site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
5880
Share Topic
Posting?
Post a:
Post a:
Links: ·SCU FAQ ·Pre-Clean ·Site IMs ·VundoFix ·Zlob/Smitfraud ·SCU Helpers
page: 1 · 2 · 3
AuthorAll Replies

Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud

Re: [Malware] Starburn software problem -Virus/malware?

Done that - after the reboot - the log just came uo without any preamble from OTL.
Here are the results:
All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{c0415407-4ed2-48e1-900e-ee869abdd1f3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0415407-4ed2-48e1-900e-ee869abdd1f3}\ deleted successfully.
C:\Documents and Settings\annas\A Youtube Downloader Free.dll moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ deleted successfully.
C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{c0415407-4ed2-48e1-900e-ee869abdd1f3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0415407-4ed2-48e1-900e-ee869abdd1f3}\ not found.
File C:\Documents and Settings\annas\A Youtube Downloader Free.dll not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{da21bd13-ca22-42e3-a071-98f08f1ca1e7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{420efb88-346f-4cb5-bbb1-cfd5efad5439}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{420efb88-346f-4cb5-bbb1-cfd5efad5439}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0415407-4ed2-48e1-900e-ee869abdd1f3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0415407-4ed2-48e1-900e-ee869abdd1f3}\ not found.
File C:\Documents and Settings\annas\A Youtube Downloader Free.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{c0415407-4ed2-48e1-900e-ee869abdd1f3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0415407-4ed2-48e1-900e-ee869abdd1f3}\ not found.
File C:\Documents and Settings\annas\A Youtube Downloader Free.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTo0.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Subscribe with ArchosLink\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gouv.fr\www.impots\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: annas
->Temp folder emptied: 721097 bytes
->Temporary Internet Files folder emptied: 5071420 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 127166264 bytes
->Flash cache emptied: 2042 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Jim Bunton
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 38638 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12089129 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 3349105189 bytes

Total Files Cleaned = 3,332.00 mb

[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: annas
->Flash cache emptied: 0 bytes

User: Default User

User: Guest
->Flash cache emptied: 0 bytes

User: Jim Bunton
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.69.0 log created on 11292012_180931

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
A question - I would like to uninstall & then reinstall Firefox. Should i do this or do you think I'm better off not using Firefox at all any more?
When I go to Tools/options it is still showing apype as default browser although Malwarebytes is blocking it.



LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne

The following should remove the Firefox issue.

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, copy and paste the contents of the following box:


:OTL
FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="

:Services

:Reg

:Files

:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Once you see a message box "Fix complete! Click OK to open the fix log."
[*]Click the OK button
[*]The log will open in Notepad (your default text editor).
{*]Save the log. Post a copy of that log in your next reply.


Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.

If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
First:
Please run OTL again, and post the new log in this thread. Note that there will not be a new Extras log this time.


Second:

Time for a reality check.

What problem(s), if any, are still unresolved?
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
Will do


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud

OTL30 nov1.Txt 99,922 bytes
So sorry - I posted the report but I don't think it took because it was too long. I now attach it.
Everything A OK now except I still have the apype problem although it is being stopped by Malwarebytes


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne

OTL logfile created on: 30/11/2012 17:22:17 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.23% Memory free
7.81 Gb Paging File | 7.29 Gb Available in Paging File | 93.37% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 27.58 Gb Free Space | 39.51% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.97% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.71 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 25.55 Gb Free Space | 12.64% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/11/22 19:44:00 | 000,394,632 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe
PRC - [2012/11/22 19:44:00 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/07/08 13:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/30 11:17:52 | 002,035,200 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12113000\algo.dll
MOD - [2012/11/30 08:13:21 | 000,098,415 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\19febd96672ffdb7ea244cef36aaa062\Zlib.dll
MOD - [2012/11/30 08:13:17 | 000,032,881 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\b6bd87c968599725b8ab2e5c25d3046a\API.dll
MOD - [2012/11/30 08:13:16 | 000,061,547 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\bc147d83c7c868eeee67082dcf55430c\File.dll
MOD - [2012/11/30 08:13:15 | 000,017,920 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll
MOD - [2012/11/30 08:13:05 | 004,547,584 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\38a10ee333cf1a9afec3f0acdf1bbebc\Scan.dll
MOD - [2012/11/30 08:13:05 | 000,020,587 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\c668a322917d32a5ea22894518aa9897\Base64.dll
MOD - [2012/11/30 08:13:04 | 000,608,256 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll
MOD - [2012/11/30 08:13:04 | 000,030,208 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\0665c25e931c1ac0151b062449e91028\XSAccessor.dll
MOD - [2012/11/30 08:13:04 | 000,020,596 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll
MOD - [2012/11/30 08:13:03 | 000,361,472 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\aff7ee779ea184f884ed432c30a58f5d\Scale.dll
MOD - [2012/11/30 08:13:03 | 000,110,705 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\7f2598c08178217a0e2c754f3d568f28\Byte.dll
MOD - [2012/11/30 08:13:03 | 000,061,546 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll
MOD - [2012/11/30 08:13:03 | 000,024,701 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/11/30 08:13:03 | 000,024,679 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll
MOD - [2012/11/30 08:13:03 | 000,024,670 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll
MOD - [2012/11/30 08:13:02 | 000,184,414 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/11/30 08:13:02 | 000,182,272 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\d0bf009923f29116535c26d228271d6d\Scan.dll
MOD - [2012/11/30 08:13:02 | 000,032,878 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/11/30 08:13:02 | 000,028,774 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/11/30 08:13:02 | 000,024,695 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll
MOD - [2012/11/30 08:13:02 | 000,024,672 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\17d0b152e63e6bfe81b4b19588538896\mro.dll
MOD - [2012/11/30 08:13:02 | 000,020,596 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\3b7106dd14676048b10bbb09a990f74c\XS.dll
MOD - [2012/11/30 08:13:02 | 000,020,592 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\b979ace6da01e63d651cce9ee2474fdc\Name.dll
MOD - [2012/11/30 08:13:01 | 000,138,752 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\44727051c604ef6b79894b64d4c63832\Expat.dll
MOD - [2012/11/30 08:13:01 | 000,094,334 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/11/30 08:13:01 | 000,077,824 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\7f177c338672436e01c4f0bdbcf94491\EV.dll
MOD - [2012/11/30 08:13:01 | 000,053,340 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/11/30 08:13:01 | 000,041,080 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll
MOD - [2012/11/30 08:13:01 | 000,030,720 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll
MOD - [2012/11/30 08:13:01 | 000,024,694 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\c344fd5536724b2af2e6453833b60203\SHA1.dll
MOD - [2012/11/30 08:13:01 | 000,024,679 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/11/30 08:13:01 | 000,020,590 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll
MOD - [2012/11/30 08:13:00 | 000,118,918 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/11/30 08:13:00 | 000,090,213 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll
MOD - [2012/11/30 08:13:00 | 000,082,048 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/11/30 08:13:00 | 000,028,779 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/11/30 08:13:00 | 000,024,681 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\c199d3c1960e7aeeecb599487952bed2\HiRes.dll
MOD - [2012/11/30 08:13:00 | 000,020,601 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/11/30 08:12:59 | 000,082,033 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/11/30 08:12:59 | 000,020,590 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/11/30 08:12:58 | 000,061,540 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/11/30 08:12:58 | 000,036,964 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/11/30 08:12:58 | 000,024,676 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/11/30 08:12:58 | 000,020,576 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/11/30 08:12:46 | 000,001,024 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-2128\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll
MOD - [2012/11/29 22:36:19 | 002,035,200 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12112901\algo.dll
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2012/11/22 19:43:58 | 000,474,504 | ---- | M] () -- C:\Program Files\Uniblue\SpeedUpMyPC\locale\en\en.dll
MOD - [2012/11/22 19:43:48 | 000,114,056 | ---- | M] () -- C:\Program Files\Uniblue\SpeedUpMyPC\InstallerExtensions.dll
MOD - [2012/11/22 19:43:48 | 000,018,824 | ---- | M] () -- C:\Program Files\Uniblue\SpeedUpMyPC\cwebpage.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2005/09/29 03:02:18 | 000,114,688 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfflib.dll
MOD - [2005/09/29 03:02:16 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfhpec.dll
MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/11/24 16:11:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/10/09 17:30:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto | Running] -- C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/09/29 04:02:26 | 000,491,520 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (wanatw)
DRV - File not found [Kernel | Boot | Stopped] -- -- (tclondrv)
DRV - File not found [Kernel | Boot | Stopped] -- -- (szkg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/10/30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/10/30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2012/03/07 13:31:08 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2012/01/05 00:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 07:57:18 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TucbAudio.sys -- (TucbAudio)
DRV - [2010/02/16 11:44:26 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/09/16 18:09:24 | 000,030,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RKHit.sys -- (RkHit)
DRV - [2008/05/22 14:06:01 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/10/03 14:06:38 | 000,022,656 | R--- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006/09/29 10:12:00 | 000,274,816 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BLvid.sys -- (APL531)
DRV - [2005/11/16 21:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »home.sweetim.com/?crg=3.1010000.···606FC20}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = »www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = »www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »www.google.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »search.live.com/results.aspx?q={···m=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Custom search"
FF - prefs.js..browser.search.selectedEngine: "Custom search"
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/25 18:27:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/24 20:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/10/13 17:10:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/10/13 17:09:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\14xRm@skywebsearch.com: C:\DOCUME~1\annas\A Youtube Downloader Free.xpi [2012/09/27 17:40:26 | 000,046,060 | ---- | M] ()

