Redirected from Google

  1. #1
    Hijacked is offline Junior Member

    Redirected from Google

    This seems like a common issue. I run Windows 7 Home Premium 64-bit.
    Here are the log contents.

    Malwarebytes' Anti-Malware 1.46
    Malwarebytes

    Database version: 5047

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    11/4/2010 9:37:40 PM
    mbam-log-2010-11-04 (21-37-40).txt

    Scan type: Quick scan
    Objects scanned: 142151
    Time elapsed: 3 minute(s), 20 second(s)

    Memory Processes Infected: 4
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 3
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 5

    Memory Processes Infected:
    C:\Users\Karin\AppData\Roaming\Microsoft\Windows\s hell.exe (Trojan.Downloader) -> Unloaded process successfully.
    C:\Users\Karin\AppData\Roaming\Microsoft\svchost.e xe (Trojan.Agent) -> Unloaded process successfully.
    C:\Users\Karin\AppData\Roaming\Seosav\okduv.exe (Spyware.Passwords.XGen) -> Unloaded process successfully.
    C:\Users\Karin\AppData\Local\Temp\dwm.exe (Trojan.Agent) -> Unloaded process successfully.

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\svchost (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\{1086254b-93c4-2c91-2f4b-ff7196c358f3} (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: c:\users\karin\appdata\local\temp\dwm.exe -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,C:\Users\Karin\AppData\Roaming\Micro soft\Windows\shell.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Users\Karin\AppData\Roaming\Microsoft\Windows\s hell.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Karin\AppData\Roaming\Microsoft\svchost.e xe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Karin\AppData\Roaming\Seosav\okduv.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
    C:\Users\Karin\AppData\Roaming\Microsoft\stor.cfg (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\Karin\AppData\Local\Temp\dwm.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    The GMER log is empty.

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows 7 Home Premium Edition
    Windows Information: (build 7600), 64-bit
    Base Board Manufacturer: Acer
    BIOS Manufacturer: American Megatrends Inc.
    System Manufacturer: Acer
    System Product Name: Aspire M3300
    Logical Drives Mask: 0x00000bfc

    Kernel Drivers (total 193):
    0x02E1A000 \SystemRoot\system32\ntoskrnl.exe
    0x033F6000 \SystemRoot\system32\hal.dll
    0x00BB7000 \SystemRoot\system32\kdcom.dll
    0x00C47000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
    0x00C54000 \SystemRoot\system32\PSHED.dll
    0x00C68000 \SystemRoot\system32\CLFS.SYS
    0x00CC6000 \SystemRoot\system32\CI.dll
    0x00ED2000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x00F76000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x00F85000 \SystemRoot\system32\DRIVERS\ACPI.sys
    0x00FDC000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
    0x00FE5000 \SystemRoot\system32\DRIVERS\msisadrv.sys
    0x00E00000 \SystemRoot\system32\DRIVERS\pci.sys
    0x00E33000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
    0x00E40000 \SystemRoot\System32\drivers\partmgr.sys
    0x00E55000 \SystemRoot\system32\DRIVERS\volmgr.sys
    0x00E6A000 \SystemRoot\System32\drivers\volmgrx.sys
    0x00EC6000 \SystemRoot\system32\DRIVERS\pciide.sys
    0x00FEF000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
    0x00D86000 \SystemRoot\System32\drivers\mountmgr.sys
    0x00DA0000 \SystemRoot\system32\DRIVERS\atapi.sys
    0x00DA9000 \SystemRoot\system32\DRIVERS\ataport.SYS
    0x00DD3000 \SystemRoot\system32\DRIVERS\msahci.sys
    0x00DDE000 \SystemRoot\system32\DRIVERS\amdsata.sys
    0x0108B000 \SystemRoot\system32\DRIVERS\storport.sys
    0x010ED000 \SystemRoot\system32\DRIVERS\amdxata.sys
    0x010F8000 \SystemRoot\system32\drivers\fltmgr.sys
    0x01144000 \SystemRoot\system32\drivers\fileinfo.sys
    0x01237000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x01158000 \SystemRoot\System32\Drivers\msrpc.sys
    0x013DA000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x01000000 \SystemRoot\System32\Drivers\cng.sys
    0x01200000 \SystemRoot\System32\drivers\pcw.sys
    0x01211000 \SystemRoot\System32\Drivers\Fs_Rec.sys
    0x01417000 \SystemRoot\system32\drivers\ndis.sys
    0x01509000 \SystemRoot\system32\drivers\NETIO.SYS
    0x01569000 \SystemRoot\System32\Drivers\ksecpkg.sys
    0x01594000 \SystemRoot\system32\DRIVERS\volsnap.sys
    0x015E0000 \SystemRoot\System32\Drivers\spldr.sys
    0x011B6000 \SystemRoot\System32\drivers\rdyboost.sys
    0x015E8000 \SystemRoot\System32\Drivers\mup.sys
    0x01400000 \SystemRoot\System32\drivers\hwpolicy.sys
    0x00C00000 \SystemRoot\System32\DRIVERS\fvevol.sys
    0x0121B000 \SystemRoot\system32\DRIVERS\disk.sys
    0x0167A000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    0x016AA000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
    0x016C0000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0x016EA000 \SystemRoot\system32\DRIVERS\mwlPSDFilter.sys
    0x016F3000 \SystemRoot\System32\Drivers\Null.SYS
    0x016FC000 \SystemRoot\System32\Drivers\Beep.SYS
    0x01703000 \SystemRoot\System32\drivers\vga.sys
    0x01711000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0x01736000 \SystemRoot\System32\drivers\watchdog.sys
    0x01746000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x0174F000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x01758000 \SystemRoot\system32\drivers\rdprefmp.sys
    0x01761000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x0176C000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x02A00000 \SystemRoot\System32\drivers\tcpip.sys
    0x0177D000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x017C7000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x017E5000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x03CED000 \SystemRoot\system32\drivers\afd.sys
    0x03D77000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x03DBC000 \SystemRoot\system32\DRIVERS\wfplwf.sys
    0x03DC5000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x03DEB000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x03C00000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x03C1B000 \SystemRoot\system32\DRIVERS\termdd.sys
    0x03C2F000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x03C80000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x03C8C000 \SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
    0x03C9F000 \SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
    0x03CA7000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0x03CB2000 \SystemRoot\System32\drivers\discache.sys
    0x03CC1000 \SystemRoot\System32\Drivers\dfsc.sys
    0x01600000 \SystemRoot\system32\DRIVERS\blbdrive.sys
    0x01611000 \SystemRoot\system32\DRIVERS\avipbb.sys
    0x01633000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x01659000 \SystemRoot\system32\DRIVERS\amdppm.sys
    0x046FE000 \SystemRoot\system32\DRIVERS\atikmdag.sys
    0x04600000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x04D15000 \SystemRoot\System32\drivers\dxgmms1.sys
    0x04D5B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0x04D7F000 \SystemRoot\system32\DRIVERS\yk62x64.sys
    0x03E81000 \SystemRoot\system32\DRIVERS\1394ohci.sys
    0x03EBF000 \??\C:\Windows\system32\drivers\UBHelper.sys
    0x03EC7000 \??\C:\Windows\system32\drivers\NTIDrvr.sys
    0x03ECF000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0x03EDC000 \SystemRoot\system32\DRIVERS\usbohci.sys
    0x03EE7000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x03F3D000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x03F4E000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0x03F6C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0x03F7B000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x03F8A000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
    0x03F93000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
    0x03FA3000 \SystemRoot\system32\DRIVERS\serscan.sys
    0x03FAB000 \SystemRoot\system32\drivers\ksthunk.sys
    0x03FB1000 \SystemRoot\system32\drivers\ks.sys
    0x03E00000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
    0x03E16000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x03E3A000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x03E46000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x04DE4000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x04218000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x04239000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x04253000 \SystemRoot\system32\DRIVERS\swenum.sys
    0x04255000 \SystemRoot\system32\DRIVERS\umbus.sys
    0x04267000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x042C1000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x042D6000 \SystemRoot\system32\drivers\AtiHdmi.sys
    0x042F6000 \SystemRoot\system32\drivers\portcls.sys
    0x04333000 \SystemRoot\system32\drivers\drmk.sys
    0x05A0A000 \SystemRoot\system32\drivers\RTKVHD64.sys
    0x00040000 \SystemRoot\System32\win32k.sys
    0x05BF2000 \SystemRoot\System32\drivers\Dxapi.sys
    0x04355000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0x05BFE000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x04372000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0x04383000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0x0438F000 \SystemRoot\system32\DRIVERS\dot4usb.sys
    0x0439F000 \SystemRoot\system32\DRIVERS\Dot4.sys
    0x043C7000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0x05A00000 \SystemRoot\system32\DRIVERS\Dot4Prt.sys
    0x043E2000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0x02485000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0x0249E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0x024A7000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0x024B5000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x005E0000 \SystemRoot\System32\TSDDD.dll
    0x00740000 \SystemRoot\System32\cdd.dll
    0x024C3000 \SystemRoot\system32\drivers\luafv.sys
    0x024E6000 \SystemRoot\system32\DRIVERS\avgntflt.sys
    0x02503000 \SystemRoot\system32\drivers\WudfPf.sys
    0x02524000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x02539000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x0254C000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0x04448000 \SystemRoot\system32\drivers\HTTP.sys
    0x04510000 \SystemRoot\system32\DRIVERS\bowser.sys
    0x0452E000 \SystemRoot\System32\drivers\mpsdrv.sys
    0x04546000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0x04573000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0x045C1000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0x064EF000 \SystemRoot\system32\drivers\peauth.sys
    0x06595000 \SystemRoot\System32\Drivers\secdrv.SYS
    0x065A0000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0x065CD000 \SystemRoot\System32\drivers\tcpipreg.sys
    0x06400000 \SystemRoot\System32\DRIVERS\srv2.sys
    0x02564000 \SystemRoot\System32\DRIVERS\srv.sys
    0x06467000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
    0x06498000 \SystemRoot\system32\DRIVERS\psi_mf.sys
    0x064A1000 \SystemRoot\system32\DRIVERS\WSDPrint.sys
    0x064AC000 \SystemRoot\System32\Drivers\fastfat.SYS
    0x77C70000 \Windows\System32\ntdll.dll
    0x480A0000 \Windows\System32\smss.exe
    0xFFF90000 \Windows\System32\apisetschema.dll
    0xFF600000 \Windows\System32\autochk.exe
    0xFFE50000 \Windows\System32\wininet.dll
    0xFFE30000 \Windows\System32\imagehlp.dll
    0x77B50000 \Windows\System32\kernel32.dll
    0xFFD20000 \Windows\System32\msctf.dll
    0xFFC40000 \Windows\System32\oleaut32.dll
    0x77E40000 \Windows\System32\psapi.dll
    0x77E30000 \Windows\System32\normaliz.dll
    0xFFBD0000 \Windows\System32\gdi32.dll
    0xFF970000 \Windows\System32\iertutil.dll
    0xFF7F0000 \Windows\System32\urlmon.dll
    0xFF7E0000 \Windows\System32\nsi.dll
    0xFF740000 \Windows\System32\clbcatq.dll
    0xFF710000 \Windows\System32\imm32.dll
    0xFF500000 \Windows\System32\ole32.dll
    0xFE770000 \Windows\System32\shell32.dll
    0xFE6D0000 \Windows\System32\msvcrt.dll
    0xFE680000 \Windows\System32\ws2_32.dll
    0xFE600000 \Windows\System32\difxapi.dll
    0xFE520000 \Windows\System32\advapi32.dll
    0xFE3F0000 \Windows\System32\rpcrt4.dll
    0xFE3A0000 \Windows\System32\Wldap32.dll
    0xFE1C0000 \Windows\System32\setupapi.dll
    0xFE120000 \Windows\System32\comdlg32.dll
    0xFE050000 \Windows\System32\usp10.dll
    0xFDFD0000 \Windows\System32\shlwapi.dll
    0xFDFB0000 \Windows\System32\sechost.dll
    0x77A50000 \Windows\System32\user32.dll
    0xFDFA0000 \Windows\System32\lpk.dll
    0xFDF60000 \Windows\System32\wintrust.dll
    0xFDDF0000 \Windows\System32\crypt32.dll
    0xFDDD0000 \Windows\System32\devobj.dll
    0xFDD90000 \Windows\System32\cfgmgr32.dll
    0xFDCF0000 \Windows\System32\comctl32.dll
    0xFDC80000 \Windows\System32\KernelBase.dll
    0xFDC70000 \Windows\System32\msasn1.dll

