• WELCOME
Welcome to the Myantispyware - free site offering help and assistance on spyware, malware and adware removal. As a guest you can only browse and view the various topics in the forums, but can not create a new topic and reply to an existing topic. If you are seeking help, you will need to be a logged into the forums with a registered account. Registering is free.
Click here to Create a free account and read How to use Spyware Removal Forum

Windows Repair

Moderator: Moderators

Re: Windows Repair

Postby stephuk » Tue Apr 12, 2011 8:20 am

Extra.txt


OTL Extras logfile created on: 12/04/2011 09:11:27 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Lee & Steph\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 86.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.15 Gb Total Space | 34.91 Gb Free Space | 25.09% Space Free | Partition Type: NTFS
Drive D: | 142.94 Gb Total Space | 13.96 Gb Free Space | 9.77% Space Free | Partition Type: NTFS

Computer Name: LEESTEPH-PC | User Name: Lee & Steph | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1098D0CE-36F6-49EB-94E9-75CBC85985FC}" = rport=137 | protocol=17 | dir=out | app=system |
"{1B78DDA0-39EC-4394-9F75-279E2CE11E1B}" = rport=445 | protocol=6 | dir=out | app=system |
"{226BB756-6098-4AD6-B57E-AB02ECD8CDA6}" = rport=138 | protocol=17 | dir=out | app=system |
"{307D40F3-8FA2-4C6C-9E5D-921D10266DD2}" = lport=137 | protocol=17 | dir=in | app=system |
"{316201CB-598F-42B3-B1DB-BB552866D7D7}" = rport=139 | protocol=6 | dir=out | app=system |
"{318E59D8-AAE0-47FF-BBAB-FC8794A042EC}" = lport=138 | protocol=17 | dir=in | app=system |
"{4D764C66-078E-4B05-AC5A-D25AF18496DA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{774A96EA-8E24-4D43-8A2C-9E3C3698D39B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{79719305-B695-4450-BFFD-F9710A8C60E8}" = lport=139 | protocol=6 | dir=in | app=system |
"{8C6ADF9C-C1F9-43A7-99AC-CDC36FE645BB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A5D45A14-A94C-4578-ACC7-27DC47E58D4C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B09B4E88-44E7-4F64-9455-FB4F21D10374}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C5A8516A-5D46-4B0D-BD1F-A9E7C79F8B81}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CA71AE05-A0DE-44B7-A533-AF45A07E77C2}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{060A942A-56D6-49DC-9247-8CBBAA065E8E}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{10C0EEFA-1216-401D-B580-095802BB4A43}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{12C259D4-FA36-42D0-82DB-8D5DA2A050B7}" = dir=in | app=c:\program files\acer arcade live\acer dvdivine\acer dvdivine.exe |
"{19015384-51B3-42A7-B006-5A2B576E33DA}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{1C1B88C5-9F1A-4729-B43A-369E0256A953}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1D589C76-DE30-420D-9AE8-494A8834954E}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{243FFA08-5426-4F5B-94BF-3945D214DD96}" = dir=in | app=c:\program files\acer arcade live\acer dv magician\acer dv magician.exe |
"{27599BCC-45B2-4BCD-B02B-D52F4B5715B3}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{285A10C2-1C7E-4224-B813-8899F65ABD3B}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{3C996F5F-2994-490B-A2DF-DB4CFC3E5FA9}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{3DE7BDE3-9042-4D2C-9903-48B623428F91}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{48720387-B656-4267-83EA-182171F7192A}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{4ED16562-0615-48B1-AC8E-05BC3A23E135}" = dir=in | app=c:\program files\acer arcade live\acer homemedia\acer homemedia.exe |
"{5030AF3F-9B85-463E-8860-AA430AE31836}" = protocol=6 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{54A581F5-1AA6-4F2C-BA5F-6EB34A8043A4}" = dir=in | app=c:\program files\acer arcade live\acer playmovie\playmovie.exe |
"{552DF5E7-437C-463E-BFA2-300B5418564D}" = dir=in | app=c:\program files\acer arcade live\acer playmovie\pmvservice.exe |
"{571FB9A8-1B31-45CA-AE76-B72FD6C8EC1C}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{5A76F22C-EB9B-487C-A7D3-FAB25E8503BD}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgam.exe |
"{5E83A1B2-0380-45D8-B6A4-8CE998513DBA}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{6F0465EC-05B2-4DFB-8B8E-653B60514E71}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{743EA48C-C01F-4597-9052-06834043091D}" = dir=in | app=c:\program files\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{79DB0F0F-A985-48A9-AECA-A9092A5A898C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7D07127C-6E08-4080-A37C-E6BCCBD40345}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{7D1C7229-5FB7-40F8-853A-7E7C19CFD5C5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{868EF96B-B5BA-4044-8F15-855778276C94}" = protocol=17 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{8E1BAA82-0FB4-4E88-B230-0B11F6561A7A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{93B185C8-00E2-49E1-8BF1-6402972DE2FC}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{95CA98DF-615B-42AC-A4A6-1E55EFC6FE3E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{97414256-6445-4A9B-BC74-408604FAB17C}" = dir=in | app=c:\program files\acer arcade live\acer videomagician\acer videomagician.exe |
"{9D2C7317-7C57-47E2-865E-D9AD3D207CC0}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{9FCC05F8-BB81-4081-A1F7-41BE16EB7687}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A2E36676-EDED-4A8D-9F3E-8098AFB6529F}" = dir=in | app=c:\program files\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe |
"{A35A5E06-5EA8-4FA2-AB82-3F99591BBF11}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{A7687185-2F7C-4D04-8096-028BBE5B8CB1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B4A3B392-B908-464C-BFC2-0C417FAA70D9}" = dir=in | app=c:\program files\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe |
"{C8EFC0E8-3206-44C5-9706-416C5B4429FA}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{CE536BB4-6C63-46F7-83E4-F6F5DE5E87A5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D3692F7A-3336-4A52-9AC8-D45490E3EB8A}" = dir=in | app=c:\program files\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{E183FBCF-E24B-487D-97D9-D6A92C780A2C}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{E1E01B63-F1FB-4B36-BA30-CDB10E548CEC}" = dir=in | app=c:\program files\acer arcade live\acer homemedia connect\acer homemedia connect.exe |
"{E99863A1-FF1C-4876-97D8-2D91422C9950}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{ED589C39-92E5-455D-9BA2-7DC7683F4F47}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgam.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B0098FF-1816-4F42-8203-FA29F5735596}" = Samsung PC Studio 3
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 15
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2CFE4799-CB85-456C-AABE-9BA2D02D81DB}" = Sky Broadband
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4B41AE13-BA0E-4328-8E83-AD2A0BEB33EB}" = Sky Player
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{582E9125-32B6-4CBA-AB48-3E33CE3DB389}" = NETGEAR RangeMax(TM) Wireless USB 2.0 Adapter WPN111
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{6003F12D-6DAF-4C3F-9FFA-F4A721DC6BBF}" = AVG 2011
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7C977DE7-EC85-46E1-A7D9-52C04EB52AE6}" = S2 Mobile Modem
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{919955B0-50EB-45DD-9165-C3BCFBF6B2D1}" = S2 PCSync
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A450831D-25F6-4F42-9662-D000B25E0D82}" = Acer PlayMovie
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B580C409-E16F-44FF-904D-3AE94E113BE0}" = Acer HomeMedia Trial Creator
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4
"{D4E53304-1F6C-4111-9872-1BCD2CF5B642}" = AVG 2011
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F429ED71-4A8B-457A-85E4-F6398CE73E58}" = AV Input Selection
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"525B631E25DA7D8F03CAFCB6E66A95DA0F0B57CB" = Windows Driver Package - Amoi Incorporated (S2usbser) Ports (01/01/2007 2.0.5.0)
"Acer GameZone Console_is1" = Acer GameZone Console DTV 2.0.1.1
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.8
"Any Audio Converter_is1" = Any Audio Converter 2.0.3
"AVG" = AVG 2011
"Coupon Printer2.0" = Coupon Printer
"DVDStyler_is1" = DVDStyler v1.7.2
"EB8470242F68F946AB0A751A9E60217725DCA27F" = Windows Driver Package - Amoi Incorporated (S2usbser) Modem (01/01/2007 2.0.5.0)
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"JDownloader" = JDownloader
"Magic DVD Copier_is1" = Magic DVD Copier Version 4.9.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Rapport_msi" = Rapport
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"TomTom HOME" = TomTom HOME 2.7.6.2056
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26/09/2010 11:36:44 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/09/2010 03:19:43 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/09/2010 04:03:01 | Computer Name = LeeSteph-PC | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 6.0.6000.16386, time stamp
0x4549b0e1, faulting module VSSAPI.DLL, version 6.0.6002.18005, time stamp 0x49e0380a,
exception code 0xc0000006, fault offset 0x0003b2e5, process id 0x16e0, application
start time 0x01cb5e191e2b1286.