[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions
[2010/08/26 19:05:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/09 09:10:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Extensions\songbird@songbirdnest.com
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions
[2012/11/25 22:13:55 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Profiles\4zdzkxi8.default-1353843710664\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/24 20:22:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/11/25 18:27:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/09/01 21:58:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/11/24 16:11:10 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 17:35:28 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/11/24 17:07:33 | 000,002,261 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Custom search.xml

O1 HOSTS File: ([2012/01/30 17:35:54 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLCFCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.DLL ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [LanceurEasyBox] "C:\Program Files\EasyBox\EasyBox.exe" -AutoStart File not found
O4 - HKCU..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk = C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk = C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe (Philips)
O4 - Startup: C:\Documents and Settings\annas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\annas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} »eic.lgservice.com/DjvuViewer/DjV···.1.4.cab (DjVuCtl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} »cdn.scan.onecare.live.com/resour···5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} »update.microsoft.com/windowsupda···43462484 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} »download.eset.com/special/eos/On···nner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\annas\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/09/14 11:31:11 | 000,000,030 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bd8fb02-d866-11e0-9845-00c12606fc20}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{715c34c2-d645-11e1-9941-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell - "" = AutoRun
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e90fc898-c743-11e1-992f-00c12606fc20}\Shell\AutoRun\command - "" = H:\PMCsetup.exe
O34 - HKLM BootExecute: (autocheck autochk /k:E *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2012/11/29 18:09:31 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/11/27 10:14:40 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/26 18:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/11/26 17:50:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Virus nov2012
[2012/11/26 17:40:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/26 14:24:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/11/26 13:52:17 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/26 10:46:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 10:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\ParetoLogic
[2012/11/26 10:25:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/26 10:01:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/25 23:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\FixItCenter
[2012/11/25 23:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/25 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/25 23:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/11/25 23:09:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/11/25 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\DriverCure
[2012/11/25 22:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\PC Utility Kit
[2012/11/25 22:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\PC Utility Kit
[2012/11/25 22:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Utility Kit
[2012/11/25 22:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit
[2012/11/25 22:14:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\QuickScan
[2012/11/25 18:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/11/25 18:27:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/11/25 18:27:50 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/11/25 18:27:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/11/25 18:27:45 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/11/25 18:27:44 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/11/25 18:27:42 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/11/25 18:27:42 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/11/25 18:27:41 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/11/25 18:26:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/11/25 18:26:51 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/25 18:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/11/25 12:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Desktop\Old Firefox Data
[2012/11/24 20:22:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\PCHealth
[2012/11/24 20:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Start Menu\Programs\HomePlayer
[2012/11/24 20:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2012/11/24 20:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentControl_v2
[2012/11/24 17:40:42 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/11/24 17:26:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/11/24 16:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/11/23 23:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Local Settings\Application Data\uTorrentControl_v2
[2012/11/23 14:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\annas\Application Data\Malwarebytes
[2012/11/23 14:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/11/23 14:04:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/15 19:28:39 | 000,000,000 | ---D | C] -- C:\Program Files\HomePlayer(2)

