarterService - ok 10:17:42.0843 3928 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 10:17:42.0843 3928 Kbdclass - ok 10:17:42.0859 3928 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 10:17:42.0859 3928 kbdhid - ok 10:17:42.0921 3928 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 10:17:42.0921 3928 kmixer - ok 10:17:42.0953 3928 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 10:17:42.0953 3928 KSecDD - ok 10:17:42.0968 3928 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 10:17:43.0000 3928 lanmanserver - ok 10:17:43.0062 3928 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 10:17:43.0078 3928 lanmanworkstation - ok 10:17:43.0078 3928 lbrtfdc - ok 10:17:43.0140 3928 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 10:17:43.0156 3928 LmHosts - ok 10:17:43.0265 3928 [ DDF15A42E27E8EFE27B18FD403151A86 ] MatSvc C:\Program Files\Microsoft Fix it Center\Matsvc.exe 10:17:43.0281 3928 MatSvc - ok 10:17:43.0328 3928 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys 10:17:43.0328 3928 MBAMProtector - ok 10:17:43.0437 3928 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 10:17:43.0453 3928 MBAMScheduler - ok 10:17:43.0531 3928 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 10:17:43.0546 3928 MBAMService - ok 10:17:43.0546 3928 mcdbus - ok 10:17:43.0671 3928 [ DF0A511F38F16016BF658FCA0090CB87 ] McrdSvc C:\WINDOWS\ehome\mcrdsvc.exe 10:17:43.0671 3928 McrdSvc - ok 10:17:43.0718 3928 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 10:17:43.0734 3928 Messenger - ok 10:17:43.0781 3928 [ B7521F69C0A9B29D356157229376FB21 ] MHN C:\WINDOWS\System32\mhn.dll 10:17:43.0781 3928 MHN - ok 10:17:43.0812 3928 [ 7F2F1D2815A6449D346FCCCBC569FBD6 ] MHNDRV C:\WINDOWS\system32\DRIVERS\mhndrv.sys 10:17:43.0812 3928 MHNDRV - ok 10:17:43.0828 3928 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 10:17:43.0828 3928 mnmdd - ok 10:17:43.0875 3928 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 10:17:43.0890 3928 mnmsrvc - ok 10:17:43.0937 3928 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 10:17:43.0937 3928 Modem - ok 10:17:43.0984 3928 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 10:17:43.0984 3928 Mouclass - ok 10:17:44.0046 3928 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 10:17:44.0046 3928 mouhid - ok 10:17:44.0062 3928 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 10:17:44.0062 3928 MountMgr - ok 10:17:44.0109 3928 [ 313265CF4F5F02ED927774DA1DB3FE00 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 10:17:44.0125 3928 MozillaMaintenance - ok 10:17:44.0171 3928 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys 10:17:44.0187 3928 MpFilter - ok 10:17:44.0234 3928 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys 10:17:44.0234 3928 mraid35x - ok 10:17:44.0250 3928 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 10:17:44.0265 3928 MRxDAV - ok 10:17:44.0328 3928 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 10:17:44.0328 3928 MRxSmb - ok 10:17:44.0390 3928 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 10:17:44.0406 3928 MSDTC - ok 10:17:44.0406 3928 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 10:17:44.0421 3928 Msfs - ok 10:17:44.0421 3928 MSIServer - ok 10:17:44.0437 3928 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 10:17:44.0437 3928 MSKSSRV - ok 10:17:44.0546 3928 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe 10:17:44.0546 3928 MsMpSvc - ok 10:17:44.0609 3928 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 10:17:44.0609 3928 MSPCLOCK - ok 10:17:44.0625 3928 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 10:17:44.0625 3928 MSPQM - ok 10:17:44.0687 3928 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 10:17:44.0687 3928 mssmbios - ok 10:17:44.0734 3928 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 10:17:44.0734 3928 MSTEE - ok 10:17:44.0781 3928 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 10:17:44.0781 3928 Mup - ok 10:17:44.0828 3928 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 10:17:44.0828 3928 NABTSFEC - ok 10:17:44.0875 3928 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 10:17:44.0890 3928 napagent - ok 10:17:44.0921 3928 [ 0DF9CC7B5CC173F545723F23E68FAC93 ] NCHSSVAD C:\WINDOWS\system32\drivers\nchssvad.sys 10:17:44.0953 3928 NCHSSVAD - ok 10:17:44.0984 3928 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 10:17:44.0984 3928 NDIS - ok 10:17:45.0015 3928 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 10:17:45.0015 3928 NdisIP - ok 10:17:45.0046 3928 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 10:17:45.0046 3928 NdisTapi - ok 10:17:45.0109 3928 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 10:17:45.0109 3928 Ndisuio - ok 10:17:45.0140 3928 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 10:17:45.0140 3928 NdisWan - ok 10:17:45.0203 3928 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 10:17:45.0218 3928 NDProxy - ok 10:17:45.0218 3928 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 10:17:45.0218 3928 NetBIOS - ok 10:17:45.0234 3928 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 10:17:45.0250 3928 NetBT - ok 10:17:45.0312 3928 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 10:17:45.0312 3928 NetDDE - ok 10:17:45.0328 3928 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 10:17:45.0328 3928 NetDDEdsdm - ok 10:17:45.0390 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 10:17:45.0390 3928 Netlogon - ok 10:17:45.0421 3928 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 10:17:45.0437 3928 Netman - ok 10:17:45.0593 3928 [ 9DA26B773BD04B867A8E9F427CD048FC ] NetSvc C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe 10:17:45.0734 3928 NetSvc - ok 10:17:45.0781 3928 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 10:17:45.0781 3928 NetTcpPortSharing - ok 10:17:45.0828 3928 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 10:17:45.0843 3928 Nla - ok 10:17:45.0921 3928 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 10:17:46.0000 3928 Npfs - ok 10:17:46.0093 3928 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 10:17:46.0234 3928 Ntfs - ok 10:17:46.0328 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 10:17:46.0343 3928 NtLmSsp - ok 10:17:46.0421 3928 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 10:17:46.0437 3928 NtmsSvc - ok 10:17:46.0453 3928 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 10:17:46.0453 3928 Null - ok 10:17:46.0546 3928 [ 2B298519EDBFCF451D43E0F1E8F1006D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 10:17:46.0578 3928 nv - ok 10:17:46.0593 3928 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 10:17:46.0593 3928 NwlnkFlt - ok 10:17:46.0656 3928 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 10:17:46.0656 3928 NwlnkFwd - ok 10:17:46.0703 3928 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 10:17:46.0703 3928 Parport - ok 10:17:46.0734 3928 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 10:17:46.0734 3928 PartMgr - ok 10:17:46.0796 3928 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 10:17:46.0812 3928 ParVdm - ok 10:17:46.0828 3928 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 10:17:46.0828 3928 PCI - ok 10:17:46.0828 3928 PCIDump - ok 10:17:46.0843 3928 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 10:17:46.0843 3928 PCIIde - ok 10:17:46.0875 3928 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 10:17:46.0875 3928 Pcmcia - ok 10:17:46.0875 3928 PDCOMP - ok 10:17:46.0890 3928 PDFRAME - ok 10:17:46.0890 3928 PDRELI - ok 10:17:46.0906 3928 PDRFRAME - ok 10:17:46.0921 3928 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys 10:17:46.0921 3928 perc2 - ok 10:17:46.0937 3928 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys 10:17:46.0937 3928 perc2hib - ok 10:17:46.0984 3928 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 10:17:47.0000 3928 PlugPlay - ok 10:17:47.0015 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 10:17:47.0015 3928 PolicyAgent - ok 10:17:47.0078 3928 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 10:17:47.0093 3928 PptpMiniport - ok 10:17:47.0093 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 10:17:47.0109 3928 ProtectedStorage - ok 10:17:47.0171 3928 [ F115AF58ABE5605D7D709CBFBD83F418 ] ProtexisLicensing C:\WINDOWS\system32\PSIService.exe 10:17:47.0187 3928 ProtexisLicensing - ok 10:17:47.0234 3928 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 10:17:47.0234 3928 PSched - ok 10:17:47.0250 3928 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 10:17:47.0265 3928 Ptilink - ok 10:17:47.0265 3928 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 10:17:47.0265 3928 PxHelp20 - ok 10:17:47.0328 3928 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys 10:17:47.0328 3928 ql1080 - ok 10:17:47.0343 3928 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 10:17:47.0343 3928 Ql10wnt - ok 10:17:47.0359 3928 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys 10:17:47.0359 3928 ql12160 - ok 10:17:47.0359 3928 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys 10:17:47.0375 3928 ql1240 - ok 10:17:47.0375 3928 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys 10:17:47.0390 3928 ql1280 - ok 10:17:47.0390 3928 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 10:17:47.0390 3928 RasAcd - ok 10:17:47.0453 3928 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 10:17:47.0468 3928 RasAuto - ok 10:17:47.0484 3928 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 10:17:47.0484 3928 Rasl2tp - ok 10:17:47.0546 3928 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 10:17:47.0562 3928 RasMan - ok 10:17:47.0578 3928 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 10:17:47.0593 3928 RasPppoe - ok 10:17:47.0609 3928 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 10:17:47.0609 3928 Raspti - ok 10:17:47.0609 3928 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 10:17:47.0625 3928 Rdbss - ok 10:17:47.0640 3928 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 10:17:47.0640 3928 RDPCDD - ok 10:17:47.0671 3928 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 10:17:47.0671 3928 rdpdr - ok 10:17:47.0734 3928 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 10:17:47.0734 3928 RDPWD - ok 10:17:47.0750 3928 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 10:17:47.0765 3928 RDSessMgr - ok 10:17:47.0781 3928 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 10:17:47.0781 3928 redbook - ok 10:17:47.0828 3928 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 10:17:47.0843 3928 RemoteAccess - ok 10:17:47.0875 3928 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 10:17:47.0890 3928 RemoteRegistry - ok 10:17:47.0921 3928 [ 5F83735559A1D9B610020065741F5AA5 ] RkHit C:\WINDOWS\system32\drivers\RKHit.sys 10:17:47.0921 3928 RkHit - ok 10:17:47.0968 3928 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 10:17:47.0984 3928 RpcLocator - ok 10:17:48.0000 3928 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 10:17:48.0015 3928 RpcSs - ok 10:17:48.0078 3928 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 10:17:48.0109 3928 RSVP - ok 10:17:48.0156 3928 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 10:17:48.0156 3928 rtl8139 - ok 10:17:48.0218 3928 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 10:17:48.0234 3928 SamSs - ok 10:17:48.0296 3928 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 10:17:48.0312 3928 SCardSvr - ok 10:17:48.0390 3928 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 10:17:48.0406 3928 Schedule - ok 10:17:48.0453 3928 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 10:17:48.0453 3928 Secdrv - ok 10:17:48.0484 3928 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 10:17:48.0500 3928 seclogon - ok 10:17:48.0515 3928 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 10:17:48.0531 3928 SENS - ok 10:17:48.0562 3928 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 10:17:48.0562 3928 serenum - ok 10:17:48.0593 3928 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 10:17:48.0593 3928 Serial - ok 10:17:48.0625 3928 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 10:17:48.0625 3928 Sfloppy - ok 10:17:48.0703 3928 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 10:17:48.0718 3928 SharedAccess - ok 10:17:48.0734 3928 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 10:17:48.0750 3928 ShellHWDetection - ok 10:17:48.0750 3928 Simbad - ok 10:17:48.0796 3928 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys 10:17:48.0796 3928 sisagp - ok 10:17:48.0843 3928 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 10:17:48.0843 3928 SkypeUpdate - ok 10:17:48.0875 3928 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 10:17:48.0890 3928 SLIP - ok 10:17:48.0937 3928 [ 2DEADE72F7CDEF9C9E8B5AB6255157CA ] SMServer C:\WINDOWS\system32\snmvtsvc.exe 10:17:49.0093 3928 SMServer - ok 10:17:49.0125 3928 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys 10:17:49.0125 3928 Sparrow - ok 10:17:49.0171 3928 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 10:17:49.0187 3928 splitter - ok 10:17:49.0234 3928 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 10:17:49.0250 3928 Spooler - ok 10:17:49.0328 3928 sprtsvc_dellsupportcenter - ok 10:17:49.0828 3928 [ 287D75A3D421D16D9FEAC81DDDCB703A ] squeezesvc C:\PROGRA~1\Squeezebox\server\SqueezeSvr.exe 10:17:58.0437 3928 squeezesvc - ok 10:17:58.0500 3928 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 10:17:58.0500 3928 sr - ok 10:17:58.0562 3928 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 10:17:58.0578 3928 srservice - ok 10:17:58.0640 3928 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 10:17:58.0640 3928 Srv - ok 10:17:58.0703 3928 [ 1CBD1B58A32DE97899F5290B05F856DB ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys 10:17:58.0703 3928 sscdbhk5 - ok 10:17:58.0718 3928 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 10:17:58.0734 3928 SSDPSRV - ok 10:17:58.0750 3928 [ 7FB07AC152D7A87E66204860002BD9A4 ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys 10:17:58.0750 3928 ssrtln - ok 10:17:58.0812 3928 Steam Client Service - ok 10:17:58.0890 3928 [ 2A2DC39623ADEF8AB3703AB9FAC4B440 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys 10:17:58.0921 3928 STHDA - ok 10:17:59.0000 3928 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 10:17:59.0015 3928 stisvc - ok 10:17:59.0046 3928 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 10:17:59.0046 3928 streamip - ok 10:17:59.0109 3928 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 10:17:59.0109 3928 swenum - ok 10:17:59.0187 3928 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 10:17:59.0187 3928 swmidi - ok 10:17:59.0187 3928 SwPrv - ok 10:17:59.0250 3928 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys 10:17:59.0250 3928 symc810 - ok 10:17:59.0265 3928 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys 10:17:59.0265 3928 symc8xx - ok 10:17:59.0281 3928 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys 10:17:59.0281 3928 sym_hi - ok 10:17:59.0296 3928 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys 10:17:59.0296 3928 sym_u3 - ok 10:17:59.0343 3928 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 10:17:59.0343 3928 sysaudio - ok 10:17:59.0406 3928 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 10:17:59.0421 3928 SysmonLog - ok 10:17:59.0437 3928 szkg - ok 10:17:59.0484 3928 [ 0C3B2A9C4BD2DD9A6C2E4084314DD719 ] taphss C:\WINDOWS\system32\DRIVERS\taphss.sys 10:17:59.0484 3928 taphss - ok 10:17:59.0515 3928 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 10:17:59.0531 3928 TapiSrv - ok 10:17:59.0578 3928 [ 4D46F63F7DDC2442941D63327C360B90 ] tbhsd C:\WINDOWS\system32\drivers\tbhsd.sys 10:17:59.0578 3928 tbhsd - ok 10:17:59.0578 3928 tclondrv - ok 10:17:59.0656 3928 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 10:17:59.0656 3928 Tcpip - ok 10:17:59.0703 3928 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 10:17:59.0718 3928 TDPIPE - ok 10:17:59.0734 3928 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 10:17:59.0734 3928 TDTCP - ok 10:17:59.0765 3928 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 10:17:59.0781 3928 TermDD - ok 10:17:59.0843 3928 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 10:17:59.0875 3928 TermService - ok 10:17:59.0968 3928 [ C89DAABDFF5BD984181F45ADF6DDB24A ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys 10:18:00.0015 3928 tfsnboio - ok 10:18:00.0031 3928 [ F093906C27FC9C59BD03D84807266107 ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys 10:18:00.0062 3928 tfsncofs - ok 10:18:00.0078 3928 [ 9294575CDAD17D1DADFCD98A2CA26E7A ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys 10:18:00.0093 3928 tfsndrct - ok 10:18:00.0109 3928 [ CDCC394CBAAC183F9BDEBF6D2F97C5C6 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys 10:18:00.0140 3928 tfsndres - ok 10:18:00.0171 3928 [ 0A6C7C989DD76BB8989FD958AC5601D0 ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys 10:18:00.0250 3928 tfsnifs - ok 10:18:00.0281 3928 [ 92A17C0D73500F9B9C3028DA9E4CDBA6 ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys 10:18:00.0296 3928 tfsnopio - ok 10:18:00.0312 3928 [ 15AB1A2BB2B35EB1DCDA39405114AFC6 ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys 10:18:00.0343 3928 tfsnpool - ok 10:18:00.0359 3928 [ 370D2779668BF3B8D14F34356C41AB9C ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys 10:18:00.0421 3928 tfsnudf - ok 10:18:00.0437 3928 [ 4564799868C4BCDF28C8EFC6D4C48C4B ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys 10:18:00.0500 3928 tfsnudfa - ok 10:18:00.0515 3928 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 10:18:00.0531 3928 Themes - ok 10:18:00.0593 3928 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 10:18:00.0609 3928 TlntSvr - ok 10:18:00.0625 3928 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys 10:18:00.0640 3928 TosIde - ok 10:18:00.0703 3928 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 10:18:00.0718 3928 TrkWks - ok 10:18:00.0781 3928 [ 78A3E03AB4792E3514FCFDB893EF7D39 ] TucbAudio C:\WINDOWS\system32\drivers\TucbAudio.sys 10:18:00.0812 3928 TucbAudio - ok 10:18:00.0859 3928 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 10:18:00.0859 3928 Udfs - ok 10:18:00.0890 3928 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys 10:18:00.0890 3928 ultra - ok 10:18:00.0968 3928 [ 586DD78A81BA2DB209C94DA23F3B1691 ] Uniblue DiskRescue C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe 10:18:00.0968 3928 Uniblue DiskRescue - ok 10:18:01.0031 3928 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 10:18:01.0046 3928 Update - ok 10:18:01.0109 3928 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 10:18:01.0125 3928 upnphost - ok 10:18:01.0171 3928 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 10:18:01.0171 3928 UPS - ok 10:18:01.0234 3928 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 10:18:01.0250 3928 usbaudio - ok 10:18:01.0312 3928 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 10:18:01.0312 3928 usbccgp - ok 10:18:01.0328 3928 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 10:18:01.0343 3928 usbehci - ok 10:18:01.0390 3928 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 10:18:01.0390 3928 usbhub - ok 10:18:01.0421 3928 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 10:18:01.0421 3928 usbprint - ok 10:18:01.0468 3928 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 10:18:01.0468 3928 usbscan - ok 10:18:01.0500 3928 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 10:18:01.0515 3928 USBSTOR - ok 10:18:01.0515 3928 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 10:18:01.0531 3928 usbuhci - ok 10:18:01.0656 3928 [ C5B70A6AA947667CE0E5FC84A05EC8B6 ] usnjsvc C:\Program Files\MSN Messenger\usnsvc.exe 10:18:01.0656 3928 usnjsvc - ok 10:18:01.0671 3928 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 10:18:01.0671 3928 VgaSave - ok 10:18:01.0718 3928 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys 10:18:01.0718 3928 viaagp - ok 10:18:01.0734 3928 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 10:18:01.0734 3928 ViaIde - ok 10:18:01.0796 3928 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 10:18:01.0796 3928 VolSnap - ok 10:18:01.0859 3928 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 10:18:01.0875 3928 VSS - ok 10:18:01.0906 3928 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll 10:18:01.0921 3928 w32time - ok 10:18:01.0953 3928 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 10:18:01.0953 3928 Wanarp - ok 10:18:01.0953 3928 wanatw - ok 10:18:02.0031 3928 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys 10:18:02.0046 3928 Wdf01000 - ok 10:18:02.0046 3928 WDICA - ok 10:18:02.0078 3928 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 10:18:02.0078 3928 wdmaud - ok 10:18:02.0109 3928 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 10:18:02.0125 3928 WebClient - ok 10:18:02.0250 3928 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 10:18:02.0250 3928 winmgmt - ok 10:18:02.0312 3928 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 10:18:02.0312 3928 WmdmPmSN - ok 10:18:02.0359 3928 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 10:18:02.0359 3928 Wmi - ok 10:18:02.0390 3928 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 10:18:02.0390 3928 WmiApSrv - ok 10:18:02.0515 3928 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 10:18:02.0531 3928 WMPNetworkSvc - ok 10:18:02.0546 3928 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys 10:18:02.0562 3928 WpdUsb - ok 10:18:02.0609 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(1) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys 10:18:02.0656 3928 WsAudio_DeviceS(1) - ok 10:18:02.0687 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(2) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys 10:18:02.0718 3928 WsAudio_DeviceS(2) - ok 10:18:02.0765 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(3) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys 10:18:02.0796 3928 WsAudio_DeviceS(3) - ok 10:18:02.0843 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(4) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys 10:18:02.0875 3928 WsAudio_DeviceS(4) - ok 10:18:02.0921 3928 [ 4160CBE59D9B5BE22E4C3897E8DB9D56 ] WsAudio_DeviceS(5) C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys 10:18:02.0953 3928 WsAudio_DeviceS(5) - ok 10:18:03.0000 3928 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 10:18:03.0015 3928 wscsvc - ok 10:18:03.0062 3928 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 10:18:03.0062 3928 WSTCODEC - ok 10:18:03.0109 3928 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 10:18:03.0125 3928 wuauserv - ok 10:18:03.0187 3928 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 10:18:03.0187 3928 WudfPf - ok 10:18:03.0250 3928 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 10:18:03.0250 3928 WudfRd - ok 10:18:03.0265 3928 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 10:18:03.0281 3928 WudfSvc - ok 10:18:03.0343 3928 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 10:18:03.0359 3928 WZCSVC - ok 10:18:03.0406 3928 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 10:18:03.0421 3928 xmlprov - ok 10:18:03.0437 3928 ================ Scan global =============================== 10:18:03.0484 3928 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 10:18:03.0531 3928 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 10:18:03.0562 3928 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 10:18:03.0578 3928 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 10:18:03.0593 3928 [Global] - ok 10:18:03.0593 3928 ================ Scan MBR ================================== 10:18:03.0625 3928 [ 91722E6BC3A2B40FF00222DCA4A3DB3E ] \Device\Harddisk0\DR0 10:18:03.0828 3928 \Device\Harddisk0\DR0 - ok 10:18:03.0828 3928 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1 10:18:03.0828 3928 \Device\Harddisk1\DR1 - ok 10:18:03.0828 3928 ================ Scan VBR ================================== 10:18:03.0843 3928 [ E277A2030501530D9C30930555EF2B92 ] \Device\Harddisk0\DR0\Partition1 10:18:03.0843 3928 \Device\Harddisk0\DR0\Partition1 - ok 10:18:03.0843 3928 ============================================================ 10:18:03.0843 3928 Scan finished 10:18:03.0843 3928 ============================================================ 10:18:03.0859 2952 Detected object count: 0 10:18:03.0859 2952 Actual detected object count: 0 10:20:48.0578 3496 Deinitialize success | |  | reply to LoPhatPhuud Hi, Just a couple of things which may or not be important. When i switched on this morning the following message came up: Windows no disk Exception processing message 00000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c Malware then proceeded to pop up telling me that it had successfully blocked access to a potentially malicious website (outgoing) I got some of the codes ie 218.10.63.240 - is it worth noting these down if I can? Also today when I close down internet explorer it shuts down Thunderbird too. I am trying not to use my machine unless absolutely neccesary but am checking in regularly to see if you are around and have more instructions. Cheers, Anna | |  LoPhatPhuudPremium,VIP,MVM join:2002-01-06 Albuquerque, NM kudos:26 Reviews:
·Comcast
| reply to Carcassonne
OTL Log OTL logfile created on: 26/11/2012 17:42:58 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1.99 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 71.78% Memory free 7.81 Gb Paging File | 7.43 Gb Available in Paging File | 95.11% Paging File free Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.82 Gb Total Space | 24.81 Gb Free Space | 35.54% Space Free | Partition Type: NTFS Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.96% Space Free | Partition Type: NTFS Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS Computer Name: DELL | User Name: annas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe PRC - [2012/07/08 13:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe PRC - [2009/12/23 17:16:26 | 001,701,224 | ---- | M] (Philips) -- C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/11/26 17:29:17 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\93e7e3d6030f426844228042348210cf\Service.dll MOD - [2012/11/26 17:29:14 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\bd5179a413bc0c4b82eedc22c6cab101\re.dll MOD - [2012/11/26 17:29:13 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll MOD - [2012/11/26 17:29:11 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\eb138ef0e4282611dbf485a302784646\LibYAML.dll MOD - [2012/11/26 17:29:09 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\e56c61f7248672819579325af3387035\POSIX.dll MOD - [2012/11/26 17:29:07 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll MOD - [2012/11/26 17:29:02 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll MOD - [2012/11/26 17:29:01 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll MOD - [2012/11/26 17:28:59 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\f233f63b6654362865c7577442edb9e3\Win32.dll MOD - [2012/11/26 17:28:56 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll MOD - [2012/11/26 17:28:53 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll MOD - [2012/11/26 17:28:51 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll MOD - [2012/11/26 17:28:49 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\4461f48e31bde5c56b31b973b773de09\List.dll MOD - [2012/11/26 17:28:48 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll MOD - [2012/11/26 17:28:48 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll MOD - [2012/11/26 17:28:46 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll MOD - [2012/11/26 17:28:44 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\c5cce8d16a1bd48692b421dcf46d3396\Util.dll MOD - [2012/11/26 17:28:41 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-3124\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll MOD - [2012/11/26 08:48:55 | 002,033,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112600\algo.dll MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll MOD - [2012/07/08 13:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll MOD - [2012/07/08 13:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll MOD - [2012/07/08 13:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\en\en.dll MOD - [2009/12/23 17:16:26 | 000,135,168 | ---- | M] () -- C:\Program Files\Philips\GoGear VIBE Device Manager\Scsi_nt.dll MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache) SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc) SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc) SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer) SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist) SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue) SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing) SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService) SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Stopped] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw) DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv) DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1) DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss) DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio) DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd) DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit) DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD) DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv) DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct) DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt) DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531) DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » home.sweetim.com/?crg=3.1010000.···606FC20}IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = » www.google.com/ieIE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···source?}IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = » www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = » www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » www.google.co.uk/IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···m=IE8SRCIE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = » apype.com/results.php?q={searchTerms}IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = » search.conduit.com/ResultsExt.as···T3220468IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Custom search" FF - prefs.js..browser.search.selectedEngine: "Custom search" FF - prefs.js..browser.startup.homepage: "http://apype.com" FF - prefs.js..extensions.enabledAddons: 14xRm%40skywebsearch.com:3.0.0.0 FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474 FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119 FF - prefs.js..keyword.URL: "http://apype.com/results.php?q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] () [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions [2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/09/27 17:40:26 | 000,046,060 | ---- | M] () (No name found) -- C:\DOCUME~1\ANNAS\A YOUTUBE DOWNLOADER FREE.XPI [2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL () O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited) O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation) O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd) O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.) O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips) O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme () O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites) O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} » eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} » cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} » update.microsoft.com/windowsupda···43462484 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} » java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O34 - HKLM BootExecute: (autocheck autochk /k:E *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate [2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic [2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic [2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter [2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS [2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center [2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0 [2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell [2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure [2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit [2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit [2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit [2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan [2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus [2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software [2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data [2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth [2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer [2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer [2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2 [2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent [2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe [2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client [2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2 [2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes [2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2) [2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 17:36:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/26 17:30:18 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012/11/26 17:28:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/11/26 17:27:47 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/26 17:26:30 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/26 17:26:29 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/26 17:26:26 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job [2012/11/26 17:26:25 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job [2012/11/26 17:26:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/11/26 15:14:03 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk [2012/11/25 22:36:38 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini [2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif [2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg [2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk [2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk [2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif [2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp [2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos [2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg [2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi [2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll [2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll [2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel [2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc [2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND [2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe [2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini [2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2012/11/25 18:26:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software [2011/10/12 19:19:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9 [2011/03/15 09:05:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files [2009/02/16 18:22:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner [2009/07/03 15:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileOpen [2012/01/31 10:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LGMOBILEAX [2011/11/03 18:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData [2012/07/14 13:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound [2012/11/26 10:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic [2012/11/25 22:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit [2010/02/27 20:55:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution [2008/01/29 15:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SongbirdVLC [2012/01/31 19:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Squeezebox [2007/04/10 09:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla! [2007/11/22 10:25:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft [2012/11/24 20:10:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer [2012/10/26 17:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2007/03/04 14:33:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZILLAbar [2008/10/09 13:32:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0} [2009/02/16 18:17:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E} [2012/07/26 10:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46} [2010/02/27 21:30:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009/04/11 13:50:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{8A09CD83-59E1-4DB1-AAFC-E25174FC6706} [2010/05/26 18:29:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C} [2012/07/09 09:07:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{F0489EF2-D393-4114-85BA-A94D71D89543} [2007/12/06 13:49:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\.wyzo [2010/10/21 09:21:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Amazon [2009/02/24 20:03:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\ArchosLink [2008/03/07 11:47:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Azureus [2008/10/09 13:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\BitTorrent [2012/04/26 12:11:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\calibre [2008/10/09 13:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\DNA [2012/11/25 22:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\DriverCure [2012/11/26 17:30:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Dropbox [2012/11/21 15:51:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\EurekaLog [2010/02/17 16:19:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\eXPert PDF Editor [2009/07/03 15:45:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\FileOpen [2012/06/30 15:45:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Firefly Studios [2012/09/30 17:42:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Free Download Manager [2010/02/27 18:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\GetRightToGo [2010/12/28 17:41:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\gtk-2.0 [2007/01/17 12:41:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Leadertech [2008/08/30 20:15:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\LGSync [2011/03/01 15:11:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\moovida-1 [2006/10/11 20:58:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\MSNInstaller [2009/05/18 17:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\NCH Swift Sound [2012/08/18 14:49:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Oracle [2009/03/06 10:53:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\OverDrive [2012/11/26 10:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\ParetoLogic [2012/11/25 22:36:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit [2011/03/13 17:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\PCDr [2012/09/07 18:48:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Philips [2012/09/07 18:31:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Philips-Songbird [2009/06/05 17:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\PIFreePC [2008/01/29 15:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Qtrax1 [2012/11/25 22:14:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\QuickScan [2012/08/10 13:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\SanDisk [2012/11/15 15:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Spotify [2010/08/26 19:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Thunderbird [2011/04/28 13:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Uniblue [2012/11/24 18:39:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\UseNeXT [2012/11/26 17:30:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\uTorrent [2007/12/07 22:27:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\annas\Application Data\Wyzo [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\?ý?????????? [2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\?ý?????????? [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F @Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA -- When angry count four; when very angry, swear. Microsoft MVP/Consumer Security 2005-2011 Gladiator Security Forum | | |
|  LoPhatPhuudPremium,VIP,MVM join:2002-01-06 Albuquerque, NM kudos:26 Reviews:
·Comcast
| reply to Carcassonne Thanks for the TDSS log. It was negative.
However, there are several adware programs installed, as well as a torrent client that I assume you did not install (came with something else, most likely).
First: Use Add/Remove Programs to uninstall the following. Note, that if there is no Add/Remove Programs entry, just go on to the next item.
Yontoo 1.10.02 µTorrent uTorrentControl_v2 Toolbar A You Tube Downloader
Second: In Firefox, remove SkyWebSearch from the list of search entries, and any addon (extension) for it.
Third: Run OTL again, and post the new log in this thread. Note that there will not be a new Extras log. -- When angry count four; when very angry, swear. Microsoft MVP/Consumer Security 2005-2011 Gladiator Security Forum | |  | Sorry - I am not sure how to remove Skysearch from the list of search entries? | |  LoPhatPhuudPremium,VIP,MVM join:2002-01-06 Albuquerque, NM kudos:26 | reply to Carcassonne Click in the Search Box and press 'Alt+UpArrow'. Then select 'Manage Search Engines'
Alternatively, left click on the arrow to the right of the currently selected search engine. Then select 'Manage Search Engines' as before. | |  | I have done both those things and I am not given that option. I just get a list of 12 previously search items | |  | sorry should have said I have never noticed Skysearch coming up | |  1 edit | reply to LoPhatPhuud
Ok - I uninstalled Utorrent No utorrentControl v2 toolbar No A youtube Downloader When I tried to remove Yontoo I got the message: C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat Error2 while loading archive: The system cannot find the specified file While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it I do not seem to be able to remove it. Machine now going very slow & capricious! Applications opening & closing unexpectedly Attatched is the OTL report OTL logfile created on: 27/11/2012 19:00:53 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free 7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32 Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS Computer Name: DELL | User Name: annas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache) SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc) SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc) SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer) SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist) SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue) SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing) SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService) SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw) DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv) DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1) DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss) DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio) DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd) DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit) DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD) DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv) DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct) DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt) DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531) DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » home.sweetim.com/?crg=3.1010000.···606FC20}IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = » www.google.com/ieIE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···source?}IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = » www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = » www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » www.google.co.uk/IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···m=IE8SRCIE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = » apype.com/results.php?q={searchTerms}IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = » search.conduit.com/ResultsExt.as···T3220468IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Custom search" FF - prefs.js..browser.search.selectedEngine: "Custom search" FF - prefs.js..browser.startup.homepage: "http://apype.com" FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474 FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119 FF - prefs.js..keyword.URL: "http://apype.com/results.php?q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] () [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions [2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL () O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation) O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd) O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips) O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme () O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites) O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} » eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} » cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} » update.microsoft.com/windowsupda···43462484 (WUWebControl Class) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} » download.eset.com/special/eos/On···nner.cab (OnlineScanner Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} » java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O34 - HKLM BootExecute: (autocheck autochk /k:E *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe [2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012 [2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate [2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic [2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic [2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter [2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS [2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center [2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0 [2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell [2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure [2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit [2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit [2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit [2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan [2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus [2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software [2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data [2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth [2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer [2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer [2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2 [2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe [2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client [2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2 [2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes [2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2) [2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job [2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job [2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe [2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat [2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk [2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini [2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif [2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg [2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat [2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe [2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk [2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk [2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif [2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp [2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos [2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg [2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi [2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll [2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll [2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel [2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc [2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND [2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe [2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini [2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== Files - Unicode (All) ==========[/color] [2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑۫粑퀣睏 [2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑۫粑퀣睏 [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F @Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA | |  | reply to Carcassonne
Ok - I uninstalled Utorrent No utorrentControl v2 toolbar No A youtube Downloader When I tried to remove Yontoo I got the message: C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat Error2 while loading archive: The system cannot find the specified file While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it I do not seem to be able to remove it. OTL Scan results: OTL logfile created on: 27/11/2012 19:00:53 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free 7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32 Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS Computer Name: DELL | User Name: annas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache) SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc) SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc) SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer) SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist) SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue) SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing) SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService) SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw) DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv) DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1) DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss) DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio) DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd) DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit) DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD) DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv) DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct) DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt) DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531) DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » home.sweetim.com/?crg=3.1010000.···606FC20}IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = » www.google.com/ieIE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···source?}IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = » www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = » www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » www.google.co.uk/IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···m=IE8SRCIE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = » apype.com/results.php?q={searchTerms}IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = » search.conduit.com/ResultsExt.as···T3220468IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Custom search" FF - prefs.js..browser.search.selectedEngine: "Custom search" FF - prefs.js..browser.startup.homepage: "http://apype.com" FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474 FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119 FF - prefs.js..keyword.URL: "http://apype.com/results.php?q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] () [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions [2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL () O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation) O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd) O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips) O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme () O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites) O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} » eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} » cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} » update.microsoft.com/windowsupda···43462484 (WUWebControl Class) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} » download.eset.com/special/eos/On···nner.cab (OnlineScanner Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} » java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O34 - HKLM BootExecute: (autocheck autochk /k:E *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe [2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012 [2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate [2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic [2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic [2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter [2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS [2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center [2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0 [2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell [2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure [2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit [2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit [2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit [2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan [2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus [2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software [2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data [2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth [2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer [2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer [2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2 [2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe [2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client [2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2 [2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes [2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2) [2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job [2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job [2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe [2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat [2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk [2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini [2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif [2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg [2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat [2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe [2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk [2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk [2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif [2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp [2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos [2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg [2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi [2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll [2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll [2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel [2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc [2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND [2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe [2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini [2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== Files - Unicode (All) ==========[/color] [2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏 [2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏 [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F @Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA | |  | reply to Carcassonne
Ok - I uninstalled Utorrent No utorrentControl v2 toolbar No A youtube Downloader When I tried to remove Yontoo I got the message: C:\Document~\ALLUSE~1\APPLIC~1\TarmaInstaller\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\setup.dat Error2 while loading archive: The system cannot find the specified file While trying to get rid of Skywebsearch I noticed that A Youtube downloader was enabled again despite my having previously disabled it I do not seem to be able to remove it. Here are the OTL scan results: OTL logfile created on: 27/11/2012 19:00:53 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1.99 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 67.20% Memory free 7.81 Gb Paging File | 7.34 Gb Available in Paging File | 93.92% Paging File free Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.82 Gb Total Space | 25.41 Gb Free Space | 36.40% Space Free | Partition Type: NTFS Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS Drive F: | 202.09 Gb Total Space | 26.30 Gb Free Space | 13.02% Space Free | Partition Type: NTFS Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive H: | 3.66 Gb Total Space | 1.42 Gb Free Space | 38.95% Space Free | Partition Type: FAT32 Drive Z: | 465.76 Gb Total Space | 196.29 Gb Free Space | 42.14% Space Free | Partition Type: NTFS Computer Name: DELL | User Name: annas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2012/09/13 00:46:52 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe PRC - [2012/03/14 04:48:58 | 003,051,619 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\SqueezeTray.exe PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/11/27 13:40:20 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\93e7e3d6030f426844228042348210cf\Service.dll MOD - [2012/11/27 13:40:18 | 000,184,414 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\bd5179a413bc0c4b82eedc22c6cab101\re.dll MOD - [2012/11/27 13:40:14 | 000,053,340 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll MOD - [2012/11/27 13:40:13 | 000,094,334 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eb138ef0e4282611dbf485a302784646\LibYAML.dll MOD - [2012/11/27 13:40:12 | 000,061,540 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\e56c61f7248672819579325af3387035\POSIX.dll MOD - [2012/11/27 13:40:11 | 000,024,676 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll MOD - [2012/11/27 13:40:09 | 000,082,033 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll MOD - [2012/11/27 13:40:07 | 000,020,590 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll MOD - [2012/11/27 13:40:06 | 000,036,964 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\f233f63b6654362865c7577442edb9e3\Win32.dll MOD - [2012/11/27 13:40:05 | 000,020,576 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll MOD - [2012/11/27 13:40:03 | 000,082,048 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll MOD - [2012/11/27 13:40:02 | 000,118,918 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll MOD - [2012/11/27 13:40:01 | 000,020,601 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\4461f48e31bde5c56b31b973b773de09\List.dll MOD - [2012/11/27 13:40:00 | 000,028,779 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll MOD - [2012/11/27 13:39:59 | 000,024,701 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll MOD - [2012/11/27 13:39:58 | 000,032,878 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll MOD - [2012/11/27 13:39:56 | 000,024,679 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\c5cce8d16a1bd48692b421dcf46d3396\Util.dll MOD - [2012/11/27 13:39:43 | 000,028,774 | R--- | M] () -- C:\Documents and Settings\annas\Local Settings\Temp\pdk-annas-2896\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll MOD - [2012/11/27 09:19:43 | 002,034,176 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112700\algo.dll MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache) SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc) SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc) SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer) SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist) SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue) SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing) SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService) SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw) DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv) DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2) DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1) DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss) DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio) DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd) DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit) DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD) DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv) DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct) DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt) DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531) DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » home.sweetim.com/?crg=3.1010000.···606FC20}IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = » www.google.com/ieIE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···source?}IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = » www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = » www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = » www.google.co.uk/IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = » search.live.com/results.aspx?q={···m=IE8SRCIE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = » apype.com/results.php?q={searchTerms}IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = » search.conduit.com/ResultsExt.as···T3220468IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Custom search" FF - prefs.js..browser.search.selectedEngine: "Custom search" FF - prefs.js..browser.startup.homepage: "http://apype.com" FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474 FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119 FF - prefs.js..keyword.URL: "http://apype.com/results.php?q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] () [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions [2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions [2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL () O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation) O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd) O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips) O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme () O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites) O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} » eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} » cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} » update.microsoft.com/windowsupda···43462484 (WUWebControl Class) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} » download.eset.com/special/eos/On···nner.cab (OnlineScanner Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} » java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} » java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe O34 - HKLM BootExecute: (autocheck autochk /k:E *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe [2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012 [2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate [2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic [2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic [2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter [2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS [2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center [2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0 [2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell [2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure [2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit [2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit [2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit [2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit [2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan [2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus [2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software [2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data [2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth [2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer [2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer [2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2 [2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe [2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client [2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2 [2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes [2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2) [2012/09/27 17:40:26 | 000,447,488 | ---- | C] (HotSummerWind Software) -- C:\Documents and Settings\annas\A Youtube Downloader Free.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/11/27 18:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012/11/27 18:27:00 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/27 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/27 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/27 13:48:09 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/27 13:38:38 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/27 13:38:38 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/27 13:38:27 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job [2012/11/27 13:38:27 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job [2012/11/27 13:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe [2012/11/27 09:43:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat [2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe [2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe [2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk [2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini [2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif [2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg [2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/11/22 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job [2012/11/20 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/10/30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/10/30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/10/30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat [2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe [2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job [2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job [2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk [2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk [2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job [2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk [2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job [2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job [2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk [2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif [2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk [2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp [2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos [2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg [2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini [2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi [2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll [2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll [2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel [2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc [2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND [2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe [2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini [2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== Files - Unicode (All) ==========[/color] [2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏 [2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑��۫粑퀣睏 [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F @Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA | |  LoPhatPhuudPremium,VIP,MVM join:2002-01-06 Albuquerque, NM kudos:26 Reviews:
·Comcast
| reply to Carcassonne Based on the additional symptoms you mention (capricious starts) you may be best served by reformatting and starting over.
I'm not to the point where that is the only option I will recommend, but we are going in that direction.
Let me know if you want to continue, or if you would prefer to just start over nowl. -- When angry count four; when very angry, swear. Microsoft MVP/Consumer Security 2005-2011 Gladiator Security Forum | |  | I like a challenge and I am finding it quite interesting so I am happy to carry on if you are! THANKS FOR YOUR PATIENCE | |  | reply to LoPhatPhuud Just to let you know I have to go out now for about an hour and a half but then will be in all evening. cheers | |  | reply to LoPhatPhuud I await further instructions! | |  LoPhatPhuudPremium,VIP,MVM join:2002-01-06 Albuquerque, NM kudos:26 Reviews:
·Comcast
| reply to Carcassonne Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, copy and paste the contents of the following box:
:OTL IE - HKLM\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) IE - HKCU\..\URLSearchHook: {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\InprocServer32 File not found IE - HKCU\..\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}: "URL" = »apype.com/results.php?q={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = »search.conduit.com/ResultsExt.as···T3220468 O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O2 - BHO: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (A Youtube Downloader Free) - {c0415407-4ed2-48e1-900e-ee869abdd1f3} - C:\Documents and Settings\annas\A Youtube Downloader Free.dll (HotSummerWind Software) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found O8 - Extra context menu item: &Subscribe with ArchosLink - Reg Error: Value error. File not found O15 - HKCU\..Trusted Domains: gouv.fr ([www.impots] http in Trusted sites) O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
:Services
:Reg
:Files
:Commands [purity] [emptytemp] [EMPTYFLASH] [Reboot]
[*]Then click the Run Fix button at the top [*]Let the program run unhindered, reboot the PC when it is done [*]Once you see a message box "Fix complete! Click OK to open the fix log." [*]Click the OK button [*]The log will open in Notepad (your default text editor). {*]Save the log. Post a copy of that log in your next reply.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. -- When angry count four; when very angry, swear. Microsoft MVP/Consumer Security 2005-2011 Gladiator Security Forum | |  | Ok - thanks! | |
|