Error - 27/09/2010 04:03:01 | Computer Name = LeeSteph-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file C:\Windows\System32\vssapi.dll for
one of the following reasons: there is a problem with the network connection, the
disk that the file is stored on, or the storage drivers installed on this computer;
or the disk is missing. Windows closed the program Windows host process (Rundll32)
because of this error. Program: Windows host process (Rundll32) File: C:\Windows\System32\vssapi.dll

The
error value is listed in the Additional Data section. User Action 1. Open the file
again. This situation might be a temporary problem that corrects itself when the
program runs again. 2. If the file still cannot be accessed and - It is on the network,
your network administrator should verify that there is not a problem with the network
and that the server can be contacted. - It is on a removable disk, for example,
a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3.
Check and repair the file system by running CHKDSK. To run CHKDSK, click Start,
click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F,
and then press ENTER. 4. If the problem persists, restore the file from a backup
copy. 5. Determine whether other files on the same disk can be opened. If not, the
disk might be damaged. If it is a hard disk, contact your administrator or computer
hardware vendor for further assistance. Additional Data Error value: C0000185 Disk
type: 3

Error - 27/09/2010 05:03:00 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/09/2010 10:08:10 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/09/2010 11:51:59 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/09/2010 14:42:49 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 27/09/2010 17:02:44 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

Error - 28/09/2010 08:56:53 | Computer Name = LeeSteph-PC | Source = WinMgmt | ID = 10
Description =

[ OSession Events ]
Error - 13/02/2011 13:47:08 | Computer Name = LeeSteph-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 13/02/2011 13:50:13 | Computer Name = LeeSteph-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 3 seconds with 0 seconds of active time. This session ended with a crash.

Error - 27/03/2011 12:36:16 | Computer Name = LeeSteph-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 12/04/2011 04:12:08 | Computer Name = LeeSteph-PC | Source = Service Control Manager | ID = 7001
Description =


< End of report >
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby stephuk » Tue Apr 12, 2011 1:00 pm

I've tried to uninstall Malwarebytes, thinking maybe now that some of the infections are gone it might work but I couldnt update it "program_error_updating (12007, 0, WinHttp SendRequest) and during the scan it froze on file mfc42u.dll . The desktop wasnt frozen though this time (I could still move the mouse) but after 3 minutes the screen went all black and I had to manually shut down.

It is annoying because it still finds 1 infected object that no other scanners have picked up so far. But maybe you'll be able to work something out with the OTL logs... hopefully!!
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby 12056 » Tue Apr 12, 2011 3:11 pm

Please reopen OTL on your desktop.
Copy and Paste the following code into the "Custom Scans and Fixes" textbox.