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012/11/30 16:30:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/30 16:24:00 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[2012/11/30 15:14:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/30 09:17:22 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/30 09:17:21 | 000,000,314 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/30 09:17:04 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/30 09:16:37 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/11/30 09:16:36 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/30 09:16:34 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\spmonitor.job
[2012/11/30 09:16:31 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/30 08:21:40 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/30 08:11:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/29 18:00:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/29 12:52:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
[2012/11/28 10:02:17 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SpeedUpMyPC.lnk
[2012/11/27 10:14:49 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\annas\Desktop\tdsskiller.exe
[2012/11/26 21:30:10 | 000,001,623 | ---- | M] () -- C:\scu.dat
[2012/11/26 17:58:09 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/26 13:52:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\TFC.exe
[2012/11/25 23:17:27 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:37:27 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\annas\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/11/25 22:36:19 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:19 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:17 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:43 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/24 19:00:38 | 000,002,412 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2012/11/24 17:26:52 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/11/24 17:07:33 | 000,000,034 | ---- | M] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/11/24 17:07:28 | 000,023,145 | ---- | M] () -- C:\Documents and Settings\annas\config.cfg
[2012/11/24 11:15:14 | 000,181,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/24 10:42:41 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/24 00:13:11 | 000,545,318 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/24 00:13:11 | 000,107,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/23 23:35:34 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:54 | 000,236,218 | ---- | M] () -- C:\28086-utorrent.0000.dmp

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/11/28 10:02:22 | 000,000,256 | ---- | C] () -- C:\WINDOWS\tasks\spmonitor.job
[2012/11/28 10:02:21 | 000,000,270 | ---- | C] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2012/11/26 18:24:11 | 000,001,623 | ---- | C] () -- C:\scu.dat
[2012/11/26 17:57:45 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\SecurityCheck.exe
[2012/11/26 14:25:07 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/25 23:14:40 | 000,000,580 | -H-- | C] () -- C:\WINDOWS\tasks\DataUpload.job
[2012/11/25 23:14:39 | 000,000,616 | -H-- | C] () -- C:\WINDOWS\tasks\ConfigExec.job
[2012/11/25 23:11:00 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/11/25 23:11:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/11/25 22:36:36 | 000,000,456 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Registration3.job
[2012/11/25 22:36:19 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\PC Utility Kit.lnk
[2012/11/25 22:36:18 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit Update3.job
[2012/11/25 22:36:16 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\PC Utility Kit.job
[2012/11/25 18:27:51 | 000,001,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/11/25 18:27:42 | 000,000,314 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/11/24 17:36:30 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/24 17:26:31 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/11/24 17:05:29 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/23 23:35:38 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\annas\Desktop\Shortcut to Problems Nov 2012.lnk
[2012/10/31 21:27:52 | 000,236,218 | ---- | C] () -- C:\28086-utorrent.0000.dmp
[2012/10/26 16:38:26 | 094,065,368 | R--- | C] () -- C:\Documents and Settings\annas\firmware_archos_android_gen8.aos
[2012/10/16 08:19:46 | 000,023,145 | ---- | C] () -- C:\Documents and Settings\annas\config.cfg
[2012/10/13 17:10:25 | 000,000,034 | ---- | C] () -- C:\Program Files\Mozilla Firefoxoverride.ini
[2012/09/27 17:40:26 | 000,046,060 | ---- | C] () -- C:\Documents and Settings\annas\A Youtube Downloader Free.xpi
[2012/07/09 09:08:19 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\DriverCoInstaller.dll
[2012/07/09 09:08:05 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\rockusbCoInstaller.dll
[2012/02/14 22:15:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/12/30 16:36:29 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\annas\.recently-used.xbel
[2010/12/27 17:45:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\annas\.ufrawrc
[2010/02/17 15:24:53 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\PUTTY.RND
[2008/11/19 15:29:47 | 000,061,224 | ---- | C] () -- C:\Documents and Settings\annas\GoToAssistDownloadHelper.exe
[2008/11/18 17:34:06 | 000,000,378 | ---- | C] () -- C:\Documents and Settings\annas\Application Data\burnaware.ini
[2007/03/24 21:17:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 23:16:15 | 000,108,032 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/11 08:55:40 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\annas\Local Settings\Application Data\fusioncache.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2005/08/16 04:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09:53:33 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#A23BEC][/color]

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2008/08/19 02:11:54 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑￿￿۫粑퀣睏
[2008/08/19 02:11:54 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ý??????????) -- C:\WINDOWS\System32\ᅵý粐۰粑￿￿۫粑퀣睏

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B174FAE
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
First:
Use Add/Remove Programs to uninstal all UniBlue Products. From the logs I see these:
Uniblue SpeedUpMyPC
Uniblue RegistryBooster
Uniblue DiskRescue 2009
Uniblue DriverScanner 2009

The first two are valueless and may cause more problems than they fix. The other twto are guilt by association

Second:
THe following should remove apype from FIrefox.

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, copy and paste the contents of the following box:


:OTL
FF - prefs.js..browser.startup.homepage: "http://apype.com"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..keyword.URL: "http://apype.com/results.php?q="
FF - user.js - File not found

:Services

:Reg

:Files

:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Once you see a message box "Fix complete! Click OK to open the fix log."
[*]Click the OK button
[*]The log will open in Notepad (your default text editor).
{*]Save the log. Post a copy of that log in your next reply.


Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.

If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Third:
To double check for apype, run Microsoft Safety Scanner. Here is a link to a Microsoft Answers thread on removing apype.com. Use Method 2.

»answers.microsoft.com/en-us/ie/f···5a5069cd
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum

Carcassonne

join:2012-11-26
11000

Okay - I've removed all Uniblue programs.
I ran OTL as described & here the log is attached.
I ran Microsoft Safety Scanner and it found nothing.
I launched Mozilla & I got -search.starburnsoftware.com!
I went to tools & apype was still showing as my homepage - I reset it to my Google homepage.
I relaunched Mozilla and.......I got my Google Homepage!
However if I open a new tab the search bar says, "Go to a Website" and there is a blank page with a search bar and Starburn Search written on it the it goes to search.starburnsoftware.com
I have installed Bit defender & it is saying that ,"this page is safe"

there

there

there


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
All processes killed
========== OTL ==========
Prefs.js: "http://apype.com" removed from browser.startup.homepage
Prefs.js: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 removed from extensions.enabledAddons
Prefs.js: "http://apype.com/results.php?q=" removed from keyword.URL
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: annas
->Temp folder emptied: 10094025 bytes
->Temporary Internet Files folder emptied: 2092278 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 113196720 bytes
->Flash cache emptied: 3626 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Jim Bunton
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 16848 bytes
->Temporary Internet Files folder emptied: 33172 bytes
->FireFox cache emptied: 2098301 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12138791 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 2424379 bytes

Total Files Cleaned = 136.00 mb

[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: annas
->Flash cache emptied: 0 bytes

User: Default User

User: Guest
->Flash cache emptied: 0 bytes

User: Jim Bunton
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.69.0 log created on 12052012_124656

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum



LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne

Download ComboFix from one of these locations:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.infospyware.net/antimalware/combofix/
 
* IMPORTANT !!! Save ComboFix.exe to your Desktop

[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[*]Double click on ComboFix.exe & follow the prompts.