    Processes (total 81):
    0 System Idle Process
    4 System
    284 C:\Windows\System32\smss.exe
    420 csrss.exe
    480 csrss.exe
    488 C:\Windows\System32\wininit.exe
    544 C:\Windows\System32\winlogon.exe
    580 C:\Windows\System32\services.exe
    600 C:\Windows\System32\lsass.exe
    608 C:\Windows\System32\lsm.exe
    704 C:\Windows\System32\svchost.exe
    820 C:\Windows\System32\svchost.exe
    884 C:\Windows\System32\atiesrxx.exe
    944 C:\Windows\System32\svchost.exe
    996 C:\Windows\System32\svchost.exe
    120 C:\Windows\System32\svchost.exe
    124 C:\Windows\System32\svchost.exe
    1116 C:\Windows\System32\svchost.exe
    1144 C:\Windows\System32\svchost.exe
    1256 C:\Windows\System32\atieclxx.exe
    1368 C:\Windows\System32\spoolsv.exe
    1396 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    1416 C:\Windows\System32\svchost.exe
    1548 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    1576 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1620 C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
    1628 C:\Windows\System32\conhost.exe
    1668 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    1744 C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
    1840 C:\Windows\System32\taskhost.exe
    1876 C:\Windows\System32\taskeng.exe
    1932 C:\Windows\System32\dwm.exe
    1992 C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
    2024 C:\Windows\explorer.exe
    1072 C:\Windows\SysWOW64\svchost.exe
    1276 C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe
    1796 C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    1588 C:\Windows\System32\svchost.exe
    2064 C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
    2204 C:\Windows\System32\svchost.exe
    2224 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    2520 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    2548 C:\Windows\System32\svchost.exe
    2588 C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    2652 C:\Windows\System32\svchost.exe
    2676 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    2728 C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    3008 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    2668 C:\Windows\System32\svchost.exe
    3088 C:\Windows\System32\svchost.exe
    3332 C:\Windows\System32\svchost.exe
    3408 WUDFHost.exe
    3720 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    3728 C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    3844 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    3948 C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
    4028 C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    3372 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    3580 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    3656 C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0brmon.exe
    3628 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    3868 C:\Program Files (x86)\iTunes\iTunesHelper.exe
    984 C:\Program Files (x86)\Secunia\PSI\psi.exe
    3700 C:\Windows\System32\SearchIndexer.exe
    4136 C:\Program Files\Windows Media Player\wmpnetwk.exe
    4752 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    4924 C:\Program Files\iPod\bin\iPodService.exe
    5036 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
    5096 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    4324 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    2992 C:\Windows\System32\svchost.exe
    5248 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    5536 C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
    5776 dllhost.exe
    3312 C:\Windows\System32\audiodg.exe
    200 C:\Windows\System32\taskeng.exe
    5948 C:\Windows\System32\SearchProtocolHost.exe
    6044 C:\Windows\System32\SearchFilterHost.exe
    1960 L:\MBRCheck.exe
    1656 C:\Windows\System32\conhost.exe
    4672 C:\Windows\System32\dllhost.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000004`06500000 (NTFS)

    PhysicalDrive0 Model Number: WDCWD10EADS-22M2B0, Rev: 01.00A01

    Size Device Name MBR Status
    --------------------------------------------
    931 GB \\.\PhysicalDrive0 Acer MBR code detected
    SHA1: 3183CBF02DD9B39C5FF84F50BA2419D633E30179


    Done!