Code: Select all
:OTL
SRV - File not found [On_Demand | Stopped] -- -- (McSysmon)
SRV - File not found [Unknown | Stopped] -- -- (McShield)
IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50545
O4 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000..\Run: [conhost] C:\Users\Lee & Steph\AppData\Roaming\Microsoft\conhost.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
[2011/04/07 17:03:49 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Roaming\Okyn
[2011/04/07 17:51:37 | 000,001,984 | -HS- | M] () -- C:\ProgramData\325cq8r6ceko405fg
[2011/04/07 17:51:37 | 000,001,984 | -HS- | M] () -- C:\Users\Lee & Steph\AppData\Local\325cq8r6ceko405fg
[2011/04/12 09:00:18 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/11 10:40:06 | 000,122,236 | ---- | M] () -- C:\Windows\System32\null0.47444498077582653.exe
[2011/04/11 10:40:00 | 000,000,000 | ---- | M] () -- C:\Windows\System32\null0.4357516266332162.exe
[2011/04/10 15:36:12 | 000,001,300 | -HS- | M] () -- C:\Users\Lee & Steph\AppData\Local\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625
[2011/04/10 15:36:12 | 000,001,300 | -HS- | M] () -- C:\ProgramData\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625
[2011/04/10 15:36:07 | 000,001,308 | ---- | M] () -- C:\Users\Lee & Steph\AppData\Roaming\853A.054
[2011/04/09 20:37:57 | 000,011,048 | -HS- | M] () -- C:\Users\Lee & Steph\AppData\Local\545f402g3t77n8y03jgnenvv20
[2011/04/09 20:37:57 | 000,011,048 | -HS- | M] () -- C:\ProgramData\545f402g3t77n8y03jgnenvv20
[2011/04/03 14:18:03 | 000,011,828 | -HS- | M] () -- C:\Users\Lee & Steph\AppData\Local\241s311368gdrya16d3481o43nc8ucw704
[2011/04/03 14:18:03 | 000,011,828 | -HS- | M] () -- C:\ProgramData\241s311368gdrya16d3481o43nc8ucw704
[2011/03/31 21:16:09 | 000,012,050 | -HS- | M] () -- C:\Users\Lee & Steph\AppData\Local\7a3d8u8784tdd04w7i4a1pj
[2011/03/31 21:16:09 | 000,012,050 | -HS- | M] () -- C:\ProgramData\7a3d8u8784tdd04w7i4a1pj
[2011/03/30 19:08:25 | 000,000,144 | ---- | M] () -- C:\ProgramData\~43835144r
[2011/03/30 19:08:25 | 000,000,112 | ---- | M] () -- C:\ProgramData\~43835144
[2011/03/30 18:26:05 | 000,000,336 | ---- | M] () -- C:\ProgramData\43835144
[2011/04/10 15:36:12 | 000,001,300 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625
[2011/04/10 15:36:12 | 000,001,300 | -HS- | C] () -- C:\ProgramData\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625
[2011/04/09 18:39:45 | 000,011,048 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\545f402g3t77n8y03jgnenvv20
[2011/04/09 18:39:45 | 000,011,048 | -HS- | C] () -- C:\ProgramData\545f402g3t77n8y03jgnenvv20
[2011/04/07 17:51:08 | 000,001,984 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\325cq8r6ceko405fg
[2011/04/07 17:51:08 | 000,001,984 | -HS- | C] () -- C:\ProgramData\325cq8r6ceko405fg
[2011/04/02 19:37:59 | 000,011,828 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\241s311368gdrya16d3481o43nc8ucw704
[2011/04/02 19:37:59 | 000,011,828 | -HS- | C] () -- C:\ProgramData\241s311368gdrya16d3481o43nc8ucw704
[2011/03/31 21:14:04 | 000,012,050 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\7a3d8u8784tdd04w7i4a1pj
[2011/03/31 21:14:04 | 000,012,050 | -HS- | C] () -- C:\ProgramData\7a3d8u8784tdd04w7i4a1pj
[2011/03/30 18:26:46 | 000,000,144 | ---- | C] () -- C:\ProgramData\~43835144r
[2011/03/30 18:26:46 | 000,000,112 | ---- | C] () -- C:\ProgramData\~43835144
[2011/03/30 18:26:05 | 000,000,336 | ---- | C] () -- C:\ProgramData\43835144
[2010/10/06 18:14:13 | 000,000,120 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Local\Qqixunoses.dat
[2010/10/06 18:14:13 | 000,000,000 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Local\Xkokomobun.bin
[2010/04/21 16:17:59 | 000,012,622 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\4L05Y3527I
[2010/04/21 16:17:59 | 000,012,622 | -HS- | C] () -- C:\ProgramData\4L05Y3527I
[2010/04/01 11:29:27 | 000,010,616 | -HS- | C] () -- C:\Users\Lee & Steph\AppData\Local\0S70
[2010/04/01 11:29:27 | 000,010,616 | -HS- | C] () -- C:\ProgramData\0S70
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FB1B13D8

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[emptyflash]



Push "Run Fix".
OTL may ask to reboot the machine. Please do so if asked.
A report will open. Copy and Paste that report in your next reply.

Then ZIP the files at: C:\_OTL\ so that I can send them to MalwareBytes for better detection in the future.
My e-mail address is: trappmanrhett@fastmail.fm
Rhett Trappman
MyAntispyware.com Forum Security Team and Moderator
12056
 
Posts: 860
Joined: Sun Apr 25, 2010 9:57 pm

Re: Windows Repair

Postby stephuk » Tue Apr 12, 2011 3:28 pm

Hi, here is the new report from OTL:

========== OTL ==========
Service McSysmon stopped successfully!
Service McSysmon deleted successfully!
Error: No service named McShield was found to stop!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McShield deleted successfully.
HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Microsoft\Windows\CurrentVersion\Run\\conhost deleted successfully.
C:\Users\Lee & Steph\AppData\Roaming\Microsoft\conhost.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08E730A4-FB02-45BD-A900-01E4AD8016F6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08E730A4-FB02-45BD-A900-01E4AD8016F6}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
C:\Users\Lee & Steph\AppData\Roaming\Okyn folder moved successfully.
C:\ProgramData\325cq8r6ceko405fg moved successfully.
C:\Users\Lee & Steph\AppData\Local\325cq8r6ceko405fg moved successfully.
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\Windows\System32\null0.47444498077582653.exe moved successfully.
C:\Windows\System32\null0.4357516266332162.exe moved successfully.
C:\Users\Lee & Steph\AppData\Local\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625 moved successfully.
C:\ProgramData\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625 moved successfully.
C:\Users\Lee & Steph\AppData\Roaming\853A.054 moved successfully.
C:\Users\Lee & Steph\AppData\Local\545f402g3t77n8y03jgnenvv20 moved successfully.
C:\ProgramData\545f402g3t77n8y03jgnenvv20 moved successfully.
C:\Users\Lee & Steph\AppData\Local\241s311368gdrya16d3481o43nc8ucw704 moved successfully.
C:\ProgramData\241s311368gdrya16d3481o43nc8ucw704 moved successfully.
C:\Users\Lee & Steph\AppData\Local\7a3d8u8784tdd04w7i4a1pj moved successfully.
C:\ProgramData\7a3d8u8784tdd04w7i4a1pj moved successfully.
C:\ProgramData\~43835144r moved successfully.
C:\ProgramData\~43835144 moved successfully.
C:\ProgramData\43835144 moved successfully.
File C:\Users\Lee & Steph\AppData\Local\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625 not found.
File C:\ProgramData\ir806823nm0e02u0748c4iw4onj73w34x6m56pw625 not found.
File C:\Users\Lee & Steph\AppData\Local\545f402g3t77n8y03jgnenvv20 not found.
File C:\ProgramData\545f402g3t77n8y03jgnenvv20 not found.
File C:\Users\Lee & Steph\AppData\Local\325cq8r6ceko405fg not found.
File C:\ProgramData\325cq8r6ceko405fg not found.
File C:\Users\Lee & Steph\AppData\Local\241s311368gdrya16d3481o43nc8ucw704 not found.
File C:\ProgramData\241s311368gdrya16d3481o43nc8ucw704 not found.
File C:\Users\Lee & Steph\AppData\Local\7a3d8u8784tdd04w7i4a1pj not found.
File C:\ProgramData\7a3d8u8784tdd04w7i4a1pj not found.
File C:\ProgramData\~43835144r not found.
File C:\ProgramData\~43835144 not found.
File C:\ProgramData\43835144 not found.
C:\Users\Lee & Steph\AppData\Local\Qqixunoses.dat moved successfully.
C:\Users\Lee & Steph\AppData\Local\Xkokomobun.bin moved successfully.
C:\Users\Lee & Steph\AppData\Local\4L05Y3527I moved successfully.
C:\ProgramData\4L05Y3527I moved successfully.
C:\Users\Lee & Steph\AppData\Local\0S70 moved successfully.
C:\ProgramData\0S70 moved successfully.
ADS C:\ProgramData\TEMP:0B4227B4 deleted successfully.
ADS C:\ProgramData\TEMP:FB1B13D8 deleted successfully.

OTL by OldTimer - Version 3.2.22.3 log created on 04122011_161818
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby stephuk » Tue Apr 12, 2011 3:38 pm

I've just restarted the computer in normal mode to see if there were any improvements...

No "select program to open file" dialogue box at start up (at least something good!) but after a couple of minutes the screen went all blue and "crash dump"...
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby stephuk » Tue Apr 12, 2011 9:04 pm

For the random sound clips problem, do u think the following is along the lines of what I would have to do? http://www.techsupportforum.com/forums/ ... 93943.html
do u think the multiple freeze/crash are also all related to this?
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby 12056 » Wed Apr 13, 2011 12:49 am

Please post me a fresh OTL, the analysts are still working on the new samples...
Will let you know, when a signature update is available.
Rhett Trappman
MyAntispyware.com Forum Security Team and Moderator
12056
 
Posts: 860
Joined: Sun Apr 25, 2010 9:57 pm

Re: Windows Repair

Postby stephuk » Wed Apr 13, 2011 8:40 am

Here is the new OTL log. Thanks for everything you're doing to help me:)

OTL logfile created on: 13/04/2011 09:27:32 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Lee & Steph\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 86.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.15 Gb Total Space | 34.97 Gb Free Space | 25.14% Space Free | Partition Type: NTFS
Drive D: | 142.94 Gb Total Space | 13.96 Gb Free Space | 9.77% Space Free | Partition Type: NTFS

Computer Name: LEESTEPH-PC | User Name: Lee & Steph | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/12 09:04:18 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Lee & Steph\Desktop\OTL.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/01/21 03:24:02 | 000,498,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\HelpPane.exe


========== Modules (SafeList) ==========

MOD - [2011/04/12 09:04:18 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Lee & Steph\Desktop\OTL.exe
MOD - [2010/08/31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/03/18 08:11:02 | 000,947,528 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2011/02/15 05:38:06 | 007,421,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2011/02/08 05:33:40 | 002,707,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG10\avgfws.exe -- (avgfws)
SRV - [2010/10/03 23:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) [Auto | Stopped] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/08/24 10:38:18 | 000,092,008 | ---- | M] (TomTom) [Auto | Stopped] -- C:\Program Files\TomTom HOME\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/01/02 13:05:42 | 003,098,152 | ---- | M] (Kontiki Inc.) [Auto | Stopped] -- C:\Program Files\Kontiki\KService.exe -- (KService)
SRV - [2008/04/25 21:30:26 | 000,024,576 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService)
SRV - [2008/03/05 07:38:34 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Stopped] -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service)
SRV - [2008/01/29 20:25:10 | 000,598,016 | ---- | M] () [Auto | Stopped] -- C:\Program Files\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2008/01/29 20:24:46 | 000,163,840 | ---- | M] () [Auto | Stopped] -- C:\Program Files\bin32\nSvcIp.exe -- (nSvcIp)
SRV - [2008/01/26 02:49:04 | 000,269,448 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -- (Acer HomeMedia Connect Service)