[*]As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it at least 20-30 minutes to finish if needed.

--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum

Carcassonne

join:2012-11-26
11000

Just realised that when I open a new tab on Int. Explorer it too gives me - search.starburnsoftware.com/#


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
Having problems posting my replies here - once more with feeling.
Attached is the report from the Combofix scan.
starburnsearch is still trying to open but is being blocked on Int. Explorer.
Unfortunately after the machine had restarted after the scan Bitdefender opened up and i could not stop it without interfering with Combofix finishing - i don't know if that had any effect?
Thans for your continuing patience - it is appreciated.



LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne

ComboFix 12-12-04.01 - annas 06/12/2012 17:25:10.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2038.1387 [GMT 1:00]
Running from: c:\documents and settings\annas\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: McAfee VirusScan *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\1354462780.bdinstall.bin
c:\documents and settings\All Users\Application Data\Dell
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_1_08044.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_1_08060.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_2_08100.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_2_08267.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_2_08298.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_2_08335.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\dsc_2_2_09085.msp
c:\documents and settings\All Users\Application Data\Dell\DSCUpdates\patch.log
c:\documents and settings\All Users\Application Data\Dell\DSL\DSLCheck.exe
c:\documents and settings\All Users\Application Data\Dell\HWDiags\PCDsysinfo.xml
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\annas\GoToAssistDownloadHelper.exe
c:\documents and settings\annas\Local Settings\Application Data\.#
c:\documents and settings\annas\Local Settings\Application Data\.#\MBX@A4@383800.###
c:\documents and settings\annas\Local Settings\Application Data\.#\MBX@A4@383810.###
c:\documents and settings\annas\Local Settings\Application Data\.#\MBX@A4@383900.###
c:\documents and settings\annas\Local Settings\Application Data\.#\MBX@A4@383920.###
c:\program files\AdVantage
c:\program files\AdVantage\AdVUninst.exe
c:\program files\codec
c:\program files\codec\AC3Filter\ac3config.exe
c:\program files\codec\AC3Filter\presets.reg
c:\program files\codec\AC3Filter\renderers win2k.reg
c:\program files\codec\AC3Filter\reset to defaults.reg
c:\program files\codec\CoreAVC\coreavc.ico
c:\program files\codec\Divx6\config.exe
c:\program files\codec\Haali\avi.dll
c:\program files\codec\Haali\dxr.dll
c:\program files\codec\Haali\mkunicode.dll
c:\program files\codec\Haali\mkx.dll
c:\program files\codec\Haali\mkzlib.dll
c:\program files\codec\Haali\mp4.dll
c:\program files\codec\Haali\ogm.dll
c:\program files\codec\Haali\splitter.ax
c:\program files\codec\Haali\ts.dll
c:\program files\codec\history.txt
c:\program files\codec\readme.txt
c:\program files\codec\Uninstall\unins000.dat
c:\program files\codec\Uninstall\unins000.exe
c:\program files\codec\XviD\xvid.ico
c:\program files\Java\jre7\bin\ssv.dll
c:\program files\OfferBox
c:\program files\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.dll
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\TEMP\pdk-SYSTEM-204\0665c25e931c1ac0151b062449e91028\XSAccessor.dll
c:\windows\TEMP\pdk-SYSTEM-204\17d0b152e63e6bfe81b4b19588538896\mro.dll
c:\windows\TEMP\pdk-SYSTEM-204\19febd96672ffdb7ea244cef36aaa062\Zlib.dll
c:\windows\TEMP\pdk-SYSTEM-204\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll
c:\windows\TEMP\pdk-SYSTEM-204\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
c:\windows\TEMP\pdk-SYSTEM-204\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
c:\windows\TEMP\pdk-SYSTEM-204\38a10ee333cf1a9afec3f0acdf1bbebc\Scan.dll
c:\windows\TEMP\pdk-SYSTEM-204\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
c:\windows\TEMP\pdk-SYSTEM-204\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll
c:\windows\TEMP\pdk-SYSTEM-204\3b7106dd14676048b10bbb09a990f74c\XS.dll
c:\windows\TEMP\pdk-SYSTEM-204\4461f48e31bde5c56b31b973b773de09\List.dll
c:\windows\TEMP\pdk-SYSTEM-204\44727051c604ef6b79894b64d4c63832\Expat.dll
c:\windows\TEMP\pdk-SYSTEM-204\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll
c:\windows\TEMP\pdk-SYSTEM-204\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
c:\windows\TEMP\pdk-SYSTEM-204\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
c:\windows\TEMP\pdk-SYSTEM-204\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
c:\windows\TEMP\pdk-SYSTEM-204\7f177c338672436e01c4f0bdbcf94491\EV.dll
c:\windows\TEMP\pdk-SYSTEM-204\7f2598c08178217a0e2c754f3d568f28\Byte.dll
c:\windows\TEMP\pdk-SYSTEM-204\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll
c:\windows\TEMP\pdk-SYSTEM-204\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll
c:\windows\TEMP\pdk-SYSTEM-204\aff7ee779ea184f884ed432c30a58f5d\Scale.dll
c:\windows\TEMP\pdk-SYSTEM-204\b6bd87c968599725b8ab2e5c25d3046a\API.dll
c:\windows\TEMP\pdk-SYSTEM-204\b979ace6da01e63d651cce9ee2474fdc\Name.dll
c:\windows\TEMP\pdk-SYSTEM-204\bc147d83c7c868eeee67082dcf55430c\File.dll
c:\windows\TEMP\pdk-SYSTEM-204\bd5179a413bc0c4b82eedc22c6cab101\re.dll
c:\windows\TEMP\pdk-SYSTEM-204\c199d3c1960e7aeeecb599487952bed2\HiRes.dll
c:\windows\TEMP\pdk-SYSTEM-204\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll
c:\windows\TEMP\pdk-SYSTEM-204\c344fd5536724b2af2e6453833b60203\SHA1.dll
c:\windows\TEMP\pdk-SYSTEM-204\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
c:\windows\TEMP\pdk-SYSTEM-204\c668a322917d32a5ea22894518aa9897\Base64.dll
c:\windows\TEMP\pdk-SYSTEM-204\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll
c:\windows\TEMP\pdk-SYSTEM-204\d0bf009923f29116535c26d228271d6d\Scan.dll
c:\windows\TEMP\pdk-SYSTEM-204\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
c:\windows\TEMP\pdk-SYSTEM-204\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll
c:\windows\TEMP\pdk-SYSTEM-204\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
c:\windows\TEMP\pdk-SYSTEM-204\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll
c:\windows\TEMP\pdk-SYSTEM-204\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
c:\windows\TEMP\pdk-SYSTEM-204\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
c:\windows\TEMP\pdk-SYSTEM-204\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll
c:\windows\TEMP\pdk-SYSTEM-204\e2e81dd6b3e5a36f0bdae076393cc11d\icuin46.dll
c:\windows\TEMP\pdk-SYSTEM-204\e2e81dd6b3e5a36f0bdae076393cc11d\icuuc46.dll
c:\windows\TEMP\pdk-SYSTEM-204\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll
c:\windows\TEMP\pdk-SYSTEM-204\e56c61f7248672819579325af3387035\POSIX.dll
c:\windows\TEMP\pdk-SYSTEM-204\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
c:\windows\TEMP\pdk-SYSTEM-204\eb138ef0e4282611dbf485a302784646\LibYAML.dll
c:\windows\TEMP\pdk-SYSTEM-204\f233f63b6654362865c7577442edb9e3\Win32.dll