    DDS (Ver_10-11-03.01) - NTFS_AMD64
    Run by Karin at 22:00:35.93 on Thu 11/04/2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.5886.4291 [GMT -4:00]


    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\System32\svchost.exe -k yksvcs
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
    C:\Windows\Explorer.EXE
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe
    c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\svchost.exe -k HPService
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
    C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0brmon.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Secunia\PSI\psi.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    L:\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.att.net
    uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_m3300&r=17360610z2 06p0435v165w45i1s241
    mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_m3300&r=17360610z2 06p0435v165w45i1s241
    mStart Page = hxxp://www.att.net
    uInternet Settings,ProxyOverride = *.local
    uInternet Settings,ProxyServer = http=127.0.0.1:50370
    uURLSearchHooks: N/A: {7757cbcc-0975-4b79-a519-90b142ca3a23} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0SrcAs.dll
    BHO: AutorunsDisabled - No File
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\s wg.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: Toolbar BHO: {efa17361-cdc0-4927-9afc-baad1f96b2ae} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstan ce.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: att.net Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB: IObit Toolbar: {efa17369-cdc0-4927-9afc-baad1f96b2ae} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll
    TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
    uRun: [Google Update] "C:\Users\Karin\AppData\Local\Google\Update\Google Update.exe" /c
    uRun: [PnxhTwETsO.exe] C:\Users\Karin\AppData\Local\Temp\PnxhTwETsO.exe
    mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
    mRun: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe
    mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    mRun: [IObitBar Browser Plugin Loader] C:\PROGRA~2\IObitBar\toolbar\1.bin\i0brmon.exe
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950D F09FAB501E03.dll/cmsidewiki.html
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    BHO-X64: AutorunsDisabled - No File
    BHO-X64: McAfee Phishing Filter - No File
    BHO-X64: scriptproxy - No File
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\s wg64.dll
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    TB-X64: {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File
    EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
    mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

    ================= FIREFOX ===================

    FF - ProfilePath - C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Pro files\nro9jnu7.default\
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 50370
    FF - prefs.js: network.proxy.type - 1
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dl l
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinti ng.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.d ll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
    FF - component: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
    FF - component: C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Pro files\nro9jnu7.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.13\npGoogleOneClick8.d ll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.d ll
    FF - plugin: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
    FF - plugin: C:\Program Files (x86)\IObitBar\toolbar\1.bin\NPi0Stub.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Users\Karin\AppData\Local\Google\Update\1.2.183 .39\npGoogleOneClick8.dll
    FF - plugin: C:\Users\Karin\AppData\Roaming\Mozilla\plugins\npg oogletalk.dll
    FF - plugin: C:\Users\Karin\AppData\Roaming\Mozilla\plugins\npg tpo3dautoplugin.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified

    ============= SERVICES / DRIVERS ===============

    R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\driv ers\mwlPSDFilter.sys [2009-6-2 22576]
    R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\driver s\mwlPSDNserv.sys [2009-6-2 20016]
    R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\driver s\mwlPSDVDisk.sys [2009-6-2 60464]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-11-25 203264]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-6-22 135336]
    R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-6-22 267944]
    R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgn tflt.sys [2010-6-22 81584]
    R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-8-28 1150496]
    R2 IObitBarService;IObit Toolbar Service;C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsv c.exe [2010-10-12 28766]
    R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-8-12 62208]
    R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-11-25 240160]
    R2 yksvc;Marvell Yukon Service;C:\Windows\System32\svchost.exe -k yksvcs [2009-7-13 27136]
    R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2010-5-28 17456]
    R3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\System32\drivers\WSDPrint.sys [2009-7-13 23040]
    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-6-25 135664]
    S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssflt r.sys [2010-10-23 48488]
    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
    S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E [2010-1-9 4925184]
    S3 PsSdk41;PsSdk41;C:\Windows\System32\drivers\pssdk4 1.sys [2010-9-29 51776]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-22 1255736]
    S4 McShield;McAfee Real-time Scanner;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe --> C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [?]
    S4 McSysmon;McAfee SystemGuards;C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon. exe --> C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe [?]
    S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-8-15 47128]
    S4 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-9-10 305448]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 366936]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

    =============== Created Last 30 ================

    2010-11-05 01:32:58 -------- d-----w- C:\Users\Karin\AppData\Roaming\Malwarebytes
    2010-11-05 01:32:39 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    2010-11-05 01:32:38 -------- d-----w- C:\PROGRA~3\Malwarebytes
    2010-11-05 01:32:37 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2010-11-05 01:32:37 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2010-11-04 10:20:54 8006480 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{244754C5-596D-42DB-87BE-14B656E83C59}\mpengine.dll
    2010-10-27 15:24:02 961024 ----a-w- C:\Windows\System32\CPFilters.dll
    2010-10-27 15:24:02 641536 ----a-w- C:\Windows\SysWow64\CPFilters.dll
    2010-10-27 15:24:02 552960 ----a-w- C:\Windows\System32\msdri.dll
    2010-10-27 15:24:02 288256 ----a-w- C:\Windows\System32\MSNP.ax
    2010-10-27 15:24:02 258560 ----a-w- C:\Windows\System32\mpg2splt.ax
    2010-10-27 15:24:02 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
    2010-10-27 15:24:02 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
    2010-10-27 15:23:55 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
    2010-10-23 13:43:59 -------- d-----w- C:\Windows\en
    2010-10-23 13:41:38 48488 ----a-w- C:\Windows\System32\drivers\fssfltr.sys
    2010-10-23 13:40:54 -------- d-----w- C:\Program Files (x86)\MSN Toolbar
    2010-10-23 13:40:49 -------- d-----w- C:\Program Files (x86)\Bing Bar Installer
    2010-10-23 13:40:47 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
    2010-10-23 13:40:47 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
    2010-10-23 13:40:47 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
    2010-10-23 13:40:47 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
    2010-10-23 13:40:28 469256 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d9d92f7c1cb72b72d\InstallManager_WLE_W LE.exe
    2010-10-23 13:40:10 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cfae7f601cb72b722\MeshBetaRemover.exe
    2010-10-23 13:39:51 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c3ecd59f1cb72b71a\DSETUP.dll
    2010-10-23 13:39:51 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c3ecd59f1cb72b71a\DXSETUP.exe
    2010-10-23 13:39:51 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c3ecd59f1cb72b71a\dsetup32.dll
    2010-10-23 13:39:48 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c209417a1cb72b719\DSETUP.dll
    2010-10-23 13:39:48 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c209417a1cb72b719\DXSETUP.exe
    2010-10-23 13:39:48 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c209417a1cb72b719\dsetup32.dll
    2010-10-23 13:38:52 -------- d-----w- C:\Users\Karin\AppData\Local\Windows Live
    2010-10-23 13:38:18 257024 ----a-w- C:\Windows\System32\mfreadwrite.dll
    2010-10-23 13:38:18 206848 ----a-w- C:\Windows\System32\mfps.dll
    2010-10-23 13:38:18 196608 ----a-w- C:\Windows\SysWow64\mfreadwrite.dll
    2010-10-23 13:38:18 1888256 ----a-w- C:\Windows\System32\WMVDECOD.DLL
    2010-10-23 13:38:18 1619456 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
    2010-10-23 13:38:17 4068864 ----a-w- C:\Windows\System32\mf.dll
    2010-10-23 13:38:17 3181568 ----a-w- C:\Windows\SysWow64\mf.dll
    2010-10-21 02:03:53 -------- d-----w- C:\Users\Karin\AppData\Roaming\Seosav
    2010-10-21 02:03:53 -------- d-----w- C:\Users\Karin\AppData\Roaming\Fuyw
    2010-10-21 02:02:44 -------- d-----w- C:\Users\Karin\AppData\Roaming\A71923186A305203F8C 41CE4525B18ED
    2010-10-16 16:07:33 -------- d-----w- C:\Users\Karin\AppData\Local\Apple Computer
    2010-10-16 16:07:25 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
    2010-10-16 16:07:25 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
    2010-10-16 16:07:25 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
    2010-10-16 16:07:08 -------- d-----w- C:\Program Files\iTunes
    2010-10-16 16:07:08 -------- d-----w- C:\Program Files\iPod
    2010-10-16 16:07:08 -------- d-----w- C:\Program Files (x86)\iTunes
    2010-10-16 16:07:08 -------- d-----w- C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
    2010-10-16 16:05:56 -------- d-----w- C:\Program Files\Bonjour
    2010-10-16 16:05:56 -------- d-----w- C:\Program Files (x86)\Bonjour
    2010-10-12 04:02:36 -------- d-----w- C:\Program Files (x86)\IObitBar
    2010-10-08 17:11:07 -------- d-----w- C:\Murach
    2010-10-08 16:46:50 92184 ----a-w- C:\Windows\SysWow64\SQSRVRES.DLL
    2010-10-08 16:26:09 50200 ----a-w- C:\Windows\SysWow64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
    2010-10-08 16:25:59 79896 ----a-w- C:\Windows\SysWow64\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
    2010-10-08 16:23:11 -------- d-----w- C:\Program Files (x86)\Microsoft Synchronization Services
    2010-10-08 16:22:05 -------- d-----w- C:\Windows\SysWow64\1033
    2010-10-08 16:22:05 -------- d-----w- C:\Windows\System32\1033
    2010-10-08 16:22:05 -------- d-----w- C:\Program Files\Microsoft SQL Server
    2010-10-08 16:01:02 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server