========== Driver Services (SafeList) ==========

DRV - [2011/04/09 18:31:15 | 000,056,888 | ---- | M] (Trusteer Ltd.) [Kernel | System | Stopped] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\25641\RapportCerberus_25641.sys -- (RapportCerberus_25641)
DRV - [2011/03/30 17:16:52 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/03/01 14:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 08:12:38 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/10 07:54:00 | 000,296,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/02/10 07:53:30 | 000,028,624 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 07:53:28 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/19 04:32:56 | 000,032,464 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/01/07 06:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/10/03 23:43:44 | 000,169,320 | ---- | M] (Trusteer Ltd.) [Kernel | System | Stopped] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/10/03 23:43:44 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2010/07/12 04:34:02 | 000,054,112 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avgfwd6x.sys -- (Avgfwfd)
DRV - [2010/06/27 15:07:12 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/13 14:31:23 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010/03/13 14:31:22 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/02/27 11:18:51 | 000,390,528 | ---- | M] (Trusteer Ltd.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\RapportBuka.sys -- (RapportBuka)
DRV - [2010/01/12 12:03:34 | 011,586,280 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/09/14 11:31:48 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/02/27 11:46:24] [Kernel | Auto | Stopped] -- C:\Program Files\Acer Arcade Live\Acer PlayMovie\000.fcl -- ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796})
DRV - [2009/09/02 19:27:45 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2008/09/29 17:12:04 | 000,012,832 | ---- | M] (Acer, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\int15.sys -- (int15)
DRV - [2008/04/22 01:49:00 | 000,043,552 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008/03/20 05:11:52 | 000,103,680 | ---- | M] (AMOI Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\S2usbser.sys -- (S2usbser)
DRV - [2008/01/29 06:55:00 | 001,042,464 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008/01/25 13:02:02 | 000,140,832 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2007/10/12 09:53:10 | 000,013,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2007/05/02 11:11:18 | 000,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2007/05/02 11:11:18 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2007/05/02 11:11:16 | 000,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2007/02/03 10:32:36 | 000,041,504 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/02/03 10:25:56 | 001,075,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Camdrl.sys -- (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
DRV - [2006/11/16 14:36:28 | 000,020,480 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DNISP50.sys -- (DNISp50)
DRV - [2006/11/16 14:36:18 | 000,021,504 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DNIMP50.sys -- (DNIMp50)
DRV - [2005/09/05 11:21:06 | 000,362,944 | ---- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WG11TND5.sys -- (AR5523)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.uk.acer.yahoo.com


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?ocid=getmsn
IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: MapShare-status@tomtom.com:1.7
FF - prefs.js..extensions.enabledItems: baseTheme@tomtom.com:1.0.2

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/10 15:28:26 | 000,000,000 | ---D | M]

[2009/07/24 12:49:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lee & Steph\AppData\Roaming\Mozilla\Extensions
[2009/07/24 12:49:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lee & Steph\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
[2010/10/06 18:32:06 | 000,000,000 | ---D | M] (Map status indicator) -- C:\PROGRAM FILES\TOMTOM HOME\XUL\EXTENSIONS\MAPSHARE-STATUS@TOMTOM.COM

O1 HOSTS File: ([2011/04/10 09:30:50 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [EmpoweringTechnology] File not found
O4 - HKLM..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\nvLsp.dll (NVIDIA)
O15 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-2900729692-2678787737-2178929654-1000\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/200 ... oader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resourc ... dfr-fr.cab (MSN Photo Upload Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/ph ... dfr-fr.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.165.172,93.188.160.232
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Lee & Steph\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lee & Steph\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/12 16:18:18 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/04/12 13:42:51 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/12 13:42:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/12 13:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/12 13:41:32 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{3338E5F6-9A41-4755-A93F-6C5D5845E38F}
[2011/04/12 09:06:05 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Lee & Steph\Desktop\OTL.exe
[2011/04/12 09:05:21 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{E8B1668D-82DC-4467-B326-2D386D99C98B}
[2011/04/11 17:36:59 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Roaming\AVG
[2011/04/11 17:35:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2011/04/11 17:35:01 | 007,592,248 | ---- | C] (AVG ) -- C:\Users\Lee & Steph\Desktop\avg_pct_stf_all_2011_24_c5.exe
[2011/04/11 17:00:34 | 012,502,472 | ---- | C] (Microsoft Corporation) -- C:\Users\Lee & Steph\Desktop\windows-kb890830-v3.17.exe
[2011/04/11 09:36:57 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{1F2157AA-01A4-4ACD-90CC-F01E269CA3B5}
[2011/04/10 20:08:53 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/04/10 15:29:57 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Roaming\AVG10
[2011/04/10 15:28:55 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/04/10 15:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar
[2011/04/10 15:28:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2011
[2011/04/10 15:26:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG
[2011/04/10 15:26:42 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2011/04/10 15:25:35 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/04/10 14:00:59 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/04/10 14:00:34 | 005,497,592 | ---- | C] (AVG Technologies) -- C:\Users\Lee & Steph\Desktop\avg_free_stb_all_2011_1321_cnet.exe
[2011/04/10 09:30:52 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011/04/10 09:30:30 | 000,000,000 | --SD | C] -- C:\Windows\System32\Microsoft
[2011/04/10 09:29:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/04/10 09:21:30 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/04/10 09:15:47 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{1323F1E6-766D-4D5C-9F89-A11DFE5776FE}
[2011/04/09 21:04:24 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\Desktop\fixshell
[2011/04/09 18:32:45 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{3D1DB50A-0A29-4553-B417-69945051DBCA}
[2011/04/07 17:38:27 | 000,566,272 | ---- | C] (AVAST Software) -- C:\Users\Lee & Steph\Desktop\aswMBR.exe
[2011/04/07 17:38:27 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\Lee & Steph\Desktop\TFC.exe
[2011/04/06 18:10:06 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{139499EC-8634-49F4-98A5-0F902EB39F85}
[2011/04/03 14:27:27 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/04/03 14:27:27 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/04/03 14:27:27 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/04/03 14:27:21 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/04/03 14:27:11 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/03 14:23:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2011/04/03 14:23:19 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/04/03 14:23:11 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Users\Lee & Steph\Desktop\HJTInstall.exe
[2011/03/31 21:11:13 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{7BE2E80F-61A7-440E-A0D7-0C7917860E14}
[2011/03/31 17:03:31 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Roaming\Malwarebytes
[2011/03/31 17:03:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/03/31 17:02:45 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Lee & Steph\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/31 16:28:27 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Lee & Steph\Desktop\HiJackThis.exe
[2011/03/30 18:26:21 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
[2011/03/30 17:16:52 | 000,134,480 | ---- | C] (AVG Technologies CZ, s.r.o. ) -- C:\Windows\System32\drivers\AVGIDSDriver.sys
[2011/03/27 17:14:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011/03/23 17:26:28 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011/03/23 17:26:28 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011/03/15 17:39:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/03/15 17:38:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/03/15 17:38:30 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/03/15 17:35:17 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/03/14 19:22:48 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Roaming\gtk-2.0
[2011/03/14 19:22:38 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\.thumbnails
[2011/03/14 19:00:24 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\.gimp-2.6
[2011/03/14 19:00:23 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\Documents\gegl-0.0
[2011/03/14 19:00:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2011/03/14 18:59:59 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2010/03/24 17:42:46 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Lee & Steph\AppData\Roaming\pcouffin.sys
[2008/07/22 09:01:25 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll

========== Files - Modified Within 30 Days ==========

[2011/04/13 09:26:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/12 17:08:24 | 112,233,269 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2011/04/12 17:03:18 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/12 17:03:03 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/12 17:03:02 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/12 17:03:01 | 000,035,465 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/04/12 17:02:48 | 336,600,742 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/04/12 16:20:33 | 000,727,486 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/04/12 16:20:33 | 000,166,798 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/04/12 13:42:51 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/12 13:33:54 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Lee & Steph\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/12 09:04:18 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Lee & Steph\Desktop\OTL.exe
[2011/04/11 18:27:28 | 000,008,592 | ---- | M] () -- C:\Users\Lee & Steph\AppData\Local\d3d9caps.dat
[2011/04/11 17:35:51 | 000,000,974 | ---- | M] () -- C:\Users\Lee & Steph\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/11 17:30:38 | 007,592,248 | ---- | M] (AVG ) -- C:\Users\Lee & Steph\Desktop\avg_pct_stf_all_2011_24_c5.exe
[2011/04/11 17:00:06 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/11 16:58:48 | 012,502,472 | ---- | M] (Microsoft Corporation) -- C:\Users\Lee & Steph\Desktop\windows-kb890830-v3.17.exe
[2011/04/10 15:37:03 | 000,649,963 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavifw.avm
[2011/04/10 15:28:30 | 000,000,834 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/04/10 12:56:32 | 005,497,592 | ---- | M] (AVG Technologies) -- C:\Users\Lee & Steph\Desktop\avg_free_stb_all_2011_1321_cnet.exe
[2011/04/10 09:30:50 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/04/09 20:59:42 | 000,026,176 | ---- | M] () -- C:\Users\Lee & Steph\Desktop\fixshell.zip
[2011/04/09 19:56:38 | 001,006,778 | ---- | M] () -- C:\Users\Lee & Steph\Desktop\rkill.com
[2011/04/09 19:55:50 | 000,001,134 | ---- | M] () -- C:\Users\Lee & Steph\Desktop\FixNCR.reg
[2011/04/09 08:37:58 | 004,317,112 | R--- | M] () -- C:\Users\Lee & Steph\Desktop\ComboFix.exe
[2011/04/07 17:48:21 | 000,000,512 | ---- | M] () -- C:\Users\Lee & Steph\Documents\MBR.dat
[2011/04/07 17:18:42 | 000,566,272 | ---- | M] (AVAST Software) -- C:\Users\Lee & Steph\Desktop\aswMBR.exe
[2011/04/07 17:18:06 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\Lee & Steph\Desktop\TFC.exe
[2011/04/03 14:23:20 | 000,001,878 | ---- | M] () -- C:\Users\Lee & Steph\Desktop\HijackThis.lnk
[2011/04/03 14:10:28 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Users\Lee & Steph\Desktop\HJTInstall.exe
[2011/03/31 16:28:30 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Lee & Steph\Desktop\HiJackThis.exe
[2011/03/30 18:01:00 | 000,035,465 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/03/30 17:16:52 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\Windows\System32\drivers\AVGIDSDriver.sys
[2011/03/26 17:23:56 | 000,004,724 | ---- | M] () -- C:\Users\Lee & Steph\.recently-used.xbel
[2011/03/26 11:02:17 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/03/15 17:39:10 | 000,001,668 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/03/14 19:00:16 | 000,000,904 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk

========== Files Created - No Company Name ==========

[2011/04/12 17:08:24 | 112,233,269 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2011/04/12 16:33:29 | 000,003,216 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/12 13:42:51 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/11 17:35:51 | 000,000,974 | ---- | C] () -- C:\Users\Lee & Steph\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/10 15:37:03 | 000,649,963 | ---- | C] () -- C:\Windows\System32\drivers\AVG\iavifw.avm
[2011/04/10 15:28:30 | 000,000,834 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/04/09 21:03:50 | 000,026,176 | ---- | C] () -- C:\Users\Lee & Steph\Desktop\fixshell.zip
[2011/04/09 20:05:39 | 000,001,134 | ---- | C] () -- C:\Users\Lee & Steph\Desktop\FixNCR.reg
[2011/04/09 09:00:51 | 004,317,112 | R--- | C] () -- C:\Users\Lee & Steph\Desktop\ComboFix.exe
[2011/04/07 17:47:43 | 000,000,512 | ---- | C] () -- C:\Users\Lee & Steph\Documents\MBR.dat
[2011/04/03 14:27:27 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/04/03 14:27:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/04/03 14:27:27 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/04/03 14:27:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/04/03 14:27:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/04/03 14:23:20 | 000,001,878 | ---- | C] () -- C:\Users\Lee & Steph\Desktop\HijackThis.lnk
[2011/03/31 16:52:50 | 001,006,778 | ---- | C] () -- C:\Users\Lee & Steph\Desktop\rkill.com
[2011/03/26 17:23:56 | 000,004,724 | ---- | C] () -- C:\Users\Lee & Steph\.recently-used.xbel
[2011/03/15 17:39:10 | 000,001,668 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/03/14 19:00:16 | 000,000,904 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010/04/17 11:30:26 | 000,035,465 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/04/17 11:30:24 | 000,035,465 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2010/03/24 17:42:46 | 000,087,608 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\inst.exe
[2010/03/24 17:42:46 | 000,007,887 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\pcouffin.cat
[2010/03/24 17:42:46 | 000,001,144 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\pcouffin.inf
[2010/03/21 15:44:42 | 000,000,107 | ---- | C] () -- C:\Windows\IfoEdit.INI
[2010/01/30 18:09:19 | 000,000,023 | ---- | C] () -- C:\Windows\System32\PCSuiteConfigFile.ini
[2010/01/30 18:09:19 | 000,000,000 | ---- | C] () -- C:\Windows\System32\PCSuiteShareFile.ini
[2010/01/30 18:09:19 | 000,000,000 | ---- | C] () -- C:\Windows\System32\PCSuiteParamFile.ini
[2010/01/28 18:03:39 | 000,000,000 | ---- | C] () -- C:\Windows\JCMKR32.INI
[2010/01/19 17:30:53 | 000,124,516 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2009/12/08 21:24:24 | 000,000,031 | ---- | C] () -- C:\Windows\UKCpInfo.sys
[2009/10/20 18:30:34 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/10/20 18:30:34 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/10/17 17:00:02 | 000,000,783 | ---- | C] () -- C:\Windows\NTIWVEDT.INI
[2009/09/02 20:40:25 | 000,001,038 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\filterclsid.dat
[2009/09/02 19:29:57 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2009/09/02 19:17:07 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/05/27 10:48:43 | 000,000,235 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\devices.xml
[2009/05/27 10:48:43 | 000,000,012 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\settings.xml
[2009/05/27 10:25:09 | 000,016,622 | ---- | C] () -- C:\Windows\hpomdl01.dat
[2009/05/26 13:17:12 | 000,000,268 | R--- | C] () -- C:\ProgramData\Importer
[2009/05/26 13:17:12 | 000,000,268 | R--- | C] () -- C:\Users\Lee & Steph\AppData\Roaming\Image Capture
[2009/05/26 13:17:12 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2009/05/05 18:14:56 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/05/04 10:49:06 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/05/03 09:38:46 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/02 21:39:18 | 000,141,312 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/02 20:10:35 | 000,651,264 | ---- | C] () -- C:\Windows\System32\libeay32.dll
[2009/05/02 20:10:35 | 000,192,512 | R--- | C] () -- C:\Windows\System32\AegisI5.exe
[2009/05/02 20:10:35 | 000,149,392 | ---- | C] () -- C:\Windows\System32\drivers\ar5523.bin
[2009/05/02 20:10:35 | 000,147,456 | ---- | C] () -- C:\Windows\System32\ssleay32.dll
[2009/05/02 19:38:20 | 000,008,592 | ---- | C] () -- C:\Users\Lee & Steph\AppData\Local\d3d9caps.dat
[2008/04/30 19:33:11 | 000,001,024 | R--- | C] () -- C:\Windows\System32\NTIOFM4.dll
[2008/04/30 19:33:11 | 000,001,024 | R--- | C] () -- C:\Windows\System32\NTIBUN5.dll
[2008/04/30 19:03:09 | 000,487,424 | ---- | C] () -- C:\Windows\System32\INT15.dll
[2008/04/30 18:53:50 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini
[2008/04/30 18:53:50 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2008/04/30 18:53:50 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat
[2008/04/30 18:41:55 | 000,003,948 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2007/02/03 08:59:04 | 000,050,127 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2006/11/02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,298,040 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,727,486 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,166,798 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/10/11 08:38:13 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2006/10/11 08:38:12 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2003/04/05 13:33:26 | 000,020,475 | ---- | C] () -- C:\Windows\hpoins01.dat
[2001/12/27 00:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 07:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/31 00:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 06:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby 12056 » Wed Apr 13, 2011 11:11 am

In the same way, try:

Code: Select all
:OTL
[2011/04/12 13:41:32 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{3338E5F6-9A41-4755-A93F-6C5D5845E38F}
[2011/04/12 09:05:21 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{E8B1668D-82DC-4467-B326-2D386D99C98B}
[2011/04/11 09:36:57 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{1F2157AA-01A4-4ACD-90CC-F01E269CA3B5}
[2011/04/10 09:15:47 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{1323F1E6-766D-4D5C-9F89-A11DFE5776FE}
[2011/04/09 18:32:45 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{3D1DB50A-0A29-4553-B417-69945051DBCA}
[2011/04/06 18:10:06 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{139499EC-8634-49F4-98A5-0F902EB39F85}
[2011/03/31 21:11:13 | 000,000,000 | ---D | C] -- C:\Users\Lee & Steph\AppData\Local\{7BE2E80F-61A7-440E-A0D7-0C7917860E14}
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4

:Commands
[emptytemp]
[purity]

Rhett Trappman
MyAntispyware.com Forum Security Team and Moderator
12056
 
Posts: 860
Joined: Sun Apr 25, 2010 9:57 pm

Postby stephuk » Wed Apr 13, 2011 11:49 am

Thanks. I've ran custom fix in OTL with the code u submited. It asked for reboot but theres no log appearing after restart. Is this normal?

Gonna re-start in normal mode now to see how it behaves.


Just restarted in normal mode. A dialogue window appeared saying that unauthorized changes have been made to Windows and asked for my Windows Activation Code. It said that activation was complete but my desktop was all black and "not genuine version of Windows" written bottom right. It then froze and went all black. Manual shut down.

Restart - desktop still black (without background) but it doesnt say "not genuine" anymore.

I've launched the internet and the following dialog box came up (please see attachement) - I'm sorry but I dont really know if I'm supposed to allow or not...

The machine is still very noisy I think (fan..)


Waiting for further instructions now - thanks!!


PS- When I closed the browser, there was a script error window (same url as before www2aglam or something like that - I've googled the url ann by the results it looks like other people are suffering with this malware)
As I said before, the error message at startup (choose program to open file) has disappeared :)
When I had the internet browser open, I didnt go onto any websites (apart from my homepage) but I've left the History tab open and could see random websites adding themselves up and piling up in the list!! Grrr!)