c:\windows\TEMP\pdk-SYSTEM-204\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll
c:\windows\TEMP\pdk-SYSTEM-204\perl514.dll
D:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_USNJSVC
-------\Service_RkHit
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2012-11-06 to 2012-12-06 )))))))))))))))))))))))))))))))
.
.
2012-12-06 16:18 . 2012-12-06 16:18 -------- d-----w- c:\documents and settings\annas\Application Data\Windows Search
2012-12-06 14:30 . 2012-12-06 14:30 -------- d-----w- c:\windows\system32\winrm
2012-12-06 14:28 . 2012-12-06 14:28 -------- d-----w- c:\documents and settings\annas\Application Data\Windows Desktop Search
2012-12-06 14:27 . 2012-12-06 15:51 -------- d-----w- c:\program files\Windows Desktop Search
2012-12-06 14:24 . 2008-03-07 17:02 98304 ------w- c:\windows\system32\dllcache\nlhtml.dll
2012-12-06 14:24 . 2008-03-07 17:02 29696 ------w- c:\windows\system32\dllcache\mimefilt.dll
2012-12-06 14:24 . 2008-03-07 17:02 192000 ------w- c:\windows\system32\dllcache\offfilt.dll
2012-12-05 12:08 . 2012-12-05 12:12 76987984 ----a-w- c:\program files\msert.exe
2012-12-03 13:18 . 2012-12-03 13:18 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Mozilla
2012-12-02 17:21 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2012-12-02 16:44 . 2012-12-02 16:44 72704 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2012-12-02 16:10 . 2012-12-02 16:10 -------- d-----w- c:\documents and settings\All Users\Application Data\BDLogging
2012-12-02 16:10 . 2012-09-21 16:16 66392 ----a-w- c:\windows\system32\drivers\bdsandbox.sys
2012-12-02 16:10 . 2007-04-11 09:11 511328 ----a-w- c:\windows\capicom.dll
2012-12-02 16:10 . 2012-10-10 13:00 481464 ----a-w- c:\windows\system32\drivers\avckf.sys
2012-12-02 16:10 . 2012-10-10 13:00 622616 ----a-w- c:\windows\system32\drivers\avc3.sys
2012-12-02 15:47 . 2012-12-02 15:47 -------- d-----w- c:\documents and settings\annas\Application Data\Bitdefender
2012-12-02 15:47 . 2012-12-02 16:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Bitdefender
2012-12-02 15:40 . 2012-08-29 16:24 161312 ----a-w- c:\windows\system32\drivers\gzflt.sys
2012-12-02 15:40 . 2012-10-31 11:13 343456 ----a-w- c:\windows\system32\drivers\trufos.sys
2012-12-02 15:40 . 2012-12-02 15:40 -------- d-----w- c:\program files\Bitdefender
2012-12-02 15:11 . 2012-12-02 15:40 -------- d-----w- c:\program files\Common Files\Bitdefender
2012-12-01 18:07 . 2012-12-01 18:13 -------- d-----w- c:\program files\Mozilla Thunderbird
2012-11-29 17:09 . 2012-11-29 17:09 -------- d-----w- C:\_OTL
2012-11-26 17:09 . 2012-11-26 17:09 -------- d-----w- c:\program files\ESET
2012-11-26 13:24 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-26 09:26 . 2012-11-26 09:26 -------- d-----w- c:\documents and settings\annas\Application Data\ParetoLogic
2012-11-26 09:25 . 2012-11-26 09:40 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2012-11-25 22:41 . 2012-11-25 22:41 -------- d-----w- c:\documents and settings\annas\Local Settings\Application Data\FixItCenter
2012-11-25 22:10 . 2012-11-25 22:17 -------- d-----w- c:\program files\Microsoft Fix it Center
2012-11-25 21:36 . 2012-11-25 21:36 -------- d-----w- c:\documents and settings\annas\Application Data\DriverCure
2012-11-25 21:36 . 2012-11-25 21:36 -------- d-----w- c:\documents and settings\annas\Application Data\PC Utility Kit
2012-11-25 21:36 . 2012-11-25 21:36 -------- d-----w- c:\program files\Common Files\PC Utility Kit
2012-11-25 21:36 . 2012-11-25 21:36 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Utility Kit
2012-11-25 21:36 . 2012-11-25 21:36 -------- d-----w- c:\program files\PC Utility Kit
2012-11-25 21:14 . 2012-11-25 21:14 -------- d-----w- c:\documents and settings\annas\Application Data\QuickScan
2012-11-25 17:26 . 2012-12-02 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-11-25 17:26 . 2012-11-25 17:26 -------- d-----w- c:\program files\AVAST Software
2012-11-25 14:54 . 2012-11-25 14:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2012-11-25 14:43 . 2012-11-25 14:43 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2012-11-24 19:22 . 2012-11-24 19:22 -------- d-----w- c:\documents and settings\annas\Local Settings\Application Data\PCHealth
2012-11-24 19:21 . 2012-12-03 09:48 -------- d-----w- c:\program files\HomePlayer
2012-11-24 19:20 . 2012-11-29 17:09 -------- d-----w- c:\program files\uTorrentControl_v2
2012-11-24 16:40 . 2012-01-31 12:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-11-23 22:23 . 2012-11-23 22:23 -------- d-----w- c:\windows\system32\wbem\Repository
2012-11-23 22:19 . 2012-11-27 13:45 -------- d-----w- c:\documents and settings\annas\Local Settings\Application Data\uTorrentControl_v2
2012-11-23 13:04 . 2012-11-23 13:04 -------- d-----w- c:\documents and settings\annas\Application Data\Malwarebytes
2012-11-23 13:04 . 2012-11-23 13:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-11-23 13:04 . 2012-11-26 13:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-22 08:37 . 2005-08-16 03:18 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-10-09 16:30 . 2012-04-05 06:47 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 16:30 . 2011-05-25 11:09 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-02 18:04 . 2005-08-16 03:18 58368 ----a-w- c:\windows\system32\synceng.dll
2012-09-24 21:16 . 2012-10-17 13:08 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-12-05 09:35 . 2012-12-05 09:35 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\annas\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\annas\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\annas\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\annas\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"SansaDispatch"="c:\documents and settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2012-08-10 79872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2005-09-08 73728]
"Bdagent"="c:\program files\Bitdefender\Bitdefender 2013\bdagent.exe" [2012-12-02 1613368]
"HomePlayer"="c:\program files\HomePlayer\HomePlayer.exe" [2007-11-06 294912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start »www.avg.com/ww.special-uninstall···e91ebb6" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\annas\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\annas\Application Data\Dropbox\bin\Dropbox.exe [2012-7-3 26868192]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Media Server Tray Tool.lnk - c:\program files\Squeezebox\SqueezeTray.exe [2011-11-3 3051619]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Philips GoGear VIBE Device Manager.lnk - c:\program files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe [2012-8-15 1701224]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-19 14:30 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:E *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Audible Download Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Audible Download Manager.lnk
backup=c:\windows\pss\Audible Download Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Uploader Oe Integration]