    ==================== Find3M ====================

    2010-11-03 02:13:45 81584 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
    2010-10-21 23:50:38 51776 ----a-w- C:\Windows\System32\drivers\pssdk41.sys
    2010-10-19 15:41:44 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2010-10-14 01:35:52 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2010-09-23 04:47:28 49016 ----a-w- C:\Windows\SysWow64\sirenacm.dll
    2010-09-23 04:32:56 301936 ----a-w- C:\Windows\WLXPGSS.SCR
    2010-09-21 18:49:02 252800 ----a-w- C:\Windows\System32\LIVESSP.DLL
    2010-09-21 18:03:14 208768 ----a-w- C:\Windows\SysWow64\LIVESSP.DLL
    2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
    2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2010-09-08 15:17:46 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
    2010-09-08 15:17:46 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
    2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
    2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
    2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
    2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
    2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
    2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
    2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2010-09-01 05:12:09 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
    2010-09-01 04:23:49 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
    2010-09-01 02:58:34 3123712 ----a-w- C:\Windows\System32\win32k.sys
    2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
    2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
    2010-08-27 06:14:02 236032 ----a-w- C:\Windows\System32\srvsvc.dll
    2010-08-27 05:46:48 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
    2010-08-27 03:38:04 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
    2010-08-27 03:37:48 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
    2010-08-27 03:37:26 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
    2010-08-26 05:27:28 148992 ----a-w- C:\Windows\System32\t2embed.dll
    2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
    2010-08-21 06:38:47 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
    2010-08-21 06:36:49 340992 ----a-w- C:\Windows\System32\schannel.dll
    2010-08-21 06:31:06 633856 ----a-w- C:\Windows\System32\comctl32.dll
    2010-08-21 06:29:47 558592 ----a-w- C:\Windows\System32\spoolsv.exe
    2010-08-21 05:36:33 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
    2010-08-21 05:36:24 224256 ----a-w- C:\Windows\SysWow64\schannel.dll
    2010-08-21 05:33:24 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll

    ============= FINISH: 22:01:00.58 ===============


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-11-03.01)

    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 6/21/2010 11:43:33 AM
    System Uptime: 11/4/2010 9:39:44 PM (1 hours ago)

    Motherboard: Acer | | FRS780M
    Processor: AMD Phenom(tm) II X4 810 Processor | CPU 1 | 2600/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 915 GiB total, 870.537 GiB free.
    D: is CDROM ()
    E: is Removable
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    L: is Removable

    ==== Disabled Device Manager Items =============

    Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318}
    Description: Standard PS/2 Keyboard
    Device ID: ACPI\PNP0303\4&4E6C81F&0
    Manufacturer: (Standard keyboards)
    Name: Standard PS/2 Keyboard
    PNP Device ID: ACPI\PNP0303\4&4E6C81F&0
    Service: i8042prt

    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Photosmart C4700 series
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Photosmart C4700 series
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:

    ==== System Restore Points ===================

    RP81: 10/22/2010 9:12:36 AM - Windows Update
    RP83: 10/22/2010 9:23:29 AM - Windows Defender Checkpoint
    RP84: 10/23/2010 9:37:58 AM - Windows Update
    RP85: 10/23/2010 9:00:33 PM - Installed Microsoft SQL Server 2008 R2 Books Online
    RP86: 10/26/2010 8:46:42 AM - Windows Update
    RP87: 10/28/2010 3:00:25 AM - Windows Update
    RP88: 10/29/2010 3:00:25 AM - Windows Update
    RP89: 10/29/2010 7:04:58 AM - Windows Update
    RP90: 11/2/2010 8:29:02 AM - Windows Update
    RP91: 11/4/2010 6:20:37 AM - Windows Update

    ==== Installed Programs ======================

    1600
    1600_Help
    1600Trb
    7-Zip 4.65
    Acer Assist
    Acer Backup Manager
    Acer eRecovery Management
    Acer Games
    Acer Registration
    Acer ScreenSaver
    Acer Updater
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.4.0 MUI
    Advanced SystemCare 3
    Advertising Center
    AIO_CDB_ProductContext
    AIO_CDB_Software
    AIO_Scan
    Apple Application Support
    Apple Software Update
    AT&T Yahoo! Browser Configuration
    att.net Toolbar
    Avira AntiVir Personal - Free Antivirus
    Backup Manager Advance
    Bing Bar
    Bing Bar Platform
    BufferChm
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    Compatibility Pack for the 2007 Office system
    Copy
    CyberLink PowerDVD 8
    D3DX10
    Definition update for Microsoft Office 2010 (KB982726)
    Destinations
    DeviceDiscovery
    DocProc
    eSobi v2
    Fax
    Google Talk Plugin
    Google Toolbar for Internet Explorer
    Google Update Helper
    GPBaseService2
    Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
    Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
    Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
    Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
    Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
    Hotkey Utility
    HPPhotoGadget
    HPPhotoSmartDiscLabelContent1
    HPPhotosmartEssential
    HPProductAssistant
    HPSSupply
    Identity Card
    ImagXpress
    IObit Toolbar
    Java Auto Updater
    Java(TM) 6 Update 22
    Junk Mail filter update
    Malwarebytes' Anti-Malware
    MarketResearch
    Marvell Miniport Driver
    Mesh Runtime
    Messenger Companion
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Home and Student 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Single Image 2010
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2010
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft SQL Server 2008
    Microsoft SQL Server 2008 Browser
    Microsoft SQL Server 2008 Common Files
    Microsoft SQL Server 2008 Database Engine Services
    Microsoft SQL Server 2008 Database Engine Shared
    Microsoft SQL Server 2008 Management Studio
    Microsoft SQL Server 2008 Policies
    Microsoft SQL Server 2008 R2 Books Online
    Microsoft SQL Server 2008 RsFx Driver
    Microsoft SQL Server 2008 Setup Support Files
    Microsoft SQL Server Compact 3.5 SP1 English
    Microsoft SQL Server Compact 3.5 SP1 Query Tools English
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual Studio Tools for Applications 2.0 - ENU
    Microsoft Works
    Mozilla Firefox (3.6.7)
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MyWinLocker
    Nero 9 Essentials
    Nero ControlCenter
    Nero DiscSpeed
    Nero DiscSpeed Help
    Nero DriveSpeed
    Nero DriveSpeed Help
    Nero Express Help
    Nero InfoTool
    Nero InfoTool Help
    Nero Installer
    Nero Online Upgrade
    Nero StartSmart
    Nero StartSmart Help
    Nero StartSmart OEM
    NeroExpress
    neroxml
    Norton Online Backup
    Password Safe
    PS_AIO_06_C4700_SW_Min
    Python 2.7
    QuickTime
    Realtek High Definition Audio Driver
    Scan
    Secunia PSI
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
    Security Update for Microsoft Word 2010 (KB2345000)
    Service Pack 1 for SQL Server 2008 (KB968369)
    SmartWebPrinting
    SolutionCenter
    Sql Server Customer Experience Improvement Program
    Status
    Toolbox
    TrayApp
    UnloadSupport
    Update for Microsoft Office 2010 (KB2202188)
    Update for Microsoft OneNote 2010 (KB2288640)
    Update for Microsoft Outlook Social Connector (KB2289116)
    WebReg
    Welcome Center
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows Media Player Firefox Plugin
    XLink Kai
    Yahoo! Install Manager
    Yahoo! Software Update