Whilst I'm waiting I decided to try on with Malwarebytes another time (with the changes made to Windows maybe it would work?) - same as usual: found 1 object infected, then froze.

Done a scan with AVG in safe mode - computer crashed before the end but it found 2 new Trojan (see log below)

Had another go with Malwarebytes, thinking maybe one of the Trojan AVG found is the infected object Malwarebytes usually picks up but no - still found 1 object infected then froze.

It's mad that I havent managed to do a complete scan with Malwarebytes, SuperAntiSpyware or even AVG...

AVG 2011 Anti-Virus command line scanner
Copyright (c) 1992 - 2011 AVG Technologies
Program version 10.0.1321, engine 10.0.1500
Virus Database: Version 1500/3571 2011-04-13

C:\Boot\BCD Locked file. Not tested.
C:\Boot\BCD.LOG Locked file. Not tested.
C:\Documents and Settings\ Locked file. Not tested.
C:\pagefile.sys Locked file. Not tested.
C:\ProgramData\Desktop\ Locked file. Not tested.
C:\ProgramData\Documents\ Locked file. Not tested.
C:\ProgramData\Favorites\ Locked file. Not tested.
C:\ProgramData\Templates\ Locked file. Not tested.
C:\Qoobox\BackEnv\ Locked file. Not tested.
C:\Qoobox\Quarantine\C\Windows\System32\spool\prtprocs\w32x86\xU9m17wS.dll.vir Trojan horse SHeur3.BUCS Object was moved to Virus Vault.
C:\System Volume Information\SystemRestore\System Volume Information\ Locked file. Not tested.
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} Locked file. Not tested.
C:\System Volume Information\{8fab7a10-634a-11e0-aa62-001d72af24f6}{3808876b-c176-4e48-b7ae-04046e6cc752} Locked file. Not tested.
C:\System Volume Information\{da90b6a4-6379-11e0-b405-00146c5bddf6}{3808876b-c176-4e48-b7ae-04046e6cc752} Locked file. Not tested.
C:\System Volume Information\{da90b6b0-6379-11e0-b405-00146c5bddf6}{3808876b-c176-4e48-b7ae-04046e6cc752} Locked file. Not tested.
C:\Users\Default\AppData\Local\History\ Locked file. Not tested.
C:\Users\Default\AppData\Local\Temporary Internet Files\ Locked file. Not tested.
C:\Users\Default\Documents\My Music\ Locked file. Not tested.
C:\Users\Default\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Default\Documents\My Videos\ Locked file. Not tested.
C:\Users\Default\NetHood\ Locked file. Not tested.
C:\Users\Default\PrintHood\ Locked file. Not tested.
C:\Users\Default\Recent\ Locked file. Not tested.
C:\Users\Default\Templates\ Locked file. Not tested.
C:\Users\Lee & Steph\AppData\Local\History\ Locked file. Not tested.
C:\Users\Lee & Steph\AppData\Local\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Users\Lee & Steph\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Locked file. Not tested.
C:\Users\Lee & Steph\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Locked file. Not tested.
C:\Users\Lee & Steph\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp Trojan horse Downloader.Agent2.ADLK Object was moved to Virus Vault.
C:\Users\Lee & Steph\Documents\My Music\ Locked file. Not tested.
C:\Users\Lee & Steph\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Lee & Steph\Documents\My Videos\ Locked file. Not tested.
C:\Users\Lee & Steph\NetHood\ Locked file. Not tested.
C:\Users\Lee & Steph\ntuser.dat Locked file. Not tested.
C:\Users\Lee & Steph\ntuser.dat.LOG1 Locked file. Not tested.
C:\Users\Lee & Steph\ntuser.dat.LOG2 Locked file. Not tested.
C:\Users\Lee & Steph\PrintHood\ Locked file. Not tested.
C:\Users\Public\Documents\My Music\ Locked file. Not tested.
C:\Users\Public\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Public\Documents\My Videos\ Locked file. Not tested.
You do not have the required permissions to view the files attached to this post.
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby 12056 » Thu Apr 14, 2011 2:53 pm

You can go ahead and allow the firewall entry, it's part of Microsoft...

Download TDSSKiller and save it to your Desktop.
Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.

Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

Code: Select all
"%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v



If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
If prompted to reboot, please do so.
When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here
Rhett Trappman
MyAntispyware.com Forum Security Team and Moderator
12056
 
Posts: 860
Joined: Sun Apr 25, 2010 9:57 pm

Re: Windows Repair

Postby stephuk » Thu Apr 14, 2011 3:17 pm

Hi, I've followed your instructions. TDSSKiller.exe is saved on my desktop but nothing seems to be happening after I've pressed OK... Am I supposed to see anything - like a scan or something?

EDIT:
As nothing was happening, I've restarted in normal mode (I was in Safe mode before).
When I pressed Run, the script I copied and pasted earlier was (already/still) there. Clicked on OK and this time the dialog box asking if I wanted to run the program came up but nothing else happenened...
Last edited by stephuk on Thu Apr 14, 2011 3:28 pm, edited 1 time in total.
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby 12056 » Thu Apr 14, 2011 3:24 pm

It should look like...

Image
Rhett Trappman
MyAntispyware.com Forum Security Team and Moderator
12056
 
Posts: 860
Joined: Sun Apr 25, 2010 9:57 pm

Re: Windows Repair

Postby stephuk » Thu Apr 14, 2011 3:29 pm

No it's not coming up :(
stephuk
 
Posts: 44
Joined: Thu Mar 31, 2011 3:44 pm

Re: Windows Repair

Postby 12056 » Thu Apr 14, 2011 3:33 pm

Are any .exe files working?
Rhett Trappman
MyAntispyware.com Forum Security Team and Moderator
12056
 
Posts: 860
Joined: Sun Apr 25, 2010 9:57 pm

PreviousNext

Return to Archived Logs

Who is online

Users browsing this forum: No registered users and 0 guests