2007-06-10 18:02 40960 ----a-w- f:\downloads\Free Download Manager\FUM\fumoei.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\freecell.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\UseNeXT\\UseNeXT.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Squeezebox\\server\\squeezeboxcp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Audible\\Bin\\AudibleDownloadHelper.exe"=
"c:\\Program Files\\Audible\\Bin\\Manager.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\LGMOBILEAX\\LGMLauncher.exe"=
"c:\\Program Files\\NCH Swift Sound\\SoundTap\\soundtap.exe"=
"c:\\Program Files\\AC3Filter\\ac3config.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\stronghold kingdoms\\StrongholdKingdoms.exe"=
"c:\\Documents and Settings\\annas\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"c:\\Program Files\\HomePlayer\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18694:TCP"= 18694:TCP:BitComet 18694 TCP
"18694:UDP"= 18694:UDP:BitComet 18694 UDP
"27629:TCP"= 27629:TCP:BitComet 27629 TCP
"27629:UDP"= 27629:UDP:BitComet 27629 UDP
"8081:TCP"= 8081:TCP:VLC
"8080:TCP"= 8080:TCP:Homeplayer
"9000:TCP"= 9000:TCP:Logitech Media Server 9000 tcp (UI)
"9001:TCP"= 9001:TCP:Logitech Media Server 9001 tcp (UI)
"9002:TCP"= 9002:TCP:Logitech Media Server 9002 tcp (UI)
"9003:TCP"= 9003:TCP:Logitech Media Server 9003 tcp (UI)
"9004:TCP"= 9004:TCP:Logitech Media Server 9004 tcp (UI)
"9005:TCP"= 9005:TCP:Logitech Media Server 9005 tcp (UI)
"9006:TCP"= 9006:TCP:Logitech Media Server 9006 tcp (UI)
"9007:TCP"= 9007:TCP:Logitech Media Server 9007 tcp (UI)
"9008:TCP"= 9008:TCP:Logitech Media Server 9008 tcp (UI)
"9009:TCP"= 9009:TCP:Logitech Media Server 9009 tcp (UI)
"9010:TCP"= 9010:TCP:Logitech Media Server 9010 tcp (UI)
"9100:TCP"= 9100:TCP:Logitech Media Server 9100 tcp (UI)
"8000:TCP"= 8000:TCP:Logitech Media Server 8000 tcp (UI)
"10000:TCP"= 10000:TCP:Logitech Media Server 10000 tcp (UI)
"9090:TCP"= 9090:TCP:Logitech Media Server 9090 tcp (UI)
"3483:UDP"= 3483:UDP:Logitech Media Server 3483 udp
"3483:TCP"= 3483:TCP:Logitech Media Server 3483 tcp
.
R0 avc3;avc3;c:\windows\system32\drivers\avc3.sys [02/12/2012 17:10 622616]
R0 gzflt;gzflt;c:\windows\system32\drivers\gzflt.sys [02/12/2012 16:40 161312]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [26/11/2012 14:24 399432]
R2 squeezesvc;Logitech Media Server;c:\progra~1\Squeezebox\server\SqueezeSvr.exe [20/11/2011 13:32 14057569]
R2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe [02/12/2012 17:10 55544]
R3 TucbAudio;TucbAudio;c:\windows\system32\drivers\TucbAudio.sys [27/02/2010 18:07 23096]
S0 tclondrv;tclondrv; [x]
S2 EasyBoxApache;EasyBoxApache; [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [26/11/2012 14:24 676936]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 12:28 160944]
S3 APL531;Hercules Blog Webcam;c:\windows\system32\drivers\BLvid.sys [18/07/2009 14:41 274816]
S3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [02/12/2012 17:10 481464]
S3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys [02/12/2012 17:10 66392]
S3 camfilt;camfilt;c:\windows\system32\drivers\camfilt.sys [18/07/2009 14:41 22656]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [27/07/2006 13:00 30192]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [13/06/2011 22:09 267568]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [26/11/2012 14:24 22856]
S3 SMServer;SMServer;c:\windows\system32\snmvtsvc.exe [27/02/2010 18:07 245760]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [04/08/2012 17:43 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [04/08/2012 17:44 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [04/08/2012 17:44 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [04/08/2012 17:45 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [04/08/2012 17:45 25704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
2009-03-04 15:32 8192 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 16:30]
.
2012-12-06 c:\windows\Tasks\ConfigExec.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 21:09]
.
2012-12-06 c:\windows\Tasks\DataUpload.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 21:09]
.
2012-12-05 c:\windows\Tasks\PC Utility Kit Registration3.job
- c:\program files\Common Files\PC Utility Kit\UUS3\UUS3.dll [2012-03-27 19:30]
.
2012-11-25 c:\windows\Tasks\PC Utility Kit Update3.job
- c:\program files\Common Files\PC Utility Kit\UUS3\Update3.exe [2012-03-27 19:30]
.
2012-11-25 c:\windows\Tasks\PC Utility Kit.job
- c:\program files\PC Utility Kit\PC Utility Kit\pcutilitykit.exe [2012-11-09 21:31]
.
2012-12-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 12:27]
.
2012-12-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-459166176-3624373595-3541044804-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 12:27]
.
2012-07-24 c:\windows\Tasks\WavePadReminder.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-07-14 12:38]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10011&barid={3944DCAE-EE02-11E1-996B-00C12606FC20}
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
TCP: DhcpNameServer = 212.27.40.241 212.27.40.240
TCP: Interfaces\{7C338859-52A3-49F6-AED7-DBFF78ABE174}: NameServer = 8.8.8.8,8.8.8.4
TCP: Interfaces\{FE60E668-8D91-4FCF-A5B3-C0421F29144F}: NameServer = 212.27.53.252,212.27.54.252
FF - ProfilePath - c:\documents and settings\annas\Application Data\Mozilla\Firefox\Profiles\7p6085ki.default-1354467496171\
FF - prefs.js: browser.search.selectedEngine - Custom search
FF - prefs.js: browser.startup.homepage - hxxp://apype.com
FF - prefs.js: keyword.URL - hxxp://apype.com/results.php?q=
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-LanceurEasyBox - c:\program files\EasyBox\EasyBox.exe
MSConfigStartUp-AdVantage - c:\documents and settings\annas\Application Data\advantage\AdVantage.exe
MSConfigStartUp-BitTorrent DNA - c:\program files\DNA\btdna.exe
MSConfigStartUp-Free Download Manager - f:\downloaded program updates\Free Download Manager\fdm.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
AddRemove-Codec_is1 - c:\program files\Codec\Uninstall\unins000.exe
AddRemove-BitTorrent DNA - c:\program files\DNA\btdna.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, »www.gmer.net
Rootkit scan 2012-12-06 17:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\documents and settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe?????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a4,8b,67,a7,41,6c,05,47,b9,04,14,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a4,8b,67,a7,41,6c,05,47,b9,04,14,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(600)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
- - - - - - - > 'explorer.exe'(3564)
c:\windows\system32\WININET.dll
c:\documents and settings\annas\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bitdefender\Bitdefender 2013\vsserv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\PSIService.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Completion time: 2012-12-06 17:54:09 - machine was rebooted
ComboFix-quarantined-files.txt 2012-12-06 16:54
.
Pre-Run: 28,202,975,232 bytes free
Post-Run: 27,982,856,192 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
.
- - End Of File - - AE7137B6C26AD8AA62934B28B312B163
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