    ==== Event Viewer Messages From Past Week ========

    11/4/2010 9:48:46 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR7.
    11/4/2010 9:41:09 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    11/4/2010 9:39:58 PM, Error: volmgr [46] - Crash dump initialization failed!
    11/4/2010 9:25:54 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    11/4/2010 9:23:51 PM, Error: NetBT [4321] - The name "CLARIDGE :1d" could not be registered on the interface with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did not allow the name to be claimed by this computer.
    11/4/2010 8:30:06 PM, Error: BROWSER [8019] - The browser was unable to promote itself to master browser. The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer.
    11/4/2010 6:43:15 PM, Error: BROWSER [8020] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is unknown.
    11/3/2010 7:33:00 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR27.
    11/3/2010 6:04:11 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer DEN that believes that it is the master browser for the domain on transport NetBT_Tcpip_{55F5755B-3F63-41ED-969B-C258197CB49E}. The master browser is stopping or an election is being forced.
    11/3/2010 2:30:11 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR26.
    11/1/2010 9:06:17 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR23.
    11/1/2010 11:18:33 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR22.
    10/31/2010 10:57:21 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR21.
    10/30/2010 7:28:09 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR19.
    10/30/2010 3:58:27 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR17.
    10/30/2010 3:54:33 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk8\DR16.
    10/30/2010 3:29:08 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR14.
    10/29/2010 12:38:53 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR13.
    10/29/2010 12:25:36 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk7\DR12.
    10/28/2010 3:01:31 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80080005: Update for Windows 7 for x64-based Systems (KB2388210).

    ==== End Of File ===========================

    Thank you for your time.

  2. #2
    broni is offline Senior Member
    Welcome aboard

    Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/


    • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    • An icon will be created on your desktop. Double-click that icon to launch the program.
    • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    • Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    • Open SUPERAntiSpyware.
    • Under "Configuration and Preferences", click the Preferences button.
    • Click the Scanning Control tab.
    • Under Scanner Options make sure the following are checked (leave all others unchecked):
      • Close browsers before scanning.
      • Terminate memory threats before quarantining.
    • Click the "Close" button to leave the control center screen.
    • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    • On the left, make sure you check C:\Fixed Drive.
    • On the right, under "Complete Scan", choose Perform Complete Scan.
    • Click "Next" to start the scan. Please be patient while it scans your computer.
    • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    • Make sure everything has a checkmark next to it and click "Next".
    • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    • If asked if you want to reboot, click "Yes".
    • To retrieve the removal information after reboot, launch SUPERAntispyware again.
      • Click Preferences, then click the Statistics/Logs tab.
      • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      • Copy and paste the Scan Log results in your next reply with a new HijackThis log.
    • Click Close to exit the program.


    Post SUPERAntiSpyware log.

  3. #3
    Hijacked is offline Junior Member
    Do you want a HijackThis log as well? I can install and run it if you do.

    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

    Generated 11/04/2010 at 11:30 PM

    Application Version : 4.45.1000

    Core Rules Database Version : 5767
    Trace Rules Database Version: 3579

    Scan type : Quick Scan
    Total Scan Time : 00:18:56

    Memory items scanned : 754
    Memory threats detected : 0
    Registry items scanned : 2841
    Registry threats detected : 0
    File items scanned : 16842
    File threats detected : 0

  4. #4
    broni is offline Senior Member
    We don't use HJT anymore. It's an outdated tool.

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:



    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

  5. #5
    Hijacked is offline Junior Member
    OTL logfile created on: 11/5/2010 12:20:24 PM - Run 1
    OTL by OldTimer - Version 3.2.17.2 Folder = C:\Users\Karin\Desktop
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 82.00% Memory free
    11.00 Gb Paging File | 10.00 Gb Available in Paging File | 85.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 915.41 Gb Total Space | 870.21 Gb Free Space | 95.06% Space Free | Partition Type: NTFS

    Computer Name: ACER | User Name: Karin | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2010/11/05 12:18:51 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\Karin\Desktop\OTL.exe
    PRC - [2010/11/02 22:13:45 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2010/11/02 22:13:45 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    PRC - [2010/11/02 22:13:45 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    PRC - [2010/10/12 00:02:36 | 000,028,766 | ---- | M] (IObit) -- C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0barsvc.exe
    PRC - [2010/10/12 00:02:36 | 000,020,480 | ---- | M] (IObit) -- C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0brmon.exe
    PRC - [2010/09/28 21:33:02 | 002,407,632 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
    PRC - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    PRC - [2010/05/28 07:04:52 | 000,911,920 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi.exe
    PRC - [2009/11/25 11:07:48 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    PRC - [2009/08/28 05:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
    PRC - [2009/08/18 03:27:26 | 000,629,280 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    PRC - [2009/08/12 19:04:44 | 000,062,208 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
    PRC - [2009/08/12 18:58:28 | 000,261,888 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
    PRC - [2009/07/03 22:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/11/05 12:18:51 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\Karin\Desktop\OTL.exe
    MOD - [2010/08/21 0132 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420f e3fa2b8113bd\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
    SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
    SRV:64bit: - [2009/09/28 09:22:00 | 000,496,128 | ---- | M] (Marvell) [Auto | Running] -- C:\Windows\SysNative\yk62x64.dll -- (yksvc)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/03 22:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
    SRV:64bit: - [2009/07/02 01:16:04 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV - [2010/11/02 22:13:45 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2010/11/02 22:13:45 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2010/10/12 00:02:36 | 000,028,766 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0barsvc.exe -- (IObitBarService)
    SRV - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\msco rsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/01/30 00:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
    SRV - [2009/09/10 09:42:46 | 000,305,448 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
    SRV - [2009/08/28 05:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
    SRV - [2009/08/25 14:38:06 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009/08/12 19:04:44 | 000,062,208 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
    SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/05/22 14:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2010/11/02 22:13:45 | 000,081,584 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
    DRV:64bit: - [2010/10/21 19:50:38 | 000,051,776 | ---- | M] (microOLAP Technologies LTD) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pssdk41.sys -- (PsSdk41)
    DRV:64bit: - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
    DRV:64bit: - [2010/05/28 07:04:52 | 000,017,456 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
    DRV:64bit: - [2010/03/02 12:35:01 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
    DRV:64bit: - [2010/02/17 14:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
    DRV:64bit: - [2010/02/17 14:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
    DRV:64bit: - [2009/10/07 03:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2009/10/07 03:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2009/09/28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
    DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2009/07/02 01:51:28 | 006,036,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
    DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/06/04 17:20:26 | 000,114,192 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
    DRV:64bit: - [2009/06/02 07:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
    DRV:64bit: - [2009/06/02 07:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
    DRV:64bit: - [2009/06/02 07:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
    DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/05/05 20:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
    DRV:64bit: - [2009/05/05 20:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
    DRV:64bit: - [2009/05/04 12:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = iGoogle Redirect
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = ATT.NET - Email, News, Sports, Entertainment and Games

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = ATT.NET - Email, News, Sports, Entertainment and Games
    IE - HKCU\..\URLSearchHook: {7757CBCC-0975-4b79-A519-90B142CA3A23} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0SrcAs.dll (IObit)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = *.local
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyServer" = http=127.0.0.1:50370

    ========== FireFox ==========

    FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
    FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
    FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.51
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    FF - prefs.js..network.proxy.http_port: 50370
    FF - prefs.js..network.proxy.type: 4


    FF - HKLM\software\mozilla\Firefox\Extensions\\smartweb printing@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/06 14:57:00 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\i0ffxtbr @IObitBar.com: C:\Program Files (x86)\IObitBar\toolbar\1.bin [2010/10/12 00:02:37 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/10/29 12:29:21 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/10/29 12:29:21 | 000,000,000 | ---D | M]

    [2010/06/22 21:28:22 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Mozilla\Extensions
    [2010/11/04 23:40:57 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Pro files\nro9jnu7.default\extensions
    [2010/09/10 12:00:27 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Pro files\nro9jnu7.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    [2010/07/09 17:33:39 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Pro files\nro9jnu7.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
    [2010/11/04 17:05:43 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Pro files\nro9jnu7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010/10/13 21:36:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/07/05 16:30:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    [2010/10/13 21:36:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    [2010/10/13 21:35:53 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

    O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\s wg64.dll (Google Inc.)
    O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\s wg.dll (Google Inc.)
    O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
    O2 - BHO: (Toolbar BHO) - {EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll (IObit)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstan ce.dll (Yahoo! Inc)
    O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (att.net Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKLM\..\Toolbar: (IObit Toolbar) - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll (IObit)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (IObit Toolbar) - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll (IObit)
    O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
    O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
    O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
    O4 - HKLM..\Run: [IObitBar Browser Plugin Loader] C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0brmon.exe (IObit)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKCU..\Run: [PnxhTwETsO.exe] C:\Users\Karin\AppData\Local\Temp\PnxhTwETsO.exe File not found
    O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (Google Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: ConsentPromptBehaviorUser = 3
    O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/...soft/wrc32.ocx (WRC Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_22)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O18:64bit: - Protocol\Handler\AutorunsDisabled - No CLSID value found
    O18:64bit: - Protocol\Handler\AutorunsDisabled\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\AutorunsDisabled\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
    O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
    O18 - Protocol\Handler\AutorunsDisabled\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
    O18 - Protocol\Handler\AutorunsDisabled\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Filter\AutorunsDisabled - No CLSID value found
    O18 - Protocol\Filter\AutorunsDisabled - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.e xe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O32 - HKLM CDRom: AutoRun - 1
    O33 - MountPoints2\{4f433e69-9f98-11df-8ead-90fba64bf4ac}\Shell - "" = AutoRun
    O33 - MountPoints2\{4f433e69-9f98-11df-8ead-90fba64bf4ac}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -- File not found
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*


    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/11/05 12:18:50 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Users\Karin\Desktop\OTL.exe
    [2010/11/04 23:08:44 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\SUPERAntiSpyware.co m
    [2010/11/04 23:08:44 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2010/11/04 23:08:38 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
    [2010/11/04 23:08:36 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2010/11/04 21:32:58 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Malwarebytes
    [2010/11/04 21:32:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    [2010/11/04 21:32:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2010/11/04 21:32:37 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2010/11/04 21:32:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2010/10/26 21:05:35 | 000,000,000 | ---D | C] -- C:\Users\Karin\Desktop\PSP
    [2010/10/23 09:43:59 | 000,000,000 | ---D | C] -- C:\Windows\en
    [2010/10/23 09:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2010/10/23 09:40:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar
    [2010/10/23 09:40:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bing Bar Installer
    [2010/10/23 09:38:52 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Local\Windows Live
    [2010/10/20 22:03:53 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Seosav
    [2010/10/20 22:03:53 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Fuyw
    [2010/10/20 22:02:44 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\A71923186A305203F8C 41CE4525B18ED
    [2010/10/17 22:23:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
    [2010/10/16 12:07:33 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Apple Computer
    [2010/10/16 12:07:33 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Local\Apple Computer
    [2010/10/16 12:07:24 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
    [2010/10/16 12:07:08 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2010/10/16 12:07:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
    [2010/10/16 12:07:08 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2010/10/16 12:07:08 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
    [2010/10/16 12:06:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
    [2010/10/16 12:06:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
    [2010/10/16 12:06:16 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Local\Apple
    [2010/10/16 12:06:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
    [2010/10/16 12:06:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
    [2010/10/16 12:05:56 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
    [2010/10/16 12:05:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
    [2010/10/16 12:05:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
    [2010/10/16 12:05:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
    [2010/10/16 11:37:13 | 000,000,000 | ---D | C] -- C:\Users\Karin\Documents\Visual Studio 2005
    [2010/10/13 21:36:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2010/10/13 21:35:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
    [2010/10/12 00:02:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObitBar
    [2010/10/08 13:11:07 | 000,000,000 | ---D | C] -- C:\Murach
    [2010/10/08 12:26:43 | 000,000,000 | ---D | C] -- C:\Users\Karin\Documents\Integration Services Script Component
    [2010/10/08 12:26:27 | 000,000,000 | ---D | C] -- C:\Users\Karin\Documents\Integration Services Script Task
    [2010/10/08 12:26:10 | 000,000,000 | ---D | C] -- C:\Users\Karin\Documents\SQL Server Management Studio
    [2010/10/08 12:24:23 | 000,000,000 | ---D | C] -- C:\Users\Karin\Documents\Visual Studio 2008
    [2010/10/08 12:23:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SDKs
    [2010/10/08 12:23:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
    [2010/10/08 12:22:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 9.0
    [2010/10/08 12:22:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
    [2010/10/08 12:22:05 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1033
    [2010/10/08 12:22:05 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1033
    [2010/10/08 12:01:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
    [2010/10/07 17:16:32 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Nero

    ========== Files - Modified Within 30 Days ==========

    [2010/11/05 12:18:51 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\Karin\Desktop\OTL.exe
    [2010/11/05 11:58:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2010/11/05 11:37:03 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-327741561-186110748-3851023233-1000UA.job
    [2010/11/05 11:17:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2010/11/05 11:00:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2010/11/05 11:00:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2010/11/05 10:57:13 | 000,870,498 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2010/11/05 10:57:13 | 000,725,304 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2010/11/05 10:57:13 | 000,145,322 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2010/11/05 10:52:59 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2010/11/05 10:52:55 | 000,000,394 | ---- | M] () -- C:\Windows\tasks\AWC Startup.job
    [2010/11/05 10:52:34 | 334,196,735 | -HS- | M] () -- C:\hiberfil.sys
    [2010/11/04 23:08:38 | 000,001,812 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/11/04 20:45:10 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-327741561-186110748-3851023233-1000Core.job
    [2010/11/02 22:13:45 | 000,081,584 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
    [2010/10/21 19:50:38 | 000,051,776 | ---- | M] (microOLAP Technologies LTD) -- C:\Windows\SysNative\drivers\pssdk41.sys
    [2010/10/20 22:04:50 | 000,000,010 | ---- | M] () -- C:\Users\Karin\AppData\Roaming\install
    [2010/10/16 14:34:59 | 000,376,376 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2010/10/16 14:32:49 | 000,000,056 | ---- | M] () -- C:\Windows\kgt2k.INI
    [2010/10/08 13:29:22 | 000,002,018 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
    [2010/10/08 12:49:13 | 000,863,798 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2010/10/06 15:49:55 | 000,147,968 | ---- | M] () -- C:\Users\Karin\Documents\M.Smith.doc

    ========== Files Created - No Company Name ==========

    [2010/11/04 23:08:38 | 000,001,812 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/10/20 22:04:50 | 000,000,010 | ---- | C] () -- C:\Users\Karin\AppData\Roaming\install
    [2010/10/16 14:15:15 | 000,000,056 | ---- | C] () -- C:\Windows\kgt2k.INI
    [2010/10/08 11:51:58 | 000,863,798 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2010/10/06 15:49:54 | 000,147,968 | ---- | C] () -- C:\Users\Karin\Documents\M.Smith.doc
    [2010/08/06 21:45:40 | 000,000,000 | ---- | C] () -- C:\Users\Karin\AppData\Roaming\wklnhst.dat
    [2010/07/25 18:07:01 | 000,001,144 | ---- | C] () -- C:\ProgramData\hpzinstall.log
    [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

    ========== LOP Check ==========

    [2010/10/20 22:03:17 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\A71923186A305203F8C 41CE4525B18ED
    [2010/06/21 11:46:30 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Acer
    [2010/11/04 2104 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Fuyw
    [2010/07/23 10:28:43 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\IObit
    [2010/06/21 11:46:29 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Leadertech
    [2010/11/04 21:37:40 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Seosav
    [2010/08/06 21:45:43 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\Template
    [2010/09/29 17:49:49 | 000,000,000 | ---D | M] -- C:\Users\Karin\AppData\Roaming\XLink Kai
    [2010/11/05 10:52:55 | 000,000,394 | ---- | M] () -- C:\Windows\Tasks\AWC Startup.job
    [2009/07/14 01:08:49 | 000,015,916 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2009/11/25 10:35:17 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
    [2010/11/05 10:52:34 | 334,196,735 | -HS- | M] () -- C:\hiberfil.sys
    [2010/11/05 10:52:36 | 1877,254,143 | -HS- | M] () -- C:\pagefile.sys
    [2009/11/25 10:43:13 | 000,002,168 | ---- | M] () -- C:\RHDSetup.log

    < %systemroot%\Fonts\*.com >
    [2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2010/09/23 00:32:56 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2010/06/21 11:48:31 | 000,000,221 | -HS- | M] () -- C:\Users\Karin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2010/11/05 12:18:51 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\Karin\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >
    [2009/06/10 17:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2010/08/04 08:20:50 | 000,000,402 | -HS- | M] () -- C:\Users\Karin\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2010/08/06 14:59:11 | 000,001,144 | ---- | M] () -- C:\ProgramData\hpzinstall.log

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Files - Unicode (All) ==========
    [2010/10/16 14:31:19 | 000,009,621 | ---- | M] ()(C:\Windows\2D??????2nd.mid) -- C:\Windows\2D格闘ツクール2nd.mid
    [2010/10/16 14:31:08 | 000,009,621 | ---- | C] ()(C:\Windows\2D??????2nd.mid) -- C:\Windows\2D格闘ツクール2nd.mid

    < End of report >

  6. #6
    Hijacked is offline Junior Member
    OTL Extras logfile created on: 11/5/2010 12:20:24 PM - Run 1
    OTL by OldTimer - Version 3.2.17.2 Folder = C:\Users\Karin\Desktop
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 82.00% Memory free
    11.00 Gb Paging File | 10.00 Gb Available in Paging File | 85.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 915.41 Gb Total Space | 870.21 Gb Free Space | 95.06% Space Free | Partition Type: NTFS

    Computer Name: ACER | User Name: Karin | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
    .url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %* File not found
    cmdfile [open] -- "%1" %* File not found
    comfile [open] -- "%1" %* File not found
    exefile [open] -- "%1" %* File not found
    helpfile [open] -- Reg Error: Key error.
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %* File not found
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1" File not found
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S File not found
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\PublicPr ofile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
    "{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
    "{104FB32A-7CE3-4C4B-B2AA-70C613FF9DFA}" = iTunes
    "{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
    "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
    "{1F9241E8-87C1-FB9C-5D76-3FF7D0318A87}" = ATI Catalyst Install Manager
    "{33EB1061-ABF1-4470-A540-32E97A610536}" = Apple Mobile Device Support
    "{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
    "{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
    "{48C0866E-57EB-444C-8371-8E4321066BC3}" = Network64
    "{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
    "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
    "{68550918-63B5-4762-85CB-3C160AA4B213}" = HP Photosmart C4700 All-in-One Driver 14.0 Rel. 6
    "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
    "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
    "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
    "{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}" = Microsoft SQL Server 2008 Native Client
    "{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
    "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
    "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
    "{EBAE9144-AF3E-4AF5-B45F-64896D651E27}" = ccc-utility64
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "HP Imaging Device Functions" = HP Imaging Device Functions 13.0
    "HP Photosmart Essential" = HP Photosmart Essential 3.5
    "HP Smart Web Printing" = HP Smart Web Printing 4.51
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
    "HPExtendedCapabilities" = HP Customer Participation Program 13.0
    "HPOCR" = OCR Software by I.R.I.S. 13.0
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "NVIDIA Drivers" = NVIDIA Drivers
    "Shop for HP Supplies" = Shop for HP Supplies