reply to Carcassonne
Still no siogn of Starburn, arrgh!

Out of curiosity, is there an entry in Add/Remove Programs for 'Starburn'?

I want to cross check a few entries in the Combofix log. Please run OTL again, and post the new log in this thread.

In the meantime, I am going to do some more research on Starburn and how to remove it.
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


Carcassonne

join:2012-11-26
11000

No nothing in "Add/remove programs.
What I am also getting which is new is that Word is falling over if I try to print anything +printer not working. I got this message just now when |I tried to print,
AppName: winword.exe AppVer: 9.0.0.3822 ModName: kernel32.dll
ModVer: 5.1.2600.5781 Offset: 0000a308
Also this morning when I booted up but before I signed in, I got the following, "wmi.prvse.exe Application Error.
The installation at "0x7c809823" referenced memory at "0x5f4cfff4" The memory could not be written. Click OK to terminate the programme.
I'll now run OTL
pip pip


Carcassonne

join:2012-11-26
11000

reply to LoPhatPhuud
Here is the OTL Log (attached)



lilhurricane
So mote it be
Premium,Mod
join:2003-01-11
Purple Zone
kudos:54
Reviews:
·Comcast
Host:
TV over IP
Software
RCN
Inside Insight
Cellphones, Provid..

OTL logfile created on: 07/12/2012 18:13:26 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\annas\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 67.66% Memory free
7.81 Gb Paging File | 7.17 Gb Available in Paging File | 91.75% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057D:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.82 Gb Total Space | 25.88 Gb Free Space | 37.07% Space Free | Partition Type: NTFS
Drive D: | 68.36 Gb Total Space | 61.50 Gb Free Space | 89.96% Space Free | Partition Type: NTFS
Drive E: | 195.31 Gb Total Space | 50.64 Gb Free Space | 25.93% Space Free | Partition Type: NTFS
Drive F: | 202.09 Gb Total Space | 24.81 Gb Free Space | 12.28% Space Free | Partition Type: NTFS
Drive G: | 10.53 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.66 Gb Total Space | 2.07 Gb Free Space | 56.69% Space Free | Partition Type: FAT32

Computer Name: DELL | User Name: annas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/12/02 17:44:28 | 001,613,368 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe

PRC - [2012/11/26 17:41:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\annas\Desktop\OTL.exe
PRC - [2012/11/02 17:01:07 | 001,343,032 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
PRC - [2012/11/02 14:12:38 | 000,055,544 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/08/10 13:13:05 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Documents and Settings\annas\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe
PRC - [2009/12/23 17:16:26 | 001,701,224 | ---- | M] (Philips) -- C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2006/11/01 22:15:50 | 000,537,480 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe

[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/12/07 09:11:00 | 000,098,415 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\19febd96672ffdb7ea244cef36aaa062\Zlib.dll

MOD - [2012/12/07 09:10:58 | 000,032,881 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\b6bd87c968599725b8ab2e5c25d3046a\API.dll
MOD - [2012/12/07 09:10:57 | 000,061,547 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\bc147d83c7c868eeee67082dcf55430c\File.dll
MOD - [2012/12/07 09:10:57 | 000,017,920 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll
MOD - [2012/12/07 09:10:47 | 004,547,584 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\38a10ee333cf1a9afec3f0acdf1bbebc\Scan.dll
MOD - [2012/12/07 09:10:47 | 000,020,587 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\c668a322917d32a5ea22894518aa9897\Base64.dll
MOD - [2012/12/07 09:10:46 | 000,608,256 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll
MOD - [2012/12/07 09:10:46 | 000,030,208 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\0665c25e931c1ac0151b062449e91028\XSAccessor.dll
MOD - [2012/12/07 09:10:46 | 000,020,596 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll
MOD - [2012/12/07 09:10:45 | 000,361,472 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\aff7ee779ea184f884ed432c30a58f5d\Scale.dll
MOD - [2012/12/07 09:10:45 | 000,110,705 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\7f2598c08178217a0e2c754f3d568f28\Byte.dll
MOD - [2012/12/07 09:10:45 | 000,061,546 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll
MOD - [2012/12/07 09:10:45 | 000,032,878 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
MOD - [2012/12/07 09:10:45 | 000,024,701 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
MOD - [2012/12/07 09:10:45 | 000,024,695 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~



lilhurricane
So mote it be
Premium,Mod
join:2003-01-11
Purple Zone
kudos:54
Reviews:
·Comcast
Host:
TV over IP
Software
RCN
Inside Insight
Cellphones, Provid..