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
    "{01C5A10F-AD9B-405B-853A-6659841A1242}" = Microsoft SQL Server 2008 Policies
    "{03E830A5-822B-D6FB-3257-E1E6A188CF22}" = Catalyst Control Center Graphics Full Existing
    "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
    "{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0B30D22F-AB4F-9379-CDE1-3019D68D72B7}" = CCC Help Chinese Traditional
    "{0E4AD541-61D5-0DF8-44C9-797C3EEBDE2C}" = CCC Help English
    "{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
    "{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
    "{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
    "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
    "{17B5E42B-670F-BE6A-7CBE-B9DFF74D81DC}" = CCC Help Norwegian
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{1D359627-1E53-8D9B-46A6-242B1D7A8B9D}" = CCC Help Turkish
    "{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{2020045B-8DCF-4449-8D5C-EB5BA37440F1}" = Microsoft SQL Server 2008 Management Studio
    "{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
    "{20c31435-2a0a-4580-be8b-ac06fc243ca4}" = Python 2.7
    "{21C205CD-3770-9454-ECC1-88BB0E2AD807}" = Catalyst Control Center Localization All
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
    "{244C6FE3-82BC-D9F0-91F9-D9909E926FCE}" = CCC Help Greek
    "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
    "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
    "{28E941CF-3D09-C540-07FF-81FDB66E8BC9}" = CCC Help Swedish
    "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
    "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
    "{2C4A0A98-66EA-427A-46B4-FED4A141E4CE}" = Catalyst Control Center Graphics Full New
    "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
    "{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
    "{30075A70-B5D2-440B-AFA3-FB2021740121}" = Backup Manager Advance
    "{32F898BE-7D45-EBC2-29F3-B0B704CC8FBB}" = ccc-core-static
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
    "{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
    "{41ACCBEB-F6BD-B9DF-8CCE-32A70F14432B}" = Catalyst Control Center Graphics Previews Vista
    "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
    "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
    "{4683C8E3-934C-4BD2-8A85-0A489A053372}" = Microsoft SQL Server 2008 R2 Books Online
    "{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A5FF1B1-7C05-19F4-17D7-B1809CDFA0CD}" = CCC Help Polish
    "{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
    "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
    "{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
    "{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
    "{4D6873BC-73C0-487D-A4B4-BA78D9EF465C}" = Catalyst Control Center - Branding
    "{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
    "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
    "{537DB9D6-1AB1-4CE9-8DE7-312256B49A98}" = PS_AIO_06_C4700_SW_Min
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
    "{58F58158-8DFE-31DA-AC1F-7E5D89A0F74F}" = Google Talk Plugin
    "{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
    "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
    "{64CDE8F2-3791-46F5-BAD2-72FFF5252FAB}" = Microsoft SQL Server Compact 3.5 SP1 Query Tools English
    "{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
    "{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
    "{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
    "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
    "{708FC368-197E-1AAB-8018-49AC1BA28B34}" = CCC Help Hungarian
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{764182F2-8B5E-5B6B-A439-02D06550F663}" = CCC Help Dutch
    "{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
    "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
    "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
    "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
    "{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
    "{87C24822-389C-45AA-9E75-0757B8F1A892}" = XLink Kai
    "{87CE7117-D736-8108-AD6A-4F0D117E94B6}" = CCC Help Spanish
    "{888934B4-09FC-4CB3-2AA4-87C2F5030C79}" = CCC Help Finnish
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8C617D96-CDAA-9025-AAEA-659B477B4B7C}" = CCC Help Czech
    "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
    "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
    "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
    "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
    "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
    "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
    "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
    "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
    "{92E5F54C-888C-51E5-A388-7B360B174311}" = CCC Help Russian
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{952D22C8-CA9F-65ED-B7C3-7CEDC08121E7}" = Catalyst Control Center Core Implementation
    "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
    "{A018A4CE-0D6F-BEB5-EDC2-D9386B2BF1B3}" = Catalyst Control Center Graphics Light
    "{A04C1E78-8EC0-7A07-FDA7-843920FE9D36}" = CCC Help Japanese
    "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A7A39878-C21D-D6D5-0F34-A01FF3E79B7F}" = CCC Help Korean
    "{A7CD6CCE-C2BC-3B61-F0CC-A842F02FB6C0}" = CCC Help Italian
    "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.4.0 MUI
    "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
    "{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
    "{B3576D1B-5763-4E8C-43CE-1B6908D0B22D}" = CCC Help German
    "{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
    "{B672D77A-8BA3-24EF-3421-8FB8E35E2A8D}" = Catalyst Control Center InstallProxy
    "{B951569A-7EC8-CF90-74AF-53610BC15097}" = CCC Help Chinese Standard
    "{BA4DA261-CB60-4690-B202-44998DFC6986}" = Microsoft SQL Server 2008 Setup Support Files
    "{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
    "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
    "{c36eebac-d47d-4758-bf59-6b6406920414}" = Nero 9 Essentials
    "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
    "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
    "{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
    "{C68F1F36-9B04-2CC8-15A4-DC9606E760EB}" = CCC Help Danish
    "{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
    "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
    "{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
    "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
    "{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
    "{DB3A97C0-EEC1-43FE-AB56-E2EA972CF111}" = 1600
    "{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
    "{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
    "{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
    "{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
    "{E647D018-2209-C4B6-493F-ECB57E6620D1}" = CCC Help French
    "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
    "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
    "{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
    "{EA79DC46-98B0-4A26-A76F-448A032E5E4D}" = 1600Trb
    "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
    "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
    "{EF2E00AB-F454-C823-0408-8F2098F2CDCB}" = CCC Help Portuguese
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
    "{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
    "{F9EB0701-776E-BF9F-5B57-760A16422520}" = CCC Help Thai
    "{FA9C3624-C693-4423-8A8B-2BC2B9F607AB}" = Microsoft SQL Server 2008 Management Studio
    "{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FEA5A8ED-93A1-44EE-9A7D-43103DB3F78D}" = 1600_Help
    "7-Zip" = 7-Zip 4.65
    "Acer Assist" = Acer Assist
    "Acer Registration" = Acer Registration
    "Acer Screensaver" = Acer ScreenSaver
    "Acer Welcome Center" = Welcome Center
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Advanced SystemCare 3_is1" = Advanced SystemCare 3
    "AT&T Yahoo! Browser Configuration" = AT&T Yahoo! Browser Configuration
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "CCleaner" = CCleaner
    "Hotkey Utility" = Hotkey Utility
    "Identity Card" = Identity Card
    "InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
    "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
    "InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}" = Acer Backup Manager
    "IObitBartoolbar Uninstall" = IObit Toolbar
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Marvell Miniport Driver" = Marvell Miniport Driver
    "Microsoft SQL Server 10" = Microsoft SQL Server 2008
    "Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
    "Mozilla Firefox (3.6.7)" = Mozilla Firefox (3.6.7)
    "Office14.SingleImage" = Microsoft Office Home and Student 2010
    "Password Safe" = Password Safe
    "Secunia PSI" = Secunia PSI
    "WildTangent acer Master Uninstall" = Acer Games
    "WinLiveSuite" = Windows Live Essentials
    "Yahoo! Companion" = att.net Toolbar
    "Yahoo! Software Update" = Yahoo! Software Update
    "YInstHelper" = Yahoo! Install Manager

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 10/31/2010 12:01:21 AM | Computer Name = ACER | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
    Dependent
    Assembly msadctls,processorArchitecture="x86",type="win32", version="1.0.1801.0"
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 10/31/2010 12:01:21 AM | Computer Name = ACER | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
    Dependent
    Assembly msadctls,processorArchitecture="x86",type="win32", version="1.0.1801.0"
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 10/31/2010 12:06:57 AM | Computer Name = ACER | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file. .

    Error - 10/31/2010 207 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 10/31/2010 207 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 1014

    Error - 10/31/2010 207 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 1014

    Error - 10/31/2010 208 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 10/31/2010 208 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 2012

    Error - 10/31/2010 208 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 2012

    Error - 10/31/2010 209 AM | Computer Name = ACER | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    [ System Events ]
    Error - 11/1/2010 12:58:04 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 1:03:14 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 1:08:24 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 5:07:17 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 5:12:27 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 5:17:37 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 5:22:47 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 5:27:57 PM | Computer Name = ACER | Source = BROWSER | ID = 8020
    Description =

    Error - 11/1/2010 5:27:57 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.

    Error - 11/1/2010 5:33:07 PM | Computer Name = ACER | Source = NetBT | ID = 4321
    Description = The name "CLARIDGE :1d" could not be registered on the interface
    with IP address 192.168.1.104. The computer with the IP address 192.168.1.64 did
    not allow the name to be claimed by this computer.


    < End of report >

  7. #7
    broni is offline Senior Member
    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyServer" = http=127.0.0.1:50370
      FF - prefs.js..network.proxy.http_port: 50370
      O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
      O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
      O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O18:64bit: - Protocol\Handler\AutorunsDisabled - No CLSID value found
      O18:64bit: - Protocol\Handler\AutorunsDisabled\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\AutorunsDisabled\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
      O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
      O18 - Protocol\Handler\AutorunsDisabled\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
      O18 - Protocol\Handler\AutorunsDisabled\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Filter\AutorunsDisabled - No CLSID value found
      O18 - Protocol\Filter\AutorunsDisabled - No CLSID value found
      O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O33 - MountPoints2\{4f433e69-9f98-11df-8ead-90fba64bf4ac}\Shell - "" = AutoRun
      O33 - MountPoints2\{4f433e69-9f98-11df-8ead-90fba64bf4ac}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -- File not found
      [2010/10/20 22:03:53 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Seosav
      [2010/10/20 22:03:53 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\Fuyw
      [2010/10/20 22:02:44 | 000,000,000 | ---D | C] -- C:\Users\Karin\AppData\Roaming\A71923186A305203F8C41CE4525B18ED
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.


    Let me know, how the redirection is.

  8. #8
    Hijacked is offline Junior Member
    I haven't finished the latest step but there seems to be no redirection anymore. I did what you said but my computer went into sleep mode in the middle of the fix and now OTL won't respond. What should I do?

  9. #9
    broni is offline Senior Member
    Re-run my script.

    Good news though

  10. #10
    Hijacked is offline Junior Member
    Save 20% on AVG Internet Security 2012 Suite!
    This is strange. Every time I start the fix script, OTL hangs. Even in Safe Mode.

+ Reply to Thread
Page 1 of 3 1 2 3 LastLast