MOD - [2012/12/07 09:10:45 | 000,024,679 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll
MOD - [2012/12/07 09:10:45 | 000,024,672 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\17d0b152e63e6bfe81b4b19588538896\mro.dll
MOD - [2012/12/07 09:10:45 | 000,024,670 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll
MOD - [2012/12/07 09:10:45 | 000,020,596 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\3b7106dd14676048b10bbb09a990f74c\XS.dll
MOD - [2012/12/07 09:10:44 | 000,184,414 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\bd5179a413bc0c4b82eedc22c6cab101\re.dll
MOD - [2012/12/07 09:10:44 | 000,182,272 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\d0bf009923f29116535c26d228271d6d\Scan.dll
MOD - [2012/12/07 09:10:44 | 000,138,752 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\44727051c604ef6b79894b64d4c63832\Expat.dll
MOD - [2012/12/07 09:10:44 | 000,094,334 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\eb138ef0e4282611dbf485a302784646\LibYAML.dll
MOD - [2012/12/07 09:10:44 | 000,077,824 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\7f177c338672436e01c4f0bdbcf94491\EV.dll
MOD - [2012/12/07 09:10:44 | 000,053,340 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
MOD - [2012/12/07 09:10:44 | 000,041,080 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll
MOD - [2012/12/07 09:10:44 | 000,030,720 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll
MOD - [2012/12/07 09:10:44 | 000,028,774 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
MOD - [2012/12/07 09:10:44 | 000,024,694 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\c344fd5536724b2af2e6453833b60203\SHA1.dll

MOD - [2012/12/07 09:10:44 | 000,024,679 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
MOD - [2012/12/07 09:10:44 | 000,020,592 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\b979ace6da01e63d651cce9ee2474fdc\Name.dll
MOD - [2012/12/07 09:10:44 | 000,020,590 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll
MOD - [2012/12/07 09:10:43 | 000,090,213 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll
MOD - [2012/12/07 09:10:42 | 000,028,779 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
MOD - [2012/12/07 09:10:42 | 000,024,681 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\c199d3c1960e7aeeecb599487952bed2\HiRes.dll
MOD - [2012/12/07 09:10:42 | 000,020,601 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\4461f48e31bde5c56b31b973b773de09\List.dll
MOD - [2012/12/07 09:10:41 | 000,118,918 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
MOD - [2012/12/07 09:10:41 | 000,082,048 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
MOD - [2012/12/07 09:10:41 | 000,082,033 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
MOD - [2012/12/07 09:10:41 | 000,020,590 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
MOD - [2012/12/07 09:10:40 | 000,061,540 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\e56c61f7248672819579325af3387035\POSIX.dll
MOD - [2012/12/07 09:10:39 | 000,024,676 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
MOD - [2012/12/07 09:10:38 | 000,036,964 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\f233f63b6654362865c7577442edb9e3\Win32.dll
MOD - [2012/12/07 09:10:38 | 000,020,576 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
MOD - [2012/12/07 09:10:36 | 000,001,024 | R--- | M] () -- C:\WINDOWS\Temp\pdk-SYSTEM-1352\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll
MOD - [2012/12/02 17:18:30 | 000,521,728 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00003_002\ashttpdsp.mdl
MOD - [2012/12/02 17:18:27 | 001,949,696 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00003_002\ashttpph.mdl
MOD - [2012/12/02 17:18:02 | 000,961,536 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00003_002\ashttprbl.mdl
MOD - [2012/12/02 17:17:47 | 000,638,976 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00003_002\ashttpbr.mdl
MOD - [2012/11/24 00:17:52 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll
MOD - [2012/11/24 00:14:12 | 007,977,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll
MOD - [2012/11/24 00:13:55 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll
MOD - [2012/11/07 20:08:02 | 000,004,608 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\ui\imsecurityal.ui
MOD - [2012/11/07 20:08:00 | 000,003,072 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\ui\accessl.ui
MOD - [2012/11/02 14:15:23 | 000,099,304 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\imsecurityal.dll
MOD - [2012/11/02 13:54:03 | 000,203,840 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\txmlutil.dll
MOD - [2012/09/07 17:09:26 | 000,394,408 | ---- | M] () -- \\?\C:\Program Files\Common Files\Bitdefender\Bitdefender Threat Scanner\trufos.dll
MOD - [2009/12/23 17:16:26 | 000,135,168 | ---- | M] () -- C:\Program Files\Philips\GoGear VIBE Device Manager\Scsi_nt.dll
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~


lilhurricane
So mote it be
Premium,Mod
join:2003-01-11
Purple Zone
kudos:54
Reviews:
·Comcast
Host:
TV over IP
Software
RCN
Inside Insight
Cellphones, Provid..

MOD - [2007/09/20 18:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/06/27 15:21:20 | 000,086,016 | ---- | M] () -- F:\Downloads\Free Download Manager\FUM\fumshext.dll
MOD - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2006/10/20 13:41:46 | 000,131,072 | ---- | M] () -- C:\WINDOWS\system32\dlcfjswr.dll
MOD - [2006/10/20 13:35:36 | 000,434,176 | ---- | M] () -- C:\WINDOWS\system32\dlcfutil.dll
MOD - [2005/09/30 08:00:54 | 000,741,376 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfprp.dll
MOD - [2005/08/26 07:43:48 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcfcfg.dll

[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EasyBoxApache)
SRV - [2012/12/07 13:41:02 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/05 10:35:24 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/11/02 17:01:07 | 001,343,032 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe -- (VSSERV)
SRV - [2012/11/02 14:12:38 | 000,055,544 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe -- (UPDATESRV)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/14 04:49:48 | 014,057,569 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Squeezebox\server\SqueezeSvr.exe -- (squeezesvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/17 18:21:24 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\WINDOWS\system32\snmvtsvc.exe -- (SMServer)
SRV - [2008/11/19 15:30:07 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2006/11/01 22:15:50 | 000,537,480 | ---- | M] ( ) [On_Demand | Running] -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device)

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~


Tuesday, 09-Apr 00:34:47